Aurentex. We build the tech. You run the event.
Compliance

DPDP Act compliance for event organizers: a practical checklist

Every registration form you publish collects personal data, which makes you a Data Fiduciary under India's DPDP Act. The rules are now notified, the deadlines are real, and the penalties reach ₹250 crore. Here is the checklist worth forwarding to your legal team.

The Aurentex Team
30 July 2026 · 7 min read
A formal corporate event with data dashboards on stage screens
Every one of those registrations is personal data, and under the DPDP Act, it is your legal responsibility.

If you run events in India, the Digital Personal Data Protection Act is not an abstract tech-industry story. DPDP Act event data obligations attach to the most ordinary thing you do: publishing a registration form. Names, phone numbers, emails, dietary preferences, company names. All of it is digital personal data, and the person legally answerable for it is you, the organizer, not your ticketing tool.

The Act passed in August 2023 and sat waiting for its operating manual. That manual arrived on 14 November 2025, when the DPDP Rules were notified with an 18-month phased rollout.1 The good news is that attendee data compliance in India is very manageable if you set it up before your next event instead of retrofitting it under a deadline.

Why this lands on event organizers

The Act divides the world into Data Fiduciaries, who decide why and how personal data is processed, and Data Principals, the people the data is about.2 When someone registers for your event, you are the fiduciary and your attendee is the principal. Your registration platform is a processor working on your behalf.

The obligations follow the fiduciary: consent, notices, erasure and breach reporting are all legally addressed to you. A platform can make each duty easy or painful, but it cannot take it off you, which is why your tooling is a compliance decision, not just a convenience one.

The timeline: what applies, and when

The Rules phase in over three dates, and the distinction matters.13

14 Nov 2025 Rules notified. Data Protection Board live. 14 Nov 2026 Consent manager registration begins. 14 May 2027 Consent, breach reporting, safeguards: fully in force. An event planned today will still be generating attendee data when the full obligations bite.
The DPDP rollout: the substantive duties land in May 2027.

The Data Protection Board exists now, consent-manager registration opens from November 2026, and in May 2027 the substantive obligations, consent notices, breach reporting, security safeguards and children's protections, take full effect.3 The honest reading: events you are planning right now will still be holding attendee data when the full obligations apply.

The checklist

Seven items. None of them require a compliance department; all of them are easier if your registration platform does the heavy lifting.

1. Fix your consent capture at registration

Consent under the Act must be free, specific, informed and given by a clear affirmative action, accompanied by a notice that says, in plain language, what data you collect and why.2 For a registration form that means: an unticked consent checkbox, a short purpose statement next to it, and a link to your privacy notice. No pre-ticked boxes, no consent buried in terms and conditions.

2. Collect only what the event needs

Every extra field is extra liability. If you will never use the attendee's date of birth, stop asking for it. A lean form converts better, and it shrinks what you must protect, export and eventually erase.

3. Decide retention before you collect

The Act expects personal data to be erased once its purpose is served, and the Rules add specific retention logic for large platforms.3 For organizers the practical move is a simple written rule, for example: attendee data is deleted or anonymized N months after the event unless the attendee opted into future communications. Write it down, put it in your privacy notice, and configure your platform to actually do it.

4. Have a breach plan you could execute this week

Under Rule 7 of the DPDP Rules, a breach means notifying both the Data Protection Board and every affected attendee, regardless of scale: an initial intimation to the Board without delay, a detailed report within 72 hours, and plain-language notice to affected individuals describing what happened and what they can do.4 Know today who would send those notices, from what address, and where your attendee contact list is exportable at 11 p.m. on a bad night.

5. Answer rights requests: access, correction, erasure

Attendees can ask what you hold about them, ask you to correct it, and ask you to erase it. Grievances must be resolved within 90 days at the outside.3 The test of readiness is operational, not legal: can you find one attendee across all your events, export their record, and delete it, in minutes rather than a support-ticket saga?

6. Careful with minors on the guest list

Processing a child's data requires verifiable parental consent, and behavioural tracking and targeted advertising at children are off the table.3 If you run college fests, education expos or family events, decide now how registrations for under-18 attendees are handled instead of discovering the question at the venue door.

7. Put your platform's obligations in writing

Your registration platform processes attendee data on your behalf, so your contract with it should say, explicitly: the data is yours, full export is available on demand, deletion is guaranteed on request or at exit, and the vendor never uses your attendee list for its own marketing. If a vendor resists writing that down, that is your answer.

What non-compliance costs

The Act's penalty schedule is written in fixed maximums rather than percentages of turnover, and the numbers are designed to be noticed.5

₹250 crore
maximum penalty for failing to maintain reasonable security safeguards5
₹200 crore
maximum penalty for failing to notify the Board or affected individuals of a breach5
72 hours
deadline for the detailed breach report to the Data Protection Board4

Two details matter. The penalties stack: a breach caused by weak safeguards, followed by a missed notification, exposes you under both heads at once.4 And the Board weighs mitigating factors, including self-disclosure, prompt remediation and a documented compliance record.5 The checklist above is not just protection against a fine; it is the evidence that reduces one.

You can delegate the work of protecting attendee data. You cannot delegate the responsibility for it.

Where Aurentex sits

We built Aurentex assuming the DPDP Act is the floor, not a feature. Attendee data on client platforms is stored in the AWS Mumbai (ap-south-1) region by default, so the jurisdiction question stays simple even though the Act does not mandate localization.3 Registration forms are yours to design, so lean collection and a proper consent checkbox are the default. Every attendee record is exportable and deletable on demand, our own breach commitment of notifying affected clients within 72 hours is written into our privacy policy, and we never market to your attendee list. When your legal team asks the seven questions above, the answers are already in the contract.

One honest caveat to close on: this article is a practical orientation, not legal advice. The Rules are new, interpretations are still settling, and a one-hour conversation between your counsel and this checklist is the cheapest insurance you will buy this year.

Common questions

Does the DPDP Act apply to small events?

Yes. The Act applies to digital personal data regardless of organizer size, so a 200-person community conference collecting names and phone numbers is in scope. The government can exempt notified classes of entities, such as certain startups, but no organizer should assume an exemption without checking.2

Am I the Data Fiduciary, or is my software vendor?

You are. The fiduciary is whoever decides why and how the data is processed, and for an event that is the organizer. Your platform is a processor acting on your instructions, which is why item 7 of the checklist, the written contract, matters so much.

When do I actually have to comply?

The Rules were notified on 14 November 2025 and phase in over 18 months, with the substantive obligations fully in force in May 2027.13 Build compliance into your next event now; retrofitting consent and retention across past events under deadline is far more painful.

Does attendee data have to be stored in India?

No. The Act uses a restriction-list model for cross-border transfers rather than a localization mandate: transfers are permitted except to countries the government restricts.3 Storing attendee data in an Indian region is still a sensible default, because it keeps the jurisdiction question simple for you and your clients.

Want registration that is compliant by default?

Consent capture built into your forms, data in AWS Mumbai, full export and deletion on demand, and a contract that says so. Your first two events are free.

Talk to us
ComplianceData ownershipIndia

Get the next one in your inbox

Occasional, practical notes on event tech. No spam.

Unsubscribe anytime. We will never share your email.

References

  1. Press Information Bureau, Government of India, "DPDP Rules, 2025 Notified" (November 2025). The Digital Personal Data Protection Rules, 2025, notified on 14 November 2025 with phased implementation.
  2. Ministry of Electronics & IT, Government of India, "The Digital Personal Data Protection Act, 2023." Defines Data Fiduciaries, Data Principals, consent requirements and the obligations attached to processing digital personal data.
  3. Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP Rules." The three-phase rollout (November 2025, November 2026, May 2027), breach reporting to the Board and all affected Data Principals, the 90-day grievance ceiling, retention provisions, cross-border transfer model, and verifiable parental consent for children.
  4. Matters.ai, "DPDP Breach Notification: 72-Hour Rule & ₹200 Cr Penalty." Rule 7 mechanics: initial intimation to the Board, the detailed report within 72 hours, plain-language notice to affected individuals, and cumulative penalty exposure.
  5. DPDPA.com, "Penalties in the Digital Personal Data Protection Act, 2023: The Schedule." Maximum penalties of ₹250 crore for failure of reasonable security safeguards and ₹200 crore for failure to notify breaches, with the Board weighing mitigating factors.

This article is general information, not legal advice. The DPDP Rules are new and interpretations are evolving; confirm specifics with counsel and the official texts above.