Sector reference
DPDP for Co-Working Spaces
- What is processed
- Member sign up details, visitor records, and Wi Fi or system logs, where the space needs them to run the workspace and keep it secure.
Why it is allowed, and when
The ordinary rules apply. The space also has to have a proper contract with any vendor handling data on its behalf, and from 13 May 2027 there is a detailed security floor every organisation has to meet.
Where the permission stops
A member directory, or an access log, is not by itself permission to pass member details around or to market from them. Nothing here sets up a special regime for co-working spaces.
Questions people actually ask
Can they keep access logs and CCTV after I stop being a member?
Only while a live reason remains, or while a law requires it. Security records can be kept for a sensible period in line with the security rules, but keeping them indefinitely after you have gone needs a justification, and habit is not one.
Can they monitor my internet usage or device data?
Only where it is genuinely necessary for a stated reason, such as keeping the network secure, and only as far as that reason needs. Watching everything by default, with no clear purpose, is not supported.
My client visited me at the space. Can the space market to them?
No. Your visitor gave their details at the desk so that they could be let in. That is the reason, and it does not stretch to them becoming a sales lead for the space.
Turning a visitor log into a prospect list is a new purpose with nothing behind it, and the person it affects never had any relationship with the space at all.
Can the space tell my company when I arrive and leave?
Only where there is a reason for it. If your company is paying for the desk and the arrangement genuinely involves attendance being reported back, that can sit inside the service being provided.
Where it does not, sending your comings and goings to somebody else is a disclosure that needs its own footing. It should also be something you were told about up front, rather than something you discover later.
What people get wrong
Being in the member directory means we can share your details with anyone here.
Holding your details is not permission to disclose them. Sharing needs a reason of its own.
We monitor all network activity because it is our Wi-Fi.
Monitoring needs a stated reason, such as keeping the network secure, and it has to stay limited to what that reason needs. Watching everything by default, with no defined purpose, is not supported by anything in the Act.
Related questions
- Does CCTV need consent under DPDP?
- Is CCTV footage personal data?
- Does DPDP apply to my small business?
This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.