DPDP NavigatorAct 2023 · Rules 2025
All guides
Role-Based Playbooks

DPDP for Community and Social Media Managers: User-Generated Content and Data

23 Jul 20268 min read

Comments, DMs, contest entries and community profiles all carry personal data obligations that don't stop at your own website's boundary.

Your community lives partly on platforms you don't control

Comments on a social post, direct messages handled through a platform inbox, and contest entries collected via a third-party form all involve personal data, but much of it sits on infrastructure owned by the social platform rather than your own systems. This doesn't remove your obligations — if you're deciding what data to collect and why (for a contest, a giveaway, or community moderation), you're likely acting as the Data Fiduciary even where the platform hosts the interaction.

Be clear internally about which parts of a campaign are 'your' data collection (a contest entry form asking for name, email and address to ship a prize) versus platform-native interactions (a public comment) where your role and access are more limited.

Contests, giveaways and lead-gen campaigns

Any campaign asking people to submit personal data (name, email, address, phone number, sometimes ID proof for prize fulfilment) needs the same itemised notice and consent treatment as any other collection point — a contest entry form is a data collection form, not just a marketing mechanic.

Be deliberate about downstream use: if entrants' emails collected for a giveaway are later added to your general marketing list, that's a new purpose beyond 'enter to win,' and needs its own clear disclosure and, generally, separate consent rather than being folded silently into the fine print.

Set a retention period for entry data and prize-fulfilment details (like shipping addresses) — these should typically be erased once the campaign concludes and prizes are delivered, not retained indefinitely in a spreadsheet.

Direct messages and moderation data

Where community management involves reviewing DMs or reports for moderation purposes, treat records kept about specific individuals (for instance, a log of a user flagged for repeated policy violations) with the same access and correction rights as any other personal data record — a flagged user can, in principle, ask what's held about them.

If a community platform or agency vendor manages your inbox and comments on your behalf, confirm there's a Data Processor contract in place, particularly if they export data (contact details harvested from DMs, for example) into a separate CRM or spreadsheet for follow-up.

Handling requests that arrive as public comments

It's common for a rights-adjacent request ('delete my info,' 'why do you have my number') to arrive as a public comment or DM rather than through a formal channel. Have a simple internal process for routing these to the right team rather than just replying with a customer-service script and moving on.

Where to go next

Use the Consent Notice Builder for contest and giveaway entry forms, and route anything that looks like a rights request through the Rights Navigator rather than handling it ad hoc in the comments.