The DPDP Act and CCTV footage, biometric access control and visitor data
How the DPDP Act 2023 and DPDP Rules 2025 apply to CCTV footage, biometric access control and visitor records, when duties start, and the State exemptions.
Ahuva Electronic Technologies · Published
Key points
- The Digital Personal Data Protection Act, 2023 (DPDP Act) governs digital personal data: data about an individual who is identifiable by or in relation to it. CCTV footage, biometric templates and visitor logs that identify people fit that definition.
- The Ministry of Electronics and Information Technology (MeitY) published the DPDP Rules, 2025 in the Gazette on 14 November 2025. The rules on notice, security safeguards, breach intimation and retention come into force 18 months later, in May 2027.
- The DPDP Act does not mention CCTV or biometrics by name, and it does not create a separate category of sensitive personal data. Its general duties apply to all personal data.
- Under rule 7 of the DPDP Rules, a Data Fiduciary must tell the Data Protection Board of India and each affected person about a personal data breach without delay, with a detailed report to the Board within 72 hours.
- The State has specific exemptions under section 17 of the DPDP Act, for example for the prevention and investigation of offences. Most of them still keep the duty to take reasonable security safeguards.
- Rule 6 of the DPDP Rules asks, at minimum, for encryption or masking, access control, access logs, backups, and one-year retention of logs and personal data unless another law requires otherwise.
Does the DPDP Act apply to CCTV footage and access-control data?
Yes, where a person can be identified. The DPDP Act applies to the processing of digital personal data in India, and defines personal data as any data about an individual who is identifiable by or in relation to such data. Processing includes collection, recording, storage, retrieval, use, sharing and erasure. A camera recording faces, a biometric reader storing fingerprint templates and a visitor system logging names and phone numbers all process personal data.
The owner of the system is usually the Data Fiduciary, the entity that decides why and how the data is processed. That is the hospital, campus, municipal corporation or plant. An integrator, maintenance contractor or cloud host that handles the data on the owner's behalf is a Data Processor. Section 8(1) of the DPDP Act keeps the Data Fiduciary responsible for processing done on its behalf, and section 8(2) requires a valid contract with any Data Processor. The Act's definition of person includes the State, so government bodies are Data Fiduciaries too, subject to the exemptions described below.
The DPDP Act has no special category for biometric data. Under the older Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, made under section 43A of the Information Technology Act, 2000 (IT Act), biometric information is sensitive personal data for body corporates. Section 44(2) of the DPDP Act omits section 43A, and under MeitY's phased commencement that takes effect with the Act's substantive provisions in May 2027. Biometrics still deserve the strongest controls, because a leaked fingerprint cannot be reissued like a card.
When do the DPDP obligations take effect?
The main obligations take effect in May 2027. Parliament enacted the DPDP Act on 11 August 2023. MeitY issued the DPDP Rules, 2025 as G.S.R. 846(E), dated 13 November 2025 and published in the Gazette on 14 November 2025. Rule 1 of the DPDP Rules sets three start points, counted from publication.
Rules 3, 5 to 16, 22 and 23 include notice (rule 3), security safeguards (rule 6), breach intimation (rule 7) and retention (rule 8). All of them start at 18 months. Buyers should check the Gazette for any later amendment before relying on these dates in a contract.
| Phase | When | What starts |
|---|---|---|
| Immediate | 14 November 2025 | Rules 1, 2 and 17 to 21: the Data Protection Board |
| One year | November 2026 | Rule 4: registration of Consent Managers |
| 18 months | May 2027 | Rules 3, 5 to 16, 22 and 23: notice, safeguards, breaches, retention, rights |
On what legal basis can CCTV, biometric and visitor data be processed?
The DPDP Act allows processing on two bases: consent given after a notice, or one of the legitimate uses listed in section 7. The Act does not decide which basis fits a particular camera or reader. That is a decision for the owner and its legal advisers, and it should be written down.
Where consent is the basis, rule 3 of the DPDP Rules requires a notice that stands on its own, lists the personal data itemised, states the specific purpose, and explains how to withdraw consent, exercise rights and complain to the Board. Section 7 lists legitimate uses that do not need consent. The ones most relevant to security systems are below.
- Section 7(a): data a person voluntarily gives for a specified purpose, such as a visitor giving details for a gate pass
- Section 7(c): the State or its instrumentalities performing a function under law, or in the interest of sovereignty, integrity or security of the State
- Section 7(f) and (g): responding to a medical emergency, or providing treatment during an epidemic or other threat to public health
- Section 7(h): ensuring safety or providing help during a disaster or a breakdown of public order
- Section 7(i): purposes of employment, including safeguarding the employer from loss or liability, which covers staff attendance and access records
What security safeguards and breach reporting does the law require?
Section 8(5) of the DPDP Act requires reasonable security safeguards to prevent a personal data breach, and rule 6 of the DPDP Rules sets the minimum. For a video management system (VMS) or access-control platform, the access logs in rule 6 mean a record of who viewed, exported or searched footage and templates.
Rule 7 sets breach duties. The Data Fiduciary must tell each affected person without delay, in plain language, what happened, the likely consequences, what is being done and what they can do. It must tell the Board without delay, and send a detailed report within 72 hours unless the Board allows longer. The Schedule to the DPDP Act sets penalties of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, and up to ₹50 crore for other breaches of the Act or Rules. The CERT-In directions of 28 April 2022 separately require a report to CERT-In within 6 hours for listed incidents, including data breaches.
- Encryption, obfuscation, masking or virtual tokens for personal data
- Access control on the computer resources used
- Logs, monitoring and review of access to personal data, to detect and investigate unauthorised access
- Backups and other measures to keep processing going after a compromise
- Retention of those logs and personal data for one year, unless another law requires otherwise
- Security safeguard clauses in the contract with every Data Processor
How long can CCTV footage and access logs be kept?
The DPDP Act sets no fixed retention period for CCTV. Section 8(7) requires erasure once the specified purpose is no longer served, unless another law requires retention. Rule 8(3) of the DPDP Rules then requires every Data Fiduciary to keep personal data, traffic data and logs of processing for at least one year from the date of processing, for the purposes in the Seventh Schedule, and to erase them afterwards unless another law requires longer.
Rule 8(3) does not mention video, and many owners overwrite footage within weeks. Owners should take legal advice on how rule 8(3) applies to each system, and document a retention period for each. For Central Government entities, CERT-In's Guidelines on Information Security Practices for Government Entities, released on 30 June 2023, already ask for CCTV footage of important and sensitive zones to be kept for at least 180 days. Retention drives storage cost directly, so the period has to be fixed before the VMS is sized.
What exemptions apply to government bodies and the State?
The State has several exemptions, but none takes a public body outside the whole DPDP Act unless the Central Government notifies it under section 17(2)(a). Most exemptions attach to a purpose, not to a type of organisation. Whether a given hospital, university or public sector undertaking counts as the State or its instrumentality is a legal question for each owner.
- Section 17(1)(c): processing for prevention, detection, investigation or prosecution of offences is exempt from most of Chapter II, Chapter III and section 16, but not from section 8(1) or 8(5), so security safeguards still apply
- Section 17(2)(a): the Act does not apply to processing by an instrumentality of the State that the Central Government notifies, in the interests of sovereignty, security of the State, public order and related grounds
- Section 17(4): for processing by the State or its instrumentalities, the erasure duty in section 8(7) and the right to erasure in section 12(3) do not apply
- Section 7(b) and (c): the State may process data without consent to provide a prescribed subsidy, benefit, service, certificate, licence or permit, or to perform a function under law
- Rule 5 and the Second Schedule: standards the State must follow when it processes data to provide a subsidy, benefit, service, certificate, licence or permit
What should an owner specify in a surveillance or access-control tender?
An owner should specify the controls that let it meet rules 6 to 8 and show that it did, rather than a line saying the system must be DPDP-compliant.
- Role-based access to live and recorded video, with every view, search and export logged
- Encryption of stored footage and biometric templates, and of links between devices and servers
- Storage of biometric templates rather than raw images, where the product allows
- A retention period per system, with automatic deletion at the end of it
- Privacy masking for cameras that overlook areas outside the intended view
- Time synchronisation to National Informatics Centre (NIC) or National Physical Laboratory (NPL) time, so logs stand up as evidence
- A Data Processor clause for the integrator and maintenance contractor, covering safeguards, breach notice to the owner and return or deletion of data at exit
- A notice at entry points and in visitor systems where consent is the basis
How Ahuva approaches surveillance and access-control data
Ahuva's surveillance scope covers IP surveillance, AI/ML analytics, automatic number plate recognition (ANPR) and centralised VMS. Its access control scope covers smart card, biometric and mobile credentials, turnstiles, boom barriers and visitor management, with CCTV and HR integration. Ahuva holds ISO 27001:2022 for information security management.
Frequently asked questions
- Is CCTV footage personal data under Indian law?
- Footage in which a person can be identified fits the DPDP Act's definition of personal data, which is any data about an individual who is identifiable by or in relation to it.
- Does the DPDP Act treat fingerprints and face data as sensitive data?
- The DPDP Act has no separate sensitive category. The older sensitive personal data (SPDI) Rules of 2011 under section 43A of the IT Act list biometric information as sensitive, until section 43A is omitted by section 44(2) of the DPDP Act.
- When does DPDP breach reporting start?
- Rule 7 of the DPDP Rules comes into force 18 months after the Rules were published on 14 November 2025, which is May 2027.
- Are police and municipal CCTV networks exempt from the DPDP Act?
- Processing to prevent, detect or investigate offences is exempt from most duties under section 17(1)(c), but reasonable security safeguards under section 8(5) still apply. Only a notified instrumentality under section 17(2)(a) is outside the Act altogether.
- Is the integrator responsible under the DPDP Act?
- An integrator or contractor handling data for the owner is a Data Processor. The owner, as Data Fiduciary, stays responsible and must have a valid contract with it.
Sources
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) · Ministry of Electronics and Information Technology
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) · Ministry of Electronics and Information Technology
- DPDP Rules, 2025 Notified (17 November 2025) · Press Information Bureau, Government of India
- Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 · Department of Information Technology (text hosted by PRS Legislative Research)
- Guidelines on Information Security Practices for Government Entities · CERT-In
- Directions under sub-section (6) of section 70B of the IT Act, 2000 (28 April 2022) · CERT-In
Related
Scoping a system like this? Talk to the team that designs, builds and maintains it.
Contact us