A worker holding a digital globe

India Factories Act Meets GDPR: Legal Insights

As global businesses increasingly establish operations across multiple jurisdictions, navigating the complexities of compliance with local laws alongside international regulations becomes crucial. One key area where this intersection is particularly pronounced is in the realm of workplace data protection and safety. In India, the Factories Act, 1948 governs occupational safety, health, and welfare of workers, while organisations operating in or serving European markets must comply with the General Data Protection Regulation (GDPR), a comprehensive EU data privacy law. Though these two legal frameworks arise from different regulatory philosophies—labour welfare and data privacy, respectively—they can intersect in several critical ways within the modern workplace.

From the standpoint of an experienced legal practitioner, understanding how the Factories Act aligns or conflicts with GDPR mandates is essential not only for compliance, but also for building ethically sound and legally resilient human resource and safety systems.

Understanding the Frameworks

The Indian Factories Act, 1948, is a social welfare legislation aimed at ensuring safe working conditions, regulating working hours, and mandating health and welfare measures for factory workers. Employers are required to maintain records regarding employees’ attendance, health status, injuries, working conditions, and machinery inspections. These records often contain personal and sensitive personal data.

In contrast, the GDPR, effective since May 2018, imposes stringent data protection obligations on organisations that process the personal data of EU citizens. This includes the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. Though India has its own data protection framework in development—most notably the Digital Personal Data Protection Act, 2023—GDPR remains a global benchmark.

Key Areas of Intersection

1. Employee Health and Safety Records

The Factories Act mandates employers to maintain detailed records of occupational injuries, medical examinations, and safety incidents. GDPR, however, classifies health data as special category data, which requires a lawful basis for processing, such as explicit consent or the necessity for carrying out obligations in the field of employment and social security law.

This creates a compliance challenge. While the Factories Act obliges record-keeping, GDPR mandates that any such processing must be minimised and adequately safeguarded. Multinational employers must implement strict access controls, encryption, and policies to justify the retention and use of health data under GDPR while still fulfilling Indian statutory obligations.

2. Biometric and Surveillance Data

Factories are increasingly using biometric attendance systems and CCTV surveillance for safety, security, and monitoring productivity. While the Factories Act does not explicitly regulate surveillance technologies, GDPR takes a strong stance on transparency and proportionality.

Organisations must assess whether such surveillance is necessary, proportionate, and done with proper notice. A Data Protection Impact Assessment (DPIA) may be required under GDPR to evaluate risks to individual rights. Employees must be informed clearly about what data is being collected, how it is used, and their rights to access or object. Balancing these obligations with Indian factory management practices is a nuanced legal task.

3. Cross-border Data Transfers

Data collected in Indian factories—such as employee health metrics or performance reviews—may be transferred to headquarters in the EU or other jurisdictions. GDPR mandates that such transfers only occur to countries that ensure an adequate level of data protection. India is not currently recognised as providing such adequacy.

Thus, companies must rely on safeguards like Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) to legitimise cross-border data flows. Simultaneously, these transfers must not violate the Indian legal requirement to maintain and produce factory records upon request by inspectors or courts.

Harmonising Compliance Approaches

For businesses straddling both frameworks, a harmonised legal compliance strategy is essential. Key recommendations include:

  • Developing a Data Governance Policy that aligns with both GDPR and Indian legal mandates, covering data minimisation, access control, retention schedules, and audit trails.
  • Training HR and Safety Personnel to understand the dual obligations of safeguarding worker welfare under the Factories Act and protecting privacy under GDPR.
  • Conducting Privacy Impact Assessments before introducing new technologies like health monitoring wearables or smart CCTV systems.
  • Obtaining Informed Consent from workers, particularly where biometric or sensitive health data is involved, even if the Factories Act does not explicitly require it.

The convergence of workplace safety laws like the Indian Factories Act with global data protection standards like the GDPR presents both legal challenges and opportunities for best practice. For experienced legal advisers, the goal is to bridge these frameworks through a pragmatic, rights-respecting approach that serves both regulatory compliance and ethical responsibility.

As India’s own data protection laws evolve, employers must stay agile, ensuring their operational practices uphold not only the letter of the law but also the fundamental rights of their workers—both to safety and to privacy.

Back to blog