Back to blog

Face the Music: Madison Square Garden Just Showed Everyone the Bill for Watching the Door

TE
The eventcloud Team 27 July 2026 · 6 min read
Face the Music: Madison Square Garden Just Showed Everyone the Bill for Watching the Door

Every event organiser has a moment, usually around 08:15 on day one, when a queue forms at the door and somebody decides how fast to get people through it. What nobody thinks about in that moment is that the door is a data collection point, and whatever you capture there is yours to protect for years afterwards. Madison Square Garden just spent three years demonstrating what happens when that goes sideways, and last week the saga ended with a fine roughly the size of a mid-tier conference coffee budget.

The New York State Liquor Authority has dropped its long running case against MSG over venue access, settling instead for a $30,000 penalty. That is $10,000 each from Madison Square Garden, Radio City Music Hall and the Beacon Theatre, and it is not for the facial recognition at all. It is for an unauthorised corporate change charge. Paperwork, in other words.

What actually happened, and what pointedly did not

The fight started in 2022, when MSG used facial recognition to identify and turn away lawyers at firms litigating against the company. The Liquor Authority took the view that licence holders must allow public access to their premises, and that a face scanning blocklist aimed at your legal opponents is not compatible with that. Three years of appeals, threats to the licence and some memorably spicy public statements followed.

According to TicketNews, the access charges were dropped as part of an agreement with the three venues, each paying the maximum allowable $10,000. Liquor Authority spokesperson Jade Kraft added that the resolution should not be read as an endorsement of any exclusion policy, facial recognition practice or admission practice, and that the agency is separately reviewing whether its rules ought to address access practices at licensed premises. MSG told reporters the penalties concerned an administrative error, not its biometric practices. Gothamist led with the paperwork angle, for good reason.

So the regulator did not bless facial recognition. It ran out of the particular rule it was using to challenge it, and pocketed a fee for something else entirely. Nobody won on the merits, because nobody argued the merits.

The reason this is worth your attention: the data got out

Here is the part that turns a New York licensing spat into a lesson for anyone running a registration desk. In June, the hacking group ShinyHunters published a large archive of MSG data after the company declined to pay a ransom. Reporting from Billboard and TNW describes a trove said to include facial recognition entry records, internal threat assessments and background check material, with the attackers claiming tens of millions of records. Those figures come from hackers and plaintiffs rather than MSG or a court, so treat them as claims. A proposed class action was filed in the Southern District of New York on 16 June by a concertgoer who says his face was scanned on entry and his biometric data ended up in the dump. MSG is separately suing WIRED over a report describing an internal database that sorted prominent guests by perceived risk.

Build a rich identity system at the door, and every dispute you ever have arrives with an attachment.

The cheapest biometric database to secure is the one you never built in the first place.

What this means for event organisers: QR code check-in is the boring, correct answer

Business events are not arenas. You are getting 600 delegates into a keynote before the CEO starts talking, and you want to know who is in the room for compliance, catering and lead capture. That is a matching problem, not a surveillance problem.

QR code check-in solves it without creating a single new category of sensitive data. The delegate already gave you their details at registration. The QR code on their badge or phone is a token pointing back at that record. Scanning it proves the ticket is valid and marks the person as arrived. No biometric template is generated, nothing irreversible is stored, and if your systems are breached the exposure is the registration data you were always holding rather than an unchangeable physical identifier. People can get a new email address. They cannot get a new face.

Check-in methodNew data created at the doorWhat a breach exposesConsent and compliance load
QR code scanA timestamp against an existing recordRegistration data you already heldStandard privacy notice
Name lookup at a kioskA timestamp, sometimes a badge reprint logRegistration data you already heldStandard privacy notice
Facial recognition entryA biometric template plus an entry image logPermanent identifiers that cannot be reissuedExplicit consent, impact assessment, retention policy, vendor audit

Under UK and EU data protection law, biometric data processed to uniquely identify someone sits in the special category bracket, so you need a specific lawful condition on top of your normal basis, plus a documented impact assessment. In Illinois, biometric privacy law lets individuals sue directly, which is why so many of these cases begin there. None of that is a reason to fear technology. It is a reason to ask whether thirty seconds saved at the door is worth a permanent compliance obligation.

The same logic applies one step earlier. The biggest privacy risk at most business events is not the scanner, it is the registration form asking for dietary requirements, accessibility needs, passport numbers for visa letters and a free text box delegates fill with things you never wanted to know. Collect what the event needs, set a retention period, delete on schedule.

The context the headlines skipped: the door was always political

Worth remembering how MSG's system actually got used. The face matching was not deployed to stop a security threat. It was deployed to enforce a commercial grudge against opposing counsel. That is the general rule dressed up as a specific scandal: once identity infrastructure exists at the entrance, somebody will eventually ask it to do a job nobody mentioned in the procurement meeting. Legal wants a list. Someone senior wants a person kept out for reasons that have nothing to do with safety.

The regulatory picture will not rescue you either, because there is no single picture. Portland restricted private sector facial recognition in places of public accommodation. Illinois runs on private lawsuits, Texas on its attorney general, Europe on AI rules layered over existing data protection law. If your conference moves city each year, your door policy has to survive all of them, which argues for a system that does the same simple thing everywhere.

Watch this space

Three things to watch. First, the Liquor Authority says it is reviewing whether to write rules on access practices at licensed premises. If New York writes them, venues will push the compliance obligations downstream into their contracts with hirers, which means you. Second, the breach litigation will put a number on what biometric entry data costs when it leaks, and that number will reach insurance quotes long before it reaches legislation. Third, expect vendors to start marketing biometric free check-in as a feature rather than an absence, the way flat fee pricing became a selling point once everyone tired of percentage stacking.

We have never found a good reason to scan a delegate's face to work out whether they paid for a ticket. A QR code, a scanner and a clean registration record get people into the room in about two seconds, and the only thing you then have to explain to your data protection officer is how long you keep the attendance list. That trade seems fine to us. Ask MSG how the other one is going.

Share this article Twitter LinkedIn
Stop paying to succeed

Run Your Next Event on Flat Pricing

Unlimited tickets, registrations and events. One price, no matter how big you grow.

Get in touch! Let's have a chat!