Sector wise readiness
Construction and EPC: an offline business, fully in scope
- Does DPDP apply to construction and EPC firms?
- Yes, fully. Two blind spots pull an apparently offline business into the baseline: biometric attendance at the site gate, and subcontractor chains several tiers deep, each layer holding labour records. Sales offices also hold buyer KYC and loan documents.
- Who this affects
- Builders, architects, EPC contractors, and their subcontractor chains.
- What to do about it
- Map the biometric capture, and get every tier of the subcontractor chain under contract.
A misconception I keep seeing when builders, architects and EPC contractors read DPDP checklists: "we are an offline business, we pour concrete."
The auditor's observation for this sector is that two blind spots pull a firm that feels entirely offline into the full baseline: long subcontractor chains, and biometric worker data.
Look at a single site. A biometric attendance scanner at the gate, capturing hundreds of workers daily. A subcontractor chain several tiers deep, each layer holding labour records. A sales office with buyer KYC, income proofs and loan documents. None of that is digital in spirit, and all of it is personal data.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent or a lawful basis for every purpose
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What construction carries from day one
- ✅ Site workforce and biometric attendance. Labour data and biometrics need a basis, minimisation and strong security. Watch for minors on site, absolutely. Biometric data on a construction gate is not a low risk system because it sits outdoors.
- ✅ Buyer lead and marketing consent. Get consent for marketing to project leads, and do not resell or share them freely.
- ✅ KYC and financial document security. Buyer ID, income, loan and payment documents need real protection.
- ✅ Bind the subcontractor chain. Subcontractors, EPC partners, design and facility vendors need Data Processing Agreements, with safeguards extended through the chain where practical.
- ✅ Client confidentiality for design and turnkey work. Architects and designers hold floor plans, preferences and security details. Protect them, and erase when the project ends.
What may not apply
- ❌ SDF obligations. Generally not, unless you also run a large consumer platform. Significant Data Fiduciary status comes only on Government notification.
- ❌ A mandatory Data Protection Officer, annual DPIAs and independent audits. These attach to SDF status once notified.
The better question
The better question is not "does a construction firm really fall under a digital data law?"
It is "who holds our workers' biometrics, how far down does our vendor chain go, and could we name every party in it?"
Law creates obligations. Scale and risk influence implementation. But biometric security and vendor contracts apply from your first site. Neither waits for scale.
If you build, how many tiers deep does your subcontractor chain go, and do you know who holds worker data at each?