Video Analytics Privacy Compliance: India’s DPDP Act vs Canada’s PIPEDA

Video analytics privacy compliance is now a board-level question, not a back-office one. The moment a camera feed is processed by AI to count people, estimate demographics, or flag suspicious behaviour, you have moved from passive recording into the active processing of personal data. For organisations that operate across India and Canada, that single capability has to satisfy two very different legal regimes at once: India’s Digital Personal Data Protection (DPDP) Act, 2023 and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). This guide breaks down where the two diverge, where they quietly agree, and the architecture that lets one deployment stay compliant in both markets.
Existing
CCTV camera
On-prem / edge
AI processing
Anonymised
counts & events
Dashboards
& alerts
DPDP: consent + residency
PIPEDA: reasonable purpose Privacy-first video analytics: where personal data is minimised before it ever leaves the site

Why video analytics is a privacy question at all
Traditional CCTV records and stores footage. AI video analytics goes further: it interprets the footage to produce structured data such as footfall counts, dwell times, queue lengths, or behaviour alerts. Where that interpretation involves identifiable individuals (a recognisable face, a tracked person, an estimated age or gender), regulators treat it as the processing of personal data. The privacy risk is not the camera; it is what the analytics layer extracts, where that extraction happens, and how long anything identifiable is retained. If you want a primer on the underlying technology first, start with our pillar guide on what AI video analytics is.
India’s DPDP Act: consent, notice, and data residency
The DPDP Act, 2023 governs the processing of digital personal data in India. Its centre of gravity is consent. Before processing personal data, a Data Fiduciary generally must give a clear notice of purpose and obtain the individual’s consent, with limited “legitimate uses” as alternatives. For video analytics this raises practical questions: how do you obtain consent from everyone walking past a camera, and what counts as adequate notice in a public retail space? In practice, the safest posture is to avoid processing identifiable personal data wherever the business goal does not require it. If you only need a footfall count, you do not need an identity.
The Act also introduces obligations around purpose limitation, data minimisation, retention only for as long as necessary, breach notification, and the rights of individuals to access and erase their data. The Government may further restrict cross-border transfers to specified countries, so data residency and the ability to keep processing inside India become design constraints rather than afterthoughts. Children’s data and Significant Data Fiduciaries carry heightened duties, which matters for any deployment near schools, families, or large-scale monitoring.
Canada’s PIPEDA: reasonable purpose and meaningful consent
PIPEDA applies to private-sector organisations that collect, use, or disclose personal information in the course of commercial activity. Its anchoring test is different in flavour: an organisation may only collect personal information for purposes that a reasonable person would consider appropriate in the circumstances, and consent must be meaningful. Canadian privacy regulators have repeatedly signalled that covert or overly broad video surveillance, and especially facial recognition, attracts close scrutiny and a high bar for justification.
PIPEDA’s ten fair information principles map closely onto operational controls: accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access, and the ability to challenge compliance. Signage that clearly identifies the purpose of monitoring, a named accountable individual, and a documented retention schedule go a long way. Note that Canada’s framework continues to evolve, and several provinces operate their own substantially similar private-sector laws, so a multi-site Canadian rollout should confirm which statute applies where.

Where the two regimes agree
Despite different vocabularies, DPDP and PIPEDA converge on the same engineering instincts. Both reward minimisation: collect the least identifiable data needed for the stated purpose. Both expect a clearly stated, limited purpose rather than open-ended surveillance. Both require retention limits and the ability to honour access and deletion. And both treat biometric identification as a higher-risk activity that demands stronger justification and, often, explicit consent. An architecture built for the stricter of the two on each dimension will generally satisfy the other.
The architecture that satisfies both: privacy-first by design
This is where deployment choices do most of the compliance work. A privacy-first video analytics stack processes frames on-premises or at the edge, converts them immediately into anonymised, non-identifying outputs such as aggregate counts and zone-level events, and discards or never persists raw identifiable data. Because the heavy processing stays inside the building, raw video does not need to traverse the public internet or land in a foreign cloud, which directly addresses DPDP data-residency concerns and PIPEDA safeguarding expectations at the same time.
KenVision is built around exactly these constraints. It works with your existing CCTV cameras, so there is no rip-and-replace and no new identifiable data source. It is camera-agnostic and deploys quickly, and it supports on-prem and edge processing so personal data can be minimised before anything leaves the site. For high-value retail use cases, behaviour alerts can be tuned to events rather than identities. You can see the broader capability set on our video surveillance solutions page, and the deeper architectural rationale in our companion article on privacy-first video AI and data sovereignty.

A practical video analytics privacy compliance checklist
Before a camera goes live, work through a short, defensible list: define the single business purpose and the minimum data needed to serve it; decide whether you can meet that purpose with anonymised aggregates instead of identities (you usually can); keep AI processing on-prem or at the edge so identifiable data stays on site; set and enforce a retention schedule with automatic deletion; post clear notice or signage describing the purpose; name an accountable owner and document a data-handling policy; build a route for individuals to make access and deletion requests; and run a privacy impact assessment for anything involving biometrics, children, or large-scale monitoring. Crucially, treat each region’s strictest requirement as your baseline so one configuration travels across India and Canada without re-engineering.

Book a privacy-first deployment review
If you operate across multiple jurisdictions and want video analytics that respects both DPDP and PIPEDA without a forklift upgrade, we can walk you through a privacy-first deployment on your existing cameras. Book a 30-minute demo and we will map your use case to the right minimisation and residency controls.
Frequently asked questions
Does AI video analytics always count as processing personal data?
Not always. If the system only produces anonymised aggregates such as footfall counts or queue lengths and never persists identifiable images, the privacy footprint is far smaller. Identification, face matching, or tracking individuals is what typically brings data into scope under DPDP and PIPEDA.
What is the biggest difference between DPDP and PIPEDA for video analytics?
DPDP is consent-and-residency centric and may restrict cross-border data transfers, while PIPEDA centres on whether a reasonable person would consider the purpose appropriate and on meaningful consent. Both, however, reward data minimisation and on-site processing.
Can on-premises processing remove most compliance risk?
It removes a large share of it. Keeping raw video and AI inference inside the building reduces cross-border transfer exposure, limits the data that could be breached, and supports retention and deletion controls. It does not replace the need for notice, a defined purpose, and an accountable owner.
Do we need consent for footfall counting in a store?
Where counting is fully anonymised and no individual is identified or tracked, the obligations are lighter, though clear signage and a documented purpose remain best practice. Demographic estimation or behaviour tracking raises the bar and should be assessed case by case.
Does KenVision require us to replace our cameras?
No. KenVision is camera-agnostic and works with existing CCTV, adding the analytics layer without a rip-and-replace, which also avoids introducing a new identifiable data source.