Compliance guide · 14 min read

DPDP Act compliance for
Indian event organisers - the honest version.

Consent language you can copy, retention rules that actually work, breach playbook, and what the Data Protection Board can fine you for. Written for organisers, not lawyers.

Consent · Registration
4 opt-ins
DPDP-ready notice
Consent notice · DPDP Act 2023
We collect your name, email, phone and company for event registration and entry. Data stored in India, retained 24 months, deleted on request.
☑ Registration confirmation Required
☐ Share contact with sponsors
☐ Photos on social media
☐ Marketing for future events
Continue → I agree

The Act, why events care, what changed from IT Rules.

The Digital Personal Data Protection Act 2023 replaces the earlier IT Rules 2011 (SPDI Rules). Draft implementation rules were released in January 2025. The Act is expected to come into force in phases through late 2026. If you collect personal data of Indians - name, email, phone, company, photo - you're a "data fiduciary" and the Act applies.

Six shifts that matter for events:

  1. Consent must be explicit and specific. One blanket consent covering registration, marketing, and sponsor sharing is not enough. Each purpose needs its own opt-in.
  2. Notice is mandatory before collection. Plain-language, itemised, in English and any regional language you offer the form in.
  3. Purpose limitation. Data collected for check-in cannot be silently used for next year's marketing without a new consent.
  4. Retention limits. Data must be deleted once the purpose is fulfilled. Draft rules propose 3 years as an outer default for inactive contacts.
  5. Data principal rights. Attendees can ask for access, correction, erasure. You must respond within a reasonable time (draft rules say 30 days).
  6. Breach notification. Report to the Data Protection Board and to affected principals promptly - draft rules mention 72 hours.

Show this above your registration form.

How we handle your data

[Organiser Name], a data fiduciary under the DPDP Act 2023, collects the following personal data from you: name, email, phone number, company, designation, dietary preference (if any).

Purpose: to register you for [Event Name], issue your entry pass, contact you about event logistics, and (with your separate consent) send you information about future events.

Sharing: data is shared with our ticketing platform (SignupDesk), payment gateway (Razorpay), WhatsApp API provider (Meta) for delivery of your entry pass, and the event venue (for entry list). We do not sell your data.

Retention: registration and check-in data is kept for 3 years for tax and audit purposes. Marketing consent-based data is kept until you unsubscribe.

Your rights: you can access, correct or delete your data by writing to [[email protected]]. Withdrawal of consent is possible any time; withdrawal affects future processing only.

Grievance officer: [Name], [phone], [email]. If unresolved, escalate to the Data Protection Board of India.

Under the form, use separate checkboxes:

  • ☑ I agree to registration and event communication. (pre-required, disabled unchecking)
  • ☐ Share my details with event sponsors for their outreach.
  • ☐ Publish photos I appear in on the event's social media and website.
  • ☐ Contact me about future events and offers from [Organiser Name].

Photos, dietary preferences, medical needs.

Some data collected at events is more sensitive than name-and-email. Handle it with extra care.

Photos and videos. Every event does group photos, session recordings, keynote reels. Under DPDP, images that identify a person are personal data. Options:

  • Include a photo consent checkbox at registration.
  • Put visible signage at the venue entrance: "Photography and videography in progress. Speak to staff if you'd prefer not to be photographed."
  • Have a "no photo" wristband available at registration desk. Photographer trained to skip them.

Dietary and medical preferences. Vegetarian/non-veg is fine to collect. Allergen data (nut allergy, gluten-free) is health-adjacent - keep it need-to-know, share only with the catering team, delete after the event.

Children under 18. Any minor's data (student attendees, kids at family events) needs verifiable parental consent. Draft rules propose govt-issued ID or DigiLocker verification of the parent. This is the highest-risk area - if in doubt, exclude under-18s from data collection entirely or use parent-of-record model.

Where can your attendee data live?

The DPDP Act does not impose blanket data localisation. Cross-border transfer is allowed except to countries on a specific negative list that the government will publish. As of Aug 2026, no such list has been notified.

Practical implication: your ticketing SaaS can host in India, Singapore, Ireland or the US - all legal today. But two watch-outs:

  • Sector-specific rules still apply. Banking (RBI), health (NDHM) and telecom already have their own localisation. If your event captures financial or health data beyond basic dietary, check.
  • Some corporates (BFSI, Defence, PSUs) mandate India-only hosting for any personal data collected during their events, regardless of DPDP. Confirm before onboarding.

SignupDesk hosts on OVH's India-region infra with encrypted daily backups to Frankfurt for disaster recovery. Full data map available on request.

The 72-hour response.

If your attendee database is exposed (leaked CSV, stolen laptop, phishing that emptied Mailchimp), here's the playbook draft rules broadly follow:

  1. Hour 0-6: contain. Rotate credentials, revoke sessions, snapshot logs.
  2. Hour 6-24: assess scope. How many records, what fields, when did it start?
  3. Hour 24-48: notify affected data principals via email and SMS. Plain-language description of what happened, what was exposed, what they should do (reset passwords, watch for phishing).
  4. Hour 48-72: file report with the Data Protection Board of India. Include incident description, affected count, containment steps, remediation timeline.
  5. Post-72h: follow-up report with root cause analysis. Update your security posture.

Failure to notify within the window is a separate offence from the breach itself. Both can be penalised.

What the Board can actually fine you.

OffenceMaximum penalty
Failure to notify a breachUp to ₹200 crore
Failure to protect personal data (major breach)Up to ₹250 crore
Processing children's data without valid consentUp to ₹200 crore
Violation of other obligationsUp to ₹50 crore
Minor / procedural lapse (first offence)₹10,000

Penalties are ceilings, not fixed amounts. The Board considers scale of the breach, nature of the data, willfulness, and cooperation during investigation.

Related SignupDesk guides.

🎟
Gateway, GST, ticket types, refund basics.
📋
Legal, ready-to-use refund language.
💬
DPDP-safe consent language for WhatsApp opt-in.

Questions organisers ask us

Do I need a Data Protection Officer?
Only if you're classified as a Significant Data Fiduciary (SDF). Most event organisers won't be. Large aggregators processing millions of records will. Draft rules will define the criteria (volume, sensitivity, risk score).
Can I email past attendees about next year's event?
Only if they consented to marketing communication when registering. If your old registration form didn't ask, you need a fresh consent - a re-permission email works if the initial context was clear.
What if a sponsor asks for the attendee list?
You can share only if attendees consented to sponsor sharing. Better: share a summary (count, demographics, interest tags) instead of the raw list. Best: give sponsors an in-event lead capture QR so attendees actively opt in.
Are B2B business cards personal data?
Yes - name, phone, email on a card are personal data. Even the LinkedIn "professional" defence doesn't override DPDP. The good news: business context implies purpose limitation is easier to justify.
Do we need to appoint a grievance officer?
Yes. Name and contact must be published on your website and event notices. It can be an existing team member; no separate hire required for most event organisers.
Compliance built into the workflow.
SignupDesk registration forms ship with DPDP-ready consent language, per-purpose opt-ins, retention timers, and one-click erasure on data principal request.