Employee Monitoring and DPDPA: Where Necessity Ends
Employee Monitoring and DPDPA: Where Necessity Ends
Watching is easy. Justifying it is the work.
The scene
The productivity tool captured screenshots every ten minutes, including personal banking tabs and medical appointments booked at lunch. Managers loved the dashboard. Nobody had asked what purpose the screenshots served.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Employer devices, employer data.
Personal data on work devices remains personal data of the employee.
Limit monitoring to what the stated purpose needs.
Employees agreed in the handbook.
Consent in an employment relationship is hard to call free; legitimate use must fit its purpose.
Rely on a clear purpose, and stay inside it.
A proportionality test
What risk does this monitoring address? Is there a less intrusive way? Who sees the output? How long is it kept? Write the answers before switching it on.
Monday morning
01 List every monitoring tool in use.
02 Write the purpose each serves.
03 Switch off features that serve none.
Questions, answered plainly
Is employee monitoring allowed under DPDPA? +
Section 7(i) allows processing for employment purposes and to safeguard the employer from loss or liability. Monitoring should be necessary and proportionate to those purposes.
Is employee consent valid for monitoring? +
Consent must be free. In an employment relationship that can be difficult to show, so employers should rely on a clearly applicable legitimate use and limit monitoring to it.
Sector · HR & Staffing The candidate you never hired is still your Data Principal. Read →
HR & Staffing · Deep dive The candidate you rejected is still in your database. Read →
HR & Staffing · Deep dive The verifier knows more than the hiring manager. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).