The DPDP Audit Tool
Compliance for DPDP Rules for CCTV Footage
📹

DPDP Rules for CCTV Footage
Liability Check

👁️

Your CCTV footage is personal data under the DPDP Act. Ignoring consent, notice, and retention rules for this data type means inviting penalties up to ₹250 Crore.

Why DPDP Rules for CCTV Footage is at Risk

Every frame of your CCTV footage captures **identifiable personal data**, from faces to movement patterns. Under the DPDP Act, processing this data without a **lawful basis** – like explicit notice or a clear legitimate interest for security – is a serious violation. This isn't just about protecting your premises; it's about protecting the privacy of everyone captured, from employees in a Bangalore tech park to customers in a Mumbai retail store. The Data Protection Board will scrutinize your **notice boards, retention policies, and data security protocols** for this sensitive information.

Common Violations

  • 1.Failing to display prominent, clear **CCTV notice boards** at entry points, detailing purpose, contact, and data rights.
  • 2.Retaining CCTV footage **longer than strictly necessary** (e.g., holding 90 days of footage when 30 days are sufficient for security purposes).
  • 3.Allowing **unrestricted access** to CCTV feeds or recordings by unauthorized personnel without a clear audit trail or purpose.

The Immediate Fix

Immediately conduct an audit of all your CCTV cameras. Ensure every camera location has a prominent, easily readable DPDP-compliant notice explaining data collection, purpose, and contact information. Define and enforce a strict data retention policy, deleting footage securely once its lawful purpose is fulfilled, typically within 30-90 days for security.

Get DPDP Updates for DPDP Rules for CCTV Footage

We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.

Unbundled consent — the DPDP gold standard. Unsubscribe anytime. Privacy Policy

or
Start 30-Second Audit

Projected Compliance Deadline: Immediate

Next step after the audit

The audit shows the gaps. Sanctum closes them. One programme covers legal position, data map, gap analysis, implementation, tooling, training, a written readiness opinion, and breach cover, under one accountable owner. See the all-in-one programme