India’s Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received Presidential assent on 11 August 2023. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The Data Protection Board of India was established the same day. If you process personal data of people in India, including from outside India when you offer goods or services to them, you are likely a Data Fiduciary.
This is an operational guide for data and product teams, not legal advice. Confirm obligations with counsel. Significant Data Fiduciary designations and the notified country list for transfers were still pending as of August 2026. Full operational compliance has been discussed on a 2026–2027 runway. Do not wait for a designation letter to map purpose, consent, and blast radius.
Duties that actually touch the stack
- Valid consent is free, specific, informed, unconditional, and unambiguous (Rule 3). Pre-ticked boxes and dark patterns fail.
- Notice before collection: what data, what purpose, how to withdraw. Available in Eighth Schedule languages on request.
- Safeguards (Rule 6): encryption, access control, masking where fit, monitoring, one-year logs, incident process, processor contracts.
- Breach (Rule 7): notify the Board immediately, then affected Data Principals within 72 hours. Failure to notify can draw penalties up to ₹200 crore. A personal data breach itself can draw up to ₹250 crore.
- Erasure when the purpose is over, consent is withdrawn, or the sector retention clock in the Third Schedule runs out. Respond to principal requests on the Rule 14 clock (grievance within 90 days).
- Children (Section 9): verifiable parental consent under 18. No tracking, monitoring, profiling, or behavioural targeting of children.
Employment is not a blank cheque
Section 7 allows certain legitimate uses, including employment. It does not let every plant dashboard republish a worker’s full history into a vendor cloud. Operator IDs, biometrics, wearables, and shift comments identify a person. Processors (MES, historian, payroll, CCTV vendors) need equivalent safeguards in the contract.
Telemetry vs the badge
Machine temperature is not personal data. The badge that opened the cell, the wearable heart-rate feed, and the quality comment that names an operator are. Tag them apart. Quality can still walk defect-rate to sensors without copying the badge table into another extract. Self-host when OT personal data cannot leave the site. Crawl metadata. Leave payloads on the floor.
Contractors and the night shift
Contract labour and 3PL staff inside the gate are still principals. Their IDs sit in access systems you do not own. The fiduciary duty does not vanish because payroll sits with a contractor. Name the processor. Limit the HQ tile that shows a face next to a scrap code.
CCTV, biometrics, and harm
Attendance biometrics and shop-floor cameras are high-risk processing. Purpose them (safety, attendance), retain them on a clock, and do not feed them into a productivity score unless that purpose was named and lawful. Section 9 still applies if you employ 16- and 17-year-old apprentices.
Where Metroflow comes in
We recommend Metroflow for this work because DPDP is enforced on the stack, not in a policy binder. Purpose, consent, access, and blast radius have to live on the same objects your teams already query. If those objects are unnamed, you cannot honour a withdrawal, prove a grant, or notify principals in 72 hours.
On the plant that means operator IDs stay scoped while quality still walks defect-rate to sensors, without another extract of the badge table.
- Why it fits. A metadata-only graph. Named owners. The same RBAC on humans and agents. Lineage you can export for the Board and for counsel.
- How it helps. Tag purpose on the metric and the identity. Walk erasure to warehouse models and downstream packs. Open breach blast radius from one query. Keep the warehouse, dbt, and BI you already run.
Continue on the Manufacturing use cases page, or try the live demo.