DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Most data generated by factory IoT — machine telemetry, sensor readings, throughput and quality metrics — is non-personal and outside the DPDP Act 2023. But smart factories also capture personal data: worker productivity and location tracking, biometric access, CCTV footage, visitor logs and wearable-device data. Wherever a data point can be linked to an identifiable person, the DPDP Act applies, requiring notice, a lawful basis, security safeguards and respect for worker rights. This tool helps you separate your non-personal factory IoT data from the personal data that falls in scope.

Factory IoT Data Protection — DPDP Guide for Smart Factories

Machine telemetry is not personal data — but worker tracking, biometrics and CCTV are. Find out which of your factory IoT data streams the DPDP Act actually covers.

Check what factory IoT data falls under DPDP

Factory IoT data protection checklist under DPDP

Which factory IoT data is personal — and which is not

A smart factory generates enormous volumes of data, but only some of it is personal data under the DPDP Act 2023. Machine telemetry, sensor readings, throughput, energy use and quality metrics are non-personal and fall outside the Act. What does fall in scope is any data that can be linked to an identifiable individual: worker productivity and location tracking, wearable-device data, biometric or facial-recognition access control, CCTV footage that captures people, and visitor logs. The distinction matters because it lets manufacturers focus DPDP effort on the relatively small slice of factory data that is actually regulated.

The risk is that these personal-data streams are often overlooked precisely because the dominant narrative around factory IoT is machine data. A plant that has thought carefully about protecting its process data may have given no thought at all to the privacy notice owed to workers whose movements it tracks, or the safeguards owed to biometric access records — which are among the most sensitive personal data it holds.

How manufacturers should handle in-scope factory data

For the personal-data streams a smart factory captures, the priorities are notice, necessity, security and retention. Workers and visitors should be clearly told what personal data is captured and why; monitoring should be limited to what is genuinely necessary rather than blanket surveillance; biometric and CCTV data should be encrypted, access-controlled and retained only as long as needed; and IoT and analytics vendors that process this data should be bound by data-processing agreements.

With DPDP Rules 2025 notified and enforcement expected around May 2027, manufacturers running smart-factory programmes should map which of their IoT data streams are personal and bring those into scope now. Niti Bharat helps manufacturing organisations draw that line clearly and put the right controls on worker, biometric and CCTV data through fixed-price engagements (₹75,000–₹3.2 lakh) — without over-engineering compliance for genuinely non-personal machine data.

Get the factory IoT data-mapping template (free)

A template to separate non-personal machine telemetry from the worker, biometric, CCTV and visitor data that falls under the DPDP Act — with a controls checklist for each.

Frequently Asked Questions

Does the DPDP Act apply to factory IoT machine data?+
Not to genuinely non-personal machine data. Sensor readings, telemetry, throughput and process metrics that cannot be linked to an identifiable individual sit outside the DPDP Act 2023. The Act applies only where data relates to and can identify a person — which in a factory means worker, biometric, CCTV and visitor data.
Is worker productivity or location tracking regulated?+
Yes. Where factory IoT tracks individual workers — location, productivity, wearable-device data — that is personal data under the DPDP Act. Workers must be given notice, monitoring should be limited to what is necessary, and the data must be secured and retained appropriately. Excessive or covert surveillance is a compliance risk.
How should biometric access data be treated?+
Biometric and facial-recognition data is among the most sensitive personal data a factory holds. It needs a clear lawful basis, strong security safeguards, worker notice, and a retention limit. Manufacturers should also consider whether a less intrusive access method would meet the same operational need.
Do we need agreements with our IoT platform vendors?+
Where an IoT platform, analytics provider or cloud vendor processes personal data on your behalf, they act as a Data Processor and should be bound by a data-processing agreement covering security, use limitation and breach handling. Pure machine-data processing that never touches personal data carries lower obligations.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Fleet GPS Tracking & DPDP Privacy GuideFounder DPDP Liability GuideGCC Data Localisation Guide (DPDP Act)DPDP Compliance ROI CalculatorSee all Reference & Checklists tools →📝 Does DPDP Apply to Hrms Platforms📝 Answer DPDP Questionnaire