DPDP and Worker CCTV: What Indian Factories Must Do
Video of a recognisable worker is personal data under India's Digital Personal Data Protection Act, 2023. A factory filming its floor must post CCTV signage, fix one lawful purpose, capture only what that purpose needs, cap retention, and lock down access. Substantive duties come into force on 14 May 2027. There is no headcount or turnover threshold: a single-shed unit is a full data fiduciary too.
You already run cameras. DPDP does not tell you to switch them off; it tells you to treat the footage as data you are answerable for, not a DVR blinking in a cabin by the gate that nobody has opened in a year. Here is the short list a plant head has to get right — and one thing most compliance blogs get comfortably wrong.
The five duties at a glance
- Notice / signage — workers must know they are filmed and why.
- Purpose limitation — one stated reason, written down, and don't quietly reuse it.
- Data minimisation — cameras on machines and lanes, off rest and private areas.
- Retention cap — a fixed short window with auto-overwrite, not a year of hoarded clips.
- Security & access — a locked-down NVR, role-based access, an access log.
Why is worker footage personal data under the DPDP Act?
The DPDP Act, 2023 governs "digital personal data" — any data about an identifiable person, processed digitally. A recognisable worker on a networked feed is exactly that. Your NVR footage, your analytics events, and any clip you export to a phone are all in scope (official Act text, MeitY).
One point busts a common reflex: under DPDP, the factory is the data fiduciary. Your CCTV integrator, the AMC vendor who maintains the system, the firm whose NVR sits in your cabin — they are at most processors. The compliance duty, and the penalty exposure, land on you, not on them. "Our security vendor handles compliance" is not a position the Act recognises.
How far does "purposes of employment" actually stretch?
Most plant heads assume DPDP means chasing a signed consent form from every worker on the line. Usually it doesn't. Section 7(i) lets an employer process personal data for the purposes of employment — its named examples are safeguarding the employer from loss, preventing corporate espionage, and protecting trade secrets and confidential information. Consent-free, on that basis.
Here is what the vendor compliance blogs skip. Every one of Section 7(i)'s statutory examples is loss- or security-defensive. A live legal debate — see LiveLaw's "Why Employment Surveillance Clauses Are Void, Not Just Risky" and the Constitutional Law and Philosophy blog — argues that stretching 7(i) to cover general productivity monitoring or disciplinary supervision reads far past those examples, and that you cannot contract out of a statutory limit. Some commentary goes further and questions 7(i)'s standing as a surveillance basis at all.
That debate is your operating instruction, not an abstraction:
- A camera justified as theft prevention, press-guard safety, gate security, loss prevention sits squarely inside 7(i)'s defensive examples. Defensible.
- A camera justified as productivity scoring or catching workers slacking is precisely the stretch critics say falls outside 7(i). Outside it, you are back to needing consent, or exposed to the argument that the basis is void.
So write your stated purpose in security and safety terms, and never quietly repurpose that footage for productivity discipline. That repurposing is the specific act that collapses your 7(i) cover, because it changes the purpose to one the section was never built to carry.
Even on the safe route, 7(i) is a permission, not a blank cheque. Lawful purpose, necessity, proportionality, and the Section 8 duties still apply in full (Section 8, India Code).
When must Indian factories comply with DPDP?
India published the DPDP Rules, 2025 in the Official Gazette on 13 November 2025 (Gazette No. 760), and Rule 1 phases the obligations across three dates rather than switching them all on at once (DPDP Rules 2025 notification, PIB; Rule 1 commencement text; S&R Associates note). This tells you what is live now versus what you still have time to build.
| Phase | Date | Rules in force | What comes into force | What it means for your floor |
|---|---|---|---|---|
| Phase 1 | 13 Nov 2025 | Rules 1, 2, 17–21 (on publication) | Data Protection Board of India constituted; core definitions and the Board's procedure operative | The regulator exists — but its full complaint-adjudication and penalty machinery is not switched on for factory CCTV on this date |
| Phase 2 | 14 Nov 2026 | Rule 4 (one year after publication) | Consent Manager registration framework | Mostly consumer-data and consent-platform territory, not core factory CCTV |
| Phase 3 | 14 May 2027 | Rules 3, 5–16, 22, 23 (eighteen months after publication) | The substantive duties that actually bind a factory: notice (Rule 3), reasonable security safeguards (Rule 6), retention/erasure timelines (Rule 8), Significant Data Fiduciary obligations, and cross-border transfer under Rule 15 / Section 16 | Your hard deadline for signage, purpose, minimisation, retention and access to be in order |
The cross-border date, resolved. Trackers disagree on whether the eighteen-month provisions (including Section 16 cross-border transfer) commence 12, 13 or 14 May 2027 — the difference is only a day-counting convention. Going to the primary source settles it: Rule 1(4) says Rules 3, 5–16, 22 and 23 "shall come into force eighteen months after the date of publication in the Official Gazette," and publication was 13 November 2025 — eighteen months on is 14 May 2027 (Rule 1 text). That is the date we use; treat any "14 May 2027" you see elsewhere as the same milestone rounded.
The Board is constituted, but its full complaint-adjudication and penalty powers for the data-fiduciary duties phase in with Phase 3. So a worker cannot yet bring an enforceable, penalisable DPDP CCTV complaint today, and no further grace period beyond 14 May 2027 is expected. Treat any new camera project between now and then as if the 2027 rules are already on: retrofitting policy onto a live deployment costs more than specifying it once. For every other camera-, safety- and privacy-deadline that lands on an Indian factory in one place, see our India factory CCTV compliance calendar 2026.
When face recognition turns your CCTV into biometric data
Plain CCTV and face-recognition CCTV are different legal animals, and the compliance mills conflate them. The moment you bolt face-recognition attendance or face-analytics onto your cameras, the footage becomes biometric processing — the most sensitive tier. Process biometrics at volume across a multi-plant operation and you can be designated a Significant Data Fiduciary (SDF), which triggers a mandatory India-based Data Protection Officer, an annual Data Protection Impact Assessment, and an independent data audit.
So face-analytics is a deliberate scope-and-cost decision, not a default checkbox on the installer's quote. If attendance runs on a badge or a fingerprint reader you already govern, adding faces to every ceiling camera may quietly upgrade your entire compliance burden.
The five duties, mapped to the floor
| DPDP principle | What it means for factory CCTV | Practical action |
|---|---|---|
| Notice / transparency | Workers must know they are filmed and why | Visible "This area is under CCTV surveillance" signage at every entrance and monitored zone, in the language your workforce actually reads; a purpose line in the handbook |
| Purpose limitation | One stated reason, no quiet reuse | Write the purpose in security/safety terms; do not repurpose it for productivity discipline |
| Data minimisation | Capture only what the purpose needs | No cameras in toilets, washrooms, changing rooms, prayer rooms or canteens — full stop; point lenses at machines, lines and lanes |
| Retention limitation | Keep footage only as long as needed | A fixed short window with auto-overwrite (see below) |
| Security & access control | Protect the footage; limit who sees it | Password-protected NVR (not admin/admin), role-based access, encrypted feeds, an access log — a Section 8 duty |
Signage is the cheapest compliance you will ever buy
Signage and a written purpose cost almost nothing and are the first thing any complaint or audit checks. Two precision points a lawyer would want you to get right:
- Signage is transparency and proportionality evidence — it shows the filming was fair and expected. It is not the same as the formal Section 5 notice, which attaches to the consent route; the Section 7 employment route does not trigger that Section 5 notice. Post the sign anyway: it is what makes your defensive purpose look reasonable if challenged.
- Put it in the language your workforce actually reads. Indian factories run heavily on inter-state migrant labour who may read neither English nor the plant state's language. A Hindi sign in a Tamil-state shed full of migrant workers from Bihar is not real notice. Match the sign to the home-state languages on your floor.
Where the money risk sits
The DPDP Act sets a maximum penalty of ₹250 crore for failure to take reasonable security safeguards against a personal-data breach. These are ceilings, not automatic fines — the Board weighs gravity, duration and mitigation.
| Contravention | Maximum penalty (DPDP Schedule) |
|---|---|
| Failure to take reasonable security safeguards | up to ₹250 crore |
| Failure to notify the Board of a breach; children's-data duties | up to ₹200 crore |
| Other contraventions (residual) | up to ₹50 crore |
But the ceiling is not your real threat model — every page quotes it, and there is no regulator factory-sweep coming. The realistic first wave of enforcement is a single disgruntled or ex-worker filing a complaint: filmed at the canteen table, or footage pulled into a discipline case. That is the believable trigger, and it makes signage, a narrow defensive purpose and short retention read as insurance against a known adversary, not a distant regulator.
Retention is your erasure defence, not disk hygiene
Every competing page tells you to set a 30–90 day window (indicative — there is no single mandated CCTV number) so you "don't hoard clips." The sharper reason: from 2027 a worker's real weapon is a data-principal erasure request, answerable in roughly 90 days, and honouring erasure against a rolling NVR is near-impossible — you cannot surgically wipe one worker from months of footage. A fixed short auto-overwrite window makes most erasure requests moot before they can bite; a year of hoarded clips turns every request into a manual crisis you cannot fulfil.
One caveat the minimisation blogs miss: your short window can collide with sector retention minima — pharma GMP records, port and critical-infrastructure CCTV mandates, some state CCTV-retention orders, insurance or incident holds. Pick the shortest window that satisfies both DPDP and any sector minimum, and document why. We work through every one of those triggers, with an Indian per-TB storage cost, in how long a factory must keep CCTV footage in India.
Worker CCTV under DPDP: basis, notice, retention, rights
Put the whole floor decision on one page. This is the security/safety CCTV route — the defensible Section 7(i) reading — mapped to what the Act actually asks of you. Cite the provisions when you write your policy; the exact wording lives in the official Act text and the DPDP Rules, 2025.
| Item | What applies to security/safety worker CCTV | DPDP reference |
|---|---|---|
| Lawful basis | "Certain legitimate uses" — processing for the purposes of employment (safeguarding the employer from loss, preventing espionage, protecting trade secrets). No consent needed on this basis. Justify a camera as productivity/discipline monitoring and you fall outside it — back to consent, or a basis that may be challenged. | Section 7(i); Section 4 |
| Consent required? | No, on the Section 7(i) route. Yes if you rely on consent (e.g. productivity monitoring, or face-recognition attendance) — and consent must be free, specific, informed, unconditional and revocable. | Sections 6, 7(i) |
| Formal notice required? | The statutory Section 5 notice attaches to the consent route, not to Section 7(i). On the employment route you do not trigger that notice — but you still owe transparency, so post signage anyway; it is your fairness/proportionality evidence. | Section 5; Rule 3 |
| What the notice / signage must say | Identity of the factory as data fiduciary; the specific purpose (security/safety, in plain terms); the retention window; the rights below and how to exercise them; a grievance contact (and DPO details if you are an SDF). In the home-state languages your workforce actually reads. | Section 5(1); Rule 3 |
| Retention | Keep footage only as long as the stated purpose needs, then erase; a fixed short auto-overwrite window is the practical form. Reconcile against any sector minimum. Enforced from 14 May 2027. | Section 8(7); Rule 8 |
| Worker (data-principal) rights | Access to a summary of their data and processing; correction/completion; erasure; a grievance-redressal route with the fiduciary first; nomination. Answer requests inside the Rules' timelines (grievance ~90 days). | Sections 11, 12, 13, 14 |
| Security duty | Reasonable security safeguards on the footage — password-protected NVR, role-based access, encryption in transit, an access log. Breach of this carries the heaviest penalty band. | Section 8(5); Rule 6 |
For a laminate-ready worker notice built from this — who signs it, where it hangs, and a bilingual English/Hindi block — use our worker CCTV privacy-notice template under DPDP.
How this connects to your camera plan
DPDP is easiest to satisfy when you decide where cameras point and why before you mount them — purpose limitation and minimisation are placement decisions, not paperwork. A defensible narrow purpose is a placement decision.
The mistakes are consistent across floors we have deployed on: a camera framed to catch a machine also clips the edge of the canteen; a gowning-room lens put in for hygiene audit also catches a rest bench; the NVR sits in a hot, unlocked cabin by the gate, still on default credentials. None of those is a policy failure — each is a placement failure a policy then has to apologise for.
That is the gap Mama closes at the front of a project: you record a short phone walkthrough of the floor, and it reads the space — zones, sightlines, hazards, rest areas — then returns a floor plan plus a placement plan that keeps lenses on machines and lanes and off private areas, data-minimised by design before a single bracket is drilled. (Our floor-deployment experience is general, not India-specific.)
This is general guidance, not legal advice — confirm your position with counsel.
FAQ
Do I need every worker's consent to run factory CCTV? Usually not. Section 7(i) permits processing for the "purposes of employment" — its examples are all security-defensive (loss, espionage), so cameras justified on that basis need no separate consent. A camera justified for productivity or discipline may fall outside 7(i), where you would need consent or risk the basis being challenged. Either way you still owe transparency, minimisation, retention limits and security under Section 8.
Who is legally responsible — us or our CCTV vendor? You. Under DPDP the factory is the data fiduciary; your integrator or AMC firm is at most a processor. The compliance duty and the penalty exposure sit with the promoter, not the vendor storing your NVR.
Are we too small for DPDP to apply? No. There is no turnover or headcount threshold. A 30-worker unit filming its floor is a full data fiduciary with the same core duties.
Does adding face recognition change anything? Yes. Face-recognition attendance or analytics turns footage into biometric data — the most sensitive tier — and at volume can push a multi-plant operator into Significant Data Fiduciary status (DPO, annual DPIA, independent audit). Treat it as a deliberate scope decision.
When do we actually have to comply? The DPDP Rules were published on 13 November 2025 and phase in over three stages: the Board from 13 Nov 2025, Consent Manager registration from 14 Nov 2026, and the substantive factory duties — notice, retention, minimisation, security, SDF and cross-border — from 14 May 2027, your practical deadline. The Board is constituted, but its full complaint-and-penalty powers for those duties phase in to 2027, so build now rather than wait.
