What India's DPDP Act means for RWAs and housing societies
RWAs hold resident phone numbers, visitor logs, CCTV and payment records. What India’s Digital Personal Data Protection Act, 2023 means for committees.
CITYTECH INNOVATIONS Team, CITYTECH INNOVATIONS
· 9 min read
A typical society holds more personal data than most small businesses: owner and tenant details, phone numbers, vehicle numbers, visitor logs, daily-help records, CCTV footage and payment history. India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules notified in November 2025 set out how organisations must handle that kind of data. This article is general information for committees, not legal advice.
Who is who under the Act
- Data Principal: the person the data is about. Residents, tenants, visitors, staff and daily help.
- Data Fiduciary: the organisation that decides why and how data is processed. For society operations, that is usually the RWA, AOA or cooperative society.
- Data Processor: an organisation that processes data on the fiduciary's behalf, such as a facility management company or a software provider like CITYTECH INNOVATIONS.
What committees should do
Collect only what you need
Ask whether each piece of data is actually needed. A visitor log needs a name, flat and time. It rarely needs a photocopy of an identity document. Daily-help verification may need police verification records, but those should be stored securely and not passed around WhatsApp groups.
Tell people what you collect and why
The Act expects a clear notice explaining what data is collected, for what purpose, and how people can exercise their rights. A one-page privacy notice on the noticeboard and in the welcome message for new residents is a practical start.
Get consent where consent is the basis
Where you rely on consent, it must be free, specific, informed and capable of being withdrawn as easily as it was given. Adding a new tenant to a promotional broadcast list without asking is the kind of thing to avoid.
Secure the data, including on personal phones
Resident lists in personal WhatsApp chats and Excel files on committee members' laptops are the most common weak point. Fiduciaries are expected to take reasonable security safeguards and to notify the Data Protection Board and affected people if there is a breach.
Delete what you no longer need
Old tenants' records, years of visitor logs and footage beyond your retention period should be deleted on a schedule the committee agrees and documents.
Respond to rights requests
People can ask to access, correct or erase their data and must have a way to raise grievances. Name a committee member as the contact and record how requests are handled.
How CITYTECH INNOVATIONS is designed for this
- The society is the Data Fiduciary. CITYTECH INNOVATIONS acts as Data Processor under a written agreement.
- Each society's data is isolated from every other society's.
- Residents see only their own tickets, payments and visitor records.
- Data is encrypted in transit and at rest, with access limited by role.
- Retention periods are set per society, and data is exported or deleted on exit.
Our Data Processing & Security page sets out the full details, including sub-processors and breach notification commitments.