The Business Case for Monitoring
Companies, especially large IT firms like TCS, argue that monitoring is essential for business. They handle vast amounts of sensitive client data across sectors like banking, healthcare, and government, making robust security a necessity. Monitoring tools
can help detect malware, prevent data leaks, and identify unusual activity on corporate networks. In a world of increasing cyber threats, companies see endpoint monitoring not as a choice, but as a critical part of their security framework to protect business-sensitive information and meet client requirements.
What Can Legally Be Monitored in India?
Employee monitoring is generally legal in India, but it comes with conditions. There isn't a single law dedicated to workplace surveillance. Instead, the rules are a mix of the Information Technology Act (2000), contract law, and the landmark 2017 Supreme Court ruling that established privacy as a fundamental right. More recently, the Digital Personal Data Protection (DPDP) Act of 2023 has given employees stronger rights, including the right to be notified about what data is being collected and for what purpose. Generally, employers can legally monitor company-owned devices and networks for legitimate business reasons, provided they inform employees about the practice. This is often done through a clause in the employment contract. However, monitoring personal devices without explicit consent or accessing personal email and social media accounts is not permitted.
The TCS Tool and Employee Concerns
The controversy at TCS involves a 'Digital User Experience Monitoring' tool reportedly installed on company laptops. Sources claim the software can track which applications are being used and for how long. While TCS stated it does not track individual activity and uses tools to monitor macro-level network performance for security and user experience, the lack of clear communication about the tool's full capabilities has fueled employee anxiety. The concern is whether a tool designed for IT security could also be used to track individual productivity, behaviour, or even form the basis for performance reviews, turning security into surveillance.
Productivity Metrics vs. Privacy
The debate at TCS is part of a wider trend in the Indian IT sector, where the pressure to appear busy can be intense. When monitoring shifts from securing a device to measuring the activity of the person using it, the line gets crossed. Tracking app usage and idle time can create a culture of 'performative work', where employees are more focused on looking active than on delivering results. This is especially relevant as AI-driven surveillance tools become more common, with a recent survey showing 75% of Indian employees fear AI will be used for workplace surveillance. Experts argue that true productivity can't be measured by login hours alone, especially for knowledge workers.
What Employees Should Understand and Do
For employees at TCS and elsewhere, awareness is the first line of defence. It is crucial to read your employment contract and any acceptable use policies carefully for clauses related to monitoring. Under the DPDP Act, you have the right to receive notice about data collection. Be mindful of the distinction between using a company device and a personal one; your expectation of privacy is much lower on hardware owned by your employer. Do not store sensitive personal information or conduct extensive personal activities on your work laptop. If you are unclear about your company's policy, ask for clarification. Understanding the stated purpose of any monitoring is key. Is it for network security, or is it for tracking individual performance? Knowing the answer helps you understand the environment you are working in and the rights you possess.














