
About This Webinar
With May 2027 marking a critical DPDP compliance milestone, retail and manufacturing organisations are moving from policy discussions to operational readiness.
For these sectors, DPDP compliance is not limited to a website consent banner or a privacy policy. Personal data moves through billing counters, loyalty programmes, POS systems, HRMS platforms, biometric terminals, CCTV systems, ERP environments, dealers, contractors, logistics partners and more.
This webinar explores what DPDP compliance for retail and manufacturing looks like in practice and how organisations can build a structured, audit-ready approach across data discovery, consent management, third-party risk, data principal rights and ongoing compliance.
This Webinar Covers:
- Finding personal data across fragmented systems:Personal data can sit across POS systems, loyalty CRMs, ERP, HRMS, biometric terminals, CCTV, IoT systems and physical records, making it difficult to know what data exists and where it resides.
- Managing consent at the point of collection: Consent needs to reflect the actual purpose for which data is collected, whether that is an e-receipt, loyalty programme, employee process or biometric attendance, rather than relying on a generic website consent flow.
- Handling Data Principal Rights: Responding to data requests becomes difficult when personal data is distributed across multiple systems, vendors and physical records that are not connected.
- Managing vendors and third parties: Vendors, dealers, contract manufacturers, logistics partners and channel partners may all process personal data, creating an ongoing third-party risk management challenge beyond the initial vendor assessment.
- Managing data across employees and contractors: Manufacturing organisations handle personal data across employees, temporary workers, contractors and visitors through HRMS, payroll, biometrics, CCTV and access-control systems.
- Building DPIAs and managing privacy risk: Higher-risk processing across areas such as biometrics, surveillance, IoT and other data-intensive systems requires organisations to identify, document and manage privacy risks systematically.
- Producing evidence on demand: Policies alone do not demonstrate operational compliance. Organisations need accessible consent records, DPIA documentation, vendor records, audit trails and breach-response evidence that can demonstrate how their controls actually work.
Why Watch This Now
- Turn DPDP requirements into operational readinessMove beyond policies and understand what DPDP compliance actually requires across the systems, people and processes that handle personal data every day.
- Find the data before you try to govern itLearn why data discovery is the starting point for consent management, Data Principal Rights, DPIAs and effective privacy governance across retail and manufacturing environments.
- Close the third-party risk gapUnderstand how vendors, dealers, contractors, logistics partners and other processors can create privacy exposure, and why one-time vendor assessments are no longer enough.
- Build evidence, not just policiesSee how consent records, DPIA documentation, vendor obligations and breach-response workflows can come together to create an audit-ready DPDP compliance framework.
- Prepare for the May 2027 deadlineGet a practical roadmap for moving from fragmented compliance activities to a connected DPDP readiness programme before substantive obligations take effect.

Nikhil Jhanji
Principal Product Manager
IDfy

Malcolm Gomes
COO
IDfy

Baidyanath Kumar
Chief Information Security Officer and Data Protection Officer
JK Lakshmi Cement

Amit Rana
General Manager, IT Security and Infrastructure
Page Industries (Jockey)
FAQs
It means managing consent, vendor risk, and audit-ready evidence at the specific points these sectors collect data: billing counters and loyalty programs for retail, plant floor biometrics and dealer networks for manufacturing.
Not as a requirement. A customer can insist on a paper receipt and refuse to share contact details, and the sale still has to go through.
No, not without separate consent. Consent for one purpose doesn't extend to another, even using the same phone number.
Yes, and it covers contract and temporary labor too, not just permanent employees.
Yes, if the company qualifies as a Significant Data Fiduciary. Incidental data like location or productivity metrics can trigger a mandatory Data Protection Impact Assessment.






