Data protection compliance: DPDP, GDPR and US state privacy law

  • India DPDP Act, 2023
  • EU and UK GDPR
  • United States 20 state laws

This is the jurisdiction detail behind our Privacy & Cookies policy. It sets out how C4 Events meets India’s Digital Personal Data Protection Act, the EU and UK GDPR, and the US state privacy laws, and exactly how you exercise a right under any of them. One address handles all of it: saurabh@wearec4e.com, subject line PRIVACY.

Last updated 6 August 2026

Who you are dealing with

C4 Events is the corporate events business of The C4E Collective. We run events for corporate clients across Asia, the Gulf and beyond, and this website is a marketing and enquiry site. The same legal entity answers under every regime below, only the label changes.

  • India

    Data Fiduciary

    Under the DPDP Act, 2023. Saurabh Garg is our Grievance Officer.

    Escalation: Data Protection Board of India.

  • EU and UK

    Data controller

    Under the EU GDPR and the UK GDPR, for everything collected on wearec4e.com.

    Escalation: the ICO, or your national supervisory authority.

  • United States

    Business / controller

    Under the state consumer privacy statutes, for the personal information described here.

    Escalation: the CPPA, or your state Attorney General.

More than one regime can cover the same person. An Indian citizen who fills in our form from Berlin has GDPR rights and DPDP rights at once. We apply whichever gives you more, and we do not ask you to prove where you live before we help you.

The four things that make compliance simple here

Most of the hard parts of privacy law are about advertising, profiling and data sales. This site does none of them, which is why the answers below are short.

  • No sale, no sharing

    Not in the ordinary sense, and not in the specific sense the California, Colorado, Connecticut and Virginia statutes give those words. None in the preceding 12 months, and never for anyone under 16.

  • No advertising technology

    No Meta Pixel, no LinkedIn Insight Tag, no Google advertising features, no retargeting, no cross-context behavioural advertising.

  • No profiling, no robots deciding

    A human reads every enquiry. Nothing here produces a legal or similarly significant effect by machine.

  • No sensitive data

    No health data, biometrics, precise geolocation, or racial, religious, political or union data. Dietary and accessibility details for an event are collected later, under contract, and deleted when the event closes.

How to exercise any right, anywhere

Email saurabh@wearec4e.com with PRIVACY in the subject. Tell us what you want done and the email address or phone number you gave us, so we can find your record. You do not need a form, a template or a lawyer.

  1. You writeOne line by email. No form, no fee, no ID document for a website enquiry record.
  2. We acknowledgeWithin 7 days, with the name of the person handling it.
  3. We resolveWithin 30 days. If a request is complex we tell you why before the first deadline passes, never after.
  4. You appealWithin 60 days if we refuse. We answer in 45 days, in writing, naming the exemption we relied on.

Our 30-day promise sits inside every statutory clock that applies to us.

ClockWhat the law allowsWhat we do
EU and UK GDPROne month, extendable by two for complex requests30 days
US state laws45 days, extendable once by a further 4530 days
US appeal45 days to answer, 60 days for you to lodge it45 days, offered in every state
India, DPDPThe period we publish for grievance redressal7 days to acknowledge, 30 to resolve
  • Cost: free. We charge only if a request is manifestly unfounded or repetitive, and we tell you first.
  • Verification: we match your request to the contact details already in our records. If it comes from a different address we ask one question that only the record holder can answer.
  • Authorised agents: an agent may act for you in California and elsewhere. Send us written permission signed by you, and we may still confirm with you directly.

What you can ask for, and where it comes from

Every right in this table is available to you here, whichever column you sit in.

Your rightIndia
DPDP
EU and UK
GDPR
United States
state laws
Know what we hold, and get a copyYesYesYes
Correct or complete itYesYesYes
Have it deletedYesYesYes
Take a portable copy elsewhereNot in the statute, we do it anywayYesYes
Withdraw consent, or objectYesYesYes
Opt out of sale, targeted ads, profilingNothing to opt out ofYesYes
Nominate someone to act if you die or lose capacityYesNot in the statuteNot in the statute
Appeal a refusal to usYesYesYes
Complain to a regulatorYesYesYes

A dash means the statute does not name that right. It does not mean we refuse it. Ask for a portable copy from India and you will get one.

India: the DPDP Act, 2023

The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and come into force in phases.

  1. 14 November 2025The Data Protection Board of India stands up. In force.
  2. 13 November 2026The consent manager provisions begin.
  3. 13 May 2027The substantive obligations on Data Fiduciaries bind.

We are not waiting for 2027. The practices on this page are already how the site runs.

Your rights as a Data Principal

  • Right to a summary, under section 11: what personal data we hold about you, what we do with it, and who we have shared it with.
  • Right to correction, completion, updating and erasure, under section 12. We erase when the purpose is served, unless a law tells us to keep the record.
  • Right to grievance redressal, under section 13, before you approach the Board.
  • Right of nomination, under section 14: you may nominate another person to exercise these rights for you in the event of death or incapacity. Name them in an email to us.
  • Right to withdraw consent at any time, under section 6(6), as easily as you gave it. One line by email is enough, and we stop.

Consent, notice and duties

We process your data for the lawful purpose you gave it for, which on this site is answering your enquiry about an event. The enquiry form carries a plain notice at the point of collection rather than a link to a wall of text. Where the Act’s legitimate uses apply, such as responding to a communication you started yourself, we say so rather than manufacturing a consent record.

The Act also puts duties on you, the Data Principal, including not filing false or frivolous complaints. We mention it because the Act does, not because we expect to need it.

Grievance, children and transfers

  • Grievance Officer: Saurabh Garg, saurabh@wearec4e.com. If we do not resolve it, you may complain to the Data Protection Board of India.
  • Breach notification runs to the Board and to every affected Data Principal, in plain language rather than in a legal notice.
  • Children: this is a business-to-business site. We do not knowingly process the data of anyone under 18, and we never use children’s data for tracking, behavioural monitoring or advertising.
  • Transfers: the Act permits transfer outside India except to territories the Central Government restricts. We honour any such restriction, and our processors are named in the privacy policy.

Europe and the United Kingdom: the GDPR

The EU GDPR and the UK GDPR give you the same core rights. If you are in the EEA, the UK or Switzerland, these are yours.

Our legal bases

Article 6 of the GDPR, and what each basis actually covers on this site.

ArticleBasisWhat we use it for
6(1)(b)ContractAnswering your enquiry, quoting for an event, and delivering an event you book.
6(1)(f)Legitimate interestsSite security, spam control, and understanding which pages get read. We have run the balancing test, we keep the data minimal, and you can object at any time.
6(1)(a)ConsentAnalytics cookies where your jurisdiction requires consent, and any marketing email. Withdrawing is one click, and it never costs you a service.
6(1)(c)Legal obligationTax and company law records, once you become a client.

Your rights

  • Access (Article 15), including a copy of the data itself.
  • Rectification (Article 16) and erasure (Article 17).
  • Restriction (Article 18) and objection (Article 21), including an absolute right to object to direct marketing.
  • Portability (Article 20): a machine-readable copy, sent to you or to another controller.
  • Not to be subject to automated decision-making (Article 22). We do none, so there is nothing here to opt out of.
  • To complain to a supervisory authority. In the UK that is the Information Commissioner’s Office. In the EEA it is the authority for the country you live or work in, and you can use it whether or not you come to us first.

Transfers, retention and breaches

  • Transfers

    Where personal data leaves the UK or the EEA we rely on the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Addendum, with the transfer risk assessment behind them.

  • Retention

    24 months for enquiries that go nowhere. Engagement plus 8 years for client records, which is the longest our tax and company law obligations require. Full list in the privacy policy.

  • Breaches

    A personal data breach that risks your rights goes to the supervisory authority within 72 hours, and to you without undue delay.

We have not appointed an Article 27 representative in the EU or the UK. We say that plainly rather than leave you guessing: write to the address above and the same people answer.

The United States: state privacy law

There is no federal privacy statute. Twenty states have a comprehensive consumer privacy law in force during 2026. Four more passed in 2026 and start later.

  • In force during 2026

    California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Texas, Florida, Maryland, Minnesota, Montana, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska and Rhode Island.

  • Passed in 2026, in force later

    Alabama, Louisiana, Oklahoma and Vermont.

Most of those statutes only bite above a threshold, commonly 100,000 residents’ data in a year, or 25,000 plus revenue from selling it. A business-to-business events company with an enquiry form is under every one of those numbers. We extend the rights anyway, to every US resident, in every state. Arguing about thresholds with someone who wants their own data deleted is a poor use of everybody’s afternoon.

Your rights, whichever state you are in

  • Know and access: the categories and the specific pieces of personal information we have collected, where we got them, why we have them, and the categories of third party we disclosed them to.
  • Delete the personal information we hold about you.
  • Correct anything inaccurate.
  • Portability: a copy in a portable, readily usable format.
  • Opt out of sale, of sharing for cross-context behavioural advertising, of targeted advertising, and of profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of. Nothing changes if you send the request anyway.
  • Limit the use of sensitive personal information. We do not collect any.
  • Appeal a refusal, which Virginia, Colorado, Connecticut and most later statutes require us to offer. Ours is described above and open to everyone.
  • Non-discrimination: exercising a right never changes the price, the service or the answer you get from us.

California specifics

The CCPA as amended by the CPRA, item by item, against what this site does.

RequirementWhere we stand
Notice at collectionIdentifiers (name, email, phone), commercial information (the event you are asking about), internet activity (pages read, via analytics). No sensitive personal information, no biometric or geolocation data. Purposes and retention are in the privacy policy.
Do Not Sell or Share My Personal InformationNo link on this site, because there is nothing to switch off. We do not sell or share personal information and have not in the last 12 months.
Opt-out preference signalsWe honour the Global Privacy Control. Since we run no sale or sharing, the signal has nothing to disable, and analytics stay off for anyone who blocks the cookie.
Shine the Light, Civil Code 1798.83We disclose no personal information to third parties for their own direct marketing. Ask us and we will confirm it in writing.
Financial incentivesNone. No loyalty programme, and we pay nobody for their data.
ComplaintsThe California Privacy Protection Agency, or the California Attorney General. In other states, your state Attorney General.

What this page is not

It describes what this website actually does, checked against the site rather than copied from a template. It is not legal advice, and we are not lawyers. If you are relying on it for your own compliance programme, have your counsel read it. If you find something here that does not match what the site does, tell us and we will fix the site or fix the page, whichever is wrong.

Contact

Saurabh Garg, Grievance Officer and privacy contact

The C4E Collective

saurabh@wearec4e.com, subject line PRIVACY

Tell us about the event.

Dates, city, headcount, and what has to go right on the day.