SocietyBee
    Billing
    Automated maintenance & charge billing
    Collections
    Track payments, send reminders
    Accounting
    Double-entry ledger & bank reconciliation
    Reports & Compliance
    Bye-law compliant statutory reports
    BeeAgent AI
    Natural language queries on your data
    For CAs & Accountants
    Manage all societies from one login
    For Treasurers
    Simple billing & audit-ready records
    For Managing Committee
    Visibility without the spreadsheets
    Blog
    Society management guides & tips
    Glossary
    Accounting & society terms explained
    vs MyGate
    Accounting vs gate security app
    vs ApnaComplex
    Multi-society CA login vs per-society pricing
    vs SocietyRun
    BeeAgent AI & zero gateway commission
    vs NoBrokerHood
    Accounting vs marketplace app
    vs Excel
    Audit trail & statutory reports vs spreadsheets
    Pricing
    Sign inStart free →
    Blog/DPDP Act 2023 for Housing Societies: What Your Committee Must Fix Before November 2026
    English·मराठी·हिंदी
    Bye-Laws & Compliance8 min read

    DPDP Act 2023 for Housing Societies: What Your Committee Must Fix Before November 2026

    Your visitor register, CCTV footage and society app all hold personal data, and under the DPDP Act your committee is legally the data fiduciary responsible for it. Here's what to fix before November.

    YR

    Yogesh Randive

    Founder, SocietyBee

    15 September 2026
    01

    What the DPDP Act Means for a Housing Society

    The Digital Personal Data Protection Act, 2023 (DPDP Act) treats any organisation that decides why and how personal data is collected as a 'data fiduciary'. A housing society doesn't need to run a business or sell anything to qualify. The moment your security guard notes down a visitor's name and phone number in the register, or your gate camera records a resident's face on the way in, the society is processing personal data, and the managing committee is the data fiduciary responsible for it.

    This surprises most committees because a society doesn't think of itself as handling 'data' the way a bank or an e-commerce company does. But the Act doesn't carve out an exemption for a 40-flat building. If your society collects a visitor's phone number, keeps a tenant's Aadhaar copy for police verification, runs CCTV at the entrance, or uses an app that holds every resident's phone number and payment history, all of it falls inside the Act.

    The other party involved, your CCTV vendor, your society management app, the security agency that supplies the guards, is typically a 'data processor' acting on the society's instructions. Under the Act, the fiduciary carries the legal responsibility even when a processor is the one physically holding the data.

    02

    Why 14 November 2026 Matters

    The DPDP Act was passed in 2023 but given an 18-month transition period before enforcement began in earnest. That window closes on 13-14 November 2026, a little over eight weeks from now. After that date, the Data Protection Board of India moves from a guidance posture to active enforcement, meaning it can act on a resident's complaint rather than simply asking an organisation to fix things quietly.

    Penalties for serious violations under the Act can run up to ₹250 crore. That figure is written with large corporations in mind, not a residential society, but the law itself makes no such distinction. What it does specify is that the persons who decide the purpose and means of processing, in a society's case, the managing committee, are the ones who answer for it. Property management platforms like ADDA and MyGate have already been running DPDP workshops for RWAs since the start of this year, and that's usually a reliable sign that the better-run societies are already ahead of this, not waiting for November.

    03

    The Three Places Every Society Is Actually Exposed

    Almost every society's DPDP risk sits in the same three places, and none of them need any malicious intent to become a violation, just a process nobody has looked at since it was set up.

    The visitor register is the most obvious. A security guard collects a visitor's name and phone number because that's how it has always been done, not because anyone asked the visitor for consent or decided how long the entry should be kept. Registers running back years with no retention policy are common.

    CCTV is the more serious exposure. Footage gets pulled for a parking dispute or a theft complaint and ends up forwarded into a resident WhatsApp group as informal justice, footage collected for security now being used for something else entirely. That gap between why data was collected and what it's actually used for is exactly what the Act is built to catch.

    The society management app is the third, and the one committees examine the least. Every resident's phone number, flat number, family details and payment history sits on a vendor's servers, and most committees have never read what that vendor's data processing agreement actually says about where the data is stored, who can access it, or how long it's kept after a resident moves out.

    Free to try

    Managing a housing society?

    Auto-generate bye-law compliant bills, track collections, and produce audit-ready reports — free for societies up to 50 flats.

    Get started free
    04

    Who Is Personally Liable if a Resident Complains

    This is the part committees underestimate most. A complaint under the DPDP Act isn't filed against 'the society' as an abstract entity, it's examined against the people who made the decision, the managing committee members who approved the CCTV vendor, signed off on the visitor management process, or never set a retention policy in the first place.

    This is the same pattern Maharashtra housing societies already know from the MCS Act, where committee members carry personal liability for bye-law non-compliance rather than the society absorbing it collectively. DPDP works the same way. There's no separate legal shield for a 40-flat committee that doesn't exist for a listed company, there's simply a much lower chance anyone has checked, until a resident actually complains.

    05

    The One-Afternoon Data Audit Every Committee Should Run

    Before fixing anything, sit down as a committee and list out every place personal data enters the society. For each one, write down what's collected, why, who can access it, and how long it's kept. Done properly, this single exercise usually surfaces most of the gaps on its own.

    • Visitor register: name, phone number, vehicle number, purpose of visit, entry and exit time
    • CCTV footage: entrance, lobby, parking, and how long each camera's footage is actually retained today
    • Society management app: resident phone numbers, flat details, family members, payment and dues history
    • Tenant and staff KYC: Aadhaar copies, PAN, police verification forms kept in physical files
    • Informal records: the treasurer's Excel sheets, the secretary's WhatsApp broadcast list, any shared Google Sheet with member details
    06

    Four Fixes Worth Making Before November

    Once the audit is done, four changes cover most of the gap for a typical society.

    • Set a CCTV retention limit, thirty days is a reasonable default unless a specific incident needs longer, and stop pulling footage into resident WhatsApp groups. Route any footage request through one named person and a short written request instead.
    • Tighten the visitor register to what security genuinely needs, and if visitor entry runs through a digital app, ask that vendor directly what happens to the data afterward.
    • Get explicit, separate consent for anything beyond basic security use. A resident directory shared for festival planning is a different consent from a directory handed to a vendor for marketing, and most societies never draw that line today.
    • Name one person, not 'the committee' collectively, as the point of contact for any resident's data request or grievance. The Act gives residents the right to ask what data the society holds on them and to request correction or deletion, and having nobody clearly responsible for that is a governance gap that looks bad the moment it's tested.
    07

    What to Ask Your Society App Vendor

    If your society runs its accounting, billing or gate access through an app, and most do now, the vendor's own DPDP posture becomes your society's exposure too. Ask directly where resident data is stored, how long it's retained after a member exits, who inside the vendor's team can access it, and what happens to it if the society ever switches software.

    On SocietyBee, society data is stored on Supabase in AWS's Mumbai region, encrypted with AES-256 at rest and TLS 1.3 in transit, with each society's data isolated from every other society on the platform, even when the same CA manages multiple societies. That's the baseline any vendor handling resident phone numbers, flat details and payment history should be able to answer without hesitation. If yours can't, that's worth knowing before November, not after a complaint.

    FAQ

    Frequently Asked Questions

    Does the DPDP Act actually apply to a housing society?

    Yes. The Act applies to any organisation that decides why and how personal data is collected, called a data fiduciary, regardless of size or whether it runs as a business. A housing society collecting visitor details, running CCTV, or storing resident data in an app qualifies the moment it does any of these.

    What is the compliance deadline for the DPDP Act?

    The Act's 18-month transition period ends on 13-14 November 2026. After that date, the Data Protection Board of India can act on complaints directly rather than operating in a guidance-only mode.

    How long should a housing society retain CCTV footage?

    There's no single number fixed by law for every use case, but thirty days is a reasonable default for routine footage unless a specific incident, a theft complaint or a police request, needs it held longer. Footage should never be forwarded into resident WhatsApp groups as a substitute for a formal request process.

    Can individual committee members be held personally liable under the DPDP Act?

    Yes, in practice. A complaint is examined against the people who decided how data is processed, which for a housing society means the managing committee members who approved the process, not an abstract 'society' entity. This mirrors how committee members already carry personal liability for bye-law non-compliance under the MCS Act.

    What is the penalty for a DPDP Act violation?

    Penalties for serious violations can run up to ₹250 crore, a figure aimed at large organisations rather than a residential society. The Act doesn't set a lower cap for smaller entities, which is why the practical fix for most societies is basic housekeeping, retention limits, consent and a named grievance contact, rather than a compliance budget.

    Explore in SocietyBee

    • Reports & Compliance

    Official & Reference Sources

    • India's DPDP Timeline: Critical Compliance Deadlines for 2026-27, India Briefing
    • DPDP Act for Housing Societies: Rules & Compliance Guide, NoBrokerHood
    • DPDP Act for Housing Societies: Complete Guide for RWAs, ADDA
    • Housing Society CCTV Policy in India (2026), Studio Matrx
    Share:WhatsAppLinkedIn
    YR

    Yogesh Randive

    Founder, SocietyBee

    Yogesh built SocietyBee after spending years helping housing societies in Mumbai manage accounts in Excel. He writes about Maharashtra co-operative law, society accounting, and the practical realities of running a housing society in India.

    In this article

    1. What the DPDP Act Means for a Housing Society
    2. Why 14 November 2026 Matters
    3. The Three Places Every Society Is Actually Exposed
    4. Who Is Personally Liable if a Resident Complains
    5. The One-Afternoon Data Audit Every Committee Should Run
    6. Four Fixes Worth Making Before November
    7. What to Ask Your Society App Vendor
    8. Frequently Asked Questions

    Related articles

    View all →
    Bye-Laws & Compliance11 min read

    Maharashtra Housing Society Rules 2026: What Changed

    The state has notified Chapter XI-B, the first dedicated rulebook for Maharashtra's 1.27 lakh housing societies, and the Co-operative Commissioner has put out a rewritten Model Bye-Laws draft to match it. Here is what changes for interest, mandatory funds, redevelopment, membership transfers and recovery of dues, and what your committee should do before the objection window closes.

    26 Aug 2026Read →
    Accounting Basics8 min read

    Why Naming and Shaming Maintenance Defaulters Backfires

    A housing society board listing defaulters by name and flat number, with warnings that food delivery and domestic help will be stopped, sounds effective, and it often is. But it's legally shaky and it breaks the trust a society runs on. Here's why committees reach for it, and what actually closes the gap between due and paid.

    9 Sept 2026Read →
    Bye-Laws & Compliance6 min read

    Video Conferencing Now Allowed for Housing Society General Body Meetings (2026)

    Missing a GBM because you're travelling no longer has to mean missing your vote. Maharashtra's 2026 rules now let members join general body meetings by video conferencing. Here is exactly what's permitted and what a society needs in place before offering it.

    24 Jul 2026Read →
    SocietyBee

    Built in Mumbai by Simplifyne Technologies Private Limited. Serving housing societies across India.

    Enquiries

    +91 95949 04493
    admin@societybee.in

    Product

    • Billing
    • Collections
    • Accounting
    • Reports & Compliance
    • BeeAgent AI
    • For CAs & Accountants
    • For Treasurers
    • For Managing Committee

    Resources

    • Blog
    • Glossary
    • SocietyBee vs MyGate
    • SocietyBee vs ApnaComplex
    • SocietyBee vs SocietyRun
    • SocietyBee vs NoBrokerHood
    • SocietyBee vs Excel

    Company

    • About
    • Trust & Security
    • Pricing
    • Early Access
    • Book a Demo
    • Contact
    • Privacy Policy
    • Terms & Conditions
    • Refund Policy

    🇮🇳 We serve housing societies across India

    Operating team based in Mumbai.

    © 2026 Simplifyne Technologies Private Limited.

    All rights reserved.