Checklists4 mins

DPDP Compliance Checklist For CCTV And Biometric Systems

A step-by-step runbook for large enterprises to align CCTV surveillance and employee biometric attendance systems with the DPDP Act 2023 and Rules 2025 before the May 2027 deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

When To Use This Checklist

This runbook is designed for Heads of Compliance at enterprises with over 1000 employees. You should use this checklist when evaluating physical security systems, onboarding new surveillance vendors, or preparing your board reporting on privacy exposure. With exactly 279 days remaining until the DPDP hard compliance deadline of 13 May 2027, addressing the data footprint of CCTV and biometric attendance systems is a critical priority.

Prerequisites For Physical Security Compliance

Before executing this checklist, you need a complete inventory of all active cameras and biometric endpoints across your facilities. You also need a comprehensive list of the third-party vendors supplying and maintaining these systems. Finally, your designated Data Protection Officer must be prepared to oversee cross-team accountability among HR, IT, and Facilities.

Step-By-Step Compliance Checklist

1. Map data flows. Owner: IT. Action: Document where video and biometric data originate and where they are stored. Evidence: System architecture diagram. Frequency: One-time.

2. Determine lawful basis. Owner: Legal. Action: Apply Section 4 requirements. Consent is the primary basis for processing, except where Section 7 legitimate uses apply for employees. Evidence: Documented justification. Frequency: Recurring review.

3. Display itemised notices. Owner: Facilities. Action: Post physical signs at camera locations detailing the surveillance per the Rules 2025. Evidence: Date-stamped photographs of physical notices. Frequency: One-time.

4. Implement consent alternatives. Owner: HR. Action: Provide non-biometric attendance options for employees who decline biometric scanning. Evidence: Log of alternative options offered and selected. Frequency: Standing process.

5. Define retention limits. Owner: IT. Action: Configure automated deletion scripts for video feeds once the security purpose is met. Evidence: Deletion logs and retention policy. Frequency: Standing process.

6. Configure access controls. Owner: Security. Action: Restrict access to biometric databases and CCTV storage. Evidence: Role-based access matrices. Frequency: Recurring review.

7. Execute processor agreements. Owner: Legal. Action: Sign DPDP-aligned contracts with your security hardware vendors. Evidence: Executed vendor contracts. Frequency: One-time.

8. Update the RoPA. Owner: Compliance. Action: Detail biometric processing and storage locations in your Record of Processing Activities. Evidence: Complete RoPA entries. Frequency: Recurring review.

DPBI Breach Intimation Readiness

Physical security databases are prime targets for unauthorized access. If a biometric database or CCTV archive is compromised, the Rules 2025 dictate strict timelines. You must intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours. Your incident response plan must name a specific control owner for physical security breaches.

Effort And Budget Reality

Managing this checklist manually across multiple facilities takes approximately 120 hours of cross-team coordination in the first quarter, followed by 30 hours monthly. Dedicated compliance tooling absorbs this effort by automating consent records, maintaining a continuous audit trail, and centralizing vendor attestations. While an existing GRC tool might store your policies, specialized software is necessary to generate the exact evidence packs an auditor requires.

Documentation Pack Requirements

Your evidence pack must include updated physical security policies, employee privacy notices, and signed vendor agreements. Your RoPA must specifically detail the lawful purpose under Section 4 for collecting face scans, fingerprints, or continuous video feeds.

Red Flags For Audit Readiness

1. Storing CCTV footage indefinitely without automated deletion scripts.

2. Forcing employees to use biometric attendance without offering a reasonable alternative.

3. Failing to display itemised physical notices at the point of surveillance.

4. Lacking a clear control owner for the hardware vendor relationship.

Run a free scan at freescan.complydp.com to baseline which physical security compliance steps are already covered and which gaps remain.

Sources

Frequently asked questions

Do we need employee consent to use biometric attendance systems?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. For employees, providing an alternative attendance method alongside clear notice is recommended to ensure compliance with the Rules 2025.

How long can we retain CCTV footage under the DPDP Act?

The Act requires deleting personal data once the specified purpose is met. You must define a strict retention period for CCTV footage and implement automated deletion to remain regulator-ready.

What happens if our biometric vendor suffers a data breach?

As the Data Fiduciary, you must intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours. Your vendor contracts must guarantee they will notify you immediately.

How should we provide notice for CCTV surveillance?

You must display itemised notices at the physical locations where surveillance occurs. The notice must inform Data Principals about the data collection and provide contact details for your Data Protection Officer.

Can our existing GRC tool handle biometric data compliance?

Standard GRC tools often act as static repositories for policies. Specialized tooling is necessary to maintain an active audit trail of physical notices, alternative consent artefacts, and automated retention logs.