FREE DEMO

Conference Privacy Notice — ICC Annual Conference 2026

1. About This Notice

This Conference Privacy Notice ("Notice") is issued by ISACA Chennai Chapter ("Chapter", "we", "us", or "our") in connection with the ICC Annual Conference 2026 ("Conference"). It sets out how we collect, use, store, share, transfer, and retain personal data about delegates, speakers, sponsors, exhibitors, and other individuals who interact with us in relation to the Conference.

This Notice is strictly issued in compliance with:

  • India's Digital Personal Data Protection Act, 2023 ("DPDPA") and rules made thereunder.
  • The General Data Protection Regulation (EU) 2016/679 ("GDPR") and its UK equivalent, the UK GDPR.
  • Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy laws.

Where any provision of this Notice applies only to residents of a specific jurisdiction, this is clearly indicated. All other provisions apply universally to all individuals whose personal data we process in connection with the Conference.

By registering for, attending, or otherwise participating in the Conference, you acknowledge that you have read and understood this Notice. Where we rely on your consent as the lawful basis for processing, such consent is sought separately, explicitly, and in a manner that is specific, informed, and freely given.

2. Identity of the Data Fiduciary / Controller

For the purposes of applicable data protection law, the entity responsible for your personal data is:

ISACA Chennai Chapter

Address

15, Luz Golden Enclave, 180/4 Luz Church Rd, Mylapore, Chennai, Tamil Nadu 600004

Under the DPDPA, ISACA Chennai Chapter acts as the Data Fiduciary. Under the GDPR and UK GDPR, the Chapter acts as the Data Controller. Under PIPEDA, ISACA Chennai Chapter is the responsible organization for personal information under its control.

3. Personal Data We Collect

We collect only such personal data as is reasonably necessary for the purposes described in Section 5 of this Notice. The categories of personal data we may collect include:

  • Identity and contact information: Full name, designation, organisation name, professional email address, postal / delivery address, and telephone number.
  • Registration and participation data: Registration tier selected, session preferences, attendance records, CPE credit data, and workshop participation records.
  • Payment information: Transaction references and payment confirmation details. We do not store full payment card details; all payment processing is conducted through PCI-DSS compliant third-party payment gateways.
  • Delegate preferences: Dietary requirements and T-shirt size, where provided voluntarily.
  • Media and communications data: Photographs, video recordings, and audio-visual content captured during Conference sessions, workshops, networking events, and related activities.
  • Correspondence: Communications you send to us before, during, or after the Conference.

We do not knowingly collect or process sensitive personal data (as defined under the DPDPA), special categories of personal data (as defined under Article 9 of the GDPR), or sensitive information (as defined under applicable provincial law in Canada) unless strictly necessary and with your explicit consent obtained separately.

4. Lawful Basis for Processing

We process your personal data only where a lawful basis exists. The applicable bases, by jurisdiction, are as follows:

India

Under the DPDPA

We process personal data primarily on the basis of consent, obtained in a free, specific, informed, unconditional, and unambiguous manner through a clear affirmative action. Contractual necessity and compliance with legal obligations may also serve as lawful bases.

EEA & UK

Under the GDPR / UK GDPR

Our lawful bases include: Contract (performance of registration); Legitimate Interests (administering and promoting the event); Legal Obligation (statutory record-keeping); and Consent (obtained separately for sponsor sharing and promotional media use).

Canada

Under PIPEDA

We process personal data on the basis of express consent where required, or implied consent where the purpose of collection is evident and reasonable in the circumstances. You may withdraw consent at any time subject to legal restrictions.

5. Purposes of Processing

We process personal data for the following specific and identified purposes:

  • Conference administration and registration: Processing registrations, issuing confirmation communications, generating delegate badges, Lanyards, managing attendance records, and coordinating front-desk and on-site operations.
  • Contractual fulfilment: Processing payments, managing cancellations and refunds, and delivering delegate kit items and other entitlements arising from registration.
  • CPE credit management: Recording session attendance and issuing CPE certificates in compliance with ISACA's Continuing Professional Education reporting requirements.
  • Event logistics and operational support: Coordinating venue, hospitality, catering, and related operational activities; managing security and safety at the Conference venue.
  • Communications: Sending you information about the Conference, including pre-event updates, session changes, logistical instructions, and post-event materials.
  • Post-event administration: Conducting post-event reconciliation, archiving records, and producing internal and published Conference reports and summaries.
  • Legal and regulatory compliance: Meeting applicable statutory, regulatory, audit, accounting, and contractual obligations.
  • Sponsor communication (consent-dependent): Where you have provided explicit, separate consent during registration, sharing your name, organization, designation, and email address with Conference sponsors for professional networking. This sharing is conditional and not a prerequisite for registration.
  • Photography and media (consent-dependent): Using photographs, videos, and audio-visual content in which you appear for pre-event, during and post-event communications, Chapter promotional and educational materials, social media, and archival records.

We do not use your personal data for automated decision-making or profiling with legal or similarly significant effects.

7. Sharing of Personal Data

We share personal data only to the extent necessary and only with the following categories of recipients:

  • Authorized service providers and operational partners: Event management companies, logistics providers, catering and hospitality suppliers, badge-printing vendors, technology service providers, and payment gateway operators engaged by us solely for purposes connected with the Conference. Such parties are bound by contractual data processing obligations.
  • Conference sponsors and commercial partners: Only where you have provided explicit consent during registration. Once your data has been transmitted to a sponsor or partner on the basis of your consent, we are unable to retrieve or delete that data from the recipient's systems. Any request to withdraw from further sponsor communications must be directed to the relevant sponsor or partner.
  • ISACA Global and affiliated entities: Chapter administration records, CPE data, and event statistics may be shared with ISACA ("ISACA Global") for the purposes of chapter governance, CPE reporting, and programme benchmarking.
  • Regulatory, legal, and governmental authorities: Where required by applicable law, court order, regulatory direction, or to protect the rights, property, or safety of the Chapter, its members, or the public.

Our Selling Policy

We do not sell, rent, or trade personal data to any third party.

8. Photography, Videography, and Media Usage

Photography, videography, and audio-visual recordings will be conducted at Conference sessions, workshops, networking events, and associated activities.

  • For delegates resident in India: By attending the Conference, you acknowledge that your image, voice, and likeness may be captured in the course of Conference activities and used by the Chapter. Where we use your image in identifiable promotional materials beyond incidental appearance, we will seek your separate consent.
  • For delegates resident in the EEA, UK, or Canada: We rely on our legitimate interests in documenting and promoting the Conference as the lawful basis for incidental photography and video in public areas of the Conference. Where your image is used in a manner that singles you out, we will seek your explicit consent separately.

Where you have concerns about specific media use, please contact us at isacachennai@isaca-chennai.org. We will make reasonable efforts to address your request, subject to editorial discretion and the practical limitations of managing third-party attendee photography in a public conference environment.

Please be aware that delegates, speakers, sponsors, and media personnel attending the Conference may independently photograph or record video in public areas. The Chapter cannot control or prevent the sharing of such independently captured content.

9. International Transfers of Personal Data

The Conference is organized and administered primarily in India. Where personal data is transferred outside India to countries that have not been notified as providing adequate data protection under the DPDPA, such transfers will be made subject to appropriate safeguards as prescribed under the DPDPA.

EEA & UK Residents

Where your personal data is transferred to a country outside the EEA or UK that has not been the subject of an adequacy decision, such transfers will be made subject to appropriate safeguards under Article 46 of the GDPR or equivalent UK GDPR provisions.

Canadian Residents

Transfers of personal data outside Canada are made only where the receiving organisation is subject to comparable privacy obligations, or where we have ensured that the transfer is otherwise compliant with PIPEDA.

10. Data Retention

We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required or permitted by applicable law.

  • Operational records: Contact and registration data is retained for the duration required to administer the Conference and for a reasonable post-event period to resolve queries, process refunds, and address complaints.
  • CPE and participation records: In accordance with ISACA CPE reporting requirements, records of Conference attendance and session participation are retained for a period of up to three (3) years from the date of the Conference.
  • Financial and accounting records: Payment transaction records and related financial data are retained for the period required under applicable Indian taxation and accounting law, which is currently a minimum of eight (8) years.
  • Marketing and consent records: Records of consent obtained and withdrawn are retained for the period necessary to demonstrate compliance with applicable law.

Following expiry of the applicable retention period, personal data will be securely deleted or anonymized, subject to our obligations under applicable law and any legitimate archival or backup requirements.

11. Your Rights

Depending on your jurisdiction of residence, you may be entitled to exercise the following rights with respect to your personal data. We will respond to all verified requests within the timeframes prescribed under applicable law.

Under the DPDPA (India)

You have the right to: obtain a summary of your data; request correction of inaccurate data or completion of incomplete data; request erasure of personal data that is no longer necessary; grievance redressal; and nominate another individual to exercise these rights in the event of death or incapacity.

Under the GDPR / UK GDPR (EEA & UK)

You have the right to: Access (obtain copy); Rectification (correct data); Erasure (deletion); Restriction of processing; Data Portability (structured format); Object to legitimate interest processing; Withdraw consent at any time; and Lodge a complaint with your national supervisory authority (e.g. the ICO in the UK).

Under PIPEDA (Canada)

You have the right to: be informed of purposes at/before collection; withdraw consent at any time; access personal info and challenge its accuracy; request correction of inaccurate data; and file a complaint with the Office of the Privacy Commissioner of Canada (OPC).

12. Security of Personal Data

We implement appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, disclosure, alteration, or destruction, commensurate with the nature of the data and the risks involved. Our service providers and operational partners are required to maintain equivalent standards of data security.

Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure. Where a personal data breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by applicable law.

13. Grievance Redressal and Contact

For any privacy-related query, concern, request to exercise your rights, or grievance in connection with this Notice or our data processing practices, please contact:

ISACA Chennai Chapter Grievance Contact

We will acknowledge receipt of your request promptly and endeavor to respond substantively within the period prescribed under applicable law, being 72 hours for breach notifications after being aware of the incident, 30 days for data subject requests under the GDPR, and a comparable reasonable period under the DPDPA and PIPEDA.

14. Updates to This Notice

We may update or revise this Notice from time to time to reflect changes in applicable law, regulatory guidance, or our processing activities. Material changes will be communicated to registered delegates by email prior to taking effect. The version of this Notice that is current at the time of the Conference will govern our processing of personal data in connection with that Conference.

The current version of this Notice is available at isaca-chennai.org/privacy-notice. The effective date and version number are stated at the top of this Notice.