Algorithmic Monitoring of Remote Employees in India
Abstract
The shift to remote and hybrid work has been accompanied by a quiet but far-reaching expansion of workplace surveillance. Employers increasingly rely on algorithmic monitoring tools that log keystrokes, capture screenshots, track application usage, and activate webcams to verify that employees working from home are productively engaged. While such tools are marketed as neutral productivity aids, they raise serious questions about the privacy, dignity, and autonomy of employees and about whether the traditional employment relationship of mutual trust can survive continuous, data-driven scrutiny.
This paper examines whether Indian law, comprising the constitutional right to privacy under Article 21, the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the emerging labor codes, together with the common law duty of good faith, adequately protects remote employees from excessive algorithmic monitoring. Drawing on a comparative analysis of the United Kingdom and the European Union and on doctrinal and judicial material, the paper argues that India’s legal framework remains fragmented and reactive and that the duty of good faith, though conceptually promising, has not been meaningfully developed in Indian employment jurisprudence to constrain monitoring practices. The paper concludes with recommendations for a purpose-built regulatory response.
1. Introduction
The COVID-19 pandemic compressed nearly a decade of workplace transformation into a matter of months, and remote work, once a marginal arrangement, became the default mode of functioning for large sections of India’s services economy. As physical supervision became impossible, employers turned to software-based alternatives. Algorithmic monitoring tools, sometimes described euphemistically as “productivity trackers” or “workforce analytics platforms,” allow an employer to log every keystroke, capture periodic or continuous screenshots of the employee’s screen, record mouse movement, track the applications and websites an employee opens, and, in more invasive deployments, activate the employee’s webcam or microphone to confirm physical presence. Employers justify these tools by reference to legitimate concerns: verifying that contracted work is being performed, protecting confidential business information, preventing data leakage, and ensuring accountability in the absence of in-person supervision.
Yet the same tools, once installed inside an employee’s own home, blur the boundary between the workplace and private life in ways traditional labor law was not designed to address. Algorithmic monitoring does not merely measure output; it renders visible activities, habits, and even emotional states that have no bearing on the work for which the employee is paid. A keystroke logger cannot distinguish an employee drafting a work email from one messaging a doctor about a personal health concern, and a webcam-based “attention tracker” transforms a bedroom or living room, spaces traditionally free from employer control, into an extension of the corporate premises under continuous watch.
The employment relationship has long been understood not merely as an exchange of labor for wages but as a relationship built on reciprocal trust. This is captured, in the common law tradition, by the implied duty of mutual trust and confidence, sometimes described as the duty of good faith: an unwritten but legally recognized expectation that neither party will act in a manner calculated to seriously damage the relationship of confidence underlying the contract of employment. This duty developed to restrain employer misconduct such as arbitrary humiliation, unjustified accusations, or oppressive supervision.
The question this paper investigates is whether that duty, or any comparable Indian doctrine, is robust enough to restrain a qualitatively different kind of employer conduct: the outsourcing of supervision to an algorithm that observes continuously, records permanently, and evaluates without the moderating influence of human judgment.
India’s regulatory response to this shift has so far been incidental rather than deliberate. Its data protection law has evolved from obligations layered onto the Information Technology Act, 2000, to a dedicated statute, the Digital Personal Data Protection Act, 2023 (DPDP Act), but neither instrument was designed with the employment relationship, still less algorithmic monitoring, as its central concern.
The newly consolidated labor codes likewise say little about digital supervision, except insofar as they recognize gig and platform work as a distinct category. Against this backdrop, the present study asks whether the duty of good faith can be revived and adapted to fill the gaps left by data protection and labor legislation, or whether India instead requires a purpose-built framework governing algorithmic monitoring, of the kind now emerging in the European Union.
Legal Framework at Issue
- Constitutional right to privacy under Article 21
- Information Technology Act, 2000
- Digital Personal Data Protection Act, 2023 (DPDP Act)
- Emerging Labour Codes
- Common law duty of good faith
2. Statement of the Research Problem
Indian law does not clearly define the limits of an employer’s power to monitor a remote employee. The right to privacy was recognized as a fundamental right by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India, but that recognition was developed principally in the context of state action and mass data collection by government schemes, not the everyday, granular surveillance conducted by private employers over their own staff. The IT Act, 2000, and its subordinate rules regulate the collection and disclosure of “sensitive personal data” but were not drafted with continuous behavioral monitoring in mind. The DPDP Act, 2023, India’s first comprehensive data protection statute, treats the employer as a “data fiduciary” and the employee as a “data principal,” but permits processing of employee data without consent for specified employment-related purposes, leaving considerable discretion to employers as to what monitoring is “necessary.” Labor law, for its part, has historically concerned itself with wages, working hours, dismissal, and industrial disputes and has said almost nothing about the manner in which supervision itself may be exercised.
This creates a regulatory gap precisely where remote work has made monitoring most intrusive and least visible to co-workers, unions, or regulators. An employee working from home has no colleague to notice if an employer’s software silently activates a webcam every ten minutes, and no inspector visits a home office to assess whether monitoring is proportionate to any genuine security risk. The research problem this paper addresses is whether existing legal doctrine, in particular the underused duty of good faith, together with the fragmented data protection and labor law framework, offers Indian remote employees adequate protection against excessive algorithmic monitoring, or whether the gap between formal legal entitlement and lived working conditions has grown too wide to close without dedicated legislative intervention.
Core Research Question
The research problem can be understood through the following central question:
Whether existing legal doctrine, in particular the underused duty of good faith, together with the fragmented data protection and labour law framework, offers Indian remote employees adequate protection against excessive algorithmic monitoring, or whether the gap between formal legal entitlement and lived working conditions has grown too wide to close without dedicated legislative intervention.
The Regulatory Gap in Remote Work
| Area | Issue Identified in the Research |
|---|---|
| Privacy | Remote monitoring can intrude into an employee’s private home environment. |
| Data Protection | Existing data protection rules were not designed specifically around continuous behavioral monitoring. |
| Labor Law | Traditional labor law has focused on wages, working hours, dismissal, and industrial disputes rather than digital supervision. |
| Algorithmic Monitoring | Automated monitoring can continuously observe, record, and evaluate employees. |
| Home-Based Work | Remote work makes intrusive monitoring less visible to co-workers, unions, and regulators. |
3. Review of Literature
Scholarship on workplace surveillance has grown rapidly alongside the technology it studies, though much of the literature originates from jurisdictions with more developed data protection regimes than India. Early regulatory attention in Europe focused on email and internet monitoring, exemplified by the European Court of Human Rights’ rulings in Halford v. United Kingdom and Copland v. United Kingdom, both holding that employees retain a reasonable expectation of privacy over personal communications made using employer-provided equipment absent clear prior warning. This line of authority culminated in the Grand Chamber’s 2017 judgment in Bărbulescu v. Romania, which synthesised earlier case law into a structured proportionality test under Article 8 of the European Convention on Human Rights, considering prior notice, the scope and intrusiveness of monitoring, the legitimacy of the employer’s stated purpose, the availability of less intrusive alternatives, the consequences for the employee, and the existence of procedural safeguards.
Algorithmic Management
Parallel literature has developed around “algorithmic management,” a term popularized in gig-economy scholarship to describe how platforms such as ride-hailing and delivery applications use software, rather than human supervisors, to assign, evaluate, and discipline workers. Commentators studying the Indian gig economy observe that such platforms deploy rating systems, automated deactivation, and route-optimization algorithms functioning as de facto managerial control while allowing platforms to deny any employment relationship altogether. This literature intersects with, but is analytically distinct from, traditional employee-monitoring scholarship, since gig workers are typically not treated as “employees” at all, whereas the remote, salaried, white-collar workforce central to this paper occupies a formal employment relationship yet faces comparably granular oversight.
Mutual Trust and Confidence
On the doctrinal side, English case law on the implied duty of mutual trust and confidence, notably Malik v. Bank of Credit and Commerce International SA, has generated substantial commentary on the scope and remedial consequences of the duty, including debate over whether it amounts to a general obligation of good faith in performing the employment contract. Indian scholarship, by contrast, has engaged comparatively little with mutual trust and confidence as a distinct tool for regulating employer conduct, tending instead to analyse employment protection through the Industrial Disputes Act’s restrictions on retrenchment, or through constitutional service jurisprudence applicable to public employment. Literature on India’s own reforms has grown since the DPDP Act, 2023, but practitioner commentary generally focuses on compliance obligations such as data minimisation and breach notification rather than on how much monitoring those principles actually permit. This paper brings these three strands, comparative privacy jurisprudence, algorithmic management scholarship, and the duty of good faith, into a single frame focused on remote-work monitoring in India.
Three Strands of Literature
- Comparative privacy jurisprudence: European case law concerning employee monitoring and privacy.
- Algorithmic management scholarship: Research concerning software-based managerial control, particularly in the gig economy.
- Duty of good faith: Doctrinal analysis of mutual trust and confidence in employment relationships.
4. Objectives of the Study
- To examine the constitutional and statutory framework governing employee privacy in India, with particular reference to algorithmic monitoring during remote work.
- To analyse the duty of good faith, or mutual trust and confidence, as it operates between employer and employee, and to assess its capacity to constrain algorithmic monitoring.
- To compare India’s regulatory position with that of the United Kingdom and the European Union.
- To examine significant judicial pronouncements, Indian and international, bearing on workplace privacy and monitoring.
- To identify gaps in the application of existing law to algorithmic monitoring in remote work arrangements.
- To recommend measured reforms capable of improving the protection of employee privacy without disregarding legitimate employer interests.
5. Research Questions
- Does Indian law adequately protect employees from excessive algorithmic monitoring while working from home?
- How does algorithmic monitoring affect, and how is it affected by, the duty of good faith between employer and employee?
- What lessons can India draw from the regulatory experience of the United Kingdom and the European Union?
- What legislative or doctrinal changes would improve privacy protection for remote workers without unduly constraining legitimate managerial oversight?
6. Research Methodology
This study adopts library-based methodology. It relies on primary legal sources, including the Constitution of India, the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, the four Labour Codes, judicial decisions of the Supreme Court of India, the House of Lords and its successor the UK Supreme Court, and the European Court of Human Rights, as well as secondary sources including academic commentary, regulatory guidance issued by the Information Commissioner’s Office in the United Kingdom, and policy analysis of the European Union’s Platform Work Directive.
No empirical fieldwork, surveys, or interviews were conducted; the analysis is confined to the interpretation and comparative evaluation of existing legal texts and judicial reasoning.
Comparative jurisdictions were selected because the United Kingdom shares India’s common law heritage and the doctrinal origin of the mutual trust and confidence principle, while the European Union has adopted the most comprehensive legislative response to algorithmic management currently in force anywhere in the world, making both jurisdictions instructive benchmarks for evaluating the adequacy of the Indian position.
7. Scope and Limitations of the Study
The study is confined to Indian labour and data protection law as applicable to employees working remotely, and to the comparative frameworks of the United Kingdom and the European Union.
It does not undertake a comprehensive survey of every state’s emerging gig-worker legislation, though it refers to selected state enactments where relevant to illustrate legislative trends.
The paper focuses on salaried, formally employed remote workers rather than gig or platform workers, although the algorithmic management literature developed in the gig-work context is drawn upon analogically where instructive.
Because the DPDP Act, 2023 is still in the process of phased implementation, with its substantive processing obligations yet to take full effect, the analysis necessarily engages with a moving regulatory target and should be read subject to subsequent rule-making and judicial interpretation.
8. Conceptual Framework: Understanding Algorithmic Monitoring
8.1 Forms and Techniques of Algorithmic Monitoring
Algorithmic monitoring in the remote-work context typically takes one or more of the following forms:
- keystroke logging;
- screen capture, which takes periodic or continuous screenshots of the active display;
- activity and idle-time tracking, which measures inactivity and infers “unproductive” time;
- application and website monitoring;
- webcam-based presence detection, using periodic image capture or continuous video to confirm the employee is at their workstation; and
- increasingly, sentiment or emotion analysis, which applies machine-learning models to facial expressions, vocal tone, or typing cadence to infer mood, stress, or engagement.
Each technique generates data that is aggregated into productivity scores, dashboards, or automated alerts, often without meaningful human review before an adverse inference, such as a poor performance rating or disciplinary action, is drawn.
8.2 Employer Rationale versus Employee Vulnerability in Remote Work
Employers advance several rationales for such monitoring:
- verifying attendance and output where physical supervision is unavailable;
- protecting client confidentiality and intellectual property in regulated industries such as banking, insurance, and information technology services; and
- detecting insider threats or data exfiltration.
These are not illegitimate concerns, particularly for India’s large business-process outsourcing and information-technology services sector, which routinely handles sensitive client data belonging to overseas customers subject to their own data protection obligations.
However, the shift to the employee’s home introduces a structural vulnerability largely absent in an office.
An employee cannot decline to install monitoring software without risking a livelihood; the home is simultaneously the site of employment and of family life, caregiving, and rest, and monitoring technology does not reliably distinguish between the two.
The bargaining-power asymmetry that has always characterised the employment relationship is, in remote work, compounded by an asymmetry of technical visibility: the employer observes continuously, while the employee typically has no comparable visibility into what data is collected, how long it is retained, or how it shapes decisions about their continued employment.
9. The Constitutional and Statutory Framework for Employee Privacy in India
9.1 Article 21 and the Right to Privacy: From Kharak Singh to Puttaswamy
The Indian Constitution does not contain an express right to privacy. For decades, the Supreme Court’s early decisions, including M.P. Sharma v. Satish Chandra and Kharak Singh v. State of Uttar Pradesh, were read as denying any independent constitutional right to privacy.
This position was decisively overturned in 2017 by a nine-judge bench in Justice K.S. Puttaswamy (Retd.) v. Union of India, which held unanimously that privacy is intrinsic to the right to life and personal liberty under Article 21, and is also reflected in the freedoms guaranteed under Article 19.
The Court described privacy as encompassing an individual’s ability to control significant aspects of their own life, including bodily autonomy, personal choices, and informational self-determination, and held that any invasion of privacy must satisfy a threefold test of legality (backed by law), legitimate aim, and proportionality between the interference and the object sought to be achieved.
Puttaswamy is foundational to any discussion of employee privacy in India, yet its direct application to private-sector monitoring is not straightforward, since fundamental rights under Part III are, as a general rule, enforceable against the state and instrumentalities falling within Article 12, not against private employers.
A private company deploying keystroke-logging software is not, without more, bound directly by Article 21 as a government department would be.
The practical significance of Puttaswamy for private employment therefore lies less in direct enforceability and more in its normative influence: it establishes privacy as a constitutional value that ordinary legislation must be interpreted to advance, and it supplies the proportionality framework that has since informed the drafting of the DPDP Act, 2023.
An earlier decision, People’s Union for Civil Liberties v. Union of India, concerning telephone tapping, had already established that interception of communications engages Article 21 and requires procedural safeguards, laying early groundwork for the proportionality reasoning later generalised in Puttaswamy.
9.2 The Information Technology Act, 2000 and the SPDI Rules, 2011
Before the DPDP Act, India’s principal statutory protection for personal data lay in the Information Technology Act, 2000, as amended in 2008, together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the SPDI Rules).
Section 43A requires a “body corporate” handling sensitive personal data to maintain reasonable security practices and makes it liable to compensate anyone who suffers wrongful loss from negligence in that regard.
Section 72A criminalises disclosure of personal information obtained under a lawful contract without consent, where intended or known to cause wrongful loss or gain.
The SPDI Rules define “sensitive personal data or information,” including financial, health, and biometric data, and require consent before collection and disclosure of purpose in a privacy policy.
These provisions, however, were designed principally to address data breaches and unauthorised disclosure to third parties; they say little about the volume or intrusiveness of monitoring an employer may conduct over its own workforce, provided it can point to a contractual basis and a stated purpose.
An employer that discloses a broadly drafted monitoring policy in an employee handbook can generally satisfy the SPDI Rules’ consent and disclosure requirements while still deploying highly intrusive surveillance, because the Rules impose no independent test of necessity or proportionality analogous to that developed in Puttaswamy or in European data protection law.
9.3 The Digital Personal Data Protection Act, 2023
The DPDP Act, 2023 received presidential assent on 11 August 2023 and represents India’s first comprehensive, cross-sectoral data protection statute.
Its substantive processing provisions were only brought into force following notification of the Digital Personal Data Protection Rules, 2025, on 13 November 2025, with core obligations commencing in phases over the following eighteen months, so the Act’s practical impact on monitoring practices is only now beginning to be tested.
It designates any entity determining the purpose and means of processing personal data as a “data fiduciary,” a category plainly including employers, and designates the individual to whom data relates, including current and former employees, applicants, interns, and contractors, as a “data principal.”
The Act is built around purpose limitation, data minimisation, and accountability, each directly relevant to monitoring:
- purpose limitation would tie monitoring to a specific, disclosed business purpose rather than open-ended surveillance;
- data minimisation would confine collection to what is reasonably necessary; and
- accountability would require the fiduciary to demonstrate compliance.
Significantly, however, Section 7 allows processing without the data principal’s consent for specified purposes, including employment-related purposes such as safeguarding the employer against loss, ensuring safety, or preventing corporate espionage.
This “deemed consent” provision, while narrower than a blanket exemption, still allows employers to process substantial employee data on their own unilateral assessment of necessity, without requiring specific, informed consent to the monitoring itself.
Because the Act does not precisely define what monitoring is “necessary,” and lacks an employment-tailored proportionality test comparable to the European Union’s General Data Protection Regulation, employers retain considerable latitude to design programmes that satisfy the letter of the Act while remaining intrusive in practice.
The Act also continues to operate alongside Section 72A of the IT Act, creating regulatory overlap not yet authoritatively resolved.
9.4 The New Labour Codes and the Regulatory Vacuum on Monitoring
Between 2019 and 2020, Parliament consolidated numerous labour statutes into four codes:
- the Code on Wages, 2019;
- the Industrial Relations Code, 2020;
- the Occupational Safety, Health and Working Conditions Code, 2020; and
- the Code on Social Security, 2020.
Of these, only the last directly acknowledges the changing nature of digital-platform work, introducing statutory definitions of “gig worker” and “platform worker” and a framework for extending social security benefits, such as accident insurance, health cover, and old-age protection, to workers engaged outside the traditional employer-employee relationship.
Several states, including Rajasthan, Karnataka, Telangana, Jharkhand, and Bihar, have since enacted or proposed platform-worker welfare legislation, with some, notably Karnataka’s proposed Bill, beginning to impose obligations on platforms regarding transparency in algorithmic management and advance notice before termination or deactivation.
None of the four Codes, however, contains a general provision regulating the manner or intensity of digital supervision over the salaried, formally employed remote workforce central to this paper.
The gig and platform worker provisions are, in any event, directed at income security rather than surveillance, and even the more progressive state legislation on algorithmic transparency is confined to platform-based gig work rather than conventional employment.
The result is a curious asymmetry: a food-delivery rider may, in states with emerging gig-worker legislation, acquire a nascent statutory right to transparency about a platform’s rating algorithm, while a salaried software engineer working from home, subject to continuous keystroke logging and webcam monitoring, has no comparable statutory entitlement at all, because labour law has not yet turned its attention to monitoring within the conventional employment relationship.
10. The Duty of Good Faith and Mutual Trust in the Employment Relationship
10.1 Origins and Development: Malik v. BCCI and the English Position
The idea that an employer owes employees a duty of good faith finds its most developed common law expression in the implied term of mutual trust and confidence, recognised by the House of Lords in Malik v. Bank of Credit and Commerce International SA.
The case arose after BCCI’s collapse amid revelations of large-scale fraud; former employees, though personally blameless, argued that the bank’s corrupt conduct had stigmatised them in the labour market and breached an implied term that neither party would, without reasonable and proper cause, act in a manner calculated or likely to destroy or seriously damage the relationship of trust and confidence between them.
The House of Lords accepted this, holding the term implied by law into every employment contract, that breach is assessed objectively rather than by reference to the employer’s subjective motive, and that damages may be recoverable even where the conduct was not specifically targeted at the employee.
Subsequent English case law has both extended and cautiously bounded the doctrine, finding it breached by conduct ranging from unfounded accusations of misconduct to arbitrary withholding of a promised benefit, while holding, through the line of authority following Johnson v. Unisys, that it does not extend to the manner of a lawful dismissal itself.
10.2 The Status of Good Faith under Indian Contract and Labour Law
India’s contract law, codified in the Indian Contract Act, 1872, does not recognise a freestanding, general duty of good faith in contractual performance comparable to that found in some civil law systems, and Indian courts have not incorporated the English mutual trust and confidence doctrine as a distinct term implied into every employment contract.
Instead, Indian jurisprudence addresses employer conduct through several partially overlapping channels.
In the public sector, principles of natural justice and constitutional fairness, developed through decisions applying Articles 14 and 21 to government service, require that disciplinary action against government employees be reasonable, non-arbitrary, and preceded by a fair hearing.
In the organised private sector, the Industrial Disputes Act, 1947, and now its successor, the Industrial Relations Code, 2020, restrict the retrenchment and dismissal of “workmen,” a category that has historically excluded supervisory, managerial, and many white-collar employees above a specified wage threshold, leaving a significant proportion of India’s remote, salaried, knowledge-economy workforce, precisely the population most exposed to algorithmic monitoring, outside the principal statutory protection against arbitrary employer conduct.
Where Indian courts have invoked good faith in employment, it has typically been in the narrower sense of requiring that a contractual discretion, for example over transfer, promotion, or termination during probation, not be exercised mala fide or for a collateral purpose, rather than as a broader obligation governing how an employer supervises or monitors employees on an ongoing basis.
This absence is not a mere doctrinal footnote; it means the duty of good faith exists in Indian law today largely as an unrealised possibility drawn from comparative jurisprudence rather than as settled, judicially enforceable doctrine.
10.3 Can the Duty of Good Faith Absorb Algorithmic Monitoring Harms?
Even if Indian courts were to recognise a general implied duty of mutual trust and confidence, its application to algorithmic monitoring would raise distinctive difficulties.
The doctrine as developed in Malik responds to discrete acts or patterns of conduct, such as a false accusation, that a court can evaluate against an objective standard of reasonableness.
Continuous algorithmic monitoring, by contrast, is not a single act but a standing condition of the employment relationship, often disclosed in advance and nominally consented to through an employment contract.
A court asked to find such monitoring calculated to destroy trust and confidence would need to grapple with the fact that employees have, at least formally, agreed to it, and that the employer can point to plausible business justifications.
The duty of good faith thus offers a promising normative vocabulary, an insistence that supervision respect the employee’s dignity and reasonable expectations, but not, without significant judicial development, a precise test for how much monitoring is too much.
It is best understood as a complement to, rather than a substitute for, specific data protection and labour regulation: capable of informing how courts interpret ambiguous terms and assess conduct in individual disputes, but not of supplying the detailed rules on notice, proportionality, and human oversight that algorithmic monitoring requires.
11. Comparative Perspectives: Lessons from the United Kingdom and the European Union
11.1 The United Kingdom: UK GDPR and the ICO’s Monitoring Guidance
The United Kingdom regulates workplace monitoring primarily through the UK GDPR and the Data Protection Act, 2018, supplemented by detailed guidance from the Information Commissioner’s Office. For over a decade, the ICO’s 2011 Employment Practices Code contained the principal sectoral guidance on monitoring at work; recognising that remote working and new monitoring technologies had rendered it outdated, the ICO consulted publicly in 2022 and, on 3 October 2023, issued updated guidance titled “Employment practices and data protection: monitoring workers.” The guidance does not prohibit monitoring but requires a valid lawful basis for processing, data protection impact assessments before introducing new measures, particularly where monitoring is covert, biometric, or uses automated analytics to draw inferences, and proportionality to a clearly identified business need. It also emphasises transparency, requiring clear disclosure of the nature and extent of monitoring, and recommends that impact assessments involve consulting affected employees absent good reason not to. Although not directly binding as statute, its interpretive weight, combined with the UK GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimisation, gives UK employees a considerably more structured basis for challenging disproportionate monitoring than currently exists under Indian law.
11.2 The European Union: GDPR Article 88 and the Platform Work Directive
Within the European Union, Article 88 of the GDPR permits, though does not itself enact, member states to adopt more specific rules safeguarding employee rights in processing personal data, and several have exercised this power. More significant for algorithmic monitoring specifically, the EU adopted Directive (EU) 2024/2831 on improving working conditions in platform work in October 2024, with a transposition deadline of 2 December 2026. While its primary focus is correctly classifying platform workers as employees through a rebuttable legal presumption triggered by indicia of employer control, its algorithmic-management provisions have broader significance here. The Directive requires digital labour platforms to inform workers, their representatives, and national authorities about automated monitoring and decision-making systems, prohibits processing especially sensitive categories of data through such systems, including a worker’s emotional or psychological state, private conversations, and data generated outside working time, and mandates human review of automated systems’ impact at least once every two years, by personnel who are trained, empowered to override automated decisions, and protected from retaliation. Although formally confined to platform work, this structural approach, mandatory disclosure, categorical limits on sensitive data, and guaranteed human oversight, offers a template readily transferable to conventional remote-employment monitoring.
11.3 The European Court of Human Rights: Bărbulescu, Halford and Copland
Alongside legislative developments, the European Court of Human Rights has developed significant jurisprudence under Article 8 of the Convention bearing directly on employer monitoring. In Halford v. United Kingdom, the Court held that an employee retained a reasonable expectation of privacy in personal calls from her office telephone where she had not been warned of monitoring. In Copland v. United Kingdom, it extended similar reasoning to telephone, email, and internet usage, holding that collection and storage of such information engaged Article 8 even without examining message content. The most comprehensive statement came in the Grand Chamber’s 2017 judgment in Bărbulescu v. Romania, arising from the dismissal of a Romanian employee after his employer accessed a messaging account he was required to open for professional use but had also used personally. The Grand Chamber held that Romania’s courts had failed to strike a fair balance between the employer’s interests and the employee’s right to private life and correspondence, and set out factors relevant to proportionality: clear prior notification of the possibility and nature of monitoring, the extent and intrusiveness actually carried out, whether legitimate reasons justified it, whether a less intrusive method existed, the seriousness of consequences for the employee, and whether adequate safeguards, including independent review, were provided. Although Bărbulescu concerned a private company, the Court’s reasoning applies through the state’s positive obligation to protect Convention rights horizontally, requiring domestic courts to weigh these factors in disputes between private employers and employees.
11.4 Comparative Takeaways for India
Three features distinguish the UK and EU frameworks from the Indian position.
- Structured proportionality: Both operationalise proportionality through structured, factor-based tests, whether the ICO’s guidance or the Bărbulescu factors, giving courts and regulators concrete criteria for assessing specific practices, whereas Indian law offers only the abstract triple test from Puttaswamy, not yet elaborated into employment-specific criteria.
- Prior impact assessment: Both impose prior impact assessment, whether the ICO’s data protection impact assessment or the Platform Work Directive’s biennial review, requiring employers to justify monitoring before, not only after, it causes harm.
- Limits on sensitive worker data: The Platform Work Directive introduces a categorical prohibition on processing certain uniquely sensitive worker data, such as emotional state and off-duty conduct, a bright-line rule India’s more open-textured “necessity” language does not currently replicate.
These observations directly inform the recommendations below.
11.5 Case Studies: What the Courts Have Said About Workplace Monitoring
11.5.1 Bărbulescu v. Romania (Application No. 61496/08, Grand Chamber, 5 September 2017)
The case arose after Mr Bărbulescu was dismissed for using a Yahoo Messenger account created for work for personal communications. His employer monitored the account and relied on the communications in disciplinary proceedings. The Grand Chamber of the European Court of Human Rights held that the employee’s private life and correspondence were engaged by the monitoring and found that the Romanian domestic courts had not adequately balanced those interests against the employer’s interests. The Court therefore found a violation of Article 8 of the European Convention on Human Rights.
The importance of Bărbulescu lies in the safeguards the Court identified for workplace monitoring. These included whether the employee had been informed in advance about the possibility and nature of monitoring, the extent and intrusiveness of the monitoring, the employer’s reasons for it, whether less intrusive methods could achieve the same purpose, the consequences for the employee, and whether adequate safeguards existed. The Court also distinguished between monitoring communications data and accessing their content, treating access to content as more intrusive.
For this research, Bărbulescu provides a useful comparative framework for assessing algorithmic monitoring in remote work. A productivity-monitoring system may have a legitimate business purpose, but that purpose does not by itself establish that every form of monitoring is justified. The case supports examining notice, necessity, scope, intrusiveness, and safeguards before treating monitoring as proportionate. It should not, however, be presented as an Indian rule, because the decision was made under Article 8 of the European Convention and concerns the obligations of the Romanian State in protecting privacy in an employment dispute.
11.5.2 Copland v. United Kingdom (Application No. 62617/00, 3 April 2007)
Copland concerned monitoring of an employee’s telephone, e-mail, and internet use at a further-education college. The monitoring included information such as telephone numbers, dates and times of calls, e-mail addresses, and internet usage. The employee had not been informed that such monitoring was taking place, and there was no monitoring policy in force at the relevant time. The European Court of Human Rights held that the collection and storage of this information fell within the scope of the employee’s private life and correspondence under Article 8.
An important point about Copland is that the Court did not require proof that the employer had read the substantive content of every communication. The records generated by the employee’s use of workplace communication systems were themselves capable of revealing information about the employee. The Court ultimately found that the interference was not “in accordance with the law” because there was no domestic law regulating the monitoring in the circumstances of the case.
Copland is relevant to algorithmic monitoring because modern systems can record metadata and usage patterns even when employers do not read message content. Keystrokes, application use, website visits, login times, device information, and similar records can collectively reveal patterns about an employee’s activities. The case therefore helps support the narrower proposition that privacy analysis should consider the collection and retention of usage information itself. It does not establish that all workplace monitoring is unlawful, nor does it directly govern private employers in India.
11.6 Indian Case Studies
11.6.1 People’s Union for Civil Liberties (PUCL) v. Union of India, (1997) 1 SCC 301
PUCL concerned telephone interception by public authorities under the Telegraph Act, 1885. The Supreme Court recognised telephone tapping as a serious invasion of privacy. It held that the interception power under Section 5(2) could be exercised only when the statutory conditions of a public emergency or the interest of public safety were satisfied, and it prescribed procedural safeguards for the exercise and review of interception powers.
The relevance of PUCL to this research is limited but important. The case shows that surveillance powers are not treated as unrestricted merely because the authority claims a legitimate objective. The Court connected intrusive interception with privacy and insisted on procedural controls. This reasoning can inform the discussion of transparency, authorisation, record-keeping, and safeguards in workplace monitoring, but PUCL was a constitutional challenge to State telephone interception and did not decide the legality of private employers monitoring employees.
11.6.2 Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1
The nine-judge Constitution Bench in Puttaswamy held that privacy is a constitutionally protected right and an intrinsic part of life and personal liberty under Article 21. The judgment treated privacy as encompassing, among other interests, individual autonomy and informational privacy. It also stated that an invasion of privacy by the State must satisfy the requirements of legality, a legitimate State aim, and proportionality.
Puttaswamy is directly relevant to the conceptual foundation of employee privacy, but its limits must be stated clearly. The case was not about workplace monitoring, and Article 21 operates as a fundamental-rights guarantee principally against State action and entities covered by Article 12. The judgment therefore does not itself impose a direct constitutional prohibition on ordinary monitoring by a private employer. Its value for this study is that it supplies a constitutional account of privacy and informational self-determination, together with a proportionality framework that can inform the interpretation and development of statutory protections applicable to private employment.
12. Judicial Trends: Case Law Analysis
Indian judicial engagement with employee privacy specifically in the context of digital monitoring remains sparse, partly because the DPDP Act is only recently operative and because disputes between individual remote employees and corporate employers, often bound by arbitration clauses or resolved through private settlement, rarely reach appellate courts in a form generating reported precedent. The doctrinal foundation nonetheless rests on a coherent line of privacy jurisprudence. In People’s Union for Civil Liberties v. Union of India, the Supreme Court held that telephone tapping, even by the state for security purposes, infringes Article 21 unless conducted through fair, just, and reasonable procedure, establishing early that surveillance of communications is a constitutional, not merely administrative, concern. This reasoning matured into the comprehensive framework of Puttaswamy, which supplies both the substantive recognition of privacy as a fundamental right and the analytical apparatus of legality, legitimate aim, and proportionality later invoked in framing the DPDP Act.
The comparative case law surveyed above performs, for present purposes, the function direct Indian precedent has not yet performed: it shows how courts in a comparable legal tradition translate abstract privacy guarantees into operative employment standards. The English tradition, through Malik v. BCCI, shows courts implying robust protective terms into the employment contract without waiting for legislation, an approach Indian courts have not yet extended to a general duty of good faith, notwithstanding scattered decisions restraining the mala fide exercise of specific contractual powers. The European human rights case law, through Halford, Copland, and Bărbulescu, shows a mature method for balancing employer and employee interests that Indian courts have not yet had occasion to develop specifically for digital workplace monitoring. Read together, this suggests the absence of Indian precedent is not evidence that algorithmic monitoring raises no legal difficulty, but that the difficulty has not yet been tested in litigation, a gap regulatory clarification could usefully anticipate rather than leaving to slow, case-by-case development.
13. Gaps in Applying Indian Law to Remote-Work Monitoring
Several distinct gaps emerge from the foregoing analysis.
| Gap | Issue Identified |
|---|---|
| Coverage gap in labour law | The Industrial Disputes Act framework and its successor Industrial Relations Code historically exclude supervisory and higher-earning white-collar employees from the definition of “workman,” leaving precisely the salaried, remote, knowledge-economy employees most exposed to algorithmic monitoring without access to the principal statutory mechanism restraining arbitrary employer conduct. |
| Standards gap in data protection law | While the DPDP Act’s principles of purpose limitation, data minimisation, and accountability are conceptually capable of restraining excessive monitoring, the Act does not translate them into concrete, employment-specific standards analogous to the ICO’s guidance or the Bărbulescu factors, leaving employers, employees, and the Data Protection Board of India without clear benchmarks. |
| Horizontality gap in constitutional law | Because Article 21 constrains state action rather than private conduct directly, the proportionality jurisprudence of Puttaswamy does not automatically extend to private-sector monitoring, depending for its practical effect on statutory intermediation that remains incomplete. |
| Doctrinal gap in contract and employment law | Indian courts have not developed a generally applicable duty of good faith or mutual trust and confidence comparable to Malik v. BCCI. |
| Institutional gap | Unlike the EU’s Platform Work Directive, which mandates periodic impact review by trained personnel empowered to override automated decisions, Indian law imposes no comparable requirement of human oversight over algorithmically generated productivity scores or disciplinary recommendations. |
| Visibility gap specific to remote work | Because monitoring occurs inside the employee’s home, without co-workers, union representatives, or inspectors present to observe it, the informal and institutional checks that might otherwise expose disproportionate supervision are largely absent, making legal clarity more, not less, important than in the traditional workplace. |
Findings and Discussion
The analysis above supports several interconnected findings.
| Finding | Key Point |
|---|---|
| Constitutional Privacy | Indian constitutional law supplies a strong normative foundation through Puttaswamy‘s recognition of privacy as intrinsic to dignity and autonomy, but this has not yet been operationalised into employment-specific rules guiding employers or employees. |
| Data Protection | India’s evolving data protection framework, culminating in the DPDP Act, 2023, marks a real improvement over the fragmentary IT Act regime it supersedes, but its employment provisions, particularly the deemed-consent exception, preserve substantial employer discretion not yet curtailed by rules, guidance, or adjudicated cases. |
| Duty of Good Faith | The duty of good faith, though doctrinally under-developed in India, retains interpretive value and offers courts a principled basis, rooted in the reciprocal character of employment, to scrutinise monitoring that is technically compliant yet substantively oppressive, provided courts are willing to develop the doctrine as English courts have done. |
| Comparative Frameworks | The comparative material shows that regulatory clarity need not come at the cost of legitimate employer interests: the UK and EU frameworks acknowledge employers’ right to monitor while imposing structured, proportionate constraints, an approach compatible with India’s own digital-economy ambitions. |
| Protection Gaps | The gaps identified above are mutually reinforcing: the absence of a developed good faith doctrine increases reliance on data protection law to do work it was not designed for, while the absence of employment-specific data protection standards increases reliance on a good faith doctrine Indian courts have not yet developed, leaving remote employees without a reliable primary source of protection in either body of law. |
Constitutional Law and Employee Privacy
Indian constitutional law supplies a strong normative foundation, through Puttaswamy‘s recognition of privacy as intrinsic to dignity and autonomy, but this has not yet been operationalised into employment-specific rules guiding employers or employees.
Evolving Data Protection Framework
India’s evolving data protection framework, culminating in the DPDP Act, 2023, marks a real improvement over the fragmentary IT Act regime it supersedes, but its employment provisions, particularly the deemed-consent exception, preserve substantial employer discretion not yet curtailed by rules, guidance, or adjudicated cases.
Duty of Good Faith in Employment
The duty of good faith, though doctrinally under-developed in India, retains interpretive value: it offers courts a principled basis, rooted in the reciprocal character of employment, to scrutinise monitoring that is technically compliant yet substantively oppressive, provided courts are willing to develop the doctrine as English courts have done.
Comparative Regulatory Material
The comparative material shows that regulatory clarity need not come at the cost of legitimate employer interests: the UK and EU frameworks acknowledge employers’ right to monitor while imposing structured, proportionate constraints, an approach compatible with India’s own digital-economy ambitions.
Interconnected Protection Gaps
Finally, the gaps identified above are mutually reinforcing: the absence of a developed good faith doctrine increases reliance on data protection law to do work it was not designed for, while the absence of employment-specific data protection standards increases reliance on a good faith doctrine Indian courts have not yet developed, leaving remote employees without a reliable primary source of protection in either body of law.
Recommendations
The analysis suggests several practical measures.
Employment-Specific Rules Under the DPDP Framework
The Central Government, in exercise of its rule-making power under the DPDP Act, 2023, should issue employment-specific rules or a sectoral code of practice that translates the Act’s general principles of purpose limitation, data minimisation, and accountability into concrete standards for algorithmic monitoring, addressing matters such as:
- the categories of monitoring data that may be collected;
- retention periods; and
- the circumstances in which continuous, as opposed to periodic, monitoring may be justified.
Mandatory Prior Notice and Impact Assessment
Employers should be statutorily required to conduct a documented assessment of the necessity and proportionality of any proposed monitoring measure before its introduction, drawing on the model of the UK ICO’s data protection impact assessment, and to provide employees with clear, specific prior notice of the nature, extent, and purpose of monitoring, rather than generalised consent buried in a standard-form employment contract.
Categorical Limits on Especially Sensitive Monitoring
Following the approach adopted in the European Union’s Platform Work Directive, Indian law should prohibit, or at minimum impose heightened safeguards on, the processing of especially sensitive categories of employee data generated through monitoring, including:
- inferred emotional or psychological states;
- biometric data collected via webcam or voice analysis; and
- any data generated outside an employee’s designated working hours.
Mandatory Human Oversight of Automated Adverse Decisions
No adverse employment decision, whether a negative performance rating, denial of a benefit, or disciplinary action, should be based solely on an automated productivity score or algorithmic inference without meaningful human review.
Employees should have a statutory right to seek an explanation of, and to contest, any such automated assessment.
Judicial and Legislative Development of the Duty of Good Faith
Indian courts should be encouraged, through appropriate litigation and academic advocacy, to recognise a general implied duty of mutual trust and confidence in Indian employment contracts, along the lines developed in Malik v. BCCI, so that the duty can operate as a residual, dignity-protecting safeguard in cases that fall outside the specific coverage of data protection or labour statutes.
Alternatively, Parliament could codify an equivalent statutory duty applicable to all employers regardless of the “workman” classification that currently limits the reach of industrial law.
A Dedicated Regulatory or Advisory Body
Consideration should be given to empowering the Data Protection Board of India, or a dedicated labour authority, to issue and periodically update sector-specific guidance on lawful workplace monitoring, akin to the UK ICO’s role, so that employers and employees have an accessible, authoritative reference point that evolves alongside monitoring technology, rather than relying solely on infrequent litigation or primary legislation to keep pace with technological change.
Conclusion
Remote work has not created employee privacy concerns from nothing; it has made visible, and considerably intensified, a tension that has always existed between an employer’s legitimate interest in supervising performance and an employee’s interest in dignity, autonomy, and a measure of private space even while at work.
India’s constitutional recognition of privacy as a fundamental right in Puttaswamy, its enactment of the DPDP Act, 2023, and its consolidation of labour law into four new Codes together represent genuine, if incomplete, progress.
Yet none of these developments was designed with algorithmic monitoring specifically in mind, and none currently supplies the structured, employment-specific proportionality standard that UK regulatory guidance and the EU’s Platform Work Directive now provide.
The duty of good faith, the reciprocal trust underlying the employment relationship, remains a conceptually attractive vehicle for restraining oppressive monitoring, but exists in Indian law today more as an aspiration drawn from comparative jurisprudence than as settled, enforceable doctrine.
Bridging this gap will require coordinated action:
- rule-making under the DPDP Act to give concrete content to its general principles;
- legislative attention to labour law’s coverage gaps; and
- a willingness on the part of Indian courts to develop the common law of employment in step with the technology that now mediates so much of it.
Absent such action, the promise of India’s privacy jurisprudence risks remaining largely theoretical for the millions of employees whose working days are recorded, scored, and evaluated by software operating quietly in the background of their homes.
References
- Constitution of India, art. 21.
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
- People’s Union for Civil Liberties v. Union of India, (1997) 1 SCC 301.
- P. Sharma v. Satish Chandra, AIR 1954 SC 300.
- Kharak Singh v. State of Uttar Pradesh, AIR 1963 SC 1295.
- The Information Technology Act, 2000, ss. 43, 43A, 66, 72, 72A.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).
- Digital Personal Data Protection Rules, 2025.
- The Code on Social Security, 2020.
- The Industrial Relations Code, 2020.
- The Industrial Disputes Act, 1947.
- The Occupational Safety, Health and Working Conditions Code, 2020.
- Malik v. Bank of Credit and Commerce International SA, [1997] UKHL 23; [1998] AC 20.
- Johnson v. Unisys Ltd, [2001] UKHL 13; [2003] 1 AC 518.
- Bărbulescu v. Romania, App. No. 61496/08, Grand Chamber, ECtHR (5 September 2017).
- Halford v. United Kingdom, (1997) 24 EHRR 523.
- Copland v. United Kingdom, (2007) 45 EHRR 37.
- European Union, General Data Protection Regulation (Regulation (EU) 2016/679), art. 88.
- Directive (EU) 2024/2831 of the European Parliament and of the Council on improving working conditions in platform work.
- UK Information Commissioner’s Office, “Employment Practices and Data Protection: Monitoring Workers” (3 October 2023).
- UK Information Commissioner’s Office, “Employment Practices Code” (2011).
- Data Protection Act 2018 (UK).
- Fairwork India, Annual Ratings Reports on Platform Work in India.
- Ministry of Labour and Employment, Government of India, e-Shram Portal Documentation.
- The Rajasthan Platform Based Gig Workers (Registration and Welfare) Act, 2023.
- The Karnataka Platform-Based Gig Workers (Social Security and Welfare) Bill, 2025.

