CCTV, privacy and the DPDP Act: practical points for Indian businesses
KINNEX Team5 min read
Video of identifiable people is personal data. India’s Digital Personal Data Protection Act, 2023 sets expectations for how organisations handle it. This article is a practical orientation, not legal advice; confirm specifics with your own counsel.
Purpose
Decide why you record: safety, security, loss prevention, compliance. Keep to that purpose. Cameras pointed into changing rooms, washrooms or private spaces are not acceptable under any purpose.
Notice
Put visible signs where cameras operate, stating that recording is in progress and who to contact. For staff, include CCTV in employment documentation.
Access
Limit who can view live and recorded footage. Use individual accounts, role-based rights and an audit log of who exported what.
Retention
Keep footage only as long as the purpose needs, and set the period deliberately. Longer is not safer; it is more data to protect and disclose. Set automatic overwrite, and a procedure to preserve clips needed for an incident.
Sharing
Share footage with police or other authorities through a documented request process. Record what was shared, when and with whom.
Security
Footage is sensitive. Encrypt storage and links where possible, change default passwords, keep recorders off the open internet, and patch firmware.
Review
Revisit camera positions and purposes regularly. Remove cameras that no longer serve a defined need.