Festival access control combines physical planning, validation technology and a trained team. Futura Tickets recommends 1 validation point for every 500-700 attendees expected per hour at the main entrance. A well-designed system safeguards the security of the venue and improves the attendee experience from the moment they arrive. QR codes and NFC wristbands are the most common validation technologies, with integrated cashless payments. Experienced organisers combine both: QR codes at the main entrance and NFC in internal zones. Digital systems provide real-time data on capacity, entry pace and congested zones. This guide explains how to calculate checkpoints, choose the right technology and coordinate the human team. It also answers the most common questions about NFC wristbands, capacity control and queues at the gates.
And before the operational side, the rule: maximum capacity isn't yours to decide, door staff qualifications vary by region, and biometrics have their own regime. Every legal requirement that follows is backed by its specific article; everything else is an operational recommendation, and is presented as such.
What does Spanish law require at a festival's gate?
The starting point isn't your plan, it's your licence. Royal Decree 2816/1982 (Real Decreto 2816/1982), the General Regulation on Public Entertainment Policing, remains in force on a supplementary basis and leaves it to the licence-granting resolution to determine «el aforo máximo permitido» ("the maximum permitted capacity"). Its article 52 adds that extracts of that licence, stamped by the authority, «deberán ser expuestos al público» ("must be displayed to the public"). Its article 73 allows a show already underway to be suspended when safety conditions are no longer met.
Exceeding that capacity comes with a price. In the Community of Madrid, article 38.11 of Ley 17/1997 classifies as a serious offence «la superación del aforo máximo permitido cuando no comporte un grave riesgo para la seguridad de personas o bienes» ("exceeding the maximum permitted capacity when it does not pose a serious risk to the safety of people or property"), while article 37.11 upgrades it to very serious when it does pose that risk. The same law requires, in article 24.2, that «las condiciones para el ejercicio del derecho de admisión deberán constar en lugar visible a la entrada de los locales, establecimientos y recintos» ("the conditions for exercising the right of admission must be displayed in a visible place at the entrance to premises, establishments and venues"): the sign isn't decoration, it's a requirement.
What changes depending on where you're setting up
| Access requirement | Community of Madrid | Catalonia |
|---|---|---|
| Access control staff | Community-accredited certificate; lacking it is a very serious offence (art. 37.15, Ley 17/1997) | Professional licence and badge, with selection tests and approved training centres |
| Right of admission | Conditions displayed visibly at the entrance (art. 24.2) | No verified data for this review |
| Safety document | Self-protection plan under RD 393/2007 | Safety report (memòria de seguretat) above 150 people of authorised capacity for music activities |
| Medical service | Nursing station if capacity exceeds 1,000, first-aid kit if it exceeds 100, under the supplementary national RD 2816/1982 (art. 11) | Nursing station from 1,000 people upwards; first-aid kit below that |
| Exceeding capacity | Serious offence (art. 38.11) or very serious if it poses a risk (art. 37.11) | No verified data for this review |
The two columns aren't fully comparable in detail because the two sets of rules aren't structured in the same way, and where we couldn't confirm a figure against an official source, we say so rather than fill in a guess. The Catalan requirements come from the official requisits i obligacions dels espectacles públics sheet from Canal Empresa, which refers to Decret 112/2010.
The self-protection plan and its misleading threshold
Royal Decree 393/2007 (Real Decreto 393/2007), which approves the Basic Self-Protection Standard, includes public entertainment events in its annex I with three thresholds: 2,000 people in closed buildings, 2,500 in demountable or seasonal enclosed facilities, and 20,000 outdoors. That last figure confuses many promoters, because its article 3.1 clarifies that the obligations apply «como norma mínima o supletoria» ("as a minimum or supplementary standard"): it's a national floor, and regions and municipalities lower it.
Article 4.1 leaves no room for ambiguity about responsibility: drawing up, implementing and maintaining the plan is the event organiser's duty, drafted by a qualified technician. And chapter 6.2 of annex II requires the person who will raise the alarm, and the emergency coordination centre, to be identified by name. A plan with a generic job title in that box hasn't been properly implemented. The full operational plan for the day, beyond the gate, is covered in our guide to event security.
How do you plan attendee flow?
Before thinking about technology, it's essential to design the physical flow of people correctly. This means sizing checkpoints appropriately for expected capacity and peak times, separating entry and exit flows, and creating dedicated lanes for priority groups.
- Calculate 1 validation point for every 500-700 attendees expected per hour
- Plan shaded waiting areas with clear signage
- Design alternative routes for peak arrival times
- Consider separate entrances by ticket type (general admission, VIP, backstage)
The maths is simple, and it's worth writing it down. A festival with 12,000 attendees that opens its gates three hours before the headliner needs to absorb 4,000 people an hour if arrivals are evenly spread, which, using the reference above, works out to between 6 and 8 validation points. If you plan on the assumption that half the crowd arrives in the final hour, that peak is 6,000 people in sixty minutes, pushing the count up to 9-12 points. Sizing for the average rather than the peak is the most expensive mistake at the gate.
The queue isn't only your problem, either. The official Canal Empresa sheet states the Catalan rule clearly: «El control d'entrada, si n'hi ha, s'ha de fer sense ocupar la via pública, de manera que les cues que pugui provocar no produeixin molèsties» ("entry control, where it exists, must be carried out without occupying the public road, so that any queues it causes don't create a nuisance"). In other words, the waiting area has to be resolved within the perimeter or with municipal authorisation, not by letting the line spill onto the pavement. Anyone who's had a neighbour's complaint at eleven at night knows that sentence decides licences.
Which validation technology should you choose?
Choosing the right validation system is crucial. QR codes scanned with smartphones are the most flexible and cost-effective option, making it easy to scale the number of checkpoints. NFC wristbands offer greater speed and support cashless payments, but require a higher upfront investment.
- QR on smartphone: validation in 1-2 seconds, low cost, easy to scale
- NFC wristbands: validation in under 1 second, cashless integration
- Combination: QR for the main entrance, NFC wristbands for internal zones
| Technology | Validation speed | Upfront investment | What to watch out for |
|---|---|---|---|
| QR on the attendee's phone | 1-2 seconds | Low | Dirty screens, low brightness and forwarded screenshots |
| NFC wristband or card | Under 1 second | High | Personalisation logistics and lost wristbands |
| Biometrics (fingerprint or face) | No measured figure of our own | High | Special category of data and mandatory prior impact assessment |
The decision isn't only about speed. QR codes are validated against a system that already holds the order, so a duplicate attempt is caught on the second scan; it's the same logic behind detecting ticket fraud. NFC wristbands win in internal zones and at the bar, but add a logistical operation — personalising, distributing, replenishing — that needs its own dedicated staff.
Can you use facial recognition or fingerprints at the gate?
The short answer is that biometrics isn't just another access technology. On 23 November 2023, Spain's Data Protection Agency (AEPD) published a guide on presence-control processing using biometric systems and, in its press release, summarised the criterion: «La utilización de datos biométricos supone un tratamiento de categorías especiales de datos de alto riesgo» ("the use of biometric data constitutes processing of a special, high-risk category of data"). It also adds a prior obligation: «De forma previa al inicio del tratamiento, será obligatoria la realización de una Evaluación de Impacto para la Protección de Datos» ("before processing begins, carrying out a Data Protection Impact Assessment will be mandatory").
For accredited staff — production, suppliers, security — the Agency's criterion is direct: «El consentimiento no puede levantar la prohibición o ser una base para determinar la licitud de este, al existir un desequilibrio» ("consent cannot lift the prohibition or serve as a basis for determining its lawfulness, given the existing imbalance"). With attendees, the relationship isn't an employment one and that imbalance isn't presumed in the same way, but classification as a special category and the impact assessment don't depend on whether there's an employment contract or not: that's our reading of the criterion, not a statement by the Agency about festivals specifically.
In practice, the sensible route for a festival is the QR code or wristband tied to an order, not the face. If there's still a genuine use case — access to a strictly controlled backstage area — the correct order is impact assessment, documented legal basis and data minimisation, before installing anything. The organiser's other data obligations are covered in our GDPR guide for events.
How do you manage zones and capacity?
At festivals with multiple stages or distinct zones, capacity control by area is essential for safety and regulatory compliance. Modern systems allow you to monitor each zone's occupancy in real time and make immediate decisions if limits are reached.
- Set capacity limits per zone before the event
- Implement two-way validation (entry and exit) in critical zones
- Set up automatic alerts at 80% and 95% of capacity
- Prepare action protocols for temporary zone closures
There's a distinction worth having clear before you sell the first ticket: legal capacity is set by the licence, and operational capacity is set by you, always below it. The margin absorbs guest passes, staff, suppliers and counting errors. And it isn't a cosmetic margin: in Madrid, exceeding the authorised figure is a serious or very serious offence depending on the risk it creates, so pushing right up to the limit isn't an inconvenience, it's a disciplinary file.
The medical provision is sized against that same figure. Article 11 of Royal Decree 2816/1982 requires a nursing station or first-aid kit «siempre que el aforo del local exceda de 1.000 o de 100 espectadores o asistentes» ("whenever the venue's capacity exceeds 1,000 or 100 spectators or attendees"), and allows the nursing station to be replaced with a first-aid kit plus ambulances. In Catalonia, the Canal Empresa sheet sets the same threshold: a nursing station from 1,000 people upwards, a first-aid kit below that. If your access control doesn't know how many people are inside each zone, that provision is being sized blind.
What role does the human team play?
Technology is only part of the equation. The access team needs to be well-trained and coordinated to guarantee a smooth operation.
- Train staff on the tools days before the event
- Appoint zone coordinators with access to the general dashboard
- Establish clear communication channels between checkpoints
- Prepare procedures for special cases: minors, disability, incidents
Who can be on that gate isn't decided by a collective agreement, it's decided by two separate laws. Ley 5/2014 de Seguridad Privada (Private Security Act), in article 6.2.a), excludes from its scope «las de información o de control en los accesos a instalaciones» ("information or control functions at facility entrances"), which may be carried out by «porteros, conserjes y demás personal auxiliar análogo» ("doormen, concierges and other similar auxiliary staff"). In other words: scanning tickets isn't a function reserved for a security guard licensed by the Ministry of the Interior.
But that gap is filled by the regions, and there, qualification does apply. In Catalonia, the Departament d'Interior issues a professional licence for access control staff, with selection tests and approved training centres. In the Community of Madrid, article 37.15 of Ley 17/1997 classifies as a very serious offence «disponer de personal para el desarrollo de la actividad de control de acceso en espectáculos públicos, actividades recreativas, establecimientos, locales e instalaciones sin el certificado acreditativo de la Comunidad de Madrid» ("employing staff to carry out access-control activities at public entertainment events, recreational activities, establishments, premises and venues without the Community of Madrid's accredited certificate"). Hiring the cheapest staffing agency without checking those credentials is, literally, the offence itself.
What real-time data does access control provide?
One of the biggest advantages of digital access control systems is the information they provide. In real time, you can see how many people are inside, the pace of entry, which zones are most congested, and whether there are fraud attempts. This information supports informed on-the-spot decisions: opening more checkpoints, redirecting flows, or alerting security.
That data also has a later use that almost nobody exploits: the arrival curve. If 55% of your crowd entered in the final hour, next year you know how many lanes you need and at what time, and you can shift the main-stage schedule to flatten the peak. Entries minus exits is also the number any emergency service asks for when it arrives on site, and the one that underpins an orderly evacuation.
Event-week checklist
Five checks, all doable in an afternoon, and each one backed by a document.
Take the capacity figure from the licence resolution, not from memory. Write down the exact number, set your operational capacity below it, and display the licence extract to the public as required by article 52 of Royal Decree 2816/1982.
Request door staff certificates in writing. The professional licence in Catalonia or the accredited certificate in the Community of Madrid, with the name and number of every person who will be on a checkpoint. If the supplier is slow to send them, that's already a warning sign.
Recalculate lanes against the peak, not the average. Using the reference of one point per 500-700 attendees/hour, run the numbers for the worst-case arrival scenario, and add a spare lane with a charged reader.
Check who raises the alarm, by name. Open the self-protection plan to chapter 6.2 and verify there's a named individual and the contact details of the emergency coordination centre, not a generic job title.
Review what data you're actually capturing at the gate. If anyone has proposed fingerprint or facial recognition, it doesn't go in without a prior impact assessment. And check that the sign with the admission conditions is displayed visibly at the entrance.
Conclusion
Efficient access control combines physical planning, the right technology and a well-coordinated team. Investing in these three pillars translates into greater safety, a better experience for attendees, and valuable data for optimising future events. Every festival is different, but the underlying principles hold: anticipate, measure and adapt. For a fuller guide to running the day of the event, see our guide on managing event day.
And a caveat about the regulatory patchwork: the thresholds in this article are the national ones and those of two regions. Anyone touring across Spain isn't complying with one rule with variations, but with several rules that look quite different from each other, and the document that actually governs is almost always your specific licence resolution, not the general regulation.
Sources
- Royal Decree 2816/1982, General Regulation on Public Entertainment and Recreational Activities Policing: articles 11, 43, 52 and 73 (consolidated text, BOE)
- Royal Decree 393/2007, Basic Self-Protection Standard: annex I, articles 3.1 and 4.1, annex II chapter 6.2 (consolidated text, BOE)
- Ley 5/2014, on Private Security: article 6.2.a) (consolidated text, BOE)
- Ley 17/1997 on Public Entertainment and Recreational Activities of the Community of Madrid: articles 24.2, 37.11, 37.15 and 38.11 (consolidated text, BOE)
- Canal Empresa (Generalitat de Catalunya): requisits i obligacions dels espectacles públics i les activitats recreatives
- Decret 112/2010, Reglament d'espectacles públics i activitats recreatives de Catalunya (Portal Jurídic de la Generalitat)
- Departament d'Interior (Generalitat de Catalunya): carnet professional per a personal de control d'accés
- AEPD: guide on presence-control processing using biometric systems (PDF)
- AEPD: the Agency publishes a guide on the use of biometric data for presence and access control (press release, 23 November 2023)