Workplace Surveillance, Productivity Software, And Employee Privacy
Introduction : In 2021, an employee working in Italy was penalized for visiting websites unrelated to his duties because of reasons like "The computer is the company's computer, therefore we can monitor everything." But here emerges the issue: is such monitoring necessary, legal, transparent, and proportional? It is just one of the numerous instances in which monitoring of the employees has become extremely invasive due to technological advancements and remote employment. The pandemic of the COVID-19 virus has not brought an end to one of its most influential changes to the work environment, hybrid working. Nowadays, the majority of the workforce spends its time partly at home and partly in the office, and it looks like this trend will persist. However, hybrid working has created a new problem for the management, how to measure productivity if your employees are not present? The answer is the wave of new technologies that have turned into a violation of the right to privacy of the employees.
In this context, our blog will analyze the current loopholes in the legislation concerning employee privacy rights in India and the place of surveillance in such rights.
Legal Provisions
Information Technology Act 2000 : The IT Act deals mainly with those legal matters that arise out of the usage of computers and electronic recordings. The section 43 of the act, which deals with unauthorized access, downloading, copying, data theft, or any damage done to computer systems, is one of the key sections used in monitoring the work environment. Section 43A pertains to compensation for non-compliance by a body corporate to safeguard sensitive personal data using appropriate security measures.
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) : Section 43A of the Information Technology Act is related to sensitive personal data or information (SPDI). It is quite reasonable to mention the gap in defining SPDI and providing the way forward. As a consequence, in 2011, SPDI guidelines related to Section 43A were issued by the central government. For instance, Rule 4 states that a body corporate engaged in SPDI should have a privacy policy, and Rule 5 relates to SPDI collection that involves lawful gathering of the information with consent. Rule 6 states when SPDI can be disclosed to another entity. Rule 7 covers SPDI transfer that includes SPDI transfer to third party both inside and outside of India.
Section 43A of the IT Act is to be read together with the SPDI Rules 2011, which continue in effect during the transition to the DPDP framework and are set to expire on May 13, 2027.
Digital Personal Data Protection Act, 2023 : Digital Personal Data Protection Act 2023 is the latest law that regulates the process of digital personal data in India. DPDP framework is much more relevant to regular employee monitoring data than to sensitive data since according to this act, personal data is the data relating to a particular person who can be identified through such data.
The Act defines two major roles : the data principal, who is the individual whose personal data it is, and the data fiduciary, the individual or entity responsible for the purpose and method of processing personal data. Section 5 deals with the notice to be provided to the data principal, in the same way as Section 4 deals with the grounds for processing personal data. Section 6 deals with consent and how it must be free, informed, unconditional, specific, and unambiguous. Section 7 deals with the legitimate use without consent under certain circumstances. Section 8 deals with the general responsibility of the data fiduciaries. Sections 11 to 14 deal with the rights of the employees.
The DPDP Rules 2025 enhances the DPDP Act 2023 through providing the procedural and operational mechanisms for implementing the obligations set out in the Act.
Legal Analysis
Existing problem with the Legal Framework : The IT Act became law in 2000, a time when the form and extent of electronic financial transactions had quite changed. Advanced technology now makes it possible to collect extremely accurate data which does not come under SPDI. What makes the framework of the IT Act flawed is the fact that it addresses cybersecurity problems but not surveillance as a practice. There are four guiding principles which govern workplace and privacy laws.
Notice
One of the key qualities of the relationship between the employer and the employee is transparency, and the employee needs to understand that he is being observed or is under surveillance. The practice of secret observation poses a major legal issue in any jurisdiction.
Under the UK GDPR, the employer needs to notify his employees about what data is collected and how and for what purpose it will be used and retained. In Australia, employers need to notify their employees regarding observation practices in some of the jurisdictions.
As per the provisions of the DPDP Act in India, the data fiduciary must provide details to the data principal regarding the processing of personal data and its purpose. For instance, in case an employer offers a laptop with monitoring software to an employee, whose software collects login/logout data. As per the DPDP act, the employer, who is the data fiduciary, must disclose such information. Section 6 requires the data principal to give consent by a notice specifying:
the personal data proposed to be processed
the purpose of processing
how the data principal can exercise their rights, and
how they can make a complaint to the data protection board
Rule 3 of the DPDP Rules, 2025, makes this more concrete, requiring that the notice be clear, independent, and comprehensible.
Consent
Legal consent as the foundation is not a straightforward process. It has been pointed out by the European Data Protection Board that in an employment context, the basis of consent is not an appropriate legal foundation for monitoring due to inherent power relations. The employees cannot refuse appropriately due to fear of backlash.
However, in the case of India, the statutory provision of consent came through the SPDI Rules' Rule 5(1). It stated that the body corporate must seek consent from the individual prior to the collection of any sensitive personal data or information, including seeking consent for the purposes for which such information is going to be used. Rule 5 also required that the purpose of such collection be an authorized purpose. This can prove useful in the context of workplace surveillance where the employer collects SPDI from the employees. However, there was one major drawback here, and that was the requirement of consent being applicable only for SPDI and not other personal information of the employees.
The DPDP Act focused on consent and highlighted it as an important statutory aspect. It provided that the consent would have to be free, specific, informed, unambiguous, and would need to be procured by explicit affirmative steps. The DPDP Act provided not only a procedure for obtaining consent but also a procedure for withdrawing consent. The right to withdraw consent is available to the data principal.
Proportionality
Proportionality in our case is simply a determination whether this particular surveillance at work is necessary and whether it is the least intrusive method to achieve legitimate business objectives.
A good illustration is the case of Serco Leisure (UK, 2023). In its enforcement notice, the ICO ordered Serco to stop using fingerprint and facial recognition technology to monitor employees’ presence as it could not show why the particular technologies were justified against less intrusive alternatives.
There is no specific regulation in India dealing with proportionality in regard to employee monitoring. Nonetheless, the DPDP Act indirectly hints at proportionality through some of the articles, namely Sections 4, 5, 6, and 8, that require that the processing of the personal data should happen with the purpose defined.
The concept of proportionality was based mostly on the case of Puttaswamy v Union of India where privacy was established as a fundamental right according to Article 21. Yet, the doctrine of Puttaswamy proportionality can only function as a means of limiting the actions of the state that affect fundamental rights. Therefore, there is no automatic assumption that a private organization is equivalent to the state when processing personal data of its employees.
Data Retention
Data retention means ascertaining the period within which the financial data of an employee, like screenshots and CCTV images, needs to be stored prior to deleting it. Under Section 6(1)(e) of the DPDP Rules, 2025, data fiduciaries are permitted to keep data for security reasons for up to one year. The period of one year for retaining data is not valid for all workplace surveillance data. There is no retention period under Indian law for workplace monitoring data like screenshots and keystrokes.
Practical Implications
The right to privacy was held by the Supreme Court to be a fundamental right under Article 21 in the case of K.S. Puttaswamy v. Union of India, and it said that any violation of privacy must be legal, legitimate, and proportional. This right creates a tension with Section 7(i) of the DPDP Act 2023, which says that a Data Fiduciary can process the personal data of the employee without the need of consent, as long as it is processed for the purposes of employment or for the specified security reasons.
If the employer thinks that processing data of a certain employee would safeguard the employer from any loss or liability as mentioned in Section 7(i), any type of employment may be interpreted broadly enough to allow for invasive kinds of employee surveillance without consent in the name of protection under Section 7(i) of the DPDP Act. And since almost anything can be classified as employment-related, the provision may allow businesses to process employee data without their consent. Such processing of data may create problems under the constitutional right to privacy and the proportionality concept established by the Puttaswamy case.
Although the DPDP framework offers adequate protections to employees’ personal data, but the expansive nature of Section 7(i), could be detrimental to the effectiveness of such security mechanisms such as consent, notice, retention period, and proportionality in mitigating workplace invasions of privacy. Such a scenario poses the risk of creating a void in between legislative and constitutional privacy protections of personal data processing.
Workplace Policy
A workplace monitoring policy should consist the following things:
Purposes and Objectives- Lay down proper and legitimate business objectives and should prohibit privacy invasive monitoring.
Scope- Specifying policies in workplaces which follows BYOD (bring your own device) and stating the scope of data that might be processed relating to the employees, devices, networks, and locations that are covered through surveillance technologies.
Monitoring Tools and Methods- Monitoring methods and technologies used should be laid out in detail and not concealed.
Data Collection and Retention- Policy should mention the kind of data collected, retention time frames, storage, anonymization, archiving, and deletion procedures.
Employee Privacy and Rights- Establish the access controls, employee data protections, and consent criteria for unnecessary monitoring.
Workplace Monitoring Checklist
Purpose and Necessity- Describe the legitimate business objective, analyze less invasive options, and decide on the need for monitoring.
Legal Basis- Determine the applicable lawful framework, complete the necessary balancing analysis, and ensure that consent is genuinely voluntary and reversible when needed.
Proportionality- Ensure that monitoring is reasonable to its objective, and consider whether the privacy invasion is necessary, especially for high-risk technologies like biometrics and keystroke recording.
Transparency- Before monitoring begins, provide clear, written notice that explains what is being observed, why, how, and for how long, and consider consulting with employees or representatives.
Data Minimisation and Retention- Collect just required data, set explicit retention and deletion periods, and make it easier for employees to exercise their data rights.
Security- Protect monitoring data by implementing proper access controls and ensuring proper security measures and agreements are in place when third-party monitoring solutions are utilized.
Policy and Review- Maintain a complete monitoring policy, review it on a regular basis for legal and technological advances, and avoid hidden monitoring unless it is clearly necessary.
BYOD Considerations- Properly differentiate between work and personal data on employee-owned devices, and ensure that necessary protections and consent requirements are met when monitoring includes personal devices.
Conclusion
Surveillance of employees in a workplace is not illegal but it should be properly explained, restricted in its scope, and be transparent with employees. The danger of surveillance and violation of privacy of the employee increases with the development of surveillance technology. The DPDP Act is strengthened by the provision that there are clear limitations on surveillance of employees, provisions for data collection transparency, and genuine business interests that override privacy infringement to increase protection for employees. It is necessary to strike a balance between the interests of the organization and the privacy of the employee. Surveillance, if done properly, can serve the genuine business interests of the organization or any body corporate and provide impartiality, but improper conduct of surveillance can weaken trust and promote bad working culture.
Author: Aastha Das in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at Khurana & Khurana, Advocates and IP Attorney.
Endnotes
Giulio Coraggio, ‘Italy: The Garante Issues First GDPR Fine Over Employees Email Metadata Privacy Breach,’ Privacy Matters, 4 June 2025.
Adv. Rashmi Acharya, ‘Legal Standards for Monitoring Employee Communications,’ Lead India, 2026.
Madigan Wolford, ‘Is Your Employer Watching You?: Invasive Employee Surveillance in the Modern Era,’ North Carolina Journal of Law & Technology, Vol. 26, Issue 4 (2025).
Information Technology Act, 2000, ss. 43, 43A (India).
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, rr. 5–7 (India).
Digital Personal Data Protection Act, 2023, ss. 4–7 (India)
Digital Personal Data Protection Rules, 2025 (India)
Digital Personal Data Protection Rules, 2025, r. 3 (India)
HM Courts & Tribunals Service, Privacy Notice for Employees, Workers and Contractors (2019).
‘Consent as the Lawful Basis for Monitoring the Activities of Employees: Really?’ INPLP, 24 June 2025.
Information Commissioner’s Office, ‘ICO Orders Serco Leisure to Stop Using Facial Recognition Technology to Monitor Attendance of Leisure Centre Employees,’ 23 February 2024
Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., AIR 2018 SC (SUPP) 1841, (2019) 1 SCC 1 (India).
CESG, BYOD Guidance: Device Security Considerations (UK Government)




Comments