News & Updates

DPDP Act 2023 and DPDP Rules 2025 for Events: What Event Organisers Need to Know About Data Protection

  1. 7 September, 2026
TL;DR:

The Digital Personal Data Protection Act 2023, along with the Digital Personal Data Protection Rules 2025, will govern how organisations and entities in India collect, process, and store digital data.

This legislation aims to ensure data protection and transparency of use for Indian citizens. It intends to give them more control over their personal data.

In the event industry, the DPDP Act and Rules will influence how organisers treat attendee data. The data fiduciary decides how attendee data will be collected and used.

Failing to implement reasonable security safeguards can attract a penalty of up to โ‚น 250 crore. Separately, failing to notify the Data Protection Board and affected data principals (the owners of the personal data i.e. the attendees in case of events) after a breach can attract a penalty of up to โ‚น 200 crore.

When attendees sign up for an event, they share personal details such as their name, phone number, address, gender, job title, organisation, and sometimes government ID details. But where does all this information go after they click โ€œRegisterโ€? This is where the Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025 become relevant.

The DPDP Act 2023 aims to make the collection and use of personal data more transparent and responsible, while giving people greater control over their personal information. The DPDP Rules 2025 fully operationalise the 2023 Act.

For the event industry, this matters because events are highly data-driven. Attendee data moves through multiple systems for event registration, badging, accreditation, analytics, CRM, sales, and marketing.

In this blog, weโ€™ll explore what the DPDP Act 2023 and DPDP Rules 2025 mean for event organisers, how it affects attendee data, and what event professionals should start considering for data protection.

What is the Digital Personal Data Protection (DPDP) Act 2023 and DPDP Rules 2025?

The Digital Personal Data Protection Act, 2023, together with the DPDP Rules, 2025, forms Indiaโ€™s framework for regulating the processing of digital personal data. For event professionals, this matters because attendee data is collected at almost every stage of an event, whether it is a conference, concert, exhibition, or government event. Full enforcement of the DPDP Actโ€™s operational provisions is set for May 2027 as per the DPDP Actโ€™s official implementation timeline.

Event-Specific Context:

  • The DPDP Act 2023 and DPDP Rules 2025 apply to event organisers whenever attendee personal data is collected or processed, which covers nearly every event.
  • The organiser is usually the Data Fiduciary, responsible for deciding why data is collected and staying accountable for it.
  • The biggest practical shifts are: justify every form field on a registration form, get fresh consent before reusing attendee data for new purposes, keep tighter control over vendors and sponsors who touch attendee data, and have a breach response plan ready, since failing on security safeguards can cost up to โ‚น 250 crores.

From the moment an attendee registers, their data may be used for various purposes across different event stages. But after they share their data, they have little control over how it is used or shared with third parties. The DPDP framework addresses this gap. It focuses on why this data is collected, how it is used, who has access to it, and how long it is retained.

What Should Event Organisers Be Prepared For?

Earlier, an attendee database could easily become a long-term marketing asset. An attendee who registered for one event might continue receiving sales emails or promotional messages months or even years later. Under the new framework, event organisers need to be more careful about using personal data beyond the purpose for which it was collected.

Letโ€™s break down further how the DPDP framework can affect everyday event operations.

What Relevant Terms Event Organisers Must Know As Per the DPDP Act?

The easiest way to understand the DPDP framework is to look at who the data belongs to, who decides why it is used, and who processes it. In an event, the attendee is generally the data principal, the organiser may be the data fiduciary, and an event technology provider may act as a data processor, depending on the specific arrangement.

DPDP termIn simple wordsEvent example
Data PrincipalThe person whose personal data is being usedAn attendee registering for a conference
Data FiduciaryThe organisation that decides why and how the data is usedAn organiser collecting attendee details for registration
Data ProcessorAn organisation processing data on behalf of the Data FiduciaryAn event-tech provider managing registration and badge printing

Data Principal: The person the data belongs to

An attendee registering for a concert shares details like name, phone number, and email address, so she or he is the data principal. Simply put, it is the person whose personal data is being collected or processed.

Other Relevant Examples:

1. At the billing counter of a shopping mall, you are the customer who gives your name, phone number, and email address (not necessarily, but often). The data is about you, so you are the data principal.

2. As a new employee in a company, you provide your name, phone number, address, bank details, and other information to the company. Since the personal data belongs to you, you are the data principal.

Data Fiduciary: The organisation deciding what happens to the data

The organiser asking for attendeesโ€™ phone numbers to send them event confirmation and important updates is the data fiduciary. The organiser decides why the information is needed and how it will be used, making it the data fiduciary for that processing activity.

Other Relevant Examples:

1. The mall collects your details so it can manage your loyalty membership and send you offers. Because the mall decides why and how your data will be used, it is the data fiduciary.

2. Your employer collects this information to manage your employment, process your salary, and handle other work-related requirements. Since the company decides why and how your data is used, it is the data fiduciary.

Data Processor: The organisation doing the processing

Now imagine the organiser uses an event registration platform to collect registrations and print attendee badges. The platform is processing attendee data on behalf of the organiser, and may therefore act as a data processor.

For example, if an organiser uses Dreamcast to manage event registration and badge printing, Dreamcast may act as a Data Processor where it processes attendee information on the organiserโ€™s behalf. The exact role depends on the specific processing activity and relationship between the organiser and technology provider.

Other Relevant Examples:

1. The mall uses a software company to run its loyalty programme. That company stores your details and sends messages on the mall’s instructions. It is the data processor.

2. The company uses a payroll software provider to calculate salaries and process employee payments. The software provider handles your information on the company’s behalf, so it may act as the data processor.

One important point: These roles depend on the actual processing activity and the relationship between the parties. An organisation is not automatically a data fiduciary or data processor simply because it handles personal data.

What Does the Data Fiduciary’s Responsibility Mean for Event Organisers?

As per the DPDP Act, the data fiduciary decides the purpose and intent of data collection and how it will be processed. So, itโ€™s not that you cannot collect attendee information anymore. You just need to be able to be clear about and be able to justify the following:

  • The intent and purpose of every single form field in your registration form
  • Its relevance to the activities or experience of the attendee at that moment or in the near future
  • How you plan to use their data and for how long you intend to retain it

What Are the Core Principles Underlying the DPDP Rules 2025?

The DPDP Act 2023 and the DPDP Rules 2025 are built around seven core principles for handling personal data. These principles apply to the entire data lifecycle: collection, use, storage, and deletion. Hereโ€™s a detailed overview in the context of events.

1. Clarity and Transparency

People should know what information you are asking for and why you need it. They should not have to read pages of complicated language to understand what they are agreeing to.

At an event:

If you ask for an attendee’s phone number, the registration process should make it clear whether it is needed for registration updates, event communication, or another specific purpose.

Everyday example:

A clothing store asks for your phone number and tells you it needs it to send your order updates. You know why your number is being collected.

After the DPDP Act is officially enforced, data principals will have the right to question data fiduciaries as to why their data is being collected.

2. Purpose Limitation

If you are collecting attendeesโ€™ personal data for a particular purpose, you must use it only for that declared purpose. Data once collected does not become eligible for use for every other purpose you wish to fulfill.

At an event:

An attendee provides an email address to receive a conference registration confirmation. You, as an organiser, should not automatically treat that as permission for unrelated marketing.

Everyday example:

A customer gives their phone number to a delivery person so the delivery can be completed. They would not expect the delivery person to start sending advertisements.

3. Data Minimisation

You should avoid collecting information simply because your event registration form has a field for it. The basic principle is: if the information is not needed for a legitimate purpose, there may be no reason to ask for it.

At an event:

If you only need an attendee’s name and company to print a badge, asking for their residential address may serve no clear purpose.

Everyday example:

A cafรฉ needs a customer’s name to put on a coffee cup. It does not need the customer’s home address to make the coffee.

4. Data Accuracy

As an event organiser, you must make reasonable efforts to ensure the personal data you use is correct and up to date, particularly when incorrect information could affect the attendee’s experience or the service being provided.

At an event:

If an attendee changes their company before the event, you should ideally be able to update the registration record and reflect the change on the attendee’s badge.

Everyday example:

If a bank has a customer’s old phone number, important alerts may go to the wrong person. Keeping the information updated helps the bank contact the right customer.

5. Storage Limitation

If the purpose for which you collected attendeesโ€™ data is over, you should have valid reasons to retain any of it in your storage.

At an event:

Once an event ends, you should know which attendee information still needs to be retained and which information no longer has a reason to remain in your systems.

Everyday example:

A person may keep a receipt for something they bought recently. There is usually little reason to keep every shopping receipt from the last 20 years.

6. Security Safeguards

Organisers must put reasonable security safeguards in place to protect personal data from breaches. In simple terms, attendee information should not be left open for anyone to access.

At an event:

A database containing thousands of attendee names, phone numbers, and email addresses should not be accessible to every person working on the event. Access should be limited to people who actually need it. Proper encryption and compliance should be in place.

Everyday example:

A shop owner would not leave the keys to the shop hanging outside the front door where anyone could take them.

7. Accountability

If you collect and use personal data, you need to take responsibility for how that data is handled throughout its journey. This means knowing what information is collected, where it goes, who can access it, and what happens if something goes wrong.

At an event:

You should be able to answer basic questions such as: What attendee data are we collecting? Who is handling it? Where is it stored? How is it protected? What happens to it after the event?

Everyday example:

If a bank collects customer phone numbers, it cannot simply ignore the situation if those numbers are accidentally exposed.

How does the DPDP Framework Impact Event Organisers in Practice?

For event organisers, the DPDP framework can affect everyday processes such as registration, ticketing, accreditation, marketing, vendor management, access control, data retention and breach response. The practical question is no longer simply whether data is being collected, but how that data moves through the event lifecycle. Letโ€™s understand the key implications of the new rules across different event stages and processes:

1. How Does DPDP Affect Event Registration Forms?

The organiser should be able to explain why each personal data field is being requested and how that information will be used.

In practice, organisers should:

  • Review every field on registration forms.
  • Remove fields that have no clear purpose.
  • Explain why required information is being collected.
  • Avoid making optional information appear mandatory.

For example, an event registration platform such as Dreamcast allows organisers to customise registration forms based on the information actually required for an event. This gives organisers greater control over which attendee details they ask for at the point of registration, rather than relying on a rigid form.

DPDP Act 2023 and DPDP Rules 2025 for Events - CTA

Consent should be treated as an actual part of the attendee journey, rather than a checkbox added at the bottom of a form. Organisers need to make it clear what data is being collected, why it is being used, and where consent is the basis for processing.

In practice, organisers should review:

  • Registration notices
  • Consent language
  • Marketing opt-ins
  • Ways for attendees to withdraw consent where applicable
  • How consent and related records are maintained

3. Can Event Organisers Use One Attendee Database for Unlimited Future Marketing?

An attendee database can be extremely valuable to an organiser, but the fact that information was collected during one event does not mean it can be used for every future purpose. 

In practice, organisers should ensure:

  • Seeking permission from attendees before using their personal data for every new event or every unique purpose.
  • Clearly stating the purpose of data collection and standing by it.

4. How Should Event Organisers Manage Vendors That Handle Attendee Data?

As data fiduciaries, organisers need to have total control over all their data processors (all the vendors handling data on behalf of the organisers). In a typical event, there is a high probability that different vendors process data at different event stages: registration, badging, communication, post-event follow-up, etc. Organisers must keep track of all of them and maintain strict oversight over how all of them are processing the data because ultimately, the accountability lies with the data fiduciaries. 

This is where the choice of event technology partner becomes important. A platform such as Dreamcast can bring several stages of the attendee journey, including registration, check-in, badging and attendee reporting, into a connected workflow. For organisers, having greater visibility over where attendee data is collected, accessed and used can make data management easier to track across the event lifecycle. 

In a typical event setting, greater visibility and control over the data journey can make it easier for organisers to meet their responsibilities as Data Fiduciaries. The technology partner’s role is therefore worth considering not only from an operational perspective, but also from a data-management perspective.

5. How Does DPDP Affect Data Sharing With Event Sponsors and Exhibitors?

Sponsors and exhibitors often want attendee information to generate leads and continue conversations after an event. DPDP makes it important for organisers to think carefully about when and why attendee information is shared.

For example: An attendee visits an exhibitor’s booth and scans their badge. That does not mean organisers should assume the attendee has agreed to every possible future use of their information.

The key question is:

What was the attendee told about this data sharing, and what basis allows the information to be shared?

This is especially important for lead retrieval, sponsor databases and post-event sales activity.

6. How Should Event Organisers Control Access to Attendee Data?

Not everyone working on an event needs access to the entire attendee database. DPDP makes data security an organisational responsibility, which means access to personal data should be handled thoughtfully.

For example: A volunteer helping attendees find their registration may need to verify a name or registration number. They probably do not need access to the complete attendee database.

Organisers should consider:

  • Who can access attendee data
  • What level of access each person needs
  • Whether former employees or temporary staff still have access
  • How access is removed when a project ends

7. How Long Should Event Organisers Retain Attendee Data?

The end of an event does not automatically mean the end of data processing. At the same time, attendee information should not simply remain in every system forever without a reason.

For example: A 50,000-person conference may leave attendee information stored in the registration platform, CRM, email system, event app, and spreadsheets months after the event.

Organisers should know what needs to be retained, why it needs to be retained, and when information that is no longer required should be removed, subject to applicable legal or other retention requirements.

8. How Should a Data Breach be Handled?

A breach involving attendee information can quickly become an event-management issue, not just an IT issue. Organisers need to know what happens if personal data is accidentally exposed, stolen, or accessed by an unauthorised person. Learn more in the following section.

What Should You Do In Case of a Data Breach as per DPDP 2025?

If an event organiser becomes aware of a personal data breach, the DPDP framework requires action without delay. The key steps are:

  • Inform affected attendees and the Data Protection Board: Tell affected Data Principals what happened, the likely impact, what is being done to reduce the risk, and what they can do to protect themselves. Notify the Data Protection Board of India about the breach without delay.
  • Submit detailed information within 72 hours: Provide the Board with detailed information about the breach within 72 hours of becoming aware of it, unless the Board allows more time.
  • Find out what happened: Identify how the breach occurred, what personal data was affected, and how many people may be impacted.
  • Take corrective action: Fix the issue, strengthen security measures, and take reasonable steps to prevent a similar breach from happening again.
  • Understand the financial risk: Failure to maintain reasonable security safeguards can attract a penalty of up to โ‚น250 crore. Failure to notify the Board or affected Data Principals about a breach can attract a penalty of up to โ‚น200 crore. Any other violations of the rules of DPDP can attract penalties up to โ‚น 50 crore.

For event organisers, the practical takeaway is simple: have a clear breach-response plan in place before an incident occurs, including who will coordinate with technology vendors, affected attendees, and the Data Protection Board.

The Bottom Line

For event organisers, DPDP is ultimately a shift in how attendee data is treated. Registration data is no longer simply a future marketing database. It is information that needs a clear purpose, controlled access, appropriate security and responsible handling throughout the event lifecycle.

As event technology continues to connect registration, ticketing, accreditation, badging, access and communication, understanding the data journey will become just as important as understanding the event journey.

FAQs

Does the DPDP Act apply to event organisers?

Yes. The DPDP Act can apply when organisers collect or process attendeesโ€™ digital personal data, including names, phone numbers, email addresses, photographs, and identification details.

How does the DPDP Act affect event registration and ticketing?

It requires organisers to think carefully about what attendee data they collect, why they collect it, how they use it, and who has access to it.

Can event organisers use attendee data for marketing after an event?

Not automatically. Organisers should consider the original purpose of collection and the applicable legal basis before using attendee data for post-event marketing.

Who is responsible for attendee data under the DPDP Act: the organiser or the event-tech provider?

It depends on their roles. An organiser may be the Data Fiduciary, while an event-tech provider may act as the Data Processor processing data on its behalf.

What is the penalty for a data breach under the DPDP Act?

Failure to maintain reasonable security safeguards can attract penalties of up to โ‚น250 crore, while certain breach-notification failures can attract penalties of up to โ‚น200 crore.

How long can event organisers retain attendee data under DPDP?

Organisers should retain personal data only for as long as there is a valid reason to retain it for the relevant purpose or another applicable requirement. They should also establish appropriate retention and deletion practices.

Mohi Gaur

Mohi Gaur is a content writer and AI/LLM analyst with a Master's in Journalism and Mass Communication and over four years of experience across content writing, editorial work, and language model analysis. Her journalism background shapes how she approaches every topic - with rigorous research, clear structure, and audience-first thinking. Having worked as a freelance writer, editor, and translator for nearly three years, she developed a strong command of long-form content, proofreading, and multilingual communication. Her experience as an AI/LLM Analyst gives her a deeper understanding of how search engines and language models evaluate content - an edge she brings directly into her writing and content strategy work.

Read All Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Let us take care
of your next event.

Create. Connect. Communicate

Dreamcast is a renowned event tech solution provider known for its capabilities to transform the event experience with an array of customisable services. We aim to empower you as a host to create your visionary event into reality while performing the best-in-class industry practices and helping you build global connections.