CCTV Laws in India: Privacy, the DPDP Act and Your Obligations

Installing CCTV is legal in India, but how and where you do it carries obligations. A plain-language look at privacy, the DPDP Act and workplace and residential rules.

Installing CCTV in India is legal and widespread, but it is not unregulated. Cameras capture personal data about identifiable people, which brings privacy rights and, increasingly, data-protection obligations into play. This is a plain-language overview to help you understand the landscape. It is general information, not legal advice — for a specific situation, consult a qualified lawyer.

The starting point: a right to privacy

The Supreme Court of India, in the 2017 Puttaswamy judgment, recognised privacy as a fundamental right under the Constitution. That does not ban CCTV, but it establishes the principle against which surveillance is judged: monitoring must be reasonable and proportionate, and it must respect a person's reasonable expectation of privacy. The clearest rule that flows from this is about where you point a camera.

Places you must not monitor

Regardless of who owns the property, cameras should never be placed where people have a strong expectation of privacy. These include:

  • Toilets, washrooms and changing rooms.
  • Bathing areas and similar private spaces.
  • Areas inside a private residence pointed into a neighbour's home or private space.

Installing cameras in such areas can attract serious criminal liability, including provisions dealing with voyeurism and violation of privacy. This is the one line that is never worth crossing.

The DPDP Act and CCTV footage

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's dedicated data-protection law, and CCTV footage of identifiable individuals is personal data under it. As the framework and its rules take effect, organisations that process such footage should expect to follow core principles:

  • Purpose limitation — collect footage for a clear, lawful purpose (security, safety) and do not repurpose it arbitrarily.
  • Notice — inform people that an area is under CCTV surveillance, typically with visible signage.
  • Data minimisation and retention — keep footage only as long as needed for the stated purpose, then delete it.
  • Security safeguards — protect stored footage from unauthorised access or leaks.
  • Accountability — organisations acting as data fiduciaries are responsible for how footage is handled.

Individuals and purely personal or domestic use enjoy lighter treatment than businesses, but any organisation systematically recording people should take these principles seriously and check the current rules as they are notified.

Signage and notice

Putting up clear signs that an area is monitored by CCTV serves two purposes: it respects the notice principle, and it strengthens the deterrent effect of the cameras. In practice, visible signage plus visible cameras is both good compliance hygiene and good security.

Workplace surveillance

Employers may install CCTV in common work areas — entrances, corridors, shop floors, warehouses — for security and safety. The reasonable approach is:

  • Inform employees that the workplace is monitored and why.
  • Restrict cameras to work areas; never in washrooms, changing rooms or rest areas where privacy is expected.
  • Limit who can access footage and log that access.
  • Set a clear retention period and delete footage after it.

Covert monitoring of employees is legally and ethically fraught and should be avoided without strong justification and legal counsel.

Residential and housing-society CCTV

Homeowners can install cameras on their own property, but common flashpoints arise in apartments and gated societies:

  • A camera should not be aimed into a neighbour's door, window or private space.
  • Society cameras in shared areas (lobbies, gates, parking) are generally acceptable but should be governed by the society's decisions, with footage access controlled and retention limited.
  • Disputes are common where a personal camera captures a shared corridor; frame the field of view as narrowly as your security need allows.

Where footage lives matters

A practical consequence of these principles is that where and how your footage is stored becomes a compliance question, not just a technical one. Systems that push every camera stream to a third-party cloud add another party holding personal data, and another set of questions about access, location and security. Keeping footage and analytics on-site reduces that surface area.

This is one reason local processing is attractive from a privacy standpoint. Parvekshak runs its AI analysis locally on-site rather than requiring footage to be streamed to a mandatory cloud, so video can stay within your premises and under your control — which aligns naturally with data-minimisation and security principles. It is a made-in-India system serving Delhi NCR, so it operates within the same legal environment as its customers. Technology choices do not replace your legal obligations, but keeping data local makes several of them easier to meet.

A short compliance checklist

  • Point cameras only at areas with a legitimate security need; never at private spaces.
  • Put up visible CCTV signage.
  • Define a clear purpose and a sensible retention period, then delete old footage.
  • Secure your recorder and footage; change default passwords and update firmware.
  • Limit and log who can access recordings.
  • For organisations, track the DPDP Act rules as they are notified and adjust practices accordingly.

In summary: CCTV is a legitimate and legal security tool in India, provided you respect privacy, give notice, secure and minimise the data you keep, and stay clear of private spaces. Treat footage as the personal data it is, and both your compliance and your customers' trust follow naturally.

Book Your Free Security Survey

Every CCTV company installs cameras. Parvekshak builds intelligent security systems that detect threats, alert instantly and help prevent incidents before they escalate.