Why Companies Monitor Laptops
Employee monitoring is not a new phenomenon in the IT sector. Companies justify it for several reasons, chief among them being data security and client confidentiality. For a firm like TCS, which handles sensitive information for global clients, ensuring
data doesn't leave the corporate network is a top priority. Monitoring tools help detect unusual activity, prevent data breaches, and ensure compliance with international standards like ISO 27001. Other stated reasons include boosting productivity by tracking time spent on various applications and improving the overall 'digital experience' for employees by monitoring network and application performance. TCS itself stated that its tools are for monitoring macro-level network performance for security and an enhanced user experience, rejecting claims of tracking individual activity.
What Can They Actually See?
The capabilities of monitoring software vary widely. Some tools simply track which applications are used and for how long. More advanced systems can log keystrokes, take periodic screenshots, track mouse movements, and monitor internet usage. According to reports, the tool at TCS allows the company to see which applications are being used and the time spent on them. While the company has not clarified the full scope, the distinction between monitoring for security threats and tracking individual productivity is a crucial one that causes concern among employees. Continuous webcam monitoring or accessing personal accounts even on a work device is generally considered over the line.
The Legal Landscape in India
Indian law does not have a single, dedicated statute for employee monitoring. Instead, the rules are a mix of the Information Technology (IT) Act, 2000, and the new Digital Personal Data Protection (DPDP) Act, 2023. Generally, employers have the right to monitor activity on company-owned devices. The IT Act permits monitoring for legitimate business purposes. However, this right is balanced against an employee's fundamental right to privacy, as established by the Supreme Court. The DPDP Act, which has significantly strengthened privacy rules, mandates that companies must provide clear notice to employees about what data is being collected and why. Covert monitoring without a clear policy and disclosure puts a company at serious legal risk.
Understanding Your Rights and Responsibilities
As an employee, your strongest protection is awareness. The DPDP Act grants you the right to be notified about data collection, to access the data held about you, and to have it corrected or erased when no longer needed. Crucially, while monitoring on company-owned devices is broadly permissible with disclosure, the rules are much stricter for personal devices used for work, which requires your explicit and informed consent. Your primary responsibility is to read your employment contract and any 'Acceptable Use Policy' documents carefully. These documents typically contain clauses outlining the company's right to monitor its property. Using your work laptop exclusively for professional tasks is the simplest way to maintain a clear boundary between your personal and work life.
Navigating the New Normal
For employees at TCS and across the IT industry, the key is to be informed, not alarmed. Assume that any activity on a company-issued device is not private. Keep personal communication, financial transactions, and sensitive personal searches on your own devices. If you have concerns about the extent of monitoring, you have the right to seek clarification. Under the DPDP Act, companies are required to have a Data Protection Officer and a grievance redressal mechanism. Familiarise yourself with these internal channels. The debate isn't about stopping monitoring entirely—which is often a client requirement in the IT sector—but about ensuring it is implemented transparently, proportionately, and for legitimate purposes.














