CCTV monitoring rules for Indian businesses
Cameras are cheap and the obligations attached to them are not obvious, so most small installations get three things wrong at once: no visible notice, footage kept forever, and everyone on the shop floor able to scroll through it.
The short version
- Visible notice at every entrance, before someone is recorded — not once they are inside.
- Have one stated purpose, and record only what serves it.
- Set a retention period and actually delete when it expires.
- Restrict who can view footage, and keep a record of who did.
- Tell your staff. Covert monitoring of employees is a different thing and far harder to defend.
Footage is personal data
A recording of an identifiable person is personal data, which places a CCTV system inside the same framework as your customer database rather than outside it. That single reframing answers most of the questions owners ask about cameras.
It means there has to be a purpose, people have to be told, the footage cannot be kept indefinitely by default, access has to be controlled, and a person can ask about material relating to them.
None of this makes cameras problematic. Preventing theft and keeping staff and customers safe are ordinary, defensible purposes. What causes problems is treating footage as though it belongs to nobody.
Notice: what it says and where it goes
A sign has to be visible before a person enters the recorded area, so that entering is a choice. A notice inside the shop, past the door camera, is notice given after the fact.
It should identify who is recording, say why in specific terms, and give a way to make contact about it. "CCTV in operation" alone does not tell anyone what they need to know.
Put signage at every entrance and at any area someone would not expect to be recorded. If you have audio recording, say so explicitly — people assume cameras and do not assume microphones.
Purpose and proportionality
Write the purpose down before installing, because it determines what is reasonable. "Preventing theft at the till and stock room, and safety at the entrance" justifies a very different camera layout from "general monitoring".
Some areas are not defensible regardless of purpose: washrooms, changing rooms, and anywhere a person is entitled to privacy. Cameras there are a serious problem, not a grey area.
Point cameras at your own premises. A camera positioned to cover a neighbour's doorway or the inside of another business is collecting data you have no purpose for and no right to.
Proportionality also cuts against resolution creep. If a camera does not serve the stated purpose, it is not a spare — it is an obligation with no benefit.
Retention, and why "forever" is the wrong answer
Most business purposes are served by days or weeks, not years. Choose a period that matches how long it actually takes you to notice an incident — commonly two to four weeks for retail — and let the system overwrite after it.
Then check that deletion happens. A recorder configured to overwrite, with someone exporting clips to a desktop folder that never gets cleared, has a retention policy on paper and an indefinite archive in practice.
Keep a specific clip longer when there is a reason — an incident under investigation, an insurance claim, a police complaint. Export it, record why it was kept and who has it, and delete it when the reason ends. That is a documented exception, which is very different from having no rule.
Who can see it, and keeping a record
Restrict live and recorded access to the people whose role requires it. In a small business that is usually the owner and one manager, not everyone who knows the recorder's password.
Change the recorder's default credentials, put it on a network segment that cannot be reached from the guest Wi-Fi, and never expose it directly to the internet. A DVR with a default password and a port forward is one of the most reliably compromised devices on any small network, and once it is taken the footage is someone else's.
Keep a simple log of who viewed or exported what and why. It sounds bureaucratic until an allegation is made about how footage was used, at which point it is the only thing that answers it.
Monitoring staff
Monitoring employees is possible and common, and it depends on them knowing. Tell staff in writing what is recorded, where, why, how long it is kept and what it may be used for — attendance, safety, investigating a specific loss.
Do not use footage for a purpose you never stated. Cameras installed for theft prevention, then used to build a case about how long someone takes on a break, is the pattern that turns a reasonable system into a dispute.
Covert monitoring is a different category entirely and should not be set up casually. If you believe you have a specific, serious problem that ordinary means cannot address, take legal advice first. We do not configure covert staff surveillance, and a provider willing to do it without asking why should worry you.
Where AI detection changes the calculation
Analytics that flag events — a fight, a fire, someone in a restricted area, an item leaving a counter unattended — generally reduce how much footage a human has to watch, which is a privacy improvement rather than a cost. Fewer people scroll through fewer hours.
Facial recognition of members of the public is a different proposition with materially heavier obligations, and it is not what stops a loss. Knowing that something happened, where and when, with the clip attached, is what lets you act.
Automatic attendance timing is operationally useful and should be described to staff as what it is: times derived from footage, for operations. It is not a tamper-proof biometric record and should not be presented as one.
This is not legal advice
This is a practical orientation, not legal advice, and it does not cover every state-level requirement or sector-specific rule that might apply to your premises.
For a decision that matters — a dispute with an employee, a police request, a subject request you are unsure how to answer — get advice on your actual facts. We can tell you what a system is technically capable of and how to configure it defensibly; we will not tell you what the law requires in your specific case.
Nothing on this site will ever ask for your password, OTP or recovery codes.
Related guides
Want this handled for you?
Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.
Talk to Our Security Team