The camera rememberslonger than the guest stayed.
Security systems collect personal data too. They need purposes and clocks like everything else.
In one line: Yes, where individuals can be identified. It should be collected for a stated purpose, secured, access-controlled and retained only as long as needed.
Footage kept for no reason is evidence waiting for a question.
The scene
The CCTV recorder kept ninety days by default. The Wi-Fi portal kept every guest's phone number and device ID forever. Both were run by vendors on contracts that said nothing about personal data.
Where the thinking breaks
Vendors run these systems
CCTV and Wi-Fi are usually managed by third parties. Contract them as processors with retention and security terms.
Monday morning
- 01Check CCTV retention settings.
- 02Check what the Wi-Fi portal stores.
- 03Add processing terms to both vendor contracts.
Questions, answered plainly
Is CCTV footage personal data under DPDPA?
Yes, where individuals can be identified. It should be collected for a stated purpose, secured, access-controlled and retained only as long as needed.
Do hotels need consent for guest Wi-Fi data?
Collecting login data should be limited to what is needed to provide the service, with clear notice. Use for marketing would need specific consent.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner