‹ All sectors

Sector reference

DPDP for Residential Societies and Visitor Management

What is processed
A visitor's name, contact details and entry or exit times, where the society is handling them for a defined security or access purpose.

Why it is allowed, and when

The ordinary rules apply. From 13 May 2027 there is also a general security floor for every organisation: encryption or something equivalent, access controls, logging and monitoring, measures to keep things running after a compromise, and matching terms in any vendor's contract.

Where the permission stops

There is no retention period written specifically for visitor logs, but two separate one year minimums can reach a society, and they cover different material. The first is a security floor: logs and personal data kept in order to detect unauthorised access, investigate it, put it right, stop it happening again and keep things running afterwards have to be held for a year. The second is broader in what it covers and narrower in why: personal data, the traffic data that goes with it, and the records of what was done have to be kept for at least a year so that the purposes the Rules list can be met. We read that second one as applying to a society, because it does not narrow who has to keep it and the Rules illustrate it with an ordinary commercial platform. Some readers take it more narrowly. Either way both are floors rather than deadlines, and where one reaches a particular record, treating early deletion as automatically safe is the wrong instinct.

Questions people actually ask

Can my society keep visitor records?

Yes, where it serves a defined security or access purpose. There is no period aimed specifically at visitor logs, but two separate one year minimums can reach a society, and they cover different material.

The first is a security floor. Logs and personal data kept in order to detect unauthorised access, investigate it, put it right and keep things running afterwards have to be held for a year.

The second is broader in what it covers and narrower in why. Personal data, the traffic data that goes with it, and the records of what was done have to be kept for at least a year, so that the purposes the Rules list can be met. The Rules illustrate that one with an ordinary online purchase, which is why a society should not assume it sits outside it.

Both are floors, not deadlines. Where one of them reaches a particular record, deleting it early is not the safe course, so a society has to work out which applies to what rather than assume a single answer covers everything.

Can the security guard look through my visitor history whenever they want?

Access has to be controlled once the security rules are in force. Leaving the whole register open to whoever is on the gate is not consistent with a requirement to have proper access controls in place.

Can the society share visitor logs with the police or a flat owner on request?

Giving them to the police can be lawful, but it needs a named route. One covers a disclosure the society is obliged to make to the State under another law. Another covers processing in the interests of preventing, detecting, investigating or prosecuting an offence.

A flat owner is a completely different question. Neither route covers handing the register to a resident, and the security purpose it was collected for does not stretch that far.

Can they use visitor photos or vehicle numbers for any other purpose?

No. Details collected for security or access control cannot be turned to something else without a fresh reason.

Can the society put defaulters' names on the notice board?

Collecting your details to run the building does not extend to publishing them. Naming you on a board that every resident, visitor and delivery rider walks past is a disclosure to people who have nothing to do with the reason your data was collected in the first place.

That needs a reason of its own, and recovering money is not one the law lists. A society can pursue dues through the routes its own governing law gives it, without turning the lobby into a publication.

The society app shows every resident's flat number and phone number. Is that allowed?

A directory is a disclosure to everyone who can open the app. What would make it lawful is a reason for that sharing, not the fact that the society already holds the information.

The safer version is the one the purpose actually needs. Contact details held by the office so the office can reach you is a far narrower thing than a searchable list of who lives where, visible to every resident and to anyone who gets hold of a login.

The society also has to secure what it holds, and a widely readable directory is difficult to square with that.

What people get wrong

The data protection law requires us to take your Aadhaar or photograph at the gate.

It requires nothing of the kind. This law authorises no particular identity document. It only governs what happens to whatever is collected, and collecting an identity document still needs its own reason.

Visitor logs are open for any resident to look through.

Details collected for security or access control cannot be turned to unrelated uses. There is also a requirement to have proper access controls, so leaving the register open to browse is difficult to square with the security duty itself.

We have to keep visitor records forever now.

A year is a minimum floor, not a licence to keep everything indefinitely. Holding anything beyond the floor still needs a purpose, or a law that requires it.

Related questions

This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.