Introduction
India's Digital Personal Data Protection (DPDP) framework is an important consideration for universities, research institutes, academic societies, and organizations that manage conferences online. A conference management system may process personal information from authors, reviewers, speakers, participants, and organizers throughout the conference lifecycle.
From research paper submission and peer review to registration, communication, scheduling, and proceedings, conference organizers should understand how personal data is collected, used, stored, accessed, and retained.
Key Takeaways
- The DPDP Act, 2023 and DPDP Rules, 2025 govern how digital personal data is processed in India.
- Academic conferences process personal data of authors, reviewers, speakers, and participants, so DPDP can be relevant.
- Key areas include privacy notices, legal basis, access controls, security safeguards, retention, and breach response.
- A conference platform helps organize data, but compliance depends on how each organization configures and uses it.
What Is India's Digital Personal Data Protection Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a legal framework for the processing of digital personal data in India. It addresses how organizations process personal data and provides rights and protections for individuals whose digital personal data is processed.
For academic conferences, the framework can be relevant because conference organizers may collect and process information about authors, reviewers, participants, speakers, and committee members.
Universities and research organizations should assess their own processing activities and determine which requirements apply to their conference workflows.
What Are the DPDP Rules 2025?
The Digital Personal Data Protection Rules, 2025 provide additional rules under India's DPDP framework. They address areas such as notices, consent management, security safeguards, personal data breach notifications, rights of individuals, and other data protection responsibilities.
Note: The rules provide for phased commencement of different provisions. Organizations should consider the applicable commencement dates and requirements when reviewing their data protection processes.
Does DPDP Apply to Academic Conferences?
DPDP requirements may be relevant to academic conferences when organizations process digital personal data within the scope of the law. A conference management system can contain information about researchers, authors, reviewers, speakers, participants, and organizers.
The exact obligations depend on the organization, the nature and purpose of the processing, the data involved, and other applicable legal requirements. Universities and research organizations should evaluate their conference workflows as part of their broader privacy and data protection practices.
What Personal Data Does a Conference Management System Process?
Depending on how it is configured, conference management software may process several types of personal information. Common examples include:
Author names and contact informationEmail addressesInstitutional affiliationsReviewer informationSpeaker and participant informationResearch paper and submission metadataConference registration informationCommunication and notification recordsAccount and login information
Organizations should identify what personal data is actually required for each conference workflow and avoid collecting information that is unnecessary for the stated purpose.
DPDP Across the Conference Workflow
DPDP and Research Paper Submission
Research paper submission is a central part of an academic conference management system. Authors may provide their names, email addresses, institutional affiliations, biographies, paper files, and other submission-related information.
Conference organizers should clearly understand the purpose for collecting this information, how it will be used, who may have access to it, and how long it needs to be retained.
ScholarMeet provides a structured research paper submission workflow as part of its broader conference management platform, helping organizers manage submissions and associated conference information in a centralized environment. Learn how to manage research paper submissions for an academic conference.
DPDP Considerations for Authors and Reviewers
Academic conferences typically involve multiple groups of users, including authors, reviewers, editors, organizers, speakers, and participants. Each group may interact with different parts of the conference management system.
Organizers should consider appropriate access controls so that users receive access to information necessary for their role. For example, reviewers may need access to assigned submissions and evaluation workflows without requiring access to unrelated participant information.
Clearly defined roles and permissions can help organizations manage conference information in a more structured manner.
DPDP and Blind Peer Review
Blind peer review is an important academic workflow for many research conferences. Depending on the review model, organizers may need to limit the visibility of author or reviewer identity information.
Blind peer-review workflows are primarily an academic and editorial practice rather than a specific DPDP requirement. However, appropriate access controls and information separation can support confidentiality and privacy within the review process.
ScholarMeet supports structured reviewer management and blind peer-review workflows as part of its conference management capabilities. See how a blind peer review system works.
Privacy Notices and Consent for Conference Participants
Organizations processing personal data should provide appropriate information to individuals about relevant data processing activities. Depending on the processing activity and legal basis, consent or another permitted basis may be relevant.
Conference organizers should consider how privacy information is presented during paper submission, registration, reviewer onboarding, and other points where personal information is collected.
Privacy notices should be clear and understandable and should explain relevant purposes for processing personal data.
Data Security, Retention, and Processing Arrangements
Data Security for Conference Management Systems
Conference management systems can contain both personal information and valuable academic research. Appropriate security measures are therefore important when organizations operate digital conference workflows.
Conference organizers should evaluate measures such as:
AuthenticationRole-based accessAuthorizationSecure data handlingEncryption where appropriateMonitoringBackupsIncident responseAccess management
Administrators should also regularly review user permissions and remove or modify access when individuals no longer require it. Security is one of the 10 essential features of a modern conference management system.
Data Retention and Deletion for Academic Conferences
Conference organizers should determine how long different categories of personal data need to be retained. Submission records, reviewer information, registration records, communications, financial information, and published proceedings may have different retention requirements.
A documented retention policy can help universities and research organizations determine which information should be retained, for what purpose, and when it should be securely deleted where appropriate.
Retention requirements may also be influenced by institutional policies, legal obligations, research requirements, publication practices, and other applicable rules.
Conference Management Platforms and Data Processors
When an organization uses an external conference management platform to process personal data, it should understand the respective responsibilities of the organization and the technology provider.
Depending on the specific arrangement, the organization and technology provider may have different roles and obligations under applicable data protection law. Universities and research institutes should review relevant contractual, privacy, security, and data processing documentation before using a platform for conference activities.
International Data Transfers
Organizations should also consider whether personal data associated with their conferences is transferred or accessed across different countries or jurisdictions.
Where international processing or transfers are involved, universities and research organizations should assess the applicable legal requirements and safeguards. This can be particularly important for institutions collaborating with international researchers, reviewers, speakers, and participants.
DPDP Considerations for Universities and Research Institutes
Universities and research institutes often conduct multiple conferences and academic events throughout the year. They may therefore process personal data across different conference committees, departments, researchers, reviewers, and participants.
A consistent conference management process can help organizations establish clearer procedures for data collection, user access, communication, paper review, retention, and proceedings management.
Institutions should also align their conference workflows with their internal privacy, information security, records management, and data governance policies.
How ScholarMeet Supports Structured Conference Data Management
ScholarMeet is a conference management platform designed for universities, colleges, research institutes, academic organizations, and research societies.
- Setup & submissions – conference creation, research paper submission, and author management.
- Review – reviewer management, blind peer review, and paper evaluation.
- Decisions & communication – decision management and communication.
- Program & proceedings – conference scheduling and proceedings management.
Bringing these workflows together can help organizations manage conference activities through a centralized platform rather than relying on multiple disconnected tools.
Organizations using ScholarMeet should assess their own DPDP responsibilities, privacy policies, security requirements, data retention practices, and processing arrangements. Compliance depends on how the platform is configured and used and on the organization's specific legal obligations.
DPDP Compliance Checklist for Conference Organizers
✓ Identify the personal data collected from authors, reviewers, and participants.
✓ Document the purposes for processing personal data.
✓ Provide appropriate privacy notices.
✓ Determine the applicable legal basis or consent requirements.
✓ Collect only information that is necessary for relevant conference workflows.
✓ Configure appropriate user roles and access permissions.
✓ Protect author and reviewer information during peer review.
✓ Establish appropriate data retention and deletion procedures.
✓ Review security safeguards for conference data.
✓ Evaluate third-party and data-processing arrangements.
✓ Consider international data processing and transfer requirements.
✓ Maintain procedures for applicable data principal requests.
✓ Review personal data breach response procedures.
✓ Keep privacy and data governance documentation up to date.
Evaluating platforms? Read how to choose the best conference management tool.
Manage Conference Data in One Structured Platform
Centralize submissions, reviewer access, communication, and proceedings with role-based workflows built for academic conferences.
Frequently Asked Questions About DPDP and Conference Management
Does the DPDP Act apply to academic conferences in India?
The DPDP framework may apply where an organization processes digital personal data within the scope of the law. Academic conferences can involve personal data belonging to authors, reviewers, speakers, participants, and organizers. Universities and conference organizers should assess their specific activities and applicable requirements.
What personal data is collected by conference management software?
Conference management software may process information such as names, email addresses, institutional affiliations, reviewer information, paper metadata, registration details, account information, and conference communications. The actual information collected depends on how the platform is configured and used by the conference organizer.
Is consent always required for academic conference data?
Not necessarily. The appropriate legal basis for processing depends on the specific processing activity and applicable legal requirements. Conference organizers should determine the appropriate basis for each relevant processing purpose rather than assuming that consent is required for every activity.
Does DPDP require blind peer review?
No. Blind peer review is an academic review methodology and is not itself a general DPDP requirement. However, appropriate access controls and separation of author and reviewer information can support confidentiality and privacy during the review process.
Should universities check DPDP requirements before selecting conference management software?
Yes. Universities and research organizations should evaluate privacy, security, data processing, retention, access controls, contractual arrangements, and other applicable requirements when selecting conference management software.
Conclusion
India's DPDP framework makes data protection an important consideration for organizations managing digital academic conferences. From research paper submission and peer review to registration, communication, scheduling, and proceedings, conference workflows can involve personal data at many stages.
Universities, colleges, research institutes, and academic societies should therefore evaluate how personal data is collected, used, accessed, stored, retained, and protected throughout the conference lifecycle.
ScholarMeet provides a centralized conference management platform covering research paper submission, author and reviewer management, blind peer review, paper evaluation, communication, scheduling, and proceedings management.
A conference management platform can help organize these workflows, but compliance with India's DPDP framework ultimately depends on the organization's specific processing activities, configuration, policies, contracts, and legal obligations.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Organizations should consult qualified legal or privacy professionals when assessing their specific obligations under India's DPDP framework.