Your footage is personal data. Treat it like it.
India's Digital Personal Data Protection Act, 2023 applies to digital personal data — and recorded footage of identifiable people qualifies. For most businesses this doesn't demand exotic technology. It demands that three questions have written answers: how long footage is kept, who can view it, and how requests for it are handled. The stakes are higher in institutional settings — a hospital campus like the ones in Jhajjar has far more people who could plausibly need footage access than a single-purpose factory, which makes a written access policy less optional, not more.
Where installers create the risk
Default passwords never changed. Recorders exposed to the internet for "remote viewing" with no thought given to who else can reach them. Retention set to maximum because nobody chose a number. None of this is malicious — it's what happens when installation ends at "the cameras work".
How Logikdesk handles it
Every enterprise handover includes a drafted retention policy for your review, role-based access configured on the recorder, and secure credential transfer. Remote viewing, where you want it, is set up deliberately — not left open. If none of this is written down for your current system, our security audit is where that starts.
What good footage governance looks like
how many days, decided on purpose (incident-review needs, client requirements, storage reality) — not whatever the recorder defaulted to.
named roles who can view live and recorded footage, individual logins instead of one shared admin password, and a log of exports.
who authorises handing footage to police, insurers, or third parties, and how it's recorded.
visible notice that CCTV operates on premises — basic transparency, and standard practice.
This page provides general information about compliance practice, not legal advice.
Frequently asked questions
How many days of footage should we keep?
There's no single mandated number for private CCTV. Most facilities we work with settle between 30 and 90 days based on incident-review needs and client requirements. What matters is that it's decided and written down.
Can employees ask to see footage of themselves?
The DPDP framework gives individuals rights over their personal data. Have a process for such requests rather than improvising the first time it happens.