What the DPDP Act Means for a Housing Society
The Digital Personal Data Protection Act, 2023 (DPDP Act) treats any organisation that decides why and how personal data is collected as a 'data fiduciary'. A housing society doesn't need to run a business or sell anything to qualify. The moment your security guard notes down a visitor's name and phone number in the register, or your gate camera records a resident's face on the way in, the society is processing personal data, and the managing committee is the data fiduciary responsible for it.
This surprises most committees because a society doesn't think of itself as handling 'data' the way a bank or an e-commerce company does. But the Act doesn't carve out an exemption for a 40-flat building. If your society collects a visitor's phone number, keeps a tenant's Aadhaar copy for police verification, runs CCTV at the entrance, or uses an app that holds every resident's phone number and payment history, all of it falls inside the Act.
The other party involved, your CCTV vendor, your society management app, the security agency that supplies the guards, is typically a 'data processor' acting on the society's instructions. Under the Act, the fiduciary carries the legal responsibility even when a processor is the one physically holding the data.
Why 14 November 2026 Matters
The DPDP Act was passed in 2023 but given an 18-month transition period before enforcement began in earnest. That window closes on 13-14 November 2026, a little over eight weeks from now. After that date, the Data Protection Board of India moves from a guidance posture to active enforcement, meaning it can act on a resident's complaint rather than simply asking an organisation to fix things quietly.
Penalties for serious violations under the Act can run up to ₹250 crore. That figure is written with large corporations in mind, not a residential society, but the law itself makes no such distinction. What it does specify is that the persons who decide the purpose and means of processing, in a society's case, the managing committee, are the ones who answer for it. Property management platforms like ADDA and MyGate have already been running DPDP workshops for RWAs since the start of this year, and that's usually a reliable sign that the better-run societies are already ahead of this, not waiting for November.
The Three Places Every Society Is Actually Exposed
Almost every society's DPDP risk sits in the same three places, and none of them need any malicious intent to become a violation, just a process nobody has looked at since it was set up.
The visitor register is the most obvious. A security guard collects a visitor's name and phone number because that's how it has always been done, not because anyone asked the visitor for consent or decided how long the entry should be kept. Registers running back years with no retention policy are common.
CCTV is the more serious exposure. Footage gets pulled for a parking dispute or a theft complaint and ends up forwarded into a resident WhatsApp group as informal justice, footage collected for security now being used for something else entirely. That gap between why data was collected and what it's actually used for is exactly what the Act is built to catch.
The society management app is the third, and the one committees examine the least. Every resident's phone number, flat number, family details and payment history sits on a vendor's servers, and most committees have never read what that vendor's data processing agreement actually says about where the data is stored, who can access it, or how long it's kept after a resident moves out.
Managing a housing society?
Auto-generate bye-law compliant bills, track collections, and produce audit-ready reports — free for societies up to 50 flats.
Get started freeWho Is Personally Liable if a Resident Complains
This is the part committees underestimate most. A complaint under the DPDP Act isn't filed against 'the society' as an abstract entity, it's examined against the people who made the decision, the managing committee members who approved the CCTV vendor, signed off on the visitor management process, or never set a retention policy in the first place.
This is the same pattern Maharashtra housing societies already know from the MCS Act, where committee members carry personal liability for bye-law non-compliance rather than the society absorbing it collectively. DPDP works the same way. There's no separate legal shield for a 40-flat committee that doesn't exist for a listed company, there's simply a much lower chance anyone has checked, until a resident actually complains.
The One-Afternoon Data Audit Every Committee Should Run
Before fixing anything, sit down as a committee and list out every place personal data enters the society. For each one, write down what's collected, why, who can access it, and how long it's kept. Done properly, this single exercise usually surfaces most of the gaps on its own.
- Visitor register: name, phone number, vehicle number, purpose of visit, entry and exit time
- CCTV footage: entrance, lobby, parking, and how long each camera's footage is actually retained today
- Society management app: resident phone numbers, flat details, family members, payment and dues history
- Tenant and staff KYC: Aadhaar copies, PAN, police verification forms kept in physical files
- Informal records: the treasurer's Excel sheets, the secretary's WhatsApp broadcast list, any shared Google Sheet with member details
Four Fixes Worth Making Before November
Once the audit is done, four changes cover most of the gap for a typical society.
- Set a CCTV retention limit, thirty days is a reasonable default unless a specific incident needs longer, and stop pulling footage into resident WhatsApp groups. Route any footage request through one named person and a short written request instead.
- Tighten the visitor register to what security genuinely needs, and if visitor entry runs through a digital app, ask that vendor directly what happens to the data afterward.
- Get explicit, separate consent for anything beyond basic security use. A resident directory shared for festival planning is a different consent from a directory handed to a vendor for marketing, and most societies never draw that line today.
- Name one person, not 'the committee' collectively, as the point of contact for any resident's data request or grievance. The Act gives residents the right to ask what data the society holds on them and to request correction or deletion, and having nobody clearly responsible for that is a governance gap that looks bad the moment it's tested.
What to Ask Your Society App Vendor
If your society runs its accounting, billing or gate access through an app, and most do now, the vendor's own DPDP posture becomes your society's exposure too. Ask directly where resident data is stored, how long it's retained after a member exits, who inside the vendor's team can access it, and what happens to it if the society ever switches software.
On SocietyBee, society data is stored on Supabase in AWS's Mumbai region, encrypted with AES-256 at rest and TLS 1.3 in transit, with each society's data isolated from every other society on the platform, even when the same CA manages multiple societies. That's the baseline any vendor handling resident phone numbers, flat details and payment history should be able to answer without hesitation. If yours can't, that's worth knowing before November, not after a complaint.
Frequently Asked Questions
Does the DPDP Act actually apply to a housing society?
Yes. The Act applies to any organisation that decides why and how personal data is collected, called a data fiduciary, regardless of size or whether it runs as a business. A housing society collecting visitor details, running CCTV, or storing resident data in an app qualifies the moment it does any of these.
What is the compliance deadline for the DPDP Act?
The Act's 18-month transition period ends on 13-14 November 2026. After that date, the Data Protection Board of India can act on complaints directly rather than operating in a guidance-only mode.
How long should a housing society retain CCTV footage?
There's no single number fixed by law for every use case, but thirty days is a reasonable default for routine footage unless a specific incident, a theft complaint or a police request, needs it held longer. Footage should never be forwarded into resident WhatsApp groups as a substitute for a formal request process.
Can individual committee members be held personally liable under the DPDP Act?
Yes, in practice. A complaint is examined against the people who decided how data is processed, which for a housing society means the managing committee members who approved the process, not an abstract 'society' entity. This mirrors how committee members already carry personal liability for bye-law non-compliance under the MCS Act.
What is the penalty for a DPDP Act violation?
Penalties for serious violations can run up to ₹250 crore, a figure aimed at large organisations rather than a residential society. The Act doesn't set a lower cap for smaller entities, which is why the practical fix for most societies is basic housekeeping, retention limits, consent and a named grievance contact, rather than a compliance budget.
Explore in SocietyBee
Yogesh Randive
Founder, SocietyBee
Yogesh built SocietyBee after spending years helping housing societies in Mumbai manage accounts in Excel. He writes about Maharashtra co-operative law, society accounting, and the practical realities of running a housing society in India.