The Blurring Line Between Security and Surveillance
Recent news, based on media reports, suggests that TCS has rolled out a “Digital User Experience Monitoring” tool on some company laptops. This isn't an isolated incident in the IT world; as hybrid work became the norm, companies have increasingly turned
to software to monitor their assets and secure sensitive data. These tools are primarily justified as a defence mechanism—a way to protect confidential client information, prevent data breaches, and ensure company systems are running smoothly. However, the capabilities of such software often blur the line between legitimate cybersecurity and employee surveillance, leaving many workers wondering exactly what is being tracked. In response to these reports, TCS issued a statement rejecting claims of individual tracking, stating that the tools are used for monitoring macro-level network performance to ensure security and an enhanced user experience.
What Can Monitoring Software Actually See?
While TCS has not publicly detailed the full scope of its tool, sources in initial reports claimed it can track which applications are used and the amount of time spent on them. Generally, such monitoring software can have a wide range of capabilities. Basic functions include logging which applications are open, tracking login and logout times, and monitoring network traffic. More advanced systems can capture screenshots, log keystrokes, and even track periods of inactivity. For most companies, the stated goal is to ensure productivity and protect data. For instance, monitoring can flag the transfer of large files or access to unauthorised websites, which could be signs of a security risk. The key concern for employees is the lack of transparency regarding which specific features are enabled, who has access to the collected data, and how that information is used.
Understanding Your Rights in India
When it comes to workplace monitoring, Indian law generally sides with the employer, especially when company-owned devices are involved. There isn't one single law that governs employee surveillance. Instead, a combination of the Information Technology Act, 2000, and the new Digital Personal Data Protection (DPDP) Act, 2023, sets the rules. Essentially, employers are permitted to monitor their own devices and networks for legitimate business purposes, such as security and productivity. However, the DPDP Act mandates that employers provide clear notice about what data is being collected and why. This notice is typically included in an employment contract or an acceptable use policy. While your fundamental right to privacy is recognized by the Supreme Court, this right is significantly limited on a work device. Accessing your personal emails or social media accounts is not permitted, but tracking your activity on the company's own systems is generally allowed.
Best Practices for Using Your Work Laptop
Given the legal landscape and the capabilities of monitoring technology, the most prudent approach is to treat your company-issued device as company property at all times. The golden rule is to maintain a strict separation between your personal and professional digital lives. Avoid using your work laptop for personal banking, sensitive conversations, private social media activity, or storing personal files. If you need to handle personal matters during the day, use your personal phone or computer. Operate under the assumption that your activity on the work device is visible to your employer. This includes the websites you visit, the applications you use, and the time you spend on them. By being mindful and keeping personal usage off company equipment, you can protect your privacy while still meeting your professional obligations. Remember, the device is provided for work, and employers have a legal right to ensure it is being used for that purpose.














