Most data generated by factory IoT — machine telemetry, sensor readings, throughput and quality metrics — is non-personal and outside the DPDP Act 2023. But smart factories also capture personal data: worker productivity and location tracking, biometric access, CCTV footage, visitor logs and wearable-device data. Wherever a data point can be linked to an identifiable person, the DPDP Act applies, requiring notice, a lawful basis, security safeguards and respect for worker rights. This tool helps you separate your non-personal factory IoT data from the personal data that falls in scope.
Machine telemetry is not personal data — but worker tracking, biometrics and CCTV are. Find out which of your factory IoT data streams the DPDP Act actually covers.
A smart factory generates enormous volumes of data, but only some of it is personal data under the DPDP Act 2023. Machine telemetry, sensor readings, throughput, energy use and quality metrics are non-personal and fall outside the Act. What does fall in scope is any data that can be linked to an identifiable individual: worker productivity and location tracking, wearable-device data, biometric or facial-recognition access control, CCTV footage that captures people, and visitor logs. The distinction matters because it lets manufacturers focus DPDP effort on the relatively small slice of factory data that is actually regulated.
The risk is that these personal-data streams are often overlooked precisely because the dominant narrative around factory IoT is machine data. A plant that has thought carefully about protecting its process data may have given no thought at all to the privacy notice owed to workers whose movements it tracks, or the safeguards owed to biometric access records — which are among the most sensitive personal data it holds.
For the personal-data streams a smart factory captures, the priorities are notice, necessity, security and retention. Workers and visitors should be clearly told what personal data is captured and why; monitoring should be limited to what is genuinely necessary rather than blanket surveillance; biometric and CCTV data should be encrypted, access-controlled and retained only as long as needed; and IoT and analytics vendors that process this data should be bound by data-processing agreements.
With DPDP Rules 2025 notified and enforcement expected around May 2027, manufacturers running smart-factory programmes should map which of their IoT data streams are personal and bring those into scope now. Niti Bharat helps manufacturing organisations draw that line clearly and put the right controls on worker, biometric and CCTV data through fixed-price engagements (₹75,000–₹3.2 lakh) — without over-engineering compliance for genuinely non-personal machine data.
A template to separate non-personal machine telemetry from the worker, biometric, CCTV and visitor data that falls under the DPDP Act — with a controls checklist for each.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.