CCTV, Biometric Attendance and Employee Monitoring Under DPDP
How the DPDP Act applies to workplace CCTV, biometric attendance and employee monitoring in India, and what employers must do before the law becomes fully enforceable.
Workplace CCTV footage and biometric attendance data both count as personal data under India's DPDP Act, which means employers running these systems have real obligations around notice, security and retention, even though full enforcement is still ahead.
Key facts at a glance
- The Digital Personal Data Protection Act 2023 covers any personal data processed digitally, including CCTV footage that can identify a person and biometric attendance records.
- Under the DPDP Rules 2025, full substantive obligations such as notice, consent, security safeguards and breach reporting become enforceable on 13 May 2027, with no stated grace period after that date.
- Penalties for failing to implement reasonable security safeguards can reach up to Rs 250 crore per instance.
- Biometric data is treated as personal data requiring particular care in storage and access control, given how sensitive and hard to change it is if compromised.
- Employers are expected to retain monitoring data only as long as needed for the stated purpose, not indefinitely.
- The Data Protection Board provisions under the Rules took effect immediately, so the enforcement architecture already exists even before full obligations bite.
Why CCTV and biometric systems are squarely in scope
Any system that captures and stores information tied to an identifiable person is processing personal data under the DPDP Act. CCTV footage of employees, visitors and premises, and biometric templates used for attendance or access control, both fit this definition clearly. Employers who run these systems are Data Fiduciaries and take on the responsibilities that come with that role, including safeguarding the data and limiting how it is used beyond its original purpose.
Consent versus legitimate employment use
Employers do not necessarily need to obtain individual consent for every use of attendance biometrics, since the Act recognises certain processing as reasonably necessary for employment-related purposes. That said, this is not a blanket exemption from all obligations. Employers must still give clear, upfront notice of what is being collected, why, and how long it will be kept, and must apply proportionate security regardless of the legal basis relied on.
What "reasonable security safeguards" means in practice
The DPDP Act does not prescribe a fixed technical checklist, but the penalty structure makes clear that security failures are treated seriously. For biometric and CCTV systems specifically, this typically means restricting who can access raw footage or templates, encrypting stored biometric data, logging access, and having a documented incident-response process if a breach occurs.
| Monitoring system | Typical personal data involved | Key employer obligation |
|---|---|---|
| CCTV (premises/office) | Footage identifying employees, visitors | Notice of surveillance, access restriction, defined retention period |
| Biometric attendance | Fingerprint or face templates, timestamps | Strong security controls, purpose limitation, secure storage |
| Access control systems | Card/biometric logs, location/time data | Retention limits, restricted access logs |
Retention: the part employers most often get wrong
A common gap is treating CCTV footage or biometric templates as data to keep forever "just in case." The DPDP framework's purpose-limitation principle points the other way: data should be held only as long as it serves the purpose it was collected for. Employers should set an explicit retention period for footage (commonly a matter of weeks to a few months, depending on business need) and for biometric templates tied to active employment, with a defined deletion process when an employee exits.
What to do before May 2027
Even though full enforcement is more than a year away, the practical work of mapping which systems collect biometric or CCTV data, documenting retention periods, and tightening access controls takes time to execute properly across an organisation. Waiting until close to the enforcement date compresses that work into a rush job with a much higher chance of gaps.
If you are not sure how exposed your current monitoring systems are under DPDP, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology — meity.gov.in
- Data Protection Board of India (as established under the DPDP Rules)
- Relevant state labour department for employment-related monitoring rules
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Does the DPDP Act apply to CCTV footage and biometric attendance data?
- Yes. CCTV footage that identifies individuals and biometric data used for attendance both count as personal data under the DPDP Act, so employers processing them are Data Fiduciaries with obligations under the law.
- Do employees need to give consent for biometric attendance systems?
- Employers generally rely on the DPDP Act's provisions for processing that is necessary for employment purposes rather than case-by-case consent for every employee, but they still must give clear notice of what is collected and why, and apply proportionate security safeguards.
- When do these DPDP obligations actually become enforceable?
- Full substantive obligations under the DPDP Rules 2025, including notice, consent and security safeguards, become enforceable on 13 May 2027, so employers have a defined runway to get monitoring systems compliant.
- What is the penalty for failing to secure biometric or CCTV data properly?
- Penalties for failing to implement reasonable security safeguards can reach up to Rs 250 crore per instance under the DPDP Act, which makes data security for sensitive systems like biometric attendance a board-level risk, not just an IT task.
- How long can an employer retain CCTV footage or biometric templates?
- The DPDP Act expects data to be retained only as long as necessary for the purpose it was collected for, so employers should set a defined retention and deletion schedule for footage and biometric templates rather than keeping them indefinitely.
- Can employees ask what monitoring data a company holds about them?
- Yes, once the DPDP Act's data-principal rights provisions are fully enforceable, employees will be able to request details of the personal data an employer holds about them, including monitoring data, subject to reasonable exceptions.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.