Society data privacy under India's DPDP Act: a practical guide
What personal data your housing society holds, how India's DPDP Act 2023 may apply to it, and a practical checklist your committee can start using now.
By GateBell Team · · 5 min read
In this article
Every housing society holds more personal data than most committee members realise. Visitor photos, vehicle numbers, phone numbers of residents and maids, ID proofs of tenants and guards: it all sits in registers, spreadsheets and phones. India's Digital Personal Data Protection Act, 2023 (DPDP Act) sets rules for how such digital data is handled. This post is general information only, not legal advice. Check the current text of the law, your state's Act, your bye-laws and speak to a qualified professional.
A note on timing
The Act was passed in 2023, and Rules under it are being put in place to bring it into force. Commencement is phased, which means different parts start on different dates. Dates and details can change through notifications, so verify the current status on the official government sources before you finalise your policy. The sensible approach is to prepare now, because the habits below are good practice whatever the exact date.
What personal data does a society hold?
List this first. You cannot protect what you have not counted.
- Visitor logs: names, phone numbers, photos, who they visited, in and out times.
- Vehicle data: registration numbers per flat, parking slot details.
- Resident directory: names, flat numbers, phone numbers, email, family members.
- Staff data: guards' and housekeeping staff's ID proofs, addresses, salary details.
- Daily help data: maids', cooks' and drivers' names, photos, phone numbers and entry codes.
- Payment records: maintenance dues, receipts, UPI references and bank transfer details.
- CCTV footage: images of residents, visitors and children.
Who is responsible? Roles in plain words
The Act uses a few terms. In simple language:
- Data principal is the person whose data it is: the resident, visitor or staff member.
- Data fiduciary is whoever decides why and how personal data is processed. A society, through its managing committee, usually decides what data to collect and why, so it is likely to be treated as a data fiduciary. Confirm this with a professional for your own set-up.
- Data processor is someone who handles data on the fiduciary's behalf, such as an app vendor, a CCTV company or an accounting firm.
If you use a vendor, you remain responsible for what you ask them to do. Ask for a written agreement about how they handle your residents' data.
Core duties, in simple terms
Notice and consent
Tell people what you collect, why, and how they can complain. Do this clearly and in simple language, ideally in English and the local language. Consent should be specific and easy to withdraw. A short notice at the gate, in the resident onboarding form and in the app is a good start. The Act also recognises some situations where data can be used without consent, but do not assume that applies to you without advice.
Purpose limitation
Use data only for the purpose you told people about. Visitor data collected for gate security should not be handed to a marketing contact or shared in a WhatsApp group. Directory data collected for emergencies should not be used for election campaigns or commercial offers.
Collect less
If you do not need a visitor's address, do not ask for it. Do not photocopy Aadhaar cards for routine entries. Collecting less means less to protect and less to leak.
Retention
Keep data only as long as it is needed. Decide a period for each type, write it down, and delete on schedule.
| Data type | Question to ask |
|---|---|
| Visitor photos | Do we need them beyond a few months? |
| Visitor details | Can we reduce them to basic entries after some time? |
| Moved-out resident data | What must we keep for accounts and legal needs? |
| Ex-staff documents | Why are we still holding them? |
Accounting and legal records may have their own minimum retention rules, so check before you delete.
Security safeguards
You are expected to take reasonable security steps. Practical examples:
- Use individual logins instead of one shared password.
- Limit who can see the full resident list and visitor history.
- Remove access when a committee member or guard leaves.
- Keep paper registers locked and out of sight of visitors.
- Do not circulate resident lists as Excel files on open groups.
Children's data
The Act has stricter rules for children's data (people under 18), including parental consent. Be careful with photos of children, school details and any child-related lists. Never publish children's names or photos in group posts or notices without parents' permission.
Grievance contact
Name one person, with a phone number or email, who handles privacy requests. Residents should be able to ask what data you hold, ask for corrections, and ask for deletion where it makes sense.
Breach readiness
The Act expects organisations to act if data is leaked, including informing the people affected and the authority in the manner prescribed. Prepare a simple plan: who to call, how to lock accounts, and how to inform residents. Practise it once.
A practical checklist for your committee
- List every place personal data is kept: registers, phones, spreadsheets, apps, CCTV.
- Pass a committee resolution naming a privacy contact person.
- Publish a short privacy notice for residents and visitors.
- Set retention periods and record them.
- Review who has access to what, and remove extra access.
- Get written terms from vendors who handle your data.
- Stop sharing resident data in open WhatsApp groups.
- Prepare a short breach response note.
- Review everything once a year and at every committee change.
Choosing tools that help
When you pick a visitor or resident app, ask how long visitor photos are kept, whether data is sold or used for ads, where it is hosted, and whether residents can delete their accounts. Our guide to choosing a visitor management system has more questions to ask. GateBell, for example, deletes visitor photos after a period the society sets and describes its approach on the security and privacy page. Whatever you choose, check the vendor's privacy policy yourself. You may also want to read about daily help attendance, where staff data needs the same care.
Privacy does not need a big budget. A short notice, a few written rules, and the discipline to delete old data will put your society well ahead of where most are today.
Frequently asked questions
Does the DPDP Act apply to a small housing society?
The Act applies to digital personal data processed in India, and it does not have a general exemption for small organisations. A society that keeps resident, visitor or staff data on a computer, app or spreadsheet is likely to be covered, but please confirm with a qualified professional.
Do we need a Data Protection Officer?
The Act requires a Data Protection Officer only for entities classified as Significant Data Fiduciaries, which is decided by the government. Most societies are unlikely to fall in that group, but every society should still name one person who answers privacy questions.
Can the guard keep a paper visitor register?
The Act is about digital personal data, so a purely paper register may fall outside it. Paper registers still carry privacy risk, so keep them closed, do not let visitors read earlier entries, and destroy old books on a schedule.
How long should visitor records be kept?
The Act says data should not be kept longer than needed for its purpose, but it does not give one number for societies. Many societies keep full visitor photos for a few months and keep only basic entries longer, and your committee should record its chosen period in a resolution.
This article is general information, not legal or professional advice. Rules differ by state and by society, so check your bye-laws and ask a qualified professional where it matters.