Neurabit VMS · Data Protection

DPDP Act and CCTV: what Indian plants need to do before May 2027

CCTV footage in which people can be identified is personal data under the Digital Personal Data Protection Act, 2023. The DPDP Rules were notified in November 2025, and most obligations on organisations apply from 13 May 2027.

This page explains, in plain terms, what that means for factory and warehouse CCTV, and how an on-premise AI video system can make compliance simpler. It is general information, not legal advice. Take advice from your own counsel.

Key facts

  • The DPDP Rules, 2025 were notified in November 2025, and most obligations on data fiduciaries, including security safeguards and breach reporting, apply from 13 May 2027.
  • Penalties under the DPDP Act go up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach.
  • Keeping CCTV footage and face templates on-premise, with role-based access and an append-only audit log, addresses several DPDP security safeguard requirements by design.
  • Neurabit VMS subscription starts at ₹800 per use case per camera per month with edge hardware included. To own the hardware instead, edge devices start at roughly ₹50,000 and each handles up to 10 cameras, with each use case licensed per camera on a perpetual or annual licence, priced on request. Discount tiers are available on request.

Does the DPDP Act apply to factory CCTV?

Yes, where the footage is digital and people in it can be identified. The employer is the data fiduciary, and workers, contractors and visitors are data principals.

For employees, Section 7 of the Act allows processing without consent for certain legitimate uses, including purposes of employment and safeguarding the employer from loss or liability. Whether that covers every camera and every analytic on your site, and how it applies to contractors and visitors, is a question for your counsel. Clear signage and a written purpose for each camera zone are a sensible baseline either way.

What the Rules ask for, in practice

  • Reasonable security safeguards, including encryption or equivalent measures, access control over who can view footage, and logs of access.
  • Retention of access logs, which the Rules set at a minimum of one year.
  • Breach notification to affected people and to the Data Protection Board, with a detailed report to the Board within 72 hours of becoming aware of it.
  • Erasing personal data once the purpose is served, which for CCTV means a defined retention period rather than keeping footage indefinitely.
  • Note that Rule 8 also sets a one-year minimum retention for personal data and associated logs for certain purposes. How this interacts with short CCTV retention periods is not yet settled, so confirm your footage retention policy with counsel.

How Neurabit VMS maps to these requirements

  • Footage is recorded and processed on your premises. Neither purchase option sends video to Neurabit.
  • Role-based access with per-camera permissions and single sign-on through OIDC or SAML.
  • An append-only, hash-chained audit log of every view and every export.
  • Retention set per camera by days or disk quota, with forecasting so you know footage will be deleted on schedule.
  • Evidence exports carry a SHA-256 manifest and a chain-of-custody statement naming who exported what and when.
  • Face templates for identity binding are consent-managed and never leave your site. Facial identity is optional.

A five-step checklist for plant CCTV

  • List every camera, what it covers and why. Remove or re-aim cameras with no clear purpose.
  • Put up clear signage at entrances and monitored zones.
  • Set and enforce a retention period per camera zone, agreed with counsel.
  • Restrict who can view and export footage, and keep the access logs for at least a year.
  • Write down your breach response: who decides, who informs the Board, and within what time.

Frequently asked questions

Is CCTV footage personal data under the DPDP Act?

Yes, digital CCTV footage in which individuals can be identified is personal data under the Digital Personal Data Protection Act, 2023.

When do DPDP obligations apply to CCTV?

The DPDP Rules were notified in November 2025. Most obligations on data fiduciaries, including security safeguards, notice and breach reporting, apply from 13 May 2027.

Do we need employee consent for workplace CCTV?

Section 7 of the DPDP Act permits processing for employment purposes and to safeguard the employer from loss or liability without consent. How far that extends for your cameras, analytics, contractors and visitors should be confirmed with counsel.

Is facial recognition CCTV allowed under the DPDP Act?

The Act does not ban it, but face data identifies people directly and carries more risk. If you use it, keep templates on-premise, restrict access tightly and document the purpose. Neurabit VMS makes facial identity optional and keeps templates on your site.

Does cloud CCTV make DPDP compliance harder?

It adds a processor, a data transfer and another party to your breach response. On-premise systems keep footage in one place under your control, which makes the security safeguard and breach obligations simpler to meet.

Get a DPDP-ready CCTV setup for your site

We tell you which of your existing cameras are usable before you spend anything, and a real engineer replies within one business day.

Request a site survey →

Last updated 24 September 2026. Technical content reviewed by Abhishek Goel, Chief Technology Officer, Neurabit Solution.