Engineering
What the DPDP Act actually asks of an event organiser
Delegate lists, badge scans, photography and session tracking are all personal data. Here is the practical shape of compliance.
Hero art direction: Venue network rack with patch panel and switch LEDs, UPS below, cable tags visible. Cool rack light.
Events collect more personal data than organisers realise
A typical conference holds: names, employers, job titles, phone numbers, email addresses, dietary requirements, accessibility needs, photographs, session attendance, sometimes location traces from access control, and occasionally payment details.
Several of those are sensitive. Most organisers have never written down which ones they hold, where they live, or when they will be deleted.
This is not legal advice, and an event with any complexity should take some. But the practical shape is straightforward and the work is mostly organisational.
Know what you hold and why
Write the inventory. One row per data type: what it is, why you collect it, which system holds it, who can see it, and how long you keep it.
The exercise takes an afternoon and it produces the two things every subsequent question depends on. It also routinely surfaces a system nobody remembered — the badge printing vendor's spreadsheet, the WhatsApp group with the delegate list in it.
Purpose has to be stated, and it has to be specific
"For event management" is not a purpose. These are:
- To issue your badge and admit you to the venue
- To cater for your stated dietary requirement
- To send you the session recordings you asked for
- To give the sponsor whose stand you scanned at your contact details
That last one deserves emphasis. A delegate whose badge is scanned at a sponsor stand needs to understand that this shares their details with that sponsor. The scan is the consent, and it only works if you have told them so — at registration, and on the signage at the stand.
Retention is where most organisers are exposed
The default behaviour is to keep everything forever, because deleting feels risky and nobody owns it.
Set a period per data type and automate it:
- Access-control scan logs — a short window after the event, unless there is a specific security reason
- Photographs — as long as you have usage rights for, and no longer
- Biometric templates from face-search galleries — the shortest of everything you hold
- Delegate contact records — as long as your stated marketing basis supports, with a clear route to withdraw
An automated deletion job is worth more than a policy document, because the policy document does not delete anything.
Rights requests will arrive
A delegate can ask what you hold and ask you to delete it. You need a named person and a process that does not depend on someone remembering which spreadsheet.
This is the strongest practical argument for keeping delegate data in one system rather than four: a rights request against one database is an afternoon. The same request against a registration platform, a CRM, a photo gallery, a badge vendor and three spreadsheets is a week, and you will still miss something.
Photography and the notice nobody reads
A sign at the entrance saying photography is taking place is the norm, and it is the minimum rather than the whole answer.
Where it matters more: if you are running face-based gallery search, that is biometric processing and it needs to be opt-in and explained, not buried in a notice. Give delegates a way to be excluded that does not require them to avoid the camera.
Processors and contracts
Every vendor touching delegate data — registration platform, badge printer, photographer, streaming provider — is processing on your behalf, and that relationship should be in the contract with the security expectations written down.
Ask them the same questions you are asking yourself: what do you hold, where, for how long, and who can see it. A vendor who cannot answer quickly is telling you something useful.

Questions we get
Follow-ups
01Do we need explicit consent for badge scanning at sponsor stands?
The delegate needs to understand that presenting their badge shares their details with that exhibitor. Stating it at registration and on stand signage is the practical approach, and it works because the action is voluntary and obvious. Scanning badges without the delegate initiating it is a different matter entirely.
02How long can we keep delegate data after the event?
As long as your stated purpose supports, and no longer. Contact records for next year's invitation have a defensible basis if you said so at registration and offer an unsubscribe. Access-control scan logs rarely have any purpose beyond the event and should go on a short timer.
03Does data have to stay in India?
The Act allows transfer other than to restricted jurisdictions, so the practical answer for most organisers is that it depends on your own commitments and your clients'. Government and BFSI clients frequently require in-country processing regardless of what the law permits, which is one of the reasons we run on-venue processing for dubbing and registration rather than in a cloud region.
Talk to the team that runs this on the floor
Send the date, the city and the headcount. We reply with numbers.
Further reading
Was this useful?


