AGIDAT – Datenschutz | Informationssicherheit

Data Protection in Manufacturing & Industry

Employee data, supply chains, video surveillance and NIS2 — data protection for manufacturing companies.

Data protection in manufacturing: special challenges

Manufacturing companies face data protection challenges that differ fundamentally from office environments: shift systems with extensive time tracking, video surveillance for safety and quality reasons, connected machinery and IoT systems, complex supply chains with numerous suppliers — and often a large workforce with a works council.

Employee data protection in manufacturing

The largest area of data protection in manufacturing companies is employee data protection:

Time tracking and shift systems

Time tracking is mandatory in many sectors and generates significant volumes of personal data. This data must be used for its intended purpose — shift-planning data must not be used for other purposes (performance evaluation, monitoring) without a clear legal basis.

Video surveillance

Many production sites use cameras — for workplace safety, quality control, theft prevention. This is generally permissible under data protection law, but tied to conditions:

  • Signage requirement (notices)
  • Limited retention period (usually 72 hours, absent an incident)
  • Purpose limitation (not for performance monitoring)
  • Works council involvement (co-determination requirement)

Works agreements

Many data-protection-relevant systems — access control, time tracking, video surveillance, IT systems — require works agreements that govern the specific data processing. These agreements must be designed to be GDPR-compliant.

Health data in manufacturing

Occupational medicine, workplace safety, illnesses, accident reports — employees' health data deserves particular care. It may only be processed on a clear legal basis and must be kept strictly separate from other HR data.

Supply chain data protection

Manufacturing companies often have long supply chains with many suppliers, logistics partners, and service providers. If these partners gain access to personal data belonging to your company or your customers, you need Data Processing Agreements (DPAs).

This also applies in the B2B context: when contact details of people at suppliers are stored (name, email, phone), this is personal data that must be processed in a GDPR-compliant manner.

NIS2 and cybersecurity obligations

The EU NIS2 Directive (Network and Information Security) affects many industrial companies — especially those classified as "important" or "essential" entities. NIS2 requires:

  • Implementation of risk management measures
  • Reporting of significant security incidents (24h/72h deadlines)
  • Management responsibility for cybersecurity
  • Security measures across the supply chain

Although NIS2 is primarily an information security topic, it overlaps substantially with data protection requirements. AGIDAT advises on an integrated basis — across both legal areas.

IoT and connected machinery

In modern production environments, machines are connected and transmit data — to manufacturers, maintenance service providers, production management systems. This raises new data protection questions:

  • Does the machine data contain personal information (e.g., operator details)?
  • What data is transmitted to the machine manufacturer?
  • Are Data Processing Agreements with machine manufacturers necessary?

We help you assess these edge cases too and establish clear rules.