India’s CCTV compliance rules raise the stakes for retailers’ surveillance governance
STQC approval and supply-chain disclosures for internet-connected CCTV cameras add a compliance layer for retailers. A recommendation for transaction-verifiable cameras at medical stores could further link surveillance systems to retail operations, privacy and data-governance requirements.
The development
India has mandated STQC approval and supply-chain disclosures for internet-connected CCTV cameras. The article also notes a Drugs Consultative Committee recommendation for transaction-verifiable CCTV at medical stores, with implications for retailer security, compliance, customer privacy and surveillance-data governance.
The numbers
- Hyderabad: 79 cameras per 1,000 people
- Indore: 72 cameras per 1,000 people
- Bangalore: 41 cameras per 1,000 people
- Delhi and Chennai: 9 cameras per 1,000 people
- Pune, Kochi and Lucknow: 7 cameras per 1,000 people
Why it matters to operators and investors
Retail technology buyers should prioritize CCTV partners with STQC-approved products, transparent supply chains and transaction-monitoring integrations, particularly for healthcare and pharmacy retail.
What to watch next
- Final notifications, implementation dates and enforcement guidance on STQC approval for internet-connected CCTV cameras.
- Clarification of which retail camera categories, imported devices, legacy installations and cloud-managed systems fall within the rules.
- Government action on the recommendation for transaction-verifiable cameras at medical stores, including any state-level pharmacy enforcement.
- Customs, procurement or certification actions that disrupt availability of low-cost imported camera models.
- Retailer or vendor disclosures of non-compliant installations, supply-chain documentation gaps, camera vulnerabilities or video-data breaches.
- Emergence of insurer, landlord, franchisor or lender requirements that make certified surveillance systems a commercial prerequisite.
- Create a camera-by-camera asset register covering model, connectivity, location, firmware, certification status, installer and data-flow ownership.
- Require vendors to provide STQC approval evidence, component and country-of-origin disclosures where applicable, software-support commitments and breach-notification obligations.
- Map video access, cloud storage, remote viewing, retention, deletion and law-enforcement request procedures against privacy and cybersecurity policies.
- Separate surveillance footage used for security from footage that could be linked to customer transactions, prescriptions or employee performance; apply stricter role-based access to the latter.
- For pharmacy formats, assess the operational feasibility and privacy implications of linking CCTV timestamps to POS or dispensing records before any mandate takes effect.
- Budget for replacement cycles, network segmentation, secure configuration, audit logs and employee training rather than treating certification as a one-time procurement check.
The counter-case
The operational impact may be overstated. Many large retailers already use certified or enterprise-grade camera systems, maintain vendor due diligence, and operate retention/access controls under existing security and privacy programs. If compliance applies chiefly to new procurements, specified camera categories, or government-facing deployments, replacement costs and disruption could be limited. The medical-store element appears to be a recommendation rather than an enforceable nationwide obligation, so it may not justify near-term changes to pharmacy surveillance operations.