Data controller or processor: who is responsible for PDPA at your event

The organiser is normally the data controller, deciding why photos are taken and how they will be used, while the photography vendor typically acts more like a processor carrying out that capture on the organiser's instructions. In practice, most event photography vendors also hold some controller-like responsibilities of their own once they decide how images are stored and delivered.

Key takeaways

  • The organiser usually decides the purpose of the photography, which places them closer to the data controller role.
  • The vendor carries out the capture and often makes its own decisions about storage and delivery, which brings in processor and controller responsibilities together.
  • Consent signage at the venue is typically the organiser's responsibility to arrange and display.
  • A government or statutory board event does not change this split in a fundamental way, though internal sign-off processes may add extra steps.
  • Clarifying roles with the vendor before the event avoids a gap where neither side assumes responsibility for a specific PDPA obligation.

What data controller and data processor mean under PDPA

A data controller decides why personal data, in this case, event photos of identifiable attendees, is being collected and what it will be used for. A data processor carries out data handling on the controller's instructions without independently deciding the purpose. These are not labels with a single fixed answer for every arrangement; they depend on who is actually making the decisions in a given booking.

For an event, the organiser is the party deciding that photography will happen, what it is for, such as marketing, a press release or an internal report, and broadly how the images will be used afterwards. That decision-making role is what typically puts the organiser closer to the controller side of the relationship, even before any contract is signed.

How responsibility typically splits between organiser and vendor

In practice, the split is less clean than a strict controller-processor line suggests. The photography vendor is carrying out the organiser's instructions, which looks like processing, but the vendor also usually makes its own decisions about how images are stored, how long a gallery stays online, and how delivery happens, which brings in some controller-like responsibility of its own.

This is why most event photography arrangements are better described as a shared responsibility than a single clear line. The organiser sets the purpose and typically owns the consent process at the venue. The vendor is responsible for how it handles the images once captured, including reasonable storage practices and not using photos beyond what was agreed with the organiser. Neither side can simply assume the other has PDPA fully covered without asking.

Since the organiser is usually the one deciding the event is happening and what the photography is for, displaying consent signage at entry points and clearly communicated areas is normally the organiser's responsibility to arrange. The vendor can advise on wording and placement from experience, but the organiser is best placed to know the venue layout and where attendees will actually see it.

The vendor's responsibility sits more on the handling side: not sharing images outside the agreed purpose, applying reasonable care to storage, and following any specific instructions the organiser gives about restricted attendees or sensitive sessions. Getting this split explicit, rather than assumed, means signage does not get forgotten because each side thought the other was arranging it.

Questions to clarify with your vendor before the event

Before the event, it is worth confirming directly: who is putting up consent signage and where, what happens if an attendee asks not to be photographed, how long the vendor's copy of the gallery stays accessible, and whether any images need extra handling because of a restricted session or a sensitive attendee list.

These questions take a few minutes to settle in writing and remove the most common source of confusion, which is each side assuming the other has a particular obligation covered. A vendor experienced with government and statutory board bookings will usually have answers ready for these questions without needing to think them through for the first time, which is worth checking for if your event has any unusual sensitivity around attendee privacy.

Putting the split in writing before signing

A short paragraph in the booking confirmation or brief, stating plainly who arranges consent signage and what the vendor's responsibilities are around storage and delivery, removes the ambiguity that a strict legal definition can leave behind. This does not need to read like a formal data processing agreement to be useful; it just needs to be clear enough that neither side is guessing.

For an organisation with its own data protection officer, this written split also gives them something concrete to review before approving a vendor, rather than having to infer the arrangement from a general services quote. Raising this early in the conversation, rather than after the contract is already signed, is the easiest way to avoid a gap surfacing later.

Questions organisers ask

Is the organiser or the photography vendor responsible for attendee consent?

The organiser is usually responsible for arranging consent signage and communicating it to attendees, since they are the party deciding the event is happening and what the photography is for. The vendor is typically responsible for how it handles the images once captured, rather than for the initial consent process itself.

Does this split change for a government or statutory board event?

The basic split does not change fundamentally, though a government or statutory board event may have its own internal sign-off process for consent wording and for which sessions can be photographed at all. Confirming those internal requirements with the organiser's own compliance team alongside the vendor is worth doing early.

Who decides what happens if an attendee does not want to be photographed?

This is typically an organiser decision communicated to the vendor as a clear instruction, such as an area to avoid or a specific person to be mindful of. The vendor follows that instruction on the day rather than making the call independently.

Does the vendor need its own PDPA policy separate from the organiser's?

Most established vendors do maintain their own practices around storage and handling, since they are making some decisions independently once images are captured. This does not replace the organiser's own consent and purpose obligations; the two sit alongside each other rather than one covering the other entirely.

If you want to talk through how consent and handling responsibilities would split for your event, reach out through our contact page before you finalise the brief.

Related reading: pdpa event photography consent guide · who owns event photos singapore · government events.

Let's talk

Planning an event in Singapore?

Send us the date, venue and programme. You will get a considered production plan and a fixed nett quote.