logo

Compliance · Analysis

What the DPDP Rules change for CCTV, and when

DPDP CCTV compliance turns on two dates. Rule 4 of the Digital Personal Data Protection Rules commences on 13 November 2026, requiring a clear consent notice wherever cameras capture identifiable people. The penalty provisions in Section 33 commence on 13 May 2027, reaching 250 crore rupees for a security safeguards failure.

By Dr. Vivek Gujar · Chief Strategy Officer, IndoAI · 1 September 2026 · 10 min read

Two things are true at once about India's data protection regime and video surveillance. The first is that most organisations running cameras are not ready. The second is that the work required is smaller and more boring than the compliance industry suggests. This piece separates the two.

Scope note

This is an operational reading written for people who own camera systems, not a legal opinion. IndoAI is not a law firm. Take advice on your own facts before you rely on any of it. Where a date or a figure appears below, it is stated so you can check it against the notified text rather than take our word for it.

The two dates that actually matter

The Digital Personal Data Protection Act was passed in 2023. The Rules under it were notified in November 2025, and they commence in tranches rather than all at once. For anyone running cameras, two commencement points do the work.

Commencement points relevant to camera systems
DateWhat commencesPractical effect
13 November 2026Rule 4, notice to the data principal A standalone, plain-language notice is required wherever identifiable individuals are captured and their data processed on the basis of consent
13 May 2027Section 33 and the penalty machinery Financial penalties become enforceable, reaching 250 crore rupees for a failure of reasonable security safeguards

The eighteen-month gap between them is not a grace period in any meaningful sense. It is the window in which the obligations exist and the fine does not. Anything you build in that window is evidence of good faith later; anything you defer is a documented decision to defer.

What DPDP CCTV compliance actually requires on site

Strip away the framework language and four obligations touch a camera system directly.

1. Notice at the point of capture

Rule 4 governs how notice is given: standalone, meaning it cannot be folded into an employment contract or a visitor register's terms; in clear and plain language; itemising what is collected and why; and carrying the means to withdraw consent and to complain. For cameras this translates into a readable notice at every entry point, backed by a fuller notice that is actually reachable.

The common failure is not the absence of a sign. It is a sign that says recording is in progress and nothing else. A notice with no stated purpose, no retention position and no grievance route does not do the work Rule 4 asks of it.

2. Purpose limitation, camera by camera

Footage collected to detect intrusion cannot quietly become footage used to assess employee productivity. Each camera needs a stated purpose, and the purpose has to be the one the system actually serves. This is where most organisations fail, and it is discoverable in an afternoon: if you cannot say in one sentence why a given camera exists, it has no lawful basis for its output.

3. Retention that ends

Personal data must be erased when the purpose is served and retention is no longer required. In practice this means a defined retention window per camera or per zone, an automatic deletion that actually runs, and a record that it ran. Thirty days is a common working figure for general surveillance; incident footage pulled for investigation is a separate, justified retention with its own end date.

4. Security safeguards you can evidence

This is the obligation the largest penalty attaches to. For camera estates it means access control on the recorder and the viewing client, encryption in transit, logs of who viewed what, and patched firmware. Default credentials on a network video recorder are the single most common finding in any honest audit, and the hardest to defend after an incident.

Where consent is not the answer

Not every camera runs on consent, and treating consent as the universal basis creates a problem you do not need. The Act contemplates certain legitimate uses where consent is not the operative basis, and employment-context processing for purposes including safeguarding the employer from loss sits in that territory.

This matters commercially. A factory running PPE detection, fire and smoke detection, forklift proximity and restricted zone alerts is not identifying anybody. There is a strong argument that much of that processing is not personal data processing at all, because the output is a helmet, a flame, a vehicle and a zone breach, not a person's identity.

The line moves the moment the system is asked who. Face-based attendance, contractor identification and visitor management all identify a specific individual, and they carry the full notice and consent design load. The practical consequence is that you should scope identity use cases separately from detection use cases, on separate cameras where possible, with their own notice and their own retention. Mixing them makes the whole estate as hard to justify as its most sensitive component.

Why architecture is a compliance decision

Where inference happens is not just a cost or latency question. It changes the compliance surface.

Compliance surface by processing location
ConsiderationCloud inferenceOn-premise inference
Parties with access to raw framesYou, the platform, its subprocessors, its hosting providerYou
Cross-border transfer questionLive, depends on the region and the notified restrictionsDoes not arise for the video itself
Evidencing erasureDepends on vendor tooling and contractual commitmentsYour own retention policy on your own storage
Breach blast radiusPotentially the vendor's whole estateOne site
Behaviour when the link dropsDetection stopsDetection continues, alerts queue

None of this makes on-premise processing automatically compliant. It makes it easier to evidence, which is a different and more useful claim. An appliance on site running inference against streams from your existing recorder means the full-resolution video never leaves the building, and what leaves is an event record: timestamp, camera, zone, detection type, confidence. That is a much smaller thing to govern than a video pipeline. See how IndoAI works for the standard topology and Edge Box for the appliance itself.

The other 2026 rule people confuse this with

Two Indian regimes now bite on camera projects and they are frequently muddled. They are unrelated in law and land at the same procurement meeting.

Product rule

BIS ER-01

MeitY notified Essential Requirements for the security of CCTV cameras in April 2024 under the Compulsory Registration Order. The relaxation permitting sale of non-conforming devices was withdrawn, and from 1 April 2026 only conforming, STQC-tested models can be sold. It governs what you may buy.

Data rule

DPDP Rules

Governs what you do with the footage: notice, purpose, retention, erasure, safeguards and the rights of the individual recorded. It applies regardless of which camera you bought. Rule 4 from 13 November 2026, penalties from 13 May 2027.

Installed systems predating ER-01 enforcement remain legal to operate; the rule bites on new purchase and on replacement under an annual maintenance contract. Our ER-01 buyer guide covers the verification steps in detail, including checking a model against the certified product list rather than trusting a brand-level claim.

A workable sequence for the next ten weeks

If you own a camera estate and have done nothing, this is the order that produces the most defensible position for the least effort.

Sequence

Weeks 1 to 2. Build the camera register. One row per camera: location, field of view, stated purpose, whether it captures identifiable individuals, who can view it, retention period, and current firmware. Expect to find cameras nobody can justify.
Weeks 3 to 4. Kill or re-purpose the unjustified cameras. This is the single highest-value step and it costs nothing.
Weeks 5 to 6. Fix safeguards: default credentials, viewer access lists, view logging, firmware. This is the obligation with the 250 crore ceiling attached.
Weeks 7 to 8. Set and automate retention. Confirm deletion actually runs and produces a record.
Weeks 9 to 10. Write the notices. Short notice at each entry, fuller notice reachable and current, grievance route staffed by a named person.

Notice writing comes last deliberately. A notice that describes a system you have not yet fixed is a written record of the gap. Fix first, then describe.

Common questions

Does the DPDP Act apply to ordinary office and factory CCTV?

It applies when the footage constitutes personal data about an identifiable individual and is processed in digital form. Ordinary CCTV usually meets both tests, because faces are identifiable and the recording is digital. What varies is the lawful basis. Some processing sits under legitimate uses rather than consent, but the analysis has to be done per purpose, not per camera.

What exactly does Rule 4 require from 13 November 2026?

Rule 4 sets out how a notice to the data principal must be given: standalone, in clear and plain language, itemising the personal data collected and the purpose, with the means to withdraw consent and to complain. For camera systems this generally means a visible, readable notice at every entry point, not a line buried in an employment contract.

Is a signboard at the gate enough?

A signboard is necessary but rarely sufficient on its own. It establishes that recording is happening. It does not by itself carry the itemised purpose, the retention position, the withdrawal route or the grievance channel. The workable pattern is a short notice at the point of capture that points to a fuller notice, with the fuller notice actually reachable and current.

What are the penalties, and when do they start?

The penalty provisions in Section 33 commence on 13 May 2027, the eighteen-month tranche. The Schedule sets a maximum of 250 crore rupees for failure to take reasonable security safeguards, with lower ceilings for other breaches. The Data Protection Board considers the nature and gravity of the breach and any mitigating action when determining the amount.

Does keeping video on premise solve the problem?

It solves part of it. On-premise processing narrows the transfer question, shortens the chain of parties who can access the footage, and makes retention easier to evidence. It does not remove the notice obligation, the purpose limitation or the erasure duty. A local recorder holding two years of unreviewed footage with no stated purpose is still a problem.

How does this interact with the BIS ER-01 camera rules?

They are separate regimes that land on the same purchase decision. ER-01 is a product cybersecurity requirement: MeitY notified Essential Requirements for the security of CCTV cameras in April 2024 under the Compulsory Registration Order, and from 1 April 2026 the relaxation was withdrawn so non-conforming cameras cannot be sold. DPDP governs what you do with the footage afterwards.

What should we do first if we have done nothing yet?

Build a camera register. One row per camera: location, what it can resolve, the purpose it serves, who can view it, how long footage is kept, and whether it captures identifiable individuals. Most organisations discover during this exercise that a third of their cameras have no stated purpose at all, which is the actual compliance gap.

If you are scoping a system now

Design the compliance position into the BOQ, not after it

The AI Adviser scopes cameras, appliance sizing and which models to activate from the live catalogue. Tell it which zones capture identifiable individuals and it will separate those from detection-only coverage, so the notice and retention design follows the architecture rather than fighting it.

Scope my system

About the author

Dr. Vivek Gujar

Co-founder and Chief Strategy Officer, IndoAI

Dr. Gujar holds a Ph.D. in seaport security, an MBA and a B.Tech, and is an ISO 27001 and ISO 9001 lead auditor. He has advised on security and compliance programmes including consultancy work for the Government of India and the Indian Port Association, and reviews IndoAI's published technical and regulatory claims. Full profile.