Industry · GDPR

Industry & GDPR: processing activities that are often underestimated

Industry is rarely associated with GDPR — wrongly so: factories process employee data, CCTV footage, access badge records, maintenance data linked to technicians, and sometimes customer data. The industrial operator is the data controller and must organise itself accordingly. This guide details typical processing activities, their legal bases, and a tailored compliance roadmap.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: GDPR.
  • Every manufacturer is concerned as a data controller, with no threshold.
  • Maintain a register.
  • Governing video surveillance and access badges.
  • Control retention periods.
  • Fines of up to €20M or 4% of global annual turnover.

Regulatory deadlines

The key dates of this regulation.

May 2018

Entry into application

In force

What does GDPR cover?

GDPR applies whenever personal data is processed, regardless of the sector. In industry, such processing is often linked to workforce management and site security — two sensitive areas involving employee monitoring.

Purely technical production data, with no link to an individual, falls more under the Data Act than under GDPR.

Is the 'Industry' sector concerned?

Every industrial operator is concerned as a data controller, with no threshold. Security processing (video surveillance, access control) and HR processing are the most sensitive and most closely scrutinised.

Maintenance data can become personal data when linked to an identifiable technician.

Detailed obligations

Maintain a register

Document HR, security and maintenance processing activities: purposes, data, retention periods, recipients, security.

Governing video surveillance and badge systems.

Define a legal basis, inform employees and proportion monitoring, without placing individuals under unjustified permanent surveillance.

Control retention periods

Apply appropriate retention periods (CCTV footage, access logs).

Secure

Implementing access management, encryption and logging.

Distinguishing personal data from industrial data.

Separating what falls under GDPR from what falls under the Data Act.

Sanctions & risks

Fines of up to €20M or 4% of global turnover. Employee monitoring (video, geolocation) receives particular scrutiny from authorities.

Disproportionate surveillance measures are a frequent ground for penalties in the sector.

Common mistakes in the sector

  • 1Disproportionate video surveillance. Placing workstations under permanent surveillance without justification.
  • 2No register in place. Failing to document HR and security processing activities.
  • 3Excessive retention. Retaining images and access logs for too long.
  • 4Regime confusion. Treating industrial data as personal data, or vice versa.

Practical case

An industrial site deploys extensive video surveillance and retains footage without any time limit. An inspection identifies the absence of a clear legal basis, disproportionate monitoring of workstations, and excessive retention. Remediation involves limiting the areas filmed, informing employees, and defining a specific retention period.

Compliance roadmap

  1. 1

    Map. Map HR, security and maintenance processing activities.

  2. 2

    Qualify legal bases. Verify the legal basis and information notices for video surveillance and access badges.

  3. 3

    Define retention periods. Set retention periods by purpose.

  4. 4

    Secure. Strengthen access controls, encryption and logging.

  5. 5

    Distinguishing the regimes. Separate personal data (GDPR) and industrial data (Data Act).

Frequently asked questions

Yes: as soon as there are employees, video surveillance, or access badges, GDPR applies.

Take action on GDPR

Free assessment or a chat with an expert dedicated to industry.

They already trust us

See how organisations in the industry sector secured their compliance with DCO.

See testimonials