Consent language you can copy, retention rules that actually work, breach playbook, and what the Data Protection Board can fine you for. Written for organisers, not lawyers.
The Digital Personal Data Protection Act 2023 replaces the earlier IT Rules 2011 (SPDI Rules). Draft implementation rules were released in January 2025. The Act is expected to come into force in phases through late 2026. If you collect personal data of Indians - name, email, phone, company, photo - you're a "data fiduciary" and the Act applies.
Six shifts that matter for events:
How we handle your data
[Organiser Name], a data fiduciary under the DPDP Act 2023, collects the following personal data from you: name, email, phone number, company, designation, dietary preference (if any).
Purpose: to register you for [Event Name], issue your entry pass, contact you about event logistics, and (with your separate consent) send you information about future events.
Sharing: data is shared with our ticketing platform (SignupDesk), payment gateway (Razorpay), WhatsApp API provider (Meta) for delivery of your entry pass, and the event venue (for entry list). We do not sell your data.
Retention: registration and check-in data is kept for 3 years for tax and audit purposes. Marketing consent-based data is kept until you unsubscribe.
Your rights: you can access, correct or delete your data by writing to [[email protected]]. Withdrawal of consent is possible any time; withdrawal affects future processing only.
Grievance officer: [Name], [phone], [email]. If unresolved, escalate to the Data Protection Board of India.
Under the form, use separate checkboxes:
Some data collected at events is more sensitive than name-and-email. Handle it with extra care.
Photos and videos. Every event does group photos, session recordings, keynote reels. Under DPDP, images that identify a person are personal data. Options:
Dietary and medical preferences. Vegetarian/non-veg is fine to collect. Allergen data (nut allergy, gluten-free) is health-adjacent - keep it need-to-know, share only with the catering team, delete after the event.
Children under 18. Any minor's data (student attendees, kids at family events) needs verifiable parental consent. Draft rules propose govt-issued ID or DigiLocker verification of the parent. This is the highest-risk area - if in doubt, exclude under-18s from data collection entirely or use parent-of-record model.
The DPDP Act does not impose blanket data localisation. Cross-border transfer is allowed except to countries on a specific negative list that the government will publish. As of Aug 2026, no such list has been notified.
Practical implication: your ticketing SaaS can host in India, Singapore, Ireland or the US - all legal today. But two watch-outs:
SignupDesk hosts on OVH's India-region infra with encrypted daily backups to Frankfurt for disaster recovery. Full data map available on request.
If your attendee database is exposed (leaked CSV, stolen laptop, phishing that emptied Mailchimp), here's the playbook draft rules broadly follow:
Failure to notify within the window is a separate offence from the breach itself. Both can be penalised.
| Offence | Maximum penalty |
|---|---|
| Failure to notify a breach | Up to ₹200 crore |
| Failure to protect personal data (major breach) | Up to ₹250 crore |
| Processing children's data without valid consent | Up to ₹200 crore |
| Violation of other obligations | Up to ₹50 crore |
| Minor / procedural lapse (first offence) | ₹10,000 |
Penalties are ceilings, not fixed amounts. The Board considers scale of the breach, nature of the data, willfulness, and cooperation during investigation.