DPDP compliance for co-working and flex-space companies
Co-working spaces collect member identity, access, and behavioural data. Here is how the DPDP Act applies to your operations.
What personal data do co-working spaces collect under DPDP?
Co-working operators collect: identity documents at onboarding (Aadhaar, PAN, passport); contact and billing details; biometric data if using fingerprint or facial recognition for access; workspace booking and usage records; visitor entry logs; CCTV footage; Wi-Fi access logs; and potentially health data for wellness facilities. Each category needs a lawful basis, a retention schedule, and appropriate security controls.
Is biometric access control lawful under DPDP?
Biometric data — fingerprints, facial recognition — is sensitive personal data under the Act and requires explicit, freely given consent from each member before collection. Members must be able to opt out and use an alternative access method (key card, PIN) without being disadvantaged. Biometric data must be stored with strong encryption, access must be strictly controlled, and it must be deleted when membership ends. If your access control vendor processes biometric data in the cloud, they need a DPA.
How must co-working spaces handle visitor data?
Visitor logs — name, phone, host member, entry/exit time — are personal data. Collect only what is necessary for security purposes. Retain visitor data for a short, defined period (typically 30–90 days) and delete on schedule. Do not use visitor data for marketing purposes without explicit consent. CCTV at entry points is covered by the physical surveillance DPDP rules — place notices, limit retention to 30 days, and control access to footage.
What rights do co-working members have under DPDP?
Members can request access to all data held about them — usage history, billing records, visitor logs associated with their account, biometric records. They can request correction of inaccurate data and erasure of non-statutory data on membership termination. Design your member portal to support these requests. On membership termination, delete biometric data immediately and other personal data after the statutory period for billing and tax records has passed.
How does DPDP apply to co-working apps and digital platforms?
Many co-working operators use apps for booking, access management, and community features. These apps collect usage data, location data (for hot-desk check-in), and social/community interaction data. Each vendor behind these apps is a Data Processor requiring a DPA. Community features — member directories, networking tools — must allow members to control what personal information is visible to other members and to opt out without losing access to core services.
What security safeguards do co-working spaces need under DPDP?
The DPDP Act requires Data Fiduciaries to implement appropriate technical and organisational security measures. For co-working spaces, this includes: encryption of biometric and identity data at rest and in transit; access controls on CCTV and visitor log systems; network security for shared Wi-Fi (member data should not be exposed to other members); vendor security assessments; and a documented breach response plan. A breach of biometric data is a high-severity incident requiring prompt Board notification.
Frequently asked questions
Do we need a separate consent for CCTV in common areas?
You do not need individual consent for CCTV in common areas — but you must inform members and visitors through clear signage. For members, include CCTV coverage in your membership agreement and privacy notice. For visitors, place prominent signage at entry. CCTV in private meeting rooms or phone booths is more invasive and would require stronger justification and member disclosure.
If a corporate client books dedicated desks for their team, who is the Data Fiduciary for that team's data?
It depends on what data is processed and by whom. If the corporate client's employees use your biometric access system, you are the Fiduciary for the biometric data (as you determine how it's collected and stored). The corporate client is the Fiduciary for their employees' employment data. You should have a DPA with the corporate client covering the data you process on their behalf (booking records, billing) and clarifying the biometric data responsibility.
How long should we keep billing and invoice data under DPDP?
Billing data and GST invoices must be retained for 7 years under tax regulations — this statutory obligation overrides any member's erasure request for those specific records. The member's personal details in those records can be retained for the statutory period. Non-statutory data — usage analytics, behavioural data, marketing preferences — should be deleted on membership termination or within the period the member consented to.
Assess your co-working space DPDP compliance
Niti Bharat's DPDP Readiness Assessment covers co-working operators — biometric consent, visitor data, CCTV rules, member rights, and app vendor DPAs.
Start Co-working DPDP Assessment