Authored by Prasanth D., an LLM (Information Technology and Cyber Security Laws) student at Government Law College Viluppuram
Surveillance infrastructure has been created to keep us safe. But in India and the rest of the world, the same cameras used to ensure the safety and security of the people have turned into instruments of violation. Hacking of Closed-Circuit Television (CCTV) systems is an under-studied corner of cybercrime jurisprudence, in which the law exists but is disjointed, enforcement is delayed, and victims may never become aware of their privacy being violated. This essay contends that the hacking of CCTV is not only a technical crime, but also a compound legal wrong that infringes upon privacy rights, facilitates other crimes and is a symptom of significant regulatory gaps in the Indian cybersecurity framework. It can only be tackled through a comprehensive and proactive legislative approach, in addition to criminal proceedings.
The Anatomy of CCTV Hacking
Today’s CCTV systems are not simply transmitters of images and events. They are systems that connect to a network, usually Internet Protocol (IP)-based, and that relay and record data on cloud servers or local network video recorders (NVRs). This is where they’re the most vulnerable. Attackers exploit default or weak passwords, unpatched operating systems and firmware, and open Remote Desktop (RDP) ports to compromise these systems. They can then watch live video, retrieve stored footage, disable cameras to begin a physical crime, and even access other corporate or home networks.
There is a much broader profile of cybercrime involving CCTV than is widely recognised. From voyeurism, with cameras placed in private areas of a property like hotel rooms, changing rooms, or domestic interiors, to targeted corporate espionage where factory floors, server rooms or bank premises are monitored by competitors or criminal organisations. Some are particularly dangerous, and include financial institutions or jewellery stores, where CCTV footage is accessed before a physical robbery, acting as a force multiplier for organised criminals.
Legal Framework in India: Present but piecemeal
The main law in India for dealing with CCTV hacking is the Information Technology Act, 2000 (IT Act), which was amended in 2008. Several provisions take effect immediately. Civil liability is provided for by Section 43, for breaches of civil rights in relation to unauthorised access to computer systems, including unauthorised entry into a CCTV network. Under Section 66, it is an offence if it is committed “dishonestly or fraudulently” and can be punished by up to three years’ imprisonment and up to five lakh rupees fine. Of particular note is Section 66E, which explicitly criminalises the intentional or knowing taking, publication, or transmission of an image of a person’s private area without their consent, under circumstances that infringe on their right to privacy.
If voyeurism is done through hacked cameras, then Section 354C of the IPC, 1860, and its counterpart under Section 77 of the Bharatiya Nyaya Sanhita, 2023, offer another direction in which the offence can be prosecuted. Section 72 of the IT Act also imposes penalties for violation of confidentiality and privacy by individuals who have legitimate access to electronic records. These provisions, taken together, form a legal net but with some loopholes.
The main problem is that there is no sector-specific CCTV regulation at the national level. India does not have an equivalent to the Surveillance Camera Code of Practice (SCoP) published by the United Kingdom under the Protection of Freedoms Act 2012, which lays down the minimum cybersecurity requirements for those who operate CCTV systems. The consequence is that the retailer who installs a hundred IP cameras has no legal responsibility to alter default credentials, update the camera firmware or isolate the camera network from other business infrastructure. The law does not make it more difficult for the hacker to hack; it only punishes the hacker.
The right to privacy without remedy in crime and public safety law.
Informational privacy, the right to control information about oneself. Informational privacy, the right to control information about oneself, is part of the fundamental right to privacy guaranteed by the Constitution, which was affirmed unanimously by a nine-judge bench of the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1. Accessing the CCTV footage of a private area is an infringement of this most intimate type of right. However, the corrective architecture of privacy violations in India is still underdeveloped.
The Digital Personal Data Protection Act, 2023 (DPDPA) does capture video data captured by CCTV systems under the purview of the term “personal data”, but the provisions of the Act are focused primarily on Data Fiduciaries, i.e. entities which decide the purpose and means of processing. The Act’s requirements aren’t intended to establish a private right of action for the individual whose camera captures footage, but rather for those who legitimately operate these cameras who are deceived by third parties into handing over that footage. The person harmed by a CCTV hack is therefore left to run a criminal complaint under the IT Act, or a tortious claim under common law, neither of which offers quick or readily available remedies.
This imbalance is a significant one. The person whose image is streamed on a darknet by a hacker can be subjected to serious reputational, psychological and economic damage. The failures of the law to turn the constitutional guarantee of privacy into an effective civil remedy for such victims is structural and neither the IT Act nor the DPDPA, as currently drafted, successfully compensates for those failures.
The issue of prosecutions remaining low is often attributed to enforcement challenges
There are statutory offences, but few instances of prosecution for hacking CCTV in India. There are a number of structural reasons for this. The first problem is detection; a camera hack can be made without any evidence other than the stolen information. Many victims, whether home or business, only find out about the breach when video comes to their attention, or is located elsewhere. National Crime Records Bureau does not make a separate classification of CCTV-related cybercrime, so it would be difficult to gauge the actual incidence of the offence in the official statistics.
Secondly, the processes of attribution are technically difficult. Attacks against IP cameras can be made in a layered fashion using proxies, VPNs or infected middle-boxes (botnets); it is difficult to trace them back to an individual attacker. The state’s cyber cells, which are expanding in size, frequently do not have the same level of forensic skills and inter-jurisdictional cooperation that is required to go after attackers on foreign servers. As India is not a part of the Budapest Convention on Cybercrime, it offers a treaty-based framework for providing mutual legal assistance in the investigation of cybercrime offences, which would greatly improve cybercrime investigations. The ongoing non-accession to the Budapest Convention is a strategic and enforcement deficit for India.
Third, corporate victims often do not wish to go to criminal court, as they may be concerned about their reputation being ruined by exposure of security vulnerabilities. This culture of resolution without prosecution also lowers prosecution rates and takes away the deterrent effect that a prosecution would have on potential criminals.
Towards a Preventive Legal Architecture
Based on the above analysis, the conclusion in this case is that the Indian law of hacking of CCTV is reactive in nature when it should be proactive; and it is punitive when it should be regulatory. Three reforms need to be made.
On the first point, it is felt that there should be legislation/notification by the Ministry of Electronics and Information Technology regarding mandatory minimum cybersecurity standards for CCTV operators under the IT Act. At least, they should have to change the default credentials when they are installed, regular firmware updates, network segmentation of surveillance systems, and encrypted transmission of footage. The Computer Emergency Response Team of India (CERT-In), which already has its mandate under Section 70B of the IT Act, is well-equipped to issue and enforce such guidelines.
Second, it is necessary to include explicit provisions regarding CCTV footage in the implementing rules of the DPDPA, which sets higher requirements and obligations for Data Fiduciaries that deploy CCTV systems in semi-public or public areas. Enforcement of obligations to notify the Data Protection Board and the affected individuals of footage breaches would encourage an increase in security investment and improve detection.
Third, India should sign the Budapest Convention or negotiate bilateral treaties for mutual legal assistance on cybercrime, at least with the key jurisdictions, with cybercrime-specific provisions. CCTV hacking is trans-border, with attacks often being launched from overseas, so that a country’s own laws are not sufficient to deter attacks.
Conclusion
CCTV systems represent a core social arrangement: loss of anonymity to achieve greater security for the community. If those systems are hacked, the bargain is violated twice: first, by the original operator who is not able to make the infrastructure secure, and second, by the State that’s supposed to protect privacy but doesn’t. The Indian statute books have the lexicon to prosecute CCTV hackers, but the regulatory grammar is missing to ensure conditions are not prepared that make hacking easy; the enforcement capability is missing to detect and attribute attacks; and the civil law grammar is missing to make the victim whole. The filling of these gaps cannot be a mere technical task but a constitutional duty under the right to privacy enshrined in Puttaswamy. The keepers of the watch are to be held responsible, as is the one who does not keep them from being watched.


