The DPDP Act and CCTV: what housing societies and large campuses need to know
Large housing societies, townships, tech parks and campuses record hours of CCTV every day. Under the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025, that footage is very likely to count as digital personal data, because it shows people and vehicles linked to people.
Here is what the Act and Rules say that matters for CCTV, what is clear, and what is still open.
Not legal advice. This is a general explainer based on our reading of the official texts listed at the end. Your site's situation may differ. Please check with a lawyer before you change policies.
First, the dates
- 11 August 2023: the DPDP Act received the President's assent.
- 13 November 2025: the DPDP Rules, 2025 were published in the Gazette (G.S.R. 846(E)). The government announced them on 14 November 2025.
- Phased start: the Rules on the Data Protection Board started immediately. The rule on Consent Managers starts one year after publication. Most of the rules that matter to a site, such as notice, security safeguards, breach intimation, retention and rights, start eighteen months after publication, which works out to 13 May 2027.
In early 2026 the ministry consulted on bringing parts of this timeline forward. We have not seen a final change in the official texts, so check the MeitY website before planning around these dates.
Does the Act apply to society CCTV?
The Act applies to digital personal data processed in India. It does not apply to personal data processed by an individual for a personal or domestic purpose. A flat owner's own doorbell camera may fall under that exemption. Gate cameras run by an RWA, facility management company or park operator are different: the organisation is not an individual acting for a domestic purpose.
Two roles in the Act matter here:
- Data Fiduciary: whoever decides why and how the data is processed. Usually the RWA, the park or campus management, or the company that owns the site.
- Data Processor: anyone processing data on the fiduciary's behalf, such as a security agency or CCTV vendor.
The open question: on what basis?
Section 4 allows processing only for a lawful purpose, either with the person's consent or for one of the "certain legitimate uses" listed in Section 7. That list does not include a general ground for "security of premises". It does include employment-related purposes, which may cover staff, but residents, visitors and delivery drivers are not employees.
So it is not yet settled how CCTV of residents and visitors fits the Act. Until the Data Protection Board or the courts give guidance, treat this as a question for your lawyer, not something to guess.
Notice: tell people clearly
Where consent is the basis, Section 5 requires a notice that tells the person what personal data is collected, the purpose, how to exercise their rights and how to complain to the Board. Rule 3 adds that the notice must stand on its own, be in clear and plain language, give an itemised description of the data, and explain how to withdraw consent as easily as it was given. People must be able to read the notice in English or in any language in the Eighth Schedule of the Constitution.
The Act does not mention CCTV signs, but signs at every entry are the simplest way to tell people before they are recorded. A good sign says:
- CCTV is in use, and who runs it (the RWA or management, by name).
- The purpose, for example "safety and security of residents, staff and property".
- Where to read the full notice (a short web link or a QR code to a page).
- Who to contact with questions, with a phone number or email.
Put the full notice on the society app, notice board and website, in the local language as well as English.
Purpose: decide it, write it down, stick to it
Write a purpose statement and keep to it. Footage collected for security should not quietly become a tool for tracking staff attendance or checking on residents' guests out of curiosity.
Retention: keep it only as long as needed
Section 8(7) says personal data should be erased once it is reasonable to assume the purpose is no longer being served, unless a law requires you to keep it. For security footage, that points towards a short, fixed retention period with automatic overwrite.
There is a complication. Rule 8(3) requires fiduciaries to keep personal data, related traffic data and logs of processing for at least one year, for the purposes listed in the Seventh Schedule (mainly requests from the government). Rule 6 also asks for logs to be kept for a year for security purposes. How Rule 8(3) applies to raw CCTV video at a residential site is not clear to us. Please get advice before deciding. Our guide to retention goes into this further.
Rights: be ready for requests
The Act gives people the right to a summary of their personal data and of how it is processed (Section 11), to correction and erasure (Section 12), to grievance redressal (Section 13) and to nominate someone (Section 14). The Rules require you to publish how people can make these requests, and to publish a contact person who can answer questions about processing (Rule 9). The government's summary says requests must be answered within ninety days at most.
For CCTV, decide who receives requests, how you check identity, how you avoid exposing other people in the footage, and how you record the response.
Security safeguards
Rule 6 lists minimum safeguards. In CCTV terms:
- Protect stored data, for example with encryption.
- Control access: personal logins, no shared passwords.
- Keep logs of who accessed footage, and review them.
- Have backups.
- Keep those logs for one year.
- Put security duties into vendor contracts.
Failing to take reasonable security safeguards carries the highest penalty in the Act's Schedule, up to ₹250 crore.
Contracts with vendors (processors)
Section 8(2) allows a fiduciary to use a processor only under a valid contract. Section 8(7)(b) requires the fiduciary to make the processor erase data when it should be erased. Contracts with your security agency and vendors should cover permitted use, who can access footage, security, breach reporting to you, and deletion at the end.
If something goes wrong
Under Rule 7, a personal data breach must be reported to each affected person without delay, and to the Board, with a detailed report within 72 hours of becoming aware of it. A leaked clip on a WhatsApp group could count.
A short checklist for your committee
- Name the fiduciary and list your processors.
- Write the purpose statement and the full notice; put up signs.
- Set retention periods and get advice on Rule 8(3).
- Publish a contact for questions and a process for requests.
- Add data protection clauses to vendor contracts.
- Write a one-page breach plan.
Gankya was designed around these ideas: every search needs a reason and goes into a tamper-evident audit log that cannot be edited, operators have personal logins and idle screens sign out, and data is purged automatically after a period the site sets. When someone asks for their data, the site can find, export or erase it, with a response letter and legal holds, and print a CCTV sign and privacy notice in English and Hindi (templates for your advisor to review). If you would like to try it on your site, a 30-day pilot is available.
Sources
- Digital Personal Data Protection Act, 2023 (Gazette of India, 11 August 2023), MeitY
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Gazette of India, 13 November 2025, MeitY
- PIB press release: "Government notifies DPDP Rules to empower citizens and protect privacy", 14 November 2025
- PIB backgrounder: "DPDP Rules, 2025 Notified", 17 November 2025
Links checked on 4 October 2026. Laws and rules change; always check the latest official text.