Does DPDP apply to CCTV cameras and physical surveillance?

Does DPDP apply to CCTV cameras and physical surveillance?
Physical Surveillance

Does DPDP apply to CCTV cameras and physical surveillance?

CCTV footage captures personal data about identifiable individuals. The DPDP Act applies — but the rules differ for public safety purposes versus commercial use.

Quick Answer: CCTV footage containing identifiable individuals is personal data under the DPDP Act, and organisations that operate CCTV systems are Data Fiduciaries for that footage. You must have a lawful basis for CCTV operation, inform individuals that they are being recorded (typically through visible signage), limit recording to what is necessary for the stated purpose, retain footage only for as long as needed, restrict access, and delete footage on schedule. The state and law enforcement operating CCTV for public safety purposes have different obligations than commercial entities using CCTV for loss prevention or employee monitoring. Enforcement begins May 2027.

Is CCTV footage personal data under the DPDP Act?

Yes. The DPDP Act defines personal data as any data about an individual who is identifiable from that data. CCTV footage that captures the faces, movements, or behaviour of identifiable individuals is personal data. Footage from a camera in a busy public area where no individuals are identifiable — for example, a crowd-counting camera with no facial detail — may not be personal data, but the threshold for identifiability is low: if you could identify someone from the footage with reasonable effort, it is personal data.

What is the lawful basis for operating CCTV systems under the DPDP Act?

Commercial entities operating CCTV for legitimate purposes — retail loss prevention, workplace security, access control — typically rely on legitimate interests as their lawful basis where the Act provides for it, or on security safeguard obligations. However, the DPDP Act's structure around 'legitimate use' is not a blanket permission: you must be able to show the processing is proportionate, necessary, and does not override individuals' interests. Employee monitoring via CCTV requires disclosure — employees must know they are being recorded and for what purpose.

Must you tell people they are being recorded on CCTV under DPDP?

Organisations operating CCTV must inform individuals they are being recorded. The standard mechanism is clear, prominent signage at all camera locations indicating that CCTV is in operation, who operates it, and the purpose. For workplace CCTV, this should also be in employee contracts or handbooks. The DPDP Act does not prescribe a specific format for CCTV notices, but the principle is that individuals should not be surprised to discover they were recorded.

How long can you retain CCTV footage under the DPDP Act?

CCTV footage should be retained only for as long as it is needed for the stated purpose. For most commercial CCTV, a 30-day rolling overwrite is standard unless an incident requires preservation. Access to footage should be strictly controlled — only security personnel, HR (for workplace incidents), or law enforcement on legal request should have access. Log all access to footage, including who reviewed it and why. Footage shared with police on request should be documented.

Does DPDP apply to facial recognition and biometric CCTV systems?

CCTV that goes beyond simple recording — using facial recognition or other biometric analysis to identify individuals — involves biometric data, which is sensitive personal data under the Act. Biometric analysis of CCTV footage requires a higher standard of justification, explicit disclosure, and in many cases explicit consent. If you are using or considering AI-powered facial recognition in your CCTV system, get specific privacy counsel before deployment.

Is using CCTV to monitor employees lawful under the DPDP Act?

Using CCTV to monitor employee performance — not just for security — is a processing activity that must be disclosed in employee privacy notices and employment contracts. Employees have the right to access footage that contains their personal data and to request correction of records derived from it. Continuous 24/7 monitoring of individual employees, particularly in non-security areas, is likely to be disproportionate. Limit workplace CCTV to areas where security monitoring is genuinely necessary.

Frequently asked questions

Do we need consent to operate CCTV in our office?

You do not need individual consent from every person who passes through your CCTV field of view, but you must inform them through prominent signage. For employees, the monitoring must be disclosed in their employment documentation. The lawful basis for most commercial CCTV is not consent but rather a legitimate security or safety purpose that is proportionate to the privacy impact. Consent would be required for more intrusive monitoring — for example, CCTV in break rooms or toilets would be unlawful regardless of consent.

How long can we retain CCTV footage?

Retain only as long as needed for the purpose. For general security monitoring with no incident, 30 days is the standard working period. If footage captures an incident — a theft, an accident, a dispute — retain it until the matter is resolved, including any legal proceedings. Do not retain footage indefinitely as a general archive; this is disproportionate and creates unnecessary data protection risk.

Can we share CCTV footage with police?

Yes, you can share footage with police on a lawful request — typically a written request citing the investigation. Document the request and your response. You are not required to give police unsupervised access to your CCTV system; provide the specific footage requested. Where police present a court order or formal requirement, compliance is generally necessary, but verify the document's authenticity and scope before sharing.

Review your physical security data practices

Niti Bharat's Privacy Gap Analysis covers physical surveillance, CCTV retention policies, employee monitoring disclosures, and facial recognition risk — a complete assessment of your non-digital data processing.

Start Privacy Gap Analysis
Previous Post Next Post

Get Free DPDP Checklist