CCTV, privacy and the DPDP Act: practical points for Indian businesses

KINNEX Team5 min read


Video of identifiable people is personal data. India’s Digital Personal Data Protection Act, 2023 sets expectations for how organisations handle it. This article is a practical orientation, not legal advice; confirm specifics with your own counsel.

Purpose

Decide why you record: safety, security, loss prevention, compliance. Keep to that purpose. Cameras pointed into changing rooms, washrooms or private spaces are not acceptable under any purpose.

Notice

Put visible signs where cameras operate, stating that recording is in progress and who to contact. For staff, include CCTV in employment documentation.

Access

Limit who can view live and recorded footage. Use individual accounts, role-based rights and an audit log of who exported what.

Retention

Keep footage only as long as the purpose needs, and set the period deliberately. Longer is not safer; it is more data to protect and disclose. Set automatic overwrite, and a procedure to preserve clips needed for an incident.

Sharing

Share footage with police or other authorities through a documented request process. Record what was shared, when and with whom.

Security

Footage is sensitive. Encrypt storage and links where possible, change default passwords, keep recorders off the open internet, and patch firmware.

Review

Revisit camera positions and purposes regularly. Remove cameras that no longer serve a defined need.

Bring us the site, the challenge or the target outcome

Book an infrastructure assessment, or reach KINNEX directly by phone or WhatsApp.