In brief
- Regulation: GDPR.
- Every manufacturer is concerned as a data controller, with no threshold.
- Maintain a register.
- Governing video surveillance and access badges.
- Control retention periods.
- Fines of up to €20M or 4% of global annual turnover.
Regulatory deadlines
The key dates of this regulation.
May 2018
Entry into application
In forceWhat does GDPR cover?
GDPR applies whenever personal data is processed, regardless of the sector. In industry, such processing is often linked to workforce management and site security — two sensitive areas involving employee monitoring.
Purely technical production data, with no link to an individual, falls more under the Data Act than under GDPR.
Is the 'Industry' sector concerned?
Every industrial operator is concerned as a data controller, with no threshold. Security processing (video surveillance, access control) and HR processing are the most sensitive and most closely scrutinised.
Maintenance data can become personal data when linked to an identifiable technician.
Detailed obligations
Maintain a register
Document HR, security and maintenance processing activities: purposes, data, retention periods, recipients, security.
Governing video surveillance and badge systems.
Define a legal basis, inform employees and proportion monitoring, without placing individuals under unjustified permanent surveillance.
Control retention periods
Apply appropriate retention periods (CCTV footage, access logs).
Secure
Implementing access management, encryption and logging.
Distinguishing personal data from industrial data.
Separating what falls under GDPR from what falls under the Data Act.
Sanctions & risks
Fines of up to €20M or 4% of global turnover. Employee monitoring (video, geolocation) receives particular scrutiny from authorities.
Disproportionate surveillance measures are a frequent ground for penalties in the sector.
Common mistakes in the sector
- 1Disproportionate video surveillance. Placing workstations under permanent surveillance without justification.
- 2No register in place. Failing to document HR and security processing activities.
- 3Excessive retention. Retaining images and access logs for too long.
- 4Regime confusion. Treating industrial data as personal data, or vice versa.
Practical case
An industrial site deploys extensive video surveillance and retains footage without any time limit. An inspection identifies the absence of a clear legal basis, disproportionate monitoring of workstations, and excessive retention. Remediation involves limiting the areas filmed, informing employees, and defining a specific retention period.
Compliance roadmap
- 1
Map. Map HR, security and maintenance processing activities.
- 2
Qualify legal bases. Verify the legal basis and information notices for video surveillance and access badges.
- 3
Define retention periods. Set retention periods by purpose.
- 4
Secure. Strengthen access controls, encryption and logging.
- 5
Distinguishing the regimes. Separate personal data (GDPR) and industrial data (Data Act).
Frequently asked questions
Yes: as soon as there are employees, video surveillance, or access badges, GDPR applies.
Take action on GDPR
Free assessment or a chat with an expert dedicated to industry.
They already trust us
See how organisations in the industry sector secured their compliance with DCO.