Abstract
The Digital Personal Data Protection Act, 2023 (DPDP Act), along with the Digital Personal Data Protection Rules, 2025 came into an effect on November 13, 2025. As per the Constitution of India, Article 21 state that, every individual has an inviolable Right to Privacy, which is also applies to a corporate workplace as well. Balancing employer’s reasonable concerns with the privacy of the employee necessitates protecting the personal data and workspace of the employee and at the same time accomplishing the organizational objectives using fair and proportionate workplace practices. For understand this term more clearly we can take the case of Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) as an analytical reference point, this article examines the concept of informational privacy within corporate workplaces.
In the modern digital economy, AI has plays a very important role in efficient business management but unchecked adoption of AI is likely to undermine data protection principles and employee privacy. This article examines the technical and managerial requirements that may be needed to reconcile these conflicting interests. By means of a comparative study of the Indian DPDP Act in relation to the GDPR of the European Union and judicial precedent such as Bärbulescu v. Romania (2017), this article seeks to examine the rights of Indian and European workers.
Keywords: Workplace Surveillance, Employee Privacy, Digital Personal Data Protection Act 2023, Monitoring of Employees, Data Protection, Artificial Intelligence.
I. Introduction
The implementation of the Digital Personal Data Protection Act, 2023 in India is a life changing event for regulatory world of the nation. India’s Digital Personal Data Protection Act, 2023 is an Independent Act which is enforced by Central Government of India and administers and implement the provision by The Ministry of Electronics and Information Technology (MeitY) by using the Digital Personal Data Protection Rules, 2025.
This stand-alone regulatory mechanism is responsible for overseeing the process of collection and protection of digital personal data in all corporate entities. In today’s time every organization use sophisticated means of surveillance such as:
- Closed Circuit Television (CCTV) cameras in the corporate premises;
- GPS trackers on corporate transportation;
- Biometric attendance devices;
- Advanced AI tools for the purposes of performance assessment and productivity scoring in real time;
- Mechanism use to monitor and control the employees.
But whether it is violating the employee’s rights or not is not considered by anyone. These technological advancements may be used for scaling up business activities and managing risks associated with running enterprises, but the possibility of violation of the constitutional rights remains largely ignored in traditional corporate systems.
To curb the issue of excessive institutional monitoring, the DPDP Act sets out clear limitations of processing that defines the employer as “Data Fiduciary” and the employee as “Data Principal.” Importantly, Clause 7(i) of the DPDP Act states an exception of specific consent which allows the processing of personal data without consent if the processing is necessary for the purposes of employment and protecting the employer from certain liabilities arising out of the enterprise.
This article presents a full doctrinal analysis of the statutory exception in Clause 7(i), identifies current forms of workplace surveillance, describes the expansion of surveillance boundaries in the context of remote working, ensures privacy outside of working hours, and considers the position of the Data Protection Board of India (DPBI).
II. Research Questions
- Q 1: At what point does the concept of a “workplace boundary” comes to an end while performing tasks at home as an employee?
- Q 2: Where Section 7(i) empowers the employer to ignore employee consent regarding the processing of employee data for “employment purposes,” what are the safeguards that will protect an employer from misusing this discretion?
- Q 3: Is the data used by AI for performance review considered Personal Data?
- Q 4: Whose responsibility is it to ascertain that surveillance practice is “proportional”? Is it up to the employer, the employee, or the judge after the legal action has been launched?
- Q 5: Where individual use his personal phone for office communication through WhatsApp / Instagram; will the employer have the right to monitor his personal device under Section 7(i)?
- Q 6: Is it ever really possible for the employee to feel “comfortable” and “safe” in a workplace as they know that they are constantly being watched?
- Q 7: Does providing privacy to employees and ensuring the protection of their privacy aid organizations in meeting their objectives quickly?
III. Research Methodology And Outcomes
In this study, the method of doctrinal and comparative legal research is applied on the basis of the constitutional principle of proportionality as a basic evaluative frame of reference. The study uses the four-part test for assessing proportionality as set out by the Supreme Court of India in the landmark case of Justice K.S. Puttaswamy (Retd.) v. Union of India. The four parts to be evaluated are:
- Legality: There is a legal basis for processing personal data (personal information).
- Legitimate Objective: It is necessary to achieve an important purpose for the organization.
- Proportionality: There should be a rational connection between the means of collecting the data and the objective sought to be met without any less restrictive alternatives available.
- Safeguards: The presence of systematic safeguards against arbitrary exercise of power.
In order to assess the limit of workplace privacy, the above framework is compared against the workplace surveillance law from around the world with special attention being paid to the judgment by European Court of Human Rights in Bärbulescu v. Romania, together with the comparative study of Indian DPDP Act and GDPR in Europe. The findings from this analysis show that, although employers are afforded more freedom under domestic laws, there is no escape for global standards without compliance with the data minimization standard.
III (i). Rights Of Indian Worker Under DPDP Act And European Worker Under GDPR
Rights Of Indian Worker Under DPDP Act
- Right to access information
- Right to correct and erasure
- Right to grievance redressal
- Right to nominate
- Have certain protection concerning consent and lawful processing
- Protection against unlawful processing subject to the Act
Rights Of European Worker Under GDPR
- Right to have detailed information
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction
- Right to data portability
- Right to object
- Protection against certain solely automated decisions
- Human intervention safeguards in specified automated decision cases
- Stronger rules concerning special categories of personal data
- Access to independent supervisory authorities
Comparison Of Worker’s Right DPDP Act And GDPR Act
| No. | Right / Protection | Rights Of Indian Worker Under DPDP Act | Rights Of European Worker Under GDPR |
|---|---|---|---|
| 1 | Status Of Worker | Data principal | Data subject |
| 2 | Right To Information | Access to personal data under Section 11 | Strong transparency required under Article 12 – 14 |
| 3 | Right To Access | Access to personal data and its processing under Section 11 | Detail right of access of personal data & its processing information under Article 15 |
| 4 | Correction / Rectification | Has right to correction of personal data under Section 12 | Right to rectification under Article 16 |
| 5 | Erasure / Right To Be Forgotten | Right to erasure, subject to the statutory framework under Sec.12 | Right to be forgotten provided under Article 17 |
| 6 | Restriction Of Processing | No right related to this term | Right of restriction of processing given under Article 18 |
| 7 | Data Portability | No right related to this term | Right of data portability is given under Article 20 |
| 8 | Right To Object | No right related to this term | Right to object is specified under Article 21 |
| 9 | Automated Decision Making | No right related to this term | Safeguard against solely automated decision making under Article 22 |
| 10 | Human Intervention | No right related to this term | In certain situation this right is provided to workers |
| 11 | Grievance Redressal | Right specified in Section 13 | Complaint to Superior authority |
| 12 | Consent | Consent is legal but DPDP Act also recognize certain legitimate uses | GDPR has legal obligation, lawful interest, consent, etc. |
| 13 | Employee Monitoring | Certain obligation is covered in it | Must comply with certain principles like; transparency, lawfulness, fairness, etc. |
| 14 | Sensitive / Special Data | No right related to this term | Give protection for special categories of personal data under Article 9 |
| 15 | Data Protection Officer | Certain obligations apply to significant data fiduciaries | Data protection officer required under Article 37 |
| 16 | International Transfers | Govt. restrictions applicable and this clause fall under Section 16 | For international transfer go through Chapter-V of GDPR |
| 17 | Regulatory Authority | Data Protection Board of India | Data Protection Authorities |
| 18 | Nomination After Death / Incapacity | Right specified in Section 14 | No directly equivalent general GDPR right |
| 19 | Penalties | Financial penalties | Potential admin fines up to €20 million / 4% of worldwide annual turnover, depends on violation |
III (ii). Comparative Legal Frameworks: Case Law And Global Statutes
A contrast of domestic laws with international standards has shown that there exist significant differences between how employee rights are protected:
- Justice K.S. Puttaswamy (Retd.) v. Union of India (2017): In this landmark Indian decision, it was determined that Right to Privacy was an intrinsic part of the Right to Life and Personal Liberty provided by Article 21 of the constitution of India. Here, informational privacy has been identified as a basic right which shall require strict adherence to the three-fold test of legality, legitimate aim, and strict proportionality whenever a state or even private entity violates it.
- Bärbulescu v. Romania (2017): The European Court of Human Rights (ECtHR) set out specific limitations as to the monitoring of employees’ electronic communication at the workplace. A company cannot pursue its legitimate interests by compelling an employee to provide a guarantee that he will perform his duties, however, the professional communication of an employee cannot be reduced to zero privacy. An employer should notify an employee clearly before any form of surveillance and should prove that there is a specific interest for such kind of monitoring and that it will not violate an employee’s private life.
- Differences Between Indian DPDP Act & EU GDPR: The main difference between the two regulatory frameworks is in regard to the processing of data without obtaining any consent. According to EU GDPR, processing of data of employees would mean a strict compliance with Article 6(1)(f) (“legitimate interests”), or domestic laws for workers under Article 88, which often state that surveillance must be the “least intrusive means” available. In contrast to it, Section 7(i) of the Indian DPDP Act establishes an explicit statutory exception for “purposes of employment,” thereby simplifying the process for collecting data by Indian companies, yet increasing the responsibility of DPBI for interpretation of this structure.
III (iii). Workplace Surveillance: Meaning And Forms
Workplace surveillance refers broadly to systematic observation, recording, tracking or analysis of employee activities for organizational, managerial, security or disciplinary purposes.
Common Forms Of Workplace Surveillance
- CCTV surveillance
- Biometric attendance
- GPS monitoring
- Email and communication monitoring
- Productivity monitoring
- AI-based monitoring
III (iv). Artificial Intelligence’s Implementation In Organisation
AI System May Use In Different Things Like
- Increase-productivity
- Performance quality
- Workplace behavior
- Employees engagement in any work
- Increase people engagement ratio
- Strengthen communication pattern and prevent misconduct of risk etc.
Workplace related factors. But use of AI in organization raise privacy related concerns like; transparency, accuracy, human review etc.
III (v). Remote Work And The Expansion Of The Workplace
Remote work complicates the concept of workplace boundaries because when an employee works from home, the employer may have legal right to know whether work is being performed or not. However, the home is simultaneously a private living environment.
Many Situations State The Difficulties About This Topic Like
- Camera monitoring
- Location monitoring
- Personal devices
- Family privacy, etc.
III (vi). Employee Privacy After Working Hours
The issue of after working hours monitoring is particularly significant where employees carry employer issued smart phones or vehicles.
A Privacy-Sensitive Framework Should Therefore Consider
- Time-based restrictions
- Purpose-based restrictions
- Location-based restrictions
- Emergency exceptions
- Separate personal profiles
- Technical separation of corporate and private information
III (vii). The Role Of The Data Protection Board
The DPDP Act, 2025 has given the provisions to establishment of the Data Protection Board of India (DPBI) as a statutory regulatory institution.
DPBI Possible Area Of Regulatory Attention To
- Excessive collection;
- Inadequate security;
- Inappropriate retention;
- Unauthorized disclosure;
- Misleading privacy notices;
- Inappropriate use of employee data;
- Systematic profiling;
- Inadequate safeguards for automated processing.
IV. Discussion: Analytical Resolution Of Core Privacy Issues
Q 1: At What Point Does The Concept Of A “Workplace Boundary” Comes To An End While Performing Tasks At Home As An Employee?
Answer: The concept of workplace boundary changes in terms of technological means of executing work. In the case of remote performance of tasks at home, the employer’s right to process data according to Article 7(i) is limited solely to professional performance of tasks and company property. Webcams constantly transmitting images, domestic sound recording, or monitoring internet usage through the same internet connection violates the principle of data minimization. Workplace boundary ends when professional performance of tasks ceases.
Q 2: Where Section 7(i) Empowers The Employer To Ignore Employee Consent Regarding The Processing Of Employee Data For “Employment Purposes,” What Are The Safeguards That Will Protect An Employer From Misusing This Discretion?
Answer: Processing Personal Data under Section 7(i) is not subject to absolute discretion, and it remains the responsibility of the Data Fiduciary under the same conditions as other processing activities. Employers are obliged by law to take all reasonable measures to protect the data from being misused, provide detailed instructions on the processing of the data, and destroy the data once the purpose of processing has been achieved.
Q 3: Is The Data Used By AI For Performance Review Considered Personal Data?
Answer: Yes. According to the DPDP Act, personal data means any information from which an individual can be identified or can be related to him/her. The AI systems that collect biometric data logs, typing speed, facial expression on call, and digitized tracking data are used to identify the particular individual. Therefore, all the telemetry generated from AI-based performance systems is considered personal data, hence subjecting the company to stringent requirements of data protection, accuracy, and retention.
Q 4: Whose Responsibility Is It To Ascertain That Surveillance Practice Is “Proportional”? Is It Up To The Employer, The Employee, Or The Judge After The Legal Action Has Been Launched?
Answer: First of all, it should be performed by the employer with the help of formal DPIA procedures prior to implementing the technology into practice. At the same time, the final binding decision on proportionality lies within the competence of the Data Protection Board of India (DPBI) in regulatory processes, as well as TDSAT and courts when the legal action has been taken.
Q 5: Where Individual Use His Personal Phone For Office Communication Through WhatsApp / Instagram; Will The Employer Have The Right To Monitor His Personal Device Under Section 7(i)?
Answer: Not at all. According to Section 7(i), monitoring is only allowed for “purposes of employment,” and this is certainly not something that authorizes an employer to intercept a physical personal property of the individual. Although it is perfectly legal for an employer to monitor enterprise-level software or sandboxed software installed in a personal device via a BYOD arrangement, he/she does not have any legal authority for the purpose of accessing private communications or local storage arrays.
Q 6: Is It Ever Really Possible For The Employee To Feel “Comfortable” And “Safe” In A Workplace As They Know That They Are Constantly Being Watched?
Answer: The security practices can provide safety to both parties and can provide transparency in operations as well, provided that the practices are taken out of the context of surveillance and are made more accountable. The security infrastructure will need to be restricted to providing passive and objective security such as using biometrics to secure entrance perimeter or recording server log-ins and log-outs. When the employees are made aware of the scope of their surveillance and limits of data utilization, this creates a transparency of operation.
Q 7: Does Providing Privacy To Employees And Ensuring The Protection Of Their Privacy Aid Organizations In Meeting Their Objectives Quickly?
Answer: Yes. Workers’ privacy has a relationship with the organization’s optimum performance in the long run. The surveillance structures that are utilized by organizations lead to demotivation, low retention, and even burnout in the institutional setup. By giving privacy to the workers, the organization will gain the trust within the institution. This will avoid the liability and DPDP penalties and enhance efficiency.
V. Recommendations
Different recommendations are provided for Indian organizations to implementing workplace surveillance likes;
- Adopt a Workplace Surveillance Policy
- Conduct a Proportionality Assessment
- Separate Work and Personal Data
- Restrict Monitoring after Working Hours
- Establish Human Monitoring for AI
- Give Employee Notice
- Limit Data Retention
- Establish Grievance Procedures
Develop Sector-Specific Standards and Conduct Time-to-time Reviews, etc.
Conclusion
The Digital Personal Data Protection Act of 2023, together with the gradual implementation of the DPDP Rules of 2025 to enforcement, requires that there be a thorough revision in the monitoring policies of corporations in India. It was clarified in the Supreme Court’s Puttaswamy ruling that the Right to Privacy in accordance with Article 21 continues to exist even when dealing with professionals.
Although Section 7(i) enables the employer to use the simplest way to process personal data for the purposes of ensuring security and managing employment, it should not serve as an instrument to legalize the constant monitoring of workers. The successful development of corporations cannot be accomplished through constant digital monitoring but through establishing systems that are based on the principle of human dignity. If workers / employees of the organization are happy then organization’s growth is surely done.
References
- Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).
- Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, S.R.(E) (notified Nov. 13, 2025) (India).
- Digital Personal Data Protection Act, 2023, § 7(i), No. 22, Acts of Parliament, 2023 (India).
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 S.C.C. 1 (India).
- Bärbulescu v. Romania, App. No. 61496/08, Eur. Ct. H.R. (2017).
- Constitution of India, Article 21.
- European General Data Protection Regulation (GDPR).

