New Delhi: A controversy over workplace monitoring at Tata Consultancy Services (TCS) has sparked a wider debate over how far Indian employers can go in monitoring employees using company-issued devices.
The issue emerged after reports claimed that TCS had deployed a Digital User Experience Monitoring tool on employee laptops. According to the reports, the tool could provide information such as applications being accessed and the time spent on them. TCS, however, has denied that it tracks individual employee activity, calling reports of employee surveillance “baseless and inaccurate”.
The company has said its tools are intended to monitor broader network performance, security, availability and employees’ digital experience.
What Triggered the TCS Workplace Surveillance Debate?
The controversy centres on an important distinction: monitoring an organisation’s IT infrastructure is not necessarily the same as monitoring individual employees.
Digital monitoring tools can have legitimate cybersecurity and operational purposes. Companies may use them to detect threats, prevent data leaks, protect confidential information, troubleshoot technical problems, maintain network performance and investigate security incidents.
Concerns can arise, however, when monitoring systems are used to create detailed profiles of individual workers, including their application usage, browsing behaviour, idle time, keystrokes, screenshots or other patterns of activity.
In the TCS case, the precise configuration and scope of the reported tool have not been independently established. It also remains unclear what information the system can collect and which teams or officials can access it. TCS maintains that it does not track individual employee activity.
Is Employee Monitoring Legal in India?
India does not currently have one comprehensive law specifically governing workplace surveillance by private employers. Instead, the legal framework involves constitutional privacy protections, data-protection requirements, the Information Technology Act and employment-related policies, contracts and internal rules.
Employers can have legitimate reasons to monitor company-owned devices, particularly for cybersecurity, data protection, intellectual-property protection, regulatory compliance and network management. However, ownership of a device does not automatically mean that an employer has unlimited authority to monitor everything an employee does on it.
The Supreme Court’s recognition of privacy as a fundamental right in the Puttaswamy judgment remains an important backdrop to the issue. The judgment established privacy as a constitutionally protected right, although privacy is not absolute and may be subject to legally justified restrictions.
This makes the purpose, method, scope and proportionality of workplace monitoring important considerations.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Does Employee Consent Allow Unlimited Surveillance?
Not necessarily.
Workplace policies and employment contracts may inform employees that corporate systems are monitored. However, simply informing an employee about monitoring should not automatically be treated as a blanket justification for every form of surveillance.
The nature of the monitoring should correspond to a legitimate purpose and should be appropriately limited to what is necessary for that purpose.
For example, monitoring network traffic to identify malware or unauthorised access is materially different from continuously recording screenshots or logging every keystroke.
The more intrusive the monitoring, the greater the questions around necessity, proportionality, transparency, access controls, retention and the safeguards protecting the collected information.
Can Employers Monitor Company Laptops?
In many circumstances, employers can implement reasonable monitoring and security controls on company-owned devices, particularly where these are connected to the organisation’s systems.
However, employees should not assume that using a company laptop means they have no privacy interests. At the same time, employers need to protect corporate information, customer data, intellectual property and IT infrastructure.
The practical challenge is therefore to establish a reasonable boundary between legitimate cybersecurity monitoring and excessive employee surveillance.
A company may have a strong justification for detecting malicious software, unauthorised data transfers or suspicious login activity. That does not automatically establish a justification for collecting unrelated personal information or monitoring employees more extensively than necessary.
What Does the TCS Row Mean for Indian Employees?
The TCS controversy highlights a broader challenge facing India’s increasingly digital workplaces.
As organisations adopt AI-powered analytics, productivity tools and employee-monitoring technologies, questions around transparency, data collection, access controls and data retention are becoming increasingly important.
Employees should understand their organisation’s IT and acceptable-use policies and determine what types of activity on company systems may be monitored.
Employers, meanwhile, should clearly communicate the purpose and scope of monitoring and ensure that security controls are appropriately designed and governed.
Where Should India Draw the Line?
The central question is no longer simply whether an employer can monitor a company device.
It is whether the extent and manner of monitoring are justified by a legitimate purpose.
Cybersecurity monitoring can help protect organisations from ransomware, insider threats, data theft and other attacks. But increasingly sophisticated monitoring technologies can also provide employers with detailed information about individual behaviour.
The TCS controversy therefore reflects a much larger issue: as Indian workplaces become more dependent on digital systems, organisations will need to balance cybersecurity, productivity and data protection with employees’ legitimate privacy expectations.
For employees, understanding workplace technology policies is becoming as important as understanding traditional employment terms. For employers, transparent and proportionate monitoring could become an increasingly important part of responsible cybersecurity governance.
About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.