Can my employer monitor my emails, calls and location under Indian data protection law?

My office has started monitoring employee emails, laptop activity and location through an app, and I want to know what limits the law places on this kind of workplace surveillance. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

Can my employer monitor my emails, calls and location under Indian data protection law? is governed in India primarily by Digital Personal Data Protection Act 2023, Section 4, Digital Personal Data Protection Act 2023, Section 6 and Information Technology Act 2000, Section 43A. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Under Section 4 of the Digital Personal Data Protection Act 2023, an employer processing an employee's personal data, including emails, location or device activity, must have a lawful basis, which is ordinarily either the employee's consent or a specified legitimate use permitted under the Act.

Section 6 requires that consent for processing personal data be free, specific, informed and unambiguous, so surveillance introduced through a vague policy buried in an employee handbook may not satisfy the standard required for valid consent.

Employer-owned devices and email accounts issued for official work are generally treated as company property, giving the employer a stronger legitimate basis to monitor their use for security and productivity, compared to monitoring personal devices or personal communications.

Excessive or covert surveillance, such as tracking an employee's personal location outside working hours or accessing personal social media, exceeds the purpose limitation principle and can be challenged as unlawful processing of personal data.

Where sensitive personal data is compromised due to inadequate security practices around such monitoring systems, an employee can also raise a grievance under Section 43A of the Information Technology Act for failure to maintain reasonable security practices.

What to do next: 1) Request a copy of the written surveillance or monitoring policy from HR; 2) Check whether consent was obtained specifically for the monitoring being carried out; 3) Object in writing if monitoring extends to personal devices or non-working hours; 4) File a grievance with the employer's data protection officer or approach the Data Protection Board if unresolved.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Digital Personal Data Protection Act 2023, Section 4 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.