Employee monitoring should be assessed purpose by purpose, against the actual information collected and the applicable employment, privacy and sector requirements. The availability of an employment-related processing ground is not an unrestricted licence to monitor. Define necessity, access, retention and how a human will use the result.
The business situation
An employer adopts a productivity tool that records screenshots every few minutes. The screenshots capture private messages and customer records even though the stated objective is attendance. The central question is whether a less intrusive record can answer the employer's real business need.
A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.
What needs examining
01. Start with the decision the employer needs to make
Distinguish attendance, security, performance management and investigation. These are different purposes with different evidentiary needs. Map office, remote and bring-your-own-device settings separately. Assess whether continuous capture is necessary, whether off-duty activity is included and whether a narrower event log would achieve the objective.
02. Read employment and privacy responsibilities together
Check the applicable processing basis and commencement position under the DPDP framework, as well as existing rules and employment obligations. Explain monitoring through accurate policies and notices. Review disciplinary use separately: a system-generated productivity score should not silently become the sole basis for an adverse employment decision without examining reliability and a fair process.
03. Control the people who can see the record
Restrict access by role and purpose. A line manager may need a conclusion without receiving raw screenshots containing unrelated personal information. Set a reasoned retention period, document access requests and define escalation for sensitive findings. Supplier terms should address secondary use, model training, incident cooperation and deletion.
Law, contract and recommended practice
DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, where applicable Use an available processing basis | Purpose-by-purpose legal assessment | Recorded basis and scope analysis |
| Employment process Use reliable material in decisions | Human review and opportunity to respond where required | Decision file and response record |
| Recommended practice Reduce unnecessary exposure | Narrow collection and restricted access | Configuration record and access history |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Can the employer rely on a signed consent form alone?
A signature does not answer necessity, fairness, scope or the availability of the chosen legal basis. Assess the actual relationship and processing. A broad form also does not cure inaccurate statements about what the tool collects.
Does remote working justify continuous screen recording?
Remote working does not by itself settle the question. Identify the legitimate operational purpose, alternatives and data captured. Customer confidentiality, private information and off-duty collection may create additional issues.
Review the monitoring configuration alongside the policy. Where the tool captures more than the stated purpose requires, narrowing the collection is often the first useful corrective step.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
- DPDP Act commencement notification: G.S.R. 843(E)MeitY · Gazette of India · Notification dated 13 November 2025. Different provisions commence in different phases.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS data privacy practice