What India's DPDP Rules Mean for Your CCTV Footage
You installed cameras to protect people and assets. But under India's Digital Personal Data Protection (DPDP) Rules, every frame that shows an identifiable face, number plate, or badge is now regulated personal data — and most facilities are running surveillance programs that were never designed with that in mind. If you manage security or IT for an office, plant, or multi-site operation, the question is no longer just "are the cameras working?" It is "can we account for the footage the way the law now expects?"
This article explains, in plain terms, what the DPDP framework means for CCTV footage in India and where typical deployments fall short. It is general guidance for facility and IT teams, not legal advice — treat your data protection officer or counsel as the final word on how the rules apply to your organisation.
Why CCTV footage counts as personal data under the DPDP Rules
The Digital Personal Data Protection Act, 2023, and the DPDP Rules notified on 14 November 2025 govern "digital personal data" — any data about an identifiable individual, held in digital form. Video that captures a recognisable person is exactly that. So is a licence plate tied to an owner, or an access-card event that identifies an employee.
In the language of the law, the organisation that decides why and how footage is captured is the "data fiduciary" (the party responsible for the data), and the people on camera are "data principals" (the individuals the data is about). Once you accept that footage is personal data, a set of obligations follows: you need a lawful basis to collect it, a defined purpose, limits on how long you keep it, and safeguards on who can see it. A camera network is no longer just an operational tool; it is a personal-data processing system.
The compliance clock is already running
The DPDP Rules take effect in phases, and that phasing gives security teams a realistic runway rather than a single deadline. The Data Protection Board — the regulator that will hear complaints and levy penalties — stood up immediately on notification. Rules for Consent Managers and certain operational provisions carry roughly a 12-month horizon. The core obligations that matter most for surveillance — consent and notice, purpose limitation, data retention and erasure workflows, children's-data protections, and security safeguards — carry an approximately 18-month runway from notification.
Eighteen months sounds comfortable until you map it against a real estate. If you operate dozens of sites with mixed camera generations, inconsistent recorder settings, and no central record of retention periods, the work of standardising all of that is measured in quarters, not weeks. The teams that treat 2026 as preparation time will be in a very different position from those that wait for the deadline to arrive.
Retention and erasure: where most CCTV setups fall short
The single most common gap is retention. A large share of installed systems either overwrite on a loop nobody has documented, or — worse — quietly keep footage far longer than any stated purpose requires because storage was over-provisioned and nobody set a limit. The DPDP framework pushes in the opposite direction: keep personal data only as long as the purpose needs it, then erase it.
Practically, that means three things for a surveillance program. First, write down a retention period for each class of footage and be able to justify it (an incident-investigation window is defensible; "indefinitely, just in case" is not). Second, make sure your recorders and video management system actually enforce that period automatically, rather than relying on disks filling up. Third, keep the retention rule consistent across every site, so a camera in one branch is not silently holding six months of footage while policy says thirty days.
Notice, signage, and the purpose you can defend
The rules expect clear, plain-language notice about what data is collected and why. For CCTV, the everyday form of that is signage: visible notices at entry points telling people the area is under surveillance, who is responsible, and the purpose. Vague "smile, you're on camera" boards do not meet the spirit of a plain-language notice.
Purpose limitation matters just as much. If footage is captured for physical security and incident investigation, using it for unrelated purposes — productivity monitoring, for instance — invites exactly the kind of challenge the law is designed to enable. Decide the purpose deliberately, state it, and stay inside it. Where cameras cover areas involving members of the public or, in some settings, minors, the stricter expectations around children's data are worth flagging early to your compliance team.
Security safeguards: who can see the footage, and can you prove it
Footage is only as compliant as the controls around it. The rules point toward reasonable security safeguards — access controls, encryption where appropriate, and monitoring — and toward being able to demonstrate them. Two questions separate a defensible program from an exposed one. Who can pull up or export recordings, and is that access restricted by role rather than shared logins? And is there an audit trail showing who accessed what, and when?
There is also a breach dimension. The framework expects prompt notification to affected individuals and, for reportable incidents, to the Data Protection Board within a tight window. A surveillance archive sitting on an unpatched recorder with a default password is precisely the kind of exposure that turns into a reportable event. Bringing footage storage onto access-controlled, monitored infrastructure — whether hardened on-premise or cloud-based — is the foundation everything else rests on.
A readiness checklist for facility and IT teams
You do not need to solve everything at once, but you do need visibility. Start by inventorying every camera and recorder across sites and confirming where footage actually lives. Document a retention period per footage type and verify the system enforces it automatically. Review who has access to live and recorded video, and move to role-based permissions with audit logging. Refresh entry-point signage so the notice is clear and current. Finally, write down the purpose of your surveillance and make sure day-to-day use matches it. Each step is measurable, and together they turn "we have cameras" into "we can account for our footage."
Key takeaways
- CCTV footage of identifiable people is personal data under India's DPDP Rules, and your organisation is the responsible data fiduciary.
- Core surveillance obligations — notice, purpose limitation, retention and erasure, and security safeguards — carry roughly an 18-month runway from the November 2025 notification, so 2026 is preparation time.
- Retention is the most common gap: define a period per footage type and make the system enforce it, consistently across every site.
- Post clear, plain-language signage, stay inside a stated purpose, and treat public or minor-facing areas with extra care.
- Lock down access with role-based permissions and audit trails, and keep footage on monitored, access-controlled infrastructure.
- This is general guidance, not legal advice — confirm specifics with your data protection officer or counsel.
Not sure how your current surveillance setup measures up? Contact Foxnet for a site assessment and we will map your cameras, storage, and access controls against a practical readiness baseline.