Surveillance guidelines, video recording safety, and audit rules for physical security at offices and branch premises.
CCTV ACCESS POLICY
Policy Overview
| Field | Details |
| Reference No. | DJTMPL/IT/POL/CCTV/2026 |
| Version | 2.0 |
| Review Date | 01-04-2026 |
| Policy Approving Authority | Board of Directors / Director |
| Policy Owner | Chief Operation Officer (COO) |
| Next Review Period | 01-04-2027 (Annual or upon material change) |
| Classification | Internal Use Only |
| Applicable To | Head Office, All Micro Centres, Field Offices – Pan-India |
Document Revision History
| Version | Release Date | Change Description |
| 1.0 | 01-06-2024 | First version |
| 2.0 | 01-04-2026 | Second version |
Table of Contents
| S. No | Particulars |
| Introduction & Background | |
| Purpose | |
| Scope | |
| Regulatory & Legal Framework | |
| Policy Statement | |
| Camera Placement & Installation Standards | |
| Monitoring Procedures & Access Control | |
| Data Retention, Storage & Deletion | |
| Roles & Responsibilities | |
| Incident Management & Non-Compliance | |
| Policy Review & Version Control |
Applicability
This policy applies to all offices and locations of DJTMPL, including the Head Office, all Branches across all states, satellite and field offices, and any third-party premises where DJTMPL CCTV equipment is installed or operated. It is mandatory for all employees, contractors, security personnel, vendors, and visitors.
1. Introduction & Background
DJTMPL & its subsidiaries are committed to protecting the safety and property of its branches while respecting the privacy rights of our staff, customers, visitors, and promoters. Closed-Circuit Television (CCTV) and video surveillance systems form a foundational element of DJTMPL’s physical security and operational integrity framework. violation of law or Company policy.
Cameras are not a guarantee of safety, but they serve as strong deterrents, alert us to potential danger, and enable timely response when incidents occur. The primary use of CCTV at DJTMPL is to record images for the future identification of individuals and the documentation of activity in the event of a violation of law or Company policy. This policy has been developed in alignment with the Digital Personal Data Protection (DPDP) Act 2023, and the Information Technology Act 2000 and its amendments.
2. Purpose
The purpose of this policy is to establish a clear, consistent, and legally compliant framework for the installation, operation, monitoring, access, and management of CCTV and video surveillance systems across all DJTMPL locations. It aims to:
- Safeguard the physical security of DJTMPL’s premises, assets, employees, customers, and visitors from threats including robbery, theft, fraud, vandalism, and unauthorised access, while simultaneously respecting and protecting the privacy rights and dignity of all individuals on DJTMPL premises.
- Ensure that surveillance footage is retained, accessed, disclosed, and disposed of in full compliance with the DPDP Act 2023, and all other applicable Indian laws and regulations.
- Define clear roles, responsibilities, and escalation paths for all personnel involved in CCTV operations — from installation and monitoring to incident response and regulatory reporting.
- Establish a documented evidentiary basis for law enforcement, regulatory enquiry, and internal disciplinary proceedings wherever required.
3. Scope
This policy covers all full-time, part-time, contractual, and temporary employees of DJTMPL, as well as interns, trainees, apprentices, and volunteers. It applies equally to all third-party vendors, contractors, service providers, and business partners who access DJTMPL premises or CCTV systems, and to customers, delivery personnel, and any other visitors present on DJTMPL-controlled premises at any time.
This policy does not apply to cameras or devices used solely for non-surveillance purposes such as video conferencing or product demonstrations. It does not apply to cameras used by law enforcement agencies pursuant to lawful authority, including body cameras, covert surveillance ordered by a competent court, or cameras installed on law enforcement vehicles.
4. Regulatory & Legal Framework
DJTMPL operates within a layered regulatory environment that directly governs how CCTV systems must be deployed, managed, and secured. Key frameworks include:
- Digital Personal Data Protection (DPDP) Act 2023 – since video footage that can identify individuals constitutes personal data, DJTMPL is classified as a Data Fiduciary and must ensure lawful basis for processing, data minimisation, purpose limitation, storage limitation, and adequate security safeguards.
- Information Technology Act 2000 and its 2008 amendments – impose obligations regarding data privacy and carry penalties for the unauthorised interception or disclosure of electronic records, including video footage.
- Prevention of Money Laundering Act (PMLA) 2002 – CCTV records at cash-handling and customer-interaction points may serve as compliance evidence in AML and KYC investigations.
- Bharatiya Nyaya Sanhita 2023 – tampering with CCTV recordings to conceal or facilitate a crime constitutes a criminal offence.
In any conflict between applicable law and this policy, the more restrictive provision shall prevail.
5. Policy Statement
DJTMPL is committed to deploying and maintaining a comprehensive, ethically operated, and legally compliant CCTV and video surveillance infrastructure across all its premises. The Company reserves the right to install, operate, and maintain video surveillance cameras at all appropriate locations as determined by security risk assessments and regulatory requirements. All camera installations must be carried out in accordance with the Safety and Security Camera Procedures specified in this policy. Information obtained from security cameras is considered Company property and will be used for safety, security, and law or policy enforcement purposes only.
Category 1 – Restricted Data
Protection of this data is required by law or regulation. The loss of confidentiality, integrity, or availability of the data could have a significant adverse impact on DJTMPL's mission, safety, finances, or reputation. Restricted data includes bank account numbers, credit and debit card numbers, Aadhaar Card Numbers, state-issued driver license and identification numbers, protected health information (PHI), computer passwords, and passport numbers.
Individuals who access, process, store, or in any other way handle Category 1 – Restricted Data must implement controls and security measures as required by relevant laws, regulations, and company policy.
Category 2 – Private Data
Includes Company data not identified as Category 1 – Restricted Data and data protected by state regulations. Private data must be protected to ensure it is only disclosed as required by law.
6. Camera Placement & Installation Standards
Every new camera installation or significant modification must be preceded by a documented physical security risk assessment conducted by the IT Head in consultation with the relevant Branch or Location Manager. The assessment must identify the specific security risks at the location and justify each camera placement decision. The following standards apply:
- Only cameras and VMS equipment approved by the IT Head from the Company's approved vendor list may be installed; no branch manager or employee may independently procure or install camera equipment.
- All cameras must be fully operational and connected to the VMS before being placed in service — non-functional or disconnected cameras must not be left in position as they create a false sense of security and may mislead individuals about the extent of actual monitoring.
- All IP cameras must be connected through a secure, network-segmented infrastructure isolated from the general corporate IT network using VLANs or equivalent controls.
- Default manufacturer passwords must be changed immediately upon installation, and firmware updated to the latest version before commissioning.
- Night-vision or low-light capability is mandatory for all external cameras and areas operating on a 24x7 basis.
- All cameras and associated systems must undergo a formal annual inspection by the IT Department to verify operational status, image quality, tamper-evidence, and alignment with placement requirements, with inspection results documented and tracked.
Security Camera Functions: Although physically identical, security cameras serve three main functional categories:
- Property Protection – Capture and store video on a centralised VMS so that if property is reported stolen or damaged, the video may identify the perpetrator.
- Personal Safety – Capture and store video on a centralised VMS so that if a person is assaulted, the video may identify the perpetrator.
- Extended Responsibility – Provide live video stream monitoring by a staff member in proximity, with footage also stored on the centralised VMS.
7. Monitoring Procedures & Access Control
Neither the installation of security cameras nor this policy constitutes an undertaking by the Company to provide continuous live monitoring of all locations. At the discretion of the Company, cameras may be monitored in real time when safety or security concerns, event monitoring, ongoing investigations, alarms, or other situations warrant such monitoring.
Monitoring Standards:
- Monitoring shall be performed by personnel trained in the technical, legal and ethical parameters of appropriate camera use, who will provide written acknowledgement that they have read and understood this policy.
- Monitoring shall be based on suspicious behaviour, not individual characteristics. Personnel will not monitor individuals based on race, gender, ethnicity, sexual orientation, disability, or other protected classifications by the Company’s Non-discrimination Policy.
- Personnel will not continuously view people becoming intimate in public areas and will not attempt to view private rooms or areas through windows.
- Access to monitoring locations or capability shall be strictly limited to trained personnel; equipment shall be configured to prevent tampering, duplicating, downloading, or transmitting recorded video information.
- Monitoring personnel who violate guidelines in this policy shall be subject to disciplinary action up to and including termination, and possible legal action where appropriate.
Access Control Standards:
- Only authorised personnel and/or business partners, as determined by this policy and authorised by key management, will have access to surveillance camera data.
- The use of dummy or placebo cameras is prohibited.
- Only authorised personnel may review images from surveillance camera data when an incident is suspected.
- Only key management or their designee may authorise copies of surveillance images.
- All requests to release surveillance records must be authorised by the respective business head and IT head.
- DJTMPL will not permit the installation or use of cameras as a tool to monitor routine performance or management issues, or the use of personal webcam or similar technology for surveillance purposes. Employees of any department with surveillance cameras shall be notified of such installation.
- The recording of audio for surveillance purposes is prohibited.
- Video monitoring will be conducted only in areas where the public does not have a reasonable expectation of privacy.
8. Data Retention, Storage & Deletion
Recorded camera images must be retained for clearly defined minimum periods to balance operational security needs, regulatory requirements, and the privacy of individuals:
- Head Office and general area cameras at Micro Centres: minimum 90 days retention as per industry practices.
- Cash counter and vault cameras at every Micro Centre and all server room cameras: minimum 180 days retention due to heightened financial risk.
- Access logs documenting all use of and access to the VMS: minimum 12 months retention.
Where an incident has occurred or is reasonably suspected, the affected footage must immediately be placed on a legal hold by the IT Head and retained until the relevant investigation, legal proceeding, regulatory enquiry, or disciplinary proceeding is fully resolved.
All footage must be stored on Company-owned or Company-contracted infrastructure and encrypted at rest. Cloud backup providers must be assessed and approved by the IT Head and must store data within India or in jurisdictions permissible under applicable data localisation rules. Storage systems must maintain a tamper-evident audit trail of all access, modification, and deletion events, and must be protected by multi-factor authentication (MFA) for all administrative users.
When footage reaches the end of its retention period and is not subject to a legal hold, it must be securely and irrecoverably deleted using approved data sanitisation methods, with each deletion recorded in the Data Disposal Register. Physical storage media that cannot be securely wiped must be physically destroyed by an approved vendor, with a destruction certificate obtained and filed.
9. Roles & Responsibilities
Clear ownership and accountability is essential to the effective governance of DJTMPL's CCTV infrastructure. Key responsibilities are as follows:
- Board of Directors and MD & CEO: Hold ultimate accountability for the governance of this policy, provide strategic oversight, and approve the policy and any material revisions.
- Chief Information Security Officer (CISO): Owns this policy, is responsible for its annual review and update, liaises with regulators on CCTV-related compliance matters, and commissions periodic security audits.
- IT Head: Responsible for day-to-day deployment, configuration, and maintenance of all CCTV equipment and the VMS; monitors system health and access logs regularly; manages all authorised user accounts.
- Compliance Officer: Oversees the audit compliance programme, manages regulatory reporting obligations, and escalates major incidents to the RBI or other authorities where required by law.
- Branch and Micro Centre Managers: Responsible for day-to-day operational oversight of CCTV at their location, including reporting camera faults, maintaining signage, and initiating the Footage Review Request process when a security incident occurs.
- HR Head: Manages the employee training and awareness programme, ensures new employees are informed of CCTV usage during onboarding, and oversees disciplinary proceedings for breaches.
- Legal Officer and Data Protection Officer (DPO): Handles data subject access requests, manages liaison with law enforcement, oversees the Disclosure Register, and conducts Data Protection Impact Assessments as required.
- Authorised CCTV Operators: Conduct live monitoring in accordance with this policy, exercise sound judgement, and never use access for any unauthorised purpose.
- All Employees: Share a general duty to report suspected tampering with, damage to, or misuse of any CCTV equipment or system to the IT Head or Branch Manager without delay.
10. Incident Management & Non-Compliance
All security incidents involving or detected by the CCTV system must be classified by severity and responded to promptly and systematically:
- Critical incidents (robbery, physical assault, unauthorised server room intrusion, or system-wide CCTV failure): Must be escalated immediately to the Branch Manager, IT Head, CISO, and MD/CEO, with law enforcement notified as appropriate.
- High-severity incidents (unauthorised access to VMS, tampering with or disabling cameras, suspected footage deletion): Must be escalated to the IT Head and CISO, with a formal investigation initiated promptly.
- Medium-severity matters (single camera failure, storage capacity alerts, log anomalies): Must be resolved within the applicable working-hour window based on zone criticality.
When an incident occurs, the IT Head must immediately place a legal hold on all relevant footage. All incidents must be documented in the CCTV Incident Register, capturing date, time, location, nature of incident, camera IDs involved, personnel notified, and actions taken. For major incidents, the Compliance Officer must assess whether regulatory reporting to the RBI, the Data Protection Board of India, or other relevant authorities is required, and must initiate such reporting within mandated timeframes.
Compliance with this policy is mandatory for all individuals within its scope. Serious or gross misconduct — including deliberately tampering with CCTV equipment or recordings, accessing the VMS or footage without authorisation, sharing or leaking footage to unauthorised persons, using footage to harass or blackmail any individual, monitoring people based on a protected characteristic, or installing any recording device without proper authorisation — may result in immediate suspension, termination of employment or contract, and referral to law enforcement or regulatory authorities.
11. Policy Review & Version Control
This policy shall be reviewed by the CISO, in consultation with the IT Head, Legal Officer, and Compliance Officer, at least once every twelve months. An unscheduled review must be initiated upon: issuance of new or amended RBI guidelines or notifications under the DPDP Act or other applicable legislation; or occurrence of a significant security incident or personal data breach involving CCTV footage that reveals gaps in current controls or procedures.
All approved versions of this policy will be version-controlled with a full change log, and superseded versions archived and retained for a minimum of seven years for audit and regulatory purposes. Upon approval of any revised version, the updated policy will be communicated to all employees and relevant stakeholders, and written acknowledgement obtained and recorded by the HR Department.