DPDP NavigatorAct 2023 · Rules 2025
All guides
Role-Based Playbooks

DPDP for Office Administrators: Visitor Logs, CCTV and Physical Access Data

16 Jul 20267 min read

The front desk register and the CCTV system are personal data collection points too. A practical look at obligations for facilities and admin teams.

Physical space data is still digital personal data

DPDP applies to digital personal data, and modern front-desk systems, CCTV footage stored on a digital recorder, and badge-access logs all qualify — a paper visitor register that's later scanned or logged into a system also brings that data into scope. Office administrators manage more personal data than the role title suggests.

This includes visitor names, phone numbers, vehicle numbers, photographs taken at check-in, and the timestamps and access logs generated every time someone badges into a building or floor.

Visitor registers and check-in systems

Give visitors basic notice at check-in about what's collected and why — a small sign or a line on the digital check-in screen describing that the data is used for building security and will be retained for a set period is enough for most visitor-management purposes; this generally rests on legitimate use given the security purpose, but a clear notice avoids ambiguity.

Set a defined retention period for visitor logs rather than keeping them indefinitely 'in case they're needed.' Most physical security purposes are served by a retention window of weeks to a few months, not years, and a shorter period also reduces what's exposed if the visitor-management system is ever compromised.

CCTV and access-control systems

CCTV footage of common areas, corridors and entry points is personal data for anyone identifiable in it. Apply the same reasonable security safeguards expected elsewhere under Section 8(5) — restrict who can view live or recorded footage, log access to recordings, and avoid pointing cameras into spaces where the security justification is weak (break rooms, individual desks without a specific incident-related reason).

Badge-access logs showing who entered which area and when should have a defined retention period too, and access to query those logs should be limited to people with an actual security or HR investigation need, logged consistently with the DPDP Rules baseline of at least a year for access logging.

Vendors in the physical security stack

Third-party security guard services, CCTV monitoring vendors, and visitor-management software providers who can access this data are Data Processors — the same Section 8(2) contracting expectations apply as with any other vendor, even though the data feels more 'operational' than 'digital.'

Where to go next

Add visitor-management, CCTV and badge-access systems to the Personal Data Inventory, and set explicit retention periods for each in the Retention Planner.