Footage kept for no reason is evidence waiting for a question.
The scene
The CCTV recorder kept ninety days by default. The Wi-Fi portal kept every guest's phone number and device ID forever. Both were run by vendors on contracts that said nothing about personal data.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
CCTV is for security, so it's exempt.
Security is a purpose, not an exemption; footage is personal data.
Set retention to the security purpose and restrict access.
Wi-Fi logins are technical data.
Phone numbers and device IDs identify people.
Minimise login data and set a deletion schedule.
Vendors run these systems
CCTV and Wi-Fi are usually managed by third parties. Contract them as processors with retention and security terms.
Monday morning
01 Check CCTV retention settings.
02 Check what the Wi-Fi portal stores.
03 Add processing terms to both vendor contracts.
Questions, answered plainly
Is CCTV footage personal data under DPDPA? +
Yes, where individuals can be identified. It should be collected for a stated purpose, secured, access-controlled and retained only as long as needed.
Do hotels need consent for guest Wi-Fi data? +
Collecting login data should be limited to what is needed to provide the service, with clear notice. Use for marketing would need specific consent.
Hospitality & Travel · Deep dive Guests check out. Their passports stay. Read →
Hospitality & Travel · Deep dive Loyalty is a promise. Profiling is a different one. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).