Table of Contents
A DPDP-focused event registration form should collect only the personal data needed for a clear event-related purpose. Organizers should explain what data they collect, why they need it, how consent works, and how attendees can exercise their rights. Optional marketing or non-essential fields should be kept separate from essential registration information.
Event registration forms are often the first point where organizers collect attendee information. Names, email addresses, phone numbers, company details, preferences, and other information can then be used across ticketing, badges, check-in, and event communication.
The Digital Personal Data Protection Act, 2023 (DPDP Act) sets requirements around the processing of digital personal data, while the Digital Personal Data Protection Rules, 2025 provide further implementation details. The Act was enacted in 2023, and the Rules were notified in November 2025.
For event organisers, this means a registration form should be designed around purpose, necessity, notice, consent, security and responsible data handling.
In this article, we’ll explain what organizers should collect, what they should avoid, how to structure registration fields and what a DPDP-focused registration form should include.
Table of Contents
What Does DPDP Mean for an Event Registration Form?
The DPDP Act requires personal data to be processed for a lawful purpose and, where consent is the applicable basis, consent must be free, specific, informed, unconditional and unambiguous, with clear affirmative action. It should also be limited to personal data necessary for the specified purpose.
Under the DPDP Rules, the registration notice should clearly list the personal data being collected and the specific purpose for which it will be used.
For an event registration form, this means organizers should ask:
- Why is this information required?
- Is it necessary for the stated event-related purpose?
- Does the attendee understand why it is being collected?
- Is the field genuinely required, or can it be optional?
- Is separate consent needed for another purpose, such as marketing?
This approach helps organizers avoid collecting large amounts of information simply because the registration system allows it.
Which Attendee Details Should Organizers Collect?
The right fields depend on the event and the purpose of processing. There is no universal list of information that every event organiser must collect.
| Registration field | Typical purpose | Suggested approach |
| Full name | Registration, badge, and identification | Usually required |
| Email address | Confirmation and event communication | Usually required |
| Mobile number | Updates, OTP, or event communication | Based on need |
| Ticket/category | Access and ticket management | Required where applicable |
| Company name | Networking or business events | Optional where not essential |
| Job title | Networking or attendee profiling | Optional |
| Session preferences | Session planning and personalisation | Optional |
| Dietary requirements | Catering | Optional, if relevant |
| Accessibility requirements | Providing requested support | Optional, where relevant |
| Home address | Specific operational or legal purpose | Collect only when necessary |
| Government ID details | Identity or access requirements | Collect only when clearly required |
The principle is simple:
Collect data because there is a defined purpose, not because it might be useful later.
Which Fields Should Be Mandatory or Optional?

Mandatory fields should generally be limited to information required to complete registration, issue a ticket or badge, process payment, provide access, or deliver the service promised to the attendee.
For example, an organiser may need a name and email address to issue a registration confirmation. A company name may be useful for a B2B conference but unnecessary for a public cultural event.
Optional fields should be clearly marked as optional. This gives attendees a meaningful choice rather than making additional data collection appear necessary for registration.
What Should the Registration Notice Include?
The DPDP Act requires notice describing the personal data and the purpose of processing.
The DPDP 2025 Rules further specify that the notice should be standalone and understandable, with an itemised description of the personal data collected and the specific purpose or purposes for processing.
A registration form should therefore explain:
- What personal data is being collected
- Why is each category of data needed
- What event, service, or purpose does the processing support
- How attendees can withdraw consent, where applicable
- How can they raise a complaint
Important Note: The notice should be written in clear, plain language instead of hiding important information inside a lengthy privacy policy. The Rules specifically emphasise clear and plain language.
How Should Consent Be Structured?
Where consent is the applicable basis for processing, it should be presented clearly and separately from unrelated requests.
For example:
☐ I agree to the processing of my personal data for event registration and event-related communication as described in the notice.
The consent request should not quietly combine unrelated purposes. The DPDP Act requires consent to be specific and limited to personal data necessary for the specified purpose.
Note: Organizers should also provide a practical method for withdrawing consent where applicable. The DPDP rule 2025 requires the withdrawal process to be as easy as the process of giving consent.
Should Marketing Consent Be Separate From Event Registration?
Yes, where marketing requires consent.
Attending an event and agreeing to receive promotional communication are different purposes. Instead of making marketing consent a condition of registration, organizers should provide a separate choice where consent is required.
For example:
☐ I would like to receive updates and promotional communication about future events.
This makes the attendee’s choice clearer and avoids mixing event participation with unrelated communication preferences.
Which Data Should Organizers Avoid Collecting Without a Clear Purpose?
Organizers should review fields such as:
- Date of birth
- Residential address
- Government identification details
- Emergency contact information
- Detailed professional information
- Additional demographic information
- Information unrelated to event delivery
These fields may be appropriate for particular events, but they should not automatically be included in every registration form.
The key question is: What specific purpose does this information serve?
If the purpose cannot be clearly explained, the field should be reconsidered.
What About Children’s Data?
The DPDP Act defines a child as an individual who has not completed 18 years of age. It includes specific requirements for processing children’s personal data, including verifiable parental consent, subject to applicable provisions and exemptions. Events aimed at students or younger participants should therefore have a registration process that accounts for these requirements rather than treating children’s registration the same as adult registration.
Note: Under Rule 10 of the DPDP Rules, companies must use reliable tools (like DigiLocker or official identity tokens) to confirm the adult’s identity and their relationship to the child.
What Should Organizers Check Before Publishing the Form?
Before making a registration form live, organizers should review:
- Purpose: Is every field linked to a defined purpose?
- Necessity: Is the information actually needed?
- Notice: Does the attendee understand what is being collected and why?
- Consent: Is consent clear and specific where required?
- Optional fields: Are non-essential fields clearly optional?
- Marketing: Is promotional consent separated where applicable?
- Children: Are additional requirements addressed for attendees under 18?
- Access: Who will be able to view or use the collected information?
- Third parties: Are registration, payment, or event technology providers appropriately managed?
This review should happen before registration opens, not after attendee data has already been collected.
How Can Event Technology Support Better Data Collection?
The event registration platform plays an important role in how attendee information is collected and managed. Organizers should look for an event registration solution that allows them to control registration fields, manage attendee information, support consent workflows, and connect registration with other event processes.
An all-in-one event registration platform such as Dreamcast can bring registration, ticketing, badge printing, digital badges, and event check-in into a connected workflow. This can reduce the need to move attendee information between multiple systems and vendors.
However, organizers remain responsible for deciding what data they collect, why they collect it, and how it should be handled.
For a broader explanation of these responsibilities, see our guide on DPDP and attendee data.

DPDP Event Registration Form Checklist
Before publishing the form, ask:
- Are only the necessary fields included?
- Is every field linked to a clear purpose?
- Are mandatory and optional fields clearly identified?
- Is the registration notice easy to understand?
- Is consent specific and clear where required?
- Is marketing consent handled separately where applicable?
- Is there a process for consent withdrawal?
- Are children’s data requirements considered where relevant?
- Are third-party data processors properly managed?
- Are access and security controls in place?
Conclusion
A DPDP-focused event registration form is not about collecting more information. It is about collecting the right information for a clearly defined purpose. Organizers should keep forms focused, explain their data practices clearly, separate optional requests from essential registration details, and build appropriate consent and data-management processes into the attendee journey.
FAQs
Not necessarily. It depends on whether the information relates to an identifiable individual. Names, email addresses, and phone numbers are common examples of personal data.
They should have a clear and lawful purpose for processing the data. Where consent is relied upon, the consent must be specific and informed rather than based on a vague future-use statement.
No. Only fields necessary for the relevant registration or event purpose should generally be mandatory. Other information can be optional where there is a genuine choice.
Yes, but the form should clearly explain the different purposes and handle consent appropriately where required. Combining unrelated purposes without clear choices can create unnecessary data-protection risks.
If the information is genuinely option al and not required for the event service, registration should normally remain possible without it. The form should clearly distinguish optional fields from information needed to complete registration.
Yes, if networking is a defined purpose of the event. Organizers should explain what information will be used for networking and provide appropriate choices where consent is required.
Not automatically. Organizers should have a clear purpose and lawful basis for any sharing. Where consent is required, attendees should be informed about the relevant data use rather than assuming that registration itself permits unrelated sharing.
Simplify Event Planning Hassle-Free