Happy Tracker

Employee Monitoring and Indian Law: What You Can Actually Do

Every few months somebody asks us the same question before buying a time tracker: is this legal in India? The honest answer is that it usually is, that almost nobody does it correctly, and that the gap between the two is one document nearly every company skips.

This is a practical guide written by people who build tracking software, not a legal opinion. It will tell you what the relevant Indian law says, where the obvious lines are, and what a workable policy contains. Before you roll anything out, have a lawyer read your policy. An hour of a labour lawyer’s time costs less than one dispute, and considerably less than one former employee with a grievance and a copy of your tracker settings.

There is no single Employee Monitoring Act in India. There are four overlapping sources.
There is no single Employee Monitoring Act in India. There are four overlapping sources.

There is no single law, and that is the first thing to understand

People search for “the employee monitoring act” and find nothing, because it does not exist. What governs monitoring in India is a stack of four things that have to be satisfied at the same time: the Information Technology Act 2000 and the rules under it, the Digital Personal Data Protection Act 2023, the constitutional position on privacy after the Puttaswamy judgment, and your own employment contract.

That last one is doing far more work than most employers realise. In the absence of a statute written specifically for workplace monitoring, what you agreed with the employee in writing is the document a dispute will turn on. It is also the only one on the list you control.

The IT Act 2000 and the SPDI Rules

The IT Act is not a monitoring statute. It is a data statute, and it matters because monitoring produces data about a person, which you then hold.

Two sections come up. Section 43A makes a body corporate liable to pay compensation if it is negligent in implementing reasonable security practices while handling sensitive personal data, and that negligence causes wrongful loss or wrongful gain. Section 72A makes disclosing personal information in breach of a lawful contract, with intent to cause or knowing you are likely to cause wrongful loss, a criminal offence.

Read those together and the obligation is clear enough: if you collect data about your staff, you are responsible for keeping it secure and for not leaking it. A folder of screenshots on a shared drive that anybody in the office can open is a real exposure, not a theoretical one.

Underneath section 43A sit the SPDI Rules of 2011 — the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules. They define sensitive personal data to include passwords, financial information, health and medical records, biometrics and sexual orientation. The obligations they impose are the familiar ones: obtain consent in writing before collecting sensitive personal data, publish a privacy policy, collect only for a lawful purpose connected with your function, do not keep it longer than needed, and let the person review and correct what you hold.

Notice what falls into the sensitive category. A keylogger captures passwords and, sooner or later, banking credentials and an OTP. That moves you from “monitoring work activity” into “collecting sensitive personal data” in a single step, and it is the clearest reason not to use one.

The DPDP Act 2023, and what consent means under it

The Digital Personal Data Protection Act 2023 was passed in August 2023 and is being brought into force in stages, with rules following. It replaces the SPDI Rules regime over time. It is worth understanding now, because it is where employee data is heading and because designing for it costs nothing extra today.

The Act works on a simple structure. You are a data fiduciary. Your employee is a data principal. Personal data may be processed for a lawful purpose, either with consent or for certain legitimate uses. Where consent is the basis, it must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and accompanied by a notice in plain language that says what is being collected and why.

Consent at work is complicated, and pretending otherwise is a mistake

Here is the uncomfortable part. Consent given by an employee to an employer is never fully free in the ordinary sense, because of the power difference. A person asked on their first day to sign a consent form or not have a job has not exercised much of a choice. Regulators everywhere treat employment consent with suspicion for exactly this reason.

The DPDP Act recognises this indirectly by providing for certain legitimate uses that do not depend on consent, including processing for purposes of employment — and it specifically contemplates things like safeguarding the employer from loss, and providing services or benefits to an employee. That is a meaningful carve-out, and monitoring that is genuinely connected to the employment relationship is likelier to sit there than to rest on a signature.

The practical consequence is not that you can skip the paperwork. It is the opposite. If your basis is employment purpose rather than consent, then the purpose has to be real and stated, the collection has to be proportionate to it, and the notice still has to exist. “We monitor because we can” is not a purpose. “We record hours against client projects because we invoice on time and materials” is.

Two more DPDP obligations are worth designing in now. You must not keep personal data once the purpose is served — so a retention period is required, not optional. And a data principal has a right to ask what you hold about them, which means somebody in your company has to be able to answer that question about an employee’s tracking data within a reasonable time.

Puttaswamy and why proportionality keeps appearing

In 2017 a nine-judge bench of the Supreme Court held in K. S. Puttaswamy v. Union of India that privacy is a fundamental right under Article 21. That judgment does not directly bind a private employer the way it binds the state, but it changed the lens through which every subsequent privacy question in India is read, including by tribunals hearing employment disputes.

The test the judgment set out — legality, a legitimate aim, and proportionality — is a genuinely useful way to sanity-check any monitoring decision, whether or not it applies to you as a matter of strict law. For each thing you record, ask three questions.

  1. Is there a rule? Is this written down somewhere the employee has seen and signed?
  2. Is there a real aim? Name the business decision this data changes. If you cannot name one, you are collecting it out of habit.
  3. Is it the least intrusive way? If a project hours report answers the question, you do not need screenshots. If screenshots answer it, you do not need a keylogger.

That third question is the one that catches most organisations out, and it is the same instinct good engineering uses anyway: collect the minimum that answers the question.

The device the work happens on changes the answer more than anything else does.
The device the work happens on changes the answer more than anything else does.

Company devices and personal devices are not the same question

This distinction settles most real-world arguments, and it is refreshingly simple.

A laptop you bought and issued

You own the hardware. You pay for it. You issued it for work. Monitoring work activity on it — hours, applications used during a tracked session, idle time, periodic screenshots — is defensible, on one condition: the employee was told, in writing, before it started.

That condition is not a formality you can add later. Monitoring that nobody was told about is the single most common failure we see, and it is the one that turns a reasonable business practice into something that reads, to everyone who hears about it afterwards, like spying.

A laptop or phone the employee owns

Here your position is far weaker, and correctly so. Their device holds family photographs, banking apps, personal chat, medical appointments, a spouse’s email. None of that is any of your business, and no employment relationship gives you a claim on it.

If you support bring-your-own-device — and plenty of Indian companies do, particularly for field staff and part-time contractors — then monitor a bounded thing rather than the machine. A web clock-in that records a timestamp. A tracked session the person starts and stops themselves. An app that only records while it is running and shows plainly that it is running. What you must not do is install something on a personal phone that keeps recording after the working day ends.

The grey zone, and how to remove it

The awkward case is a company laptop used for personal life in the evening, which describes almost every company laptop in India. Do not try to solve this with a legal argument. Solve it with a schedule: tracking runs when the person starts it and stops when they stop it, and everybody knows that is how it works. Idle detection helps here too, because it stops a forgotten timer from quietly recording somebody’s Saturday.

What crosses the line

Some things are hard to defend under any reading of Indian law, and more importantly, are hard to defend to your own team. If you are doing any of these, stop before you worry about the policy.

Six practices that are difficult to justify under any purpose you could write down.
Six practices that are difficult to justify under any purpose you could write down.
  • Keystroke logging. It captures passwords, OTPs, private messages and anything typed into a personal account on a break. There is no work purpose that survives contact with what a keylogger actually collects.
  • Reading personal email or personal chat, including when it was opened on a company laptop. The account is not yours and the correspondence is not about your business.
  • Webcam or microphone capture without clear, specific notice. Silent camera access is indefensible. Even with notice it is difficult to justify for office work, and it is the setting most likely to end a rollout.
  • Location tracking outside working hours, or continuous location at all. For genuine field staff, a location stamp at clock-in and clock-out answers the business question. A moving dot on a map all day does not.
  • Monitoring nobody was told about. Whatever the technical merits, this is the one that produces the grievance, the resignation and the WhatsApp screenshot.
  • Keeping everything for ever with no stated retention period and nobody accountable for the store. Every month you hold data you do not need is a month of risk with no benefit.

A useful private test, and one no statute contains: could you read this setting aloud to the person it applies to, in a room with their colleagues, without needing to soften it? If not, the problem is the setting, not the wording.

The written policy is the artefact that matters

If you take one thing from this article, take this. A monitoring policy, written in plain language, signed at joining and re-signed whenever it changes, is worth more than every other precaution combined.

It is worth more legally, because it establishes notice and purpose, which is what both the SPDI Rules and the DPDP Act are built around. It is worth more practically, because a team that has read a specific list of what is and is not recorded does not spend its energy inventing worse possibilities. And it is worth more in a dispute, because a signed document beats two people’s recollection of a conversation.

What a monitoring policy has to contain. Six clauses, in plain language.
What a monitoring policy has to contain. Six clauses, in plain language.

What goes in it

  1. Exactly what is recorded. Not “activity data”. A literal list: hours worked, application and website names during a tracked session, idle time, screenshots at a stated interval, and nothing else.
  2. Exactly what is not recorded. This clause does more for adoption than the rest of the policy put together. No keystrokes. No personal email. No camera. No microphone. No home location. Say it plainly.
  3. When it runs. Only while the tracker is running, on working days, started and stopped by the employee.
  4. Which devices. Company devices only, or a named bounded arrangement for personal ones.
  5. Who can see it. Named roles, not “management”. An employee should know precisely who can open their week.
  6. How long it is kept. A number of days for screenshots and activity, and what happens on the day after. Ours default to a plan-level retention window that deletes screenshots and activity detail automatically while keeping the time totals that payroll and invoicing depend on.
  7. What it is used for, and what it will not be used for. If it feeds invoicing and project estimates rather than individual performance reviews, write that down. Then honour it.
  8. How an employee sees their own data, and who they ask. Under the DPDP Act this stops being a courtesy.

Keep it to two pages. A policy nobody finishes is a policy nobody has consented to in any meaningful sense.

Contractors, interns and people outside India

Three situations that come up constantly and are handled badly.

Contractors are not employees, so an employment-purpose basis does not obviously apply. Put the monitoring terms in the contract itself, not in an HR policy they never received. In practice contractors are often more comfortable with tracking than employees, because it is how their invoice is justified.

Interns and trainees get the same policy as everyone else. A shorter tenure is not a reason for weaker notice, and the person who feels least able to object is the person whose consent deserves the most care.

Staff or clients abroad change the picture. If you employ anyone in the EU or the UK, GDPR applies to them and its bar for monitoring is higher, with a documented assessment expected before you start. If an Indian team works on the data of a European client, contractual obligations often flow down to you regardless of where your servers are. Ask before you assume Indian law is the only law in the room.

Where the data lives

Security is not separate from legality here — section 43A ties them together directly. A few things are worth confirming about any tracking product, ours included.

  • Who holds the data and where. Data residency matters to some Indian clients contractually even when it does not matter statutorily.
  • Whether access is role-based, so a team lead sees their own team and not the whole company.
  • Whether deletion is real. When a retention period expires, are the files actually removed, or just hidden from a screen?
  • Whether access is logged. If a manager opens somebody’s screenshots, there should be a record of it. This protects the employee and the manager.
  • What happens when somebody leaves. Their data should not sit in an active workspace indefinitely.

A word about why you are monitoring at all

Almost every monitoring problem we have watched go wrong started as a question that the data could not answer. Somebody suspected a team was under-delivering and reached for screenshots, when what they needed was hours against projects. Somebody wanted to know why a project overran and turned on activity levels, when the answer was thirty-one hours of unbilled revisions sitting in the time log.

The heaviest settings are usually the least informative. Activity percentage measures typing, not thinking. A screenshot shows a screen, not progress. Hours against a task, collected with the team’s knowledge, tells you more about a business than either, and costs you nothing in trust. If you are choosing what to switch on, the argument for restraint is not only legal — it is that a rollout people accept produces better data than one they resent.

What to do on Monday morning

  1. Write down, in one line each, what your tracking currently records. Open the settings and check rather than trusting your memory of what was configured last year.
  2. Turn off anything you cannot attach a business decision to. Do this before you write anything, because the policy is easier to write once the settings are defensible.
  3. Draft the two-page policy using the eight points above. Write the “what we do not record” section first.
  4. Set a retention period for screenshots and activity detail, and confirm the deletion actually happens.
  5. Send it to a labour lawyer. One hour of review. Ask specifically about your state’s position and about your contractor agreements.
  6. Announce it in a room, not in an email, and take questions. Then have everybody sign, including the founders.

Do that and you are in a better position than most companies of your size in India, legally and otherwise. Skip the fifth step and you are still in a better position than most. Skip the sixth and none of the rest of it helps you.

Happy Tracker records hours, application and website activity during tracked sessions, idle time and optional screenshots, with per-plan retention that deletes the detail on a schedule while keeping the totals. There is no keystroke logging and no camera access, and there never will be.