The DPDP Act and CCTV: what housing societies and large campuses need to know

Large housing societies, townships, tech parks and campuses record hours of CCTV every day. Under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025, that footage is very likely to count as digital personal data, because it shows people and vehicles linked to people.

Here is what the Act and Rules say that matters for CCTV, what is clear, and what is still open.

Not legal advice. This is a general explainer based on our reading of the official texts listed at the end. Your site's situation may differ. Please check with a lawyer before you change policies.

First, the dates

In early 2026 the ministry consulted on bringing parts of this timeline forward. We have not seen a final change in the official texts, so check the MeitY website before planning around these dates.

Does the Act apply to society CCTV?

The Act applies to digital personal data processed in India. It does not apply to personal data processed by an individual for a personal or domestic purpose. A flat owner's own doorbell camera may fall under that exemption. Gate cameras run by an RWA, facility management company or park operator are different: the organisation is not an individual acting for a domestic purpose.

Two roles in the Act matter here:

The open question: on what basis?

Section 4 allows processing only for a lawful purpose, either with the person's consent or for one of the "certain legitimate uses" listed in Section 7. That list does not include a general ground for "security of premises". It does include employment-related purposes, which may cover staff, but residents, visitors and delivery drivers are not employees.

So it is not yet settled how CCTV of residents and visitors fits the Act. Until the Data Protection Board or the courts give guidance, treat this as a question for your lawyer, not something to guess.

Notice: tell people clearly

Where consent is the basis, Section 5 requires a notice that tells the person what personal data is collected, the purpose, how to exercise their rights and how to complain to the Board. Rule 3 adds that the notice must stand on its own, be in clear and plain language, give an itemised description of the data, and explain how to withdraw consent as easily as it was given. People must be able to read the notice in English or in any language in the Eighth Schedule of the Constitution.

The Act does not mention CCTV signs, but signs at every entry are the simplest way to tell people before they are recorded. A good sign says:

Put the full notice on the society app, notice board and website, in the local language as well as English.

Purpose: decide it, write it down, stick to it

Write a purpose statement and keep to it. Footage collected for security should not quietly become a tool for tracking staff attendance or checking on residents' guests out of curiosity.

Retention: keep it only as long as needed

Section 8(7) says personal data should be erased once it is reasonable to assume the purpose is no longer being served, unless a law requires you to keep it. For security footage, that points towards a short, fixed retention period with automatic overwrite.

There is a complication. Rule 8(3) requires fiduciaries to keep personal data, related traffic data and logs of processing for at least one year, for the purposes listed in the Seventh Schedule (mainly requests from the government). Rule 6 also asks for logs to be kept for a year for security purposes. How Rule 8(3) applies to raw CCTV video at a residential site is not clear to us. Please get advice before deciding. Our guide to retention goes into this further.

Rights: be ready for requests

The Act gives people the right to a summary of their personal data and of how it is processed (Section 11), to correction and erasure (Section 12), to grievance redressal (Section 13) and to nominate someone (Section 14). The Rules require you to publish how people can make these requests, and to publish a contact person who can answer questions about processing (Rule 9). The government's summary says requests must be answered within ninety days at most.

For CCTV, decide who receives requests, how you check identity, how you avoid exposing other people in the footage, and how you record the response.

Security safeguards

Rule 6 lists minimum safeguards. In CCTV terms:

Failing to take reasonable security safeguards carries the highest penalty in the Act's Schedule, up to ₹250 crore.

Contracts with vendors (processors)

Section 8(2) allows a fiduciary to use a processor only under a valid contract. Section 8(7)(b) requires the fiduciary to make the processor erase data when it should be erased. Contracts with your security agency and vendors should cover permitted use, who can access footage, security, breach reporting to you, and deletion at the end.

If something goes wrong

Under Rule 7, a personal data breach must be reported to each affected person without delay, and to the Board, with a detailed report within 72 hours of becoming aware of it. A leaked clip on a WhatsApp group could count.

A short checklist for your committee

Gankya was designed around these ideas: every search needs a reason and goes into a tamper-evident audit log that cannot be edited, operators have personal logins and idle screens sign out, and data is purged automatically after a period the site sets. When someone asks for their data, the site can find, export or erase it, with a response letter and legal holds, and print a CCTV sign and privacy notice in English and Hindi (templates for your advisor to review). If you would like to try it on your site, a 30-day pilot is available.

Sources

Links checked on 4 October 2026. Laws and rules change; always check the latest official text.