Skip to content
← Writing
20 June 2026·3 min read

India's 2026 camera rules, explained: STQC, MeitY, and DPDP

STQC certification is now mandatory for CCTV in India, MeitY has closed the grace periods, and the DPDP Act lands in 2027. What every gated community should know about the new rules — and do now.

If you look after security for a housing society, a campus, or a commercial complex in India, three regulatory changes now sit on top of every camera you own. They arrived close together, they point in the same direction, and many operators only hear about them when a vendor mentions it in passing. Here is the short version — and what to actually do.

What changed

STQC certification is mandatory. Since 1 April 2026, CCTV equipment used in India is expected to meet STQC (Standardisation Testing and Quality Certification) requirements. The intent is simple: surveillance hardware on Indian soil should be tested and accountable, not an unknown box quietly streaming to an unknown server.

MeitY closed the grace periods. An office memorandum from MeitY dated 16 January 2026 tightened the timeline and removed the breathing room operators had been counting on. In practice, "we'll deal with it later" stopped being a strategy.

The DPDP Act is next. Enforcement of the Digital Personal Data Protection Act is expected from 13 May 2027. Footage of people is personal data. Once the Act applies, how you capture, store, share, and delete that footage becomes a legal obligation rather than an IT preference.

Why the three matter together

Read on their own, each looks like paperwork. Read together, they describe one shift: India is asking its physical security to be sovereign, accountable, and privacy-respecting at the same time.

The model most gates run today struggles on all three counts. Imported cameras point at imported recorders that stream to servers the operator cannot see inside, built for other countries' rules. That arrangement is hard to certify, hard to audit, and hard to defend under a data-protection law — which happens to be exactly what the new regime asks for.

What a gated community should do now

You do not need to rip everything out. You need to know where you stand.

  1. Inventory your cameras. Note the make, the model, and where each one sends its data. You cannot certify or defend what you have not mapped.
  2. Ask vendors for their STQC status in writing. A clear answer tells you a lot; a vague one tells you more.
  3. Keep footage on the property. The fewer places a frame travels, the smaller your compliance surface and your risk.
  4. Write a retention policy, and follow it. Decide how long clips live, who can export them, and log every override. DPDP rewards deletion, not hoarding.
  5. Prefer processing at the edge. If recognition happens on site, on hardware you can account for, residency and auditability stop being promises and become facts.

Where Atlas fits

Atlas was built for exactly this moment. A small box behind the guard cabin works on the cameras a property already owns; raw video never leaves the premises, and every event is written to an access-controlled, exportable audit log. We begin with the vehicle — read the number plate and check it against the VAHAN registry, with cloned-plate detection on the roadmap — and people, zones, and crowds on the roadmap too, on the same box.

If the 2026 rules have landed on your desk, that is a good reason to talk. Read the detail on our compliance page, or book a one-gate pilot and see it on your own cameras.