Back to blog

ID, Robot: Ticketmaster Now Wants Your Face Before It Sells You a Ticket

TE
The eventcloud Team 3 August 2026 · 6 min read
ID, Robot: Ticketmaster Now Wants Your Face Before It Sells You a Ticket

Somewhere in the last few weeks, a large number of people sat down to buy a concert ticket and were asked, instead, to take a photograph of their own face. Then, in a fair few cases, to hold up a passport next to it. Ticketmaster has rolled out identity verification through a third party called Persona, and the internet has reacted in the way the internet reacts to being asked for a passport before it is allowed to spend money.

It would be easy to file this under "big ticketing company does big ticketing company thing" and move on. Do not. If you run conferences, trade shows or corporate events, this story is not really about Ticketmaster. It is about the argument between the data you would love to collect at registration and the data your attendees will actually hand over. Ticketmaster ran that experiment in public, at enormous scale, and published the results in the form of several thousand furious posts.

What Ticketmaster Actually Started Asking For

According to Ticketmaster's own help centre, certain accounts are now prompted to complete what the company calls a security check. In most cases that means a live selfie. In some cases it also means uploading an official photo ID, such as a driving licence, state ID or passport, which Persona then compares against the selfie while checking that the document itself is genuine. The stated purpose is to give what Ticketmaster describes as real fans, rather than bots, a fair shot at tickets.

The checks are not limited to one moment in the funnel. They can fire when you sign in, when you register for an artist presale, when you submit a ticket request, when Ticketmaster's systems flag suspicious behaviour and email you a link, and even when you ask to remove your phone number from your account. Fans under 18 need a parent or guardian to complete the check for them.

Then there is the retention question, which is where the mood turned. Persona holds biometric data for no more than 60 days on successful verifications, but for up to three years on unsuccessful ones, for fraud prevention purposes. So the people most likely to have their face stored longest are the ones the system could not confirm. As TicketNews reported, that asymmetry was one of the loudest complaints in a backlash that ran from mid June through the end of July, alongside a general reluctance to hand biometrics to a company whose own help centre still carries a page about a data security incident.

To be fair to Persona, the credentials are real: SOC 2 Type 2, ISO 27001, NIST 800-63 IAL2, and compliance with GDPR and CCPA. This is not a dodgy operation, it is a well certified one, which is rather the point. The objection was never that the vendor was bad. It was that the ask was big.

What This Means for Your Custom Registration Forms

Every field on a registration form is a trade. You get data, and you pay for it in completed registrations. Most organisers know this and then ignore it, because the sales team wants job title, the sponsor wants company size, marketing wants how did you hear about us, and finance wants a purchase order reference. Nobody in that meeting is representing the person who just wanted to attend your event.

What Ticketmaster has usefully demonstrated is that the cost curve is not linear. Asking someone to photograph their passport is not slightly more expensive than asking for a phone number. It is a different category of ask entirely, and it converts accordingly.

What you ask forWhat it costs the attendeeWhat it costs you if it leaks
Name and emailSecondsLow, and expected
Job title and companySeconds, mild irritationLow
Phone numberReal hesitation, spam anxietyModerate
Dietary and accessibility needsWillingly given if the reason is obviousHigh, this is health adjacent data
Government ID or biometricsAbandonment for a meaningful shareSevere, and potentially actionable

The practical lesson is not "never verify identity". Plenty of events genuinely need it: closed government sessions, regulated industry conferences, anything with a security clearance requirement, anything where a badge grants access to something valuable. The lesson is that verification should be scoped to the events and the ticket types that need it, rather than applied as a blanket tax on everyone who wants to attend. If your custom registration forms ask a delegate for a passport scan to attend a free breakfast briefing, you have not built a security control, you have built a very effective way to reduce attendance.

A field you cannot delete is a field you have to defend. Collect accordingly.

A Short History of Tickets That Know Who You Are

None of this is new, it has just got more literal. The paper ticket was a bearer instrument: whoever held it got in, and nobody asked whose name was on it, because there was no name on it. Then came will call, which was identity verification performed by a bored student with a clipboard.

Barcodes made tickets trackable but not personal. Named tickets made them personal but not verified. Mobile and app-only ticketing, which clubs such as Bayern Munich have now adopted wholesale, made them personal, verified and rotating. Each step tightened the link between a seat and a human being.

Biometric verification at the point of purchase is the next notch, and the first one where the industry has hit the wall of public tolerance. That wall is useful information. It tells you where attendees think the line sits, and it sits somewhere after "prove you own this account" and somewhere before "give a third party your face for three years".

Watch This Space: The Law Is Catching Up With Faces

Here is the part that should interest anyone running events on both sides of the Atlantic. Biometric data is not just sensitive in the vibes sense, it is sensitive in the statutory sense. Under UK and EU GDPR, biometric data processed to uniquely identify someone is special category data, which means you need a specific lawful basis on top of your normal one, and consent obtained under duress at a checkout page is not a strong candidate. In the United States, Illinois' Biometric Information Privacy Act lets individuals sue directly rather than waiting for a regulator, and several other states have been steadily building comparable regimes.

So the question for organisers over the next 18 months is not "can we verify identity". The technology is commodity now, and it works. The question is whether you can say, in one sentence, why this event needed this data, and whether that sentence would survive contact with a regulator. If it takes you a paragraph, you probably cannot.

Our own view at eventcloud is unglamorous: most B2B events do not need biometrics, they need a clean registration flow, a barcode that cannot be duplicated, and a check-in process fast enough that nobody at the door has time to get suspicious. Identity assurance at conferences is usually a door problem dressed up as a data problem. Ticketmaster is solving a much harder version of it, against industrial scalpers, and it is still getting shouted at. Anyone tempted to copy the approach for a 400 person summit should read the replies first.

Share this article Twitter LinkedIn
Stop paying to succeed

Run Your Next Event on Flat Pricing

Unlimited tickets, registrations and events. One price, no matter how big you grow.

Get in touch! Let's have a chat!