Manufacturing and industrial IoT
Manufacturers combine employee/contractor, visitor, dealer/customer, connected-product and industrial security data across plants, offices, dealers and global engineering/support teams. Machine telemetry is not automatically personal data, but becomes in scope when linked to a driver, operator, home, account, voice, location or device owner.
Systems and flows
Section titled “Systems and flows”ERP/SAP, HR/payroll, contractor management, access control, CCTV, occupational health, dealer CRM, warranty/service, connected vehicle/product cloud, mobile app, call centre, PLM/quality, SIEM, industrial historian and remote support. Map IT/OT boundaries and global shared services.
Purpose catalogue
Section titled “Purpose catalogue”Separate workforce administration, site safety, access/security, production quality, warranty, predictive maintenance, remote diagnostics, product improvement, recall, marketing and dealer analytics. A safety purpose does not authorise indefinite productivity surveillance or advertising.
CCTV, biometrics and location
Section titled “CCTV, biometrics and location”For each camera/reader/track:
- physical zone and field of view;
- purpose and threat/safety rationale;
- signage/notice and assisted route;
- recording/audio/analytics features;
- access and disclosure;
- retention trigger/duration;
- law-enforcement request route;
- worker/visitor grievance;
- vendor/cloud destination.
Disable face recognition, emotion inference or biometric templates by default. Enabling them requires a necessity/proportionality assessment, legal source and heightened security.
Connected products
Section titled “Connected products”Bind device telemetry to purpose versions and service state. Use pseudonymous device/subject references in the control plane. Product sale/transfer, shared use and offline operation require identity reassociation, reset and deletion flows. Firmware and connector compromise are both privacy and safety threats.
Minimum configuration
Section titled “Minimum configuration”Plant/legal entity, workforce categories, labour/union/contract obligations, camera/access zones, dealer and connected-product recipients, remote support countries, OT/IT systems, product safety retention, vendor contracts, security incident routes and clean product transfer.
Incident and retention
Section titled “Incident and retention”CERT-In and future DPDP tests run alongside sector/critical-infrastructure duties if the system is actually notified/covered. Preserve safety, quality, warranty, recall and litigation records under exact sources; delete or aggregate unrelated granular behaviour/location when purpose expires.
Evidence
Section titled “Evidence”Zone assessment, notice snapshot, access review, footage disclosure log, device-purpose version, remote support session, vendor assessment, retention decision, product transfer/reset certificate and incident timeline.
Open counsel questions
Section titled “Open counsel questions”- Which employment, factory, safety, automotive/device and state CCTV requirements apply?
- Is a dealer/service centre a processor or independent Fiduciary for each flow?
- Are any systems notified protected systems under critical-infrastructure law?
- What telemetry remains non-personal after account/device reassociation risk is considered?