Home/ Articles/ Employer Monitoring Rights
Workplace Rights

Can Your Employer Track You on a Company Laptop Without Telling You?

10 min read
Workplace Rights
Monitoring on a company device is legal in India — but the law on how, how much, and whether you have to be told first has shifted significantly in the past two years. The short answer is: yes, they can. The more useful answer is: not without limits, and increasingly not without telling you.

If you work on a company-issued laptop, your employer has both the technical ability and a reasonable legal basis to monitor how that device is being used. That’s the baseline. What most employees don’t know is where the legal limits on that monitoring actually sit — and how significantly those limits have tightened since the Digital Personal Data Protection Act 2023 rules were notified in November 2025.

The Three Legal Layers That Govern This

Employer monitoring in India isn’t governed by one single law. It sits at the intersection of three overlapping frameworks, each adding a different constraint.

Layer 1

IT Act 2000 — the historical baseline

Section 69 of the IT Act permits interception, monitoring, or decryption of information on a device, particularly for legitimate business security purposes. This is the provision most employers have historically relied on. It’s broad, but it was never designed with employee privacy specifically in mind.

Layer 2

Constitutional right to privacy — Puttaswamy (2017)

The Supreme Court’s landmark 2017 judgment in Justice K.S. Puttaswamy v. Union of India recognised privacy as a fundamental right under Article 21. This established that even in an employment context, surveillance must be proportionate to a legitimate aim — not simply unlimited because a device is company-owned.

Layer 3

DPDP Act 2023 — the most significant recent shift

India’s first comprehensive data protection law, passed in August 2023 with rules notified in November 2025. It classifies employee monitoring data as personal data, requires a lawful purpose, mandates transparency and data minimisation, and sets penalties of up to ₹250 crore for data breaches. Full compliance is required by May 2027, but employers are expected to be building toward it now.

What an Employer Can Legally Monitor on a Company Device

The general principle that’s consistently corroborated across all three frameworks: if the device belongs to the employer, monitoring for a specific, legitimate, proportionate business purpose is permitted.

What’s Being MonitoredGenerally Permissible?
Work emails on the company email account YES — if disclosed in policy
Access to company systems, files, and databases YES — standard security practice
Websites visited on the company network during work hours YES — if disclosed in policy
Screenshots at periodic intervals for specific security purposes YES — if disclosed and proportionate
Continuous keystroke logging throughout the entire workday INCREASINGLY NO — viewed as disproportionate
Full screen recording without any specific justification INCREASINGLY NO — disproportionate under DPDP Act
Personal emails accessed on the company laptop GREY AREA — disclosure required; scope contested
Monitoring outside work hours NO — disproportionate; violates purpose limitation

The “Without Telling You” Part — What the DPDP Act Changed

This is where the most meaningful shift in the law has happened. Under the older IT Act framework, covert monitoring was legally murky but widely practised. Under the DPDP Act 2023, the transparency requirement has become significantly more explicit.

Monitoring Data = Personal Data Under the DPDP Act
Personal Data = Requires Lawful Purpose + Notice + Proportionality
Employers must state why they’re collecting data, what they’re collecting, and ensure the scope is limited to what the stated purpose actually requires
Section 7(i) of the DPDP Act — the “employment purposes” provision Employers can process employee data without separate consent under this provision, but only for purposes genuinely connected to employment — the Act’s examples are preventing corporate espionage, protecting trade secrets, and safeguarding classified information. These are all security-specific. Blanket continuous surveillance of an entire workforce does not fit this exemption cleanly.
The monitoring disclosure in your employment contract matters more than most people realise Most offer letters and IT policies include a clause stating that company devices may be monitored. Under the current framework, this disclosure — however buried — is a significant factor in determining the legality of monitoring. If you signed an offer letter that included a monitoring or acceptable use clause, that’s the agreement in effect for company devices.

Company Device vs Your Personal Device: A Different Standard

The device ownership question genuinely changes the legal calculus.

Company Device

Higher employer latitude, but still requires disclosure and proportionality

Because the employer owns the device, their monitoring rights are broader. Disclosed monitoring for legitimate security or productivity purposes is generally permissible within work hours.

Your Personal Device

Significantly more restricted — even during work hours

If your employer asks to install monitoring software on your personal device, or accesses data on a personal device in a BYOD arrangement, consent requirements are considerably more stringent and the threshold for proportionality is much higher.

What “Proportionality” Actually Means in Practice

The proportionality principle — drawn from the Puttaswamy judgment and reinforced by the DPDP Act — is the key limiting concept on employer monitoring. It means the scope of surveillance must match the legitimate need behind it.

1

A financial firm logging database access to prevent insider trading

Specific, security-related, directly connected to a legitimate and regulatorily-mandated concern. Clearly proportionate.

2

Logging websites visited on the company network during work hours

Disclosed in policy, within work hours, serves a legitimate productivity and security interest. Generally proportionate.

3

Continuous keystroke logging of every employee throughout the workday

Disproportionate without a specific security justification. Collecting far more data than any stated business purpose actually requires. Increasingly challenged under the DPDP Act framework.

4

Monitoring activity outside designated work hours

Violates purpose limitation — if the stated purpose is work productivity or security, activity outside work hours falls outside that stated purpose by definition.

“The shift in 2026 is from ‘can we monitor?’ to ‘can we justify this specific monitoring for this specific purpose?’ That’s a meaningful change for both employers building compliance and employees understanding what they can reasonably expect.”

WorkRightsIndia

Where the DPDP Act Is Still Being Rolled Out

It’s worth being honest about the implementation timeline, since several sources confuse what’s currently in force with what’s coming.

Already Active

Data Protection Board of India — operational now

The structural oversight body is in place and handling complaints. The framework’s principles are in effect.

November 2026

Consent Manager Framework becomes operational

Third-party consent management mechanisms go live, strengthening how employee consent is collected and managed.

May 2027

Full compliance deadline — all obligations enforceable

Complete DPDP Act compliance required, including notice requirements, individual rights handling, and breach notification processes.

Current Position

2026 is the “build year” — directional requirements are clear

Even before May 2027, the direction is unambiguous: transparency, proportionality, and documented purpose for any monitoring activity.

What You Can Reasonably Ask Your Employer

  1. What monitoring software, if any, is installed on company devices — a reasonable question to ask HR or IT, particularly when starting a remote role.
  2. What your employer’s IT acceptable use policy says — this document governs what monitoring is disclosed and what the rules are for using the device.
  3. Whether any monitoring extends outside work hours or to personal communications — these are the areas where employer authority is weakest and proportionality arguments are strongest.

Quick Reference

QuestionAccurate Answer
Can they monitor a company laptop? Yes — if disclosed and for a legitimate purpose
Can they do it without telling you? Increasingly no — DPDP Act requires transparency
Can they monitor your personal emails on a company device? Grey area — disclosure required; proportionality contested
Can they monitor outside work hours? Generally no — violates purpose limitation
Can they install monitoring on your personal phone or laptop? Not without explicit, meaningful consent — much higher standard

The One Line to Remember

A company laptop can be monitored — that’s established. But monitoring must now be disclosed, proportionate to a specific legitimate purpose, and limited to work hours. Covert, continuous, or blanket surveillance without a clear business justification sits in increasingly uncertain legal territory under the DPDP Act framework.

This article is for informational purposes only and does not constitute legal advice. The Digital Personal Data Protection Act 2023 is being implemented in phases, with full enforcement expected by May 2027. Rules and employer obligations may evolve during the transition period. For advice specific to your situation, consult a qualified lawyer. Information in this article is current as of July 2026.

Scroll to Top