Answer in one line: Manufacturers must unify notices and bases across employees, visitors/CCTV, biometrics, dealers, warranty customers, and owner-linked IoT telemetry — then enforce retention limits and DSRs across plants, 3PLs, and cloud vendors under Section 8.

Based on the manufacturing industry map in the DPDP Handbook.


Why plants are not “low digital risk”

Factories concentrate workforce biometrics, CCTV, contractor badges, dealer CRMs, and increasingly connected products. OT and IT teams often own systems that HR and legal never inventoried — until a DSR or breach arrives.


Figure 1 — Manufacturing personal-data map

Figure 1. Manufacturer — HR, CCTV, biometrics, dealers, warranty, IoT, vendors
flowchart TD
  HUB([Manufacturer / auto / FMCG / logistics]) --> S1[Employees / contractors]
  HUB --> S2[Visitors / plant CCTV]
  HUB --> S3[Biometric attendance]
  HUB --> S4[Dealer / distributor contacts]
  HUB --> S5[Warranty / service customers]
  HUB --> S6[IoT / connected-product telemetry]
  HUB --> S7[Vendors / 3PLs / cloud]
  S1 --> B1[Employment notice + basis]
  S2 --> B2[Visitor notice + short retention]
  S3 --> B3[Workplace notice + retention limit]
  S4 --> B4[B2B contact consent / contract]
  S5 --> B5[Product notice + purpose consent]
  S6 --> B6[Owner-linked consent + purpose]
  S7 --> B7[DPA + breach SLA]
  B1 --> REG[(Unified notice / consent register)]
  B2 --> REG
  B3 --> REG
  B4 --> REG
  B5 --> REG
  B6 --> REG
  B7 --> REG
  REG --> Q{DSR or purpose ends?}
  Q -->|Yes| OUT([Fulfil DSR / erase where lawful])
  Q -->|No| REG
  class HUB,S1,S2,S3,S4,S5,S6,S7,B1,B2,B3,B4,B5,B6,B7 act;
  class Q dec;
  class REG start;
  class OUT ok;
  classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
  classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
  classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
  classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
  classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
  classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;

Stream-by-stream controls

StreamControl focus
Employees / contractorsEmployment notice + role-based access + exit erase
Visitors / plant CCTVVisible notice + short retention + restricted viewing
Biometric attendanceWorkplace notice, necessity, retention limit
Dealer / distributor contactsB2B consent or contract purpose; no silent SMS blasts
Warranty / service customersProduct notice + purpose consent
IoT / connected productsOwner-linked consent; minimise telemetry that identifies people
3PLs / cloud / vendorsDPA + breach SLA + deletion on exit

Figure 2 — Fiduciary vs processor path on the shop floor

Figure 2. Manufacturing accountability — fiduciary notice vs processor DPA, then DSR
flowchart TD
  A([Plant / product / HR data touch]) --> B{Own fiduciary or processor?}
  B -->|Fiduciary| C[Notice + lawful basis]
  B -->|Processor for customer| D[Back-to-back DPA Sec 8-2]
  C --> E[Map employees / CCTV / IoT / dealers]
  D --> E
  E --> F[(Unified register + retention)]
  F --> G{DSR or purpose ends?}
  G -->|Yes| H([Fulfil DSR / erase where lawful])
  G -->|No| F
  class A,C,D,E act;
  class B,G dec;
  class F start;
  class H ok;
  classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
  classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
  classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
  classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
  classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
  classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;

Plant & HQ checklist

  1. Walk each plant: badge, CCTV NVR, biometric terminals, visitor apps.
  2. Tag IoT telemetry fields that can identify an owner or driver.
  3. Align dealer CRM campaigns with documented purpose.
  4. Add erasure / export clauses to 3PL and cloud contracts.
  5. Assign a single privacy owner across HR, IT, OT, and quality.

FAQ

Is biometric attendance always allowed?

Only with a clear workplace notice, necessity for the stated purpose, and retention limits. Prefer less intrusive alternatives where they meet the same security need.

Do dealer phone lists need consent?

Individual contacts are personal data. Marketing and promotional messages need a lawful basis — typically consent or a carefully scoped contractual purpose with opt-out.

Who owns connected-car or appliance telemetry?

If telemetry links to an identifiable owner in India, treat it as personal data with product notice and purpose limits — even when the “device” feels industrial.

How do we start without a huge programme?

Start with the handbook map, one plant pilot, and PII discovery on shared drives — then scale via consulting + platform.

Related reading

Informational only — not legal advice. Deadline context: organisations should treat 13 May 2027 as the practical compliance horizon under the notified Rules timeline.