India’s manufacturing sector employs 12 crore people. Biometric attendance systems, dealer management data, and worker health records put manufacturers squarely in DPDP’s crosshairs.
What DPDP Act 2023 obligations apply to manufacturing companies? Manufacturing companies process personal data of employees, contractors, customers, and supply chain partners, creating DPDP Act 2023 compliance obligations across multiple functions. HR departments must update employee data practices, obtain consent for CCTV and biometric attendance systems, and implement data retention schedules. Sales and CRM teams must ensure customer data is collected with valid consent and stored securely. Procurement teams must sign DPAs with vendors who access employee or customer data as part of their services.
Most manufacturers don’t think of themselves as data-intensive businesses. But biometric attendance, worker health records, dealer data, and contract labour files create significant DPDP exposure that is often invisible until enforcement begins.
Your obligations differ based on company size and sub-sector. Select your type to see the most relevant compliance requirements, typical gaps, and penalty exposure.
| Obligation | DPDP Section | Max Penalty | Typical Gap |
|---|---|---|---|
| Biometric attendance consent (fingerprint / face) | Section 4 | ₹200 Cr | Biometric data collected at onboarding without explicit, purpose-specific consent forms |
| ESI / medical records handling | Section 4 | ₹200 Cr | Medical data accessible to HR generalists and managers without need-to-know access restriction |
| Contractor / labour data sharing with agencies | Section 9 | ₹200 Cr | No Data Processing Agreement (DPA) with labour contractors and compliance agencies |
| Dealer contact data in DMS | Section 6 | ₹50 Cr | No privacy notice or consent from individual dealer contacts stored in DMS |
| CCTV footage of factory floor | Section 6 | ₹50 Cr | No retention or deletion policy for CCTV footage; often retained indefinitely |
| Employee GPS tracking (vehicle / fleet) | Section 6 | ₹50 Cr | Location tracking of vehicles and fleet drivers without informed consent or privacy notice |
| Obligation | DPDP Section | Max Penalty | Typical Gap |
|---|---|---|---|
| Statutory compliance data (PF, ESI, labour) shared with CA / consultant | Section 6 | ₹50 Cr | Payroll and statutory data emailed to CA firms without a written DPA in place |
| Customer / buyer personal data in ERP | Section 6 | ₹50 Cr | ERP system accessible to all employees without role-based access restriction |
| Export customer data (foreign buyers) | Cross-border (Section 16) | ₹50 Cr | No cross-border data transfer assessment for export customer records stored in India |
| Worker skill / performance data | Section 6 | ₹50 Cr | No privacy notice for workers explaining what performance data is collected and why |
| Biometric attendance (where deployed) | Section 4 | ₹200 Cr | Attendance system vendor agreement does not include data protection terms |
| Obligation | DPDP Section | Max Penalty | Typical Gap |
|---|---|---|---|
| Clinical trial participant data | Section 4 | ₹200 Cr | Trial data consent forms pre-date DPDP Act; not aligned to the new explicit consent standard |
| Drug adverse event reporter data | Section 4 | ₹200 Cr | Reporter health information stored in pharmacovigilance systems without DPDP-compliant controls |
| Quality inspector / auditor personal data | Section 6 | ₹50 Cr | No privacy notice for external auditors and quality inspectors whose data is collected during audits |
| Import / export agent personal data | Section 6 | ₹50 Cr | Agent personal data (passport, address, contact details) in customs documentation is uncontrolled |
| Medical representative data | Section 6 | ₹50 Cr | MR location tracking and call reporting without adequate consent and data minimisation |
| API / bulk drug supplier personal data | Section 6 | ₹50 Cr | Supplier contact data and audit records stored beyond retention period without deletion policy |
Five questions. Understand your manufacturing DPDP exposure in under 2 minutes.
This is the single largest DPDP exposure for Indian manufacturers — and the most commonly overlooked.
India has an estimated 50 lakh+ biometric attendance devices deployed across factories, warehouses, and offices. Each one processing fingerprint or face data without explicit consent is a Section 4 violation — up to ₹200 Cr per violation. Most manufacturers switched to biometric attendance without realising it created a significant DPDP exposure.
The fix is not to remove the systems. It is to implement: (1) explicit consent notices at enrolment, (2) encryption of biometric templates, (3) access restriction to the attendance system, (4) a documented retention and deletion schedule, and (5) a Data Processing Agreement with the attendance system vendor.
From a targeted biometric compliance audit to a full DPDP readiness assessment and vendor DPA pack, Niti Bharat helps manufacturers close their exposure efficiently.
Tell us about your manufacturing operation. We’ll get back to you within one business day with a tailored compliance plan.
Yes. The Digital Personal Data Protection (DPDP) Act 2023 applies to any organisation that collects, stores, or processes personal data of Indian residents, regardless of sector. Manufacturing companies process large volumes of personal data — worker biometric records, ESI and health data, dealer and distributor contact data, and contract labour files — all of which fall under DPDP obligations. Enforcement is expected from May 2027.
Biometric attendance systems are not inherently illegal under the DPDP Act, but they are subject to the highest tier of compliance requirements. Fingerprint and face recognition data fall under sensitive personal data (Section 4), requiring explicit, purpose-specific consent from every enrolled worker, encryption of stored biometric data, role-restricted access, and a Data Processing Agreement with the attendance system vendor. Many manufacturers currently operate these systems without any of these controls, which constitutes a direct Section 4 violation.
The DPDP Act prescribes a penalty of up to ₹200 Cr for failure to implement adequate security safeguards for sensitive personal data including biometric data. This penalty can be applied per category per violation, meaning a manufacturer with 10,000 workers enrolled in a biometric attendance system without explicit consent faces cumulative exposure across all enrolled individuals.
Yes, but the central government may notify certain exemptions for small-scale Data Fiduciaries under the DPDP Act. However, MSMEs that use biometric attendance, process Aadhaar or PAN numbers for statutory compliance, or share employee data with contractors or CA firms are likely to have compliance obligations regardless of size. It is prudent for all MSMEs to assess their exposure before enforcement begins.
A Data Processing Agreement is a legally binding contract between a Data Fiduciary (the manufacturer) and a Data Processor (a vendor that handles personal data on the manufacturer’s behalf). Under DPDP Act Sections 8 and 12, manufacturers are liable for data breaches caused by their processors. Without DPAs in place with attendance system vendors, ERP providers, labour contractors, and CA firms, manufacturers carry the full legal and financial risk of any data breach or misuse by those vendors.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.