Can Your Employer Track You on a Company Laptop Without Telling You?
If you work on a company-issued laptop, your employer has both the technical ability and a reasonable legal basis to monitor how that device is being used. That’s the baseline. What most employees don’t know is where the legal limits on that monitoring actually sit — and how significantly those limits have tightened since the Digital Personal Data Protection Act 2023 rules were notified in November 2025.
The Three Legal Layers That Govern This
Employer monitoring in India isn’t governed by one single law. It sits at the intersection of three overlapping frameworks, each adding a different constraint.
IT Act 2000 — the historical baseline
Section 69 of the IT Act permits interception, monitoring, or decryption of information on a device, particularly for legitimate business security purposes. This is the provision most employers have historically relied on. It’s broad, but it was never designed with employee privacy specifically in mind.
Constitutional right to privacy — Puttaswamy (2017)
The Supreme Court’s landmark 2017 judgment in Justice K.S. Puttaswamy v. Union of India recognised privacy as a fundamental right under Article 21. This established that even in an employment context, surveillance must be proportionate to a legitimate aim — not simply unlimited because a device is company-owned.
DPDP Act 2023 — the most significant recent shift
India’s first comprehensive data protection law, passed in August 2023 with rules notified in November 2025. It classifies employee monitoring data as personal data, requires a lawful purpose, mandates transparency and data minimisation, and sets penalties of up to ₹250 crore for data breaches. Full compliance is required by May 2027, but employers are expected to be building toward it now.
What an Employer Can Legally Monitor on a Company Device
The general principle that’s consistently corroborated across all three frameworks: if the device belongs to the employer, monitoring for a specific, legitimate, proportionate business purpose is permitted.
| What’s Being Monitored | Generally Permissible? |
|---|---|
| Work emails on the company email account | YES — if disclosed in policy |
| Access to company systems, files, and databases | YES — standard security practice |
| Websites visited on the company network during work hours | YES — if disclosed in policy |
| Screenshots at periodic intervals for specific security purposes | YES — if disclosed and proportionate |
| Continuous keystroke logging throughout the entire workday | INCREASINGLY NO — viewed as disproportionate |
| Full screen recording without any specific justification | INCREASINGLY NO — disproportionate under DPDP Act |
| Personal emails accessed on the company laptop | GREY AREA — disclosure required; scope contested |
| Monitoring outside work hours | NO — disproportionate; violates purpose limitation |
The “Without Telling You” Part — What the DPDP Act Changed
This is where the most meaningful shift in the law has happened. Under the older IT Act framework, covert monitoring was legally murky but widely practised. Under the DPDP Act 2023, the transparency requirement has become significantly more explicit.
Personal Data = Requires Lawful Purpose + Notice + Proportionality
Company Device vs Your Personal Device: A Different Standard
The device ownership question genuinely changes the legal calculus.
Higher employer latitude, but still requires disclosure and proportionality
Because the employer owns the device, their monitoring rights are broader. Disclosed monitoring for legitimate security or productivity purposes is generally permissible within work hours.
Significantly more restricted — even during work hours
If your employer asks to install monitoring software on your personal device, or accesses data on a personal device in a BYOD arrangement, consent requirements are considerably more stringent and the threshold for proportionality is much higher.
What “Proportionality” Actually Means in Practice
The proportionality principle — drawn from the Puttaswamy judgment and reinforced by the DPDP Act — is the key limiting concept on employer monitoring. It means the scope of surveillance must match the legitimate need behind it.
A financial firm logging database access to prevent insider trading
Specific, security-related, directly connected to a legitimate and regulatorily-mandated concern. Clearly proportionate.
Logging websites visited on the company network during work hours
Disclosed in policy, within work hours, serves a legitimate productivity and security interest. Generally proportionate.
Continuous keystroke logging of every employee throughout the workday
Disproportionate without a specific security justification. Collecting far more data than any stated business purpose actually requires. Increasingly challenged under the DPDP Act framework.
Monitoring activity outside designated work hours
Violates purpose limitation — if the stated purpose is work productivity or security, activity outside work hours falls outside that stated purpose by definition.
“The shift in 2026 is from ‘can we monitor?’ to ‘can we justify this specific monitoring for this specific purpose?’ That’s a meaningful change for both employers building compliance and employees understanding what they can reasonably expect.”
WorkRightsIndiaWhere the DPDP Act Is Still Being Rolled Out
It’s worth being honest about the implementation timeline, since several sources confuse what’s currently in force with what’s coming.
Data Protection Board of India — operational now
The structural oversight body is in place and handling complaints. The framework’s principles are in effect.
Consent Manager Framework becomes operational
Third-party consent management mechanisms go live, strengthening how employee consent is collected and managed.
Full compliance deadline — all obligations enforceable
Complete DPDP Act compliance required, including notice requirements, individual rights handling, and breach notification processes.
2026 is the “build year” — directional requirements are clear
Even before May 2027, the direction is unambiguous: transparency, proportionality, and documented purpose for any monitoring activity.
What You Can Reasonably Ask Your Employer
- What monitoring software, if any, is installed on company devices — a reasonable question to ask HR or IT, particularly when starting a remote role.
- What your employer’s IT acceptable use policy says — this document governs what monitoring is disclosed and what the rules are for using the device.
- Whether any monitoring extends outside work hours or to personal communications — these are the areas where employer authority is weakest and proportionality arguments are strongest.
Quick Reference
| Question | Accurate Answer |
|---|---|
| Can they monitor a company laptop? | Yes — if disclosed and for a legitimate purpose |
| Can they do it without telling you? | Increasingly no — DPDP Act requires transparency |
| Can they monitor your personal emails on a company device? | Grey area — disclosure required; proportionality contested |
| Can they monitor outside work hours? | Generally no — violates purpose limitation |
| Can they install monitoring on your personal phone or laptop? | Not without explicit, meaningful consent — much higher standard |
The One Line to Remember
A company laptop can be monitored — that’s established. But monitoring must now be disclosed, proportionate to a specific legitimate purpose, and limited to work hours. Covert, continuous, or blanket surveillance without a clear business justification sits in increasingly uncertain legal territory under the DPDP Act framework.
This article is for informational purposes only and does not constitute legal advice. The Digital Personal Data Protection Act 2023 is being implemented in phases, with full enforcement expected by May 2027. Rules and employer obligations may evolve during the transition period. For advice specific to your situation, consult a qualified lawyer. Information in this article is current as of July 2026.