Tata Consultancy Services (TCS), one of India’s largest IT services companies, has reportedly deployed a Digital User Experience Monitoring tool on laptops issued to its employees, potentially giving the company unprecedented visibility into how its workforce uses corporate devices. Reportedly, the software can provide information about which applications employees use and how much time they spend on them. With TCS employing nearly 600,000 people, the scale of the reported deployment makes the development significant and raises questions about where legitimate cybersecurity monitoring ends and workplace surveillance begins.
A legitimate cybersecurity purpose, but unclear boundaries
There is a legitimate business case for monitoring corporate devices. TCS handles sensitive information belonging to banks, financial institutions, healthcare companies, governments and multinational corporations. Endpoint monitoring can help identify malware, detect unusual activity, investigate security incidents and prevent confidential information from being transferred outside corporate systems. The company therefore has a clear interest in ensuring that devices issued to employees are not being misused or compromised.
The problem, however, begins when monitoring a device starts becoming a means of monitoring the person using it. Knowing that a corporate laptop is running a particular application can be useful for IT troubleshooting or cybersecurity. Knowing precisely how long an individual employee spends on different applications, when the employee switches between them and how frequently the system registers inactivity creates a much more detailed picture of that employee’s behaviour. Such information can potentially become a behavioural profile rather than merely a security log.
Why the lack of transparency matters
That distinction is particularly important because TCS has not publicly explained the precise scope of the reported deployment. The identity of the software provider, the categories of information being collected, the length of time for which the information will be retained and the people or teams authorised to access it have not been publicly established. It is also unclear whether the information is being collected purely for cybersecurity and digital-experience purposes or whether it could eventually be used by managers or HR teams to assess individual employees.
This lack of clarity is what makes the development particularly sensitive. Employee monitoring does not necessarily become problematic simply because a company-owned laptop is being monitored. A company can reasonably expect to have significant control over its own devices and networks. But hardware ownership should not become a blanket justification for collecting every piece of behavioural information that technology makes available. The important questions are why the information is collected, whether it is necessary for that purpose, who can access it and whether it can subsequently be used for a different purpose.
How monitoring could be weaponised against employees
The potential for such technology to be weaponised against employees is perhaps the biggest concern. Application usage and periods of inactivity may look objective because they are generated by software, but they do not necessarily provide an accurate picture of productivity. An employee could spend an hour reading technical documentation, attending a meeting, speaking to a client on the telephone or thinking through a complicated programming problem while generating very little measurable computer activity. A system that sees inactivity may record a period of low activity; it cannot necessarily understand what the employee was actually doing.
If managers begin treating such data as a proxy for productivity, the consequences could be significant. A worker who spends relatively little time on a particular corporate application could be perceived as underperforming even if their work is being completed efficiently. Long periods of inactivity could be interpreted as unauthorised breaks. Frequent browser activity could be treated as evidence of non-work-related browsing even when the employee is researching a technical problem. Over time, such information could potentially influence appraisals, promotions, project allocation, performance-improvement plans or even disciplinary proceedings.
This creates the possibility of turning workplace monitoring into a digital version of presenteeism. Instead of employees being judged by the quality and outcome of their work, they could increasingly feel compelled to maintain visible computer activity simply because the system is watching. The workplace incentive then changes from producing results to appearing active.
Could it turn productivity into surveillance?
That concern is particularly relevant in India’s IT sector, where long working hours and constant availability have already become subjects of intense debate. The material reviewed for this article includes employees describing workplaces where leaving on time could be interpreted as a lack of commitment and where there was greater pressure to appear busy than simply deliver results. One employee described a culture in which “performance” could become synonymous with visible activity rather than actual work.
Research cited in the same material also raises concerns about treating longer working hours as synonymous with greater productivity. A WHO/ILO study estimated that hundreds of millions of people worldwide were working 55 hours or more per week and associated such exposure with an increased risk of ischaemic heart disease and stroke. Another study of Indian bank employees found an association between longer working hours and higher levels of burnout and stress. The lesson is not that every additional hour is inherently harmful, but that organisations should be cautious about creating systems that reward visible activity rather than sustainable productivity.
The privacy question under India’s data-protection framework
There is also a genuine privacy question. India’s Digital Personal Data Protection Act recognises certain employment-related purposes for processing personal data, including protecting employers from losses and liability and preventing corporate espionage or protecting intellectual property. That means employee monitoring is not automatically unlawful. But the existence of a legitimate employment purpose does not answer the larger question of proportionality. A company that needs endpoint telemetry to prevent data theft does not automatically need an unlimited behavioural history of every employee.
The scale of TCS’s workforce makes this even more consequential. Monitoring hundreds of thousands of employees can generate an enormous dataset containing application usage patterns, device activity and potentially other information depending on how the software is configured. Individually, these data points may appear innocuous. Aggregated over months or years, however, they can reveal detailed patterns about how particular employees work. The larger the dataset, the greater the importance of access controls, retention limits and safeguards against misuse.
The 600,000-employee data problem
There is another complication involving client-owned virtual desktop infrastructure. Many IT employees work through client environments, meaning that the boundary between an employee’s TCS device and a client’s systems can become complicated. If monitoring extends into virtual environments, the system could potentially encounter information belonging to TCS clients as well. A security tool intended to prevent data leakage must therefore itself be designed carefully enough to ensure that it does not unnecessarily collect or centralise sensitive information.
What happens when employees work on client systems?
TCS is also not the first Indian IT major to face questions around employee monitoring. Cognizant previously faced scrutiny over its use of ProHance, a workforce-management platform capable of recording login times, application and website usage and periods of inactivity. The company said the tool was used only on specific projects at client request and was intended to understand processes and identify inefficiencies rather than evaluate individual employee performance. That distinction is critical: analysing how a process works is fundamentally different from building a behavioural profile of the person performing it.
Cognizant and Infosys offer cautionary precedents
The experience of Infosys in France provides another useful comparison. French labour authorities examined how Infosys recorded working hours for certain employees and found shortcomings in the reliability and auditability of those records. Infosys was fined because its system for recording employee working hours failed to meet local legal standards for reliability, auditability, and monitoring for certain staff categories.
The larger issue was not simply whether employees were being monitored, but whether the employer could reliably demonstrate what hours employees had actually worked. European jurisdictions generally impose significantly stronger restrictions and safeguards around employee monitoring than India, making the French example a reminder that workplace surveillance is not merely an internal corporate matter.
TCS therefore needs to answer some basic questions about the reported deployment. Employees should know what information the software collects, whether that information is tied to individual identities, how long it is retained and who can access it. Most importantly, the company should clarify whether the data can be used for performance evaluation, attendance monitoring or disciplinary action. If the purpose is cybersecurity, employees should not later discover that information collected for security has quietly become a productivity-monitoring system.
What TCS should clarify
There is nothing inherently wrong with TCS monitoring its corporate infrastructure. A company responsible for sensitive client data must have strong cybersecurity controls. But security cannot become a blank cheque for collecting employee information. The principle should be simple: collect what is necessary to secure the system, not everything that technology makes technically possible to collect.
The real issue, therefore, is not simply whether TCS is watching its employees. It is whether employees know what is being watched, why it is being watched, who is watching it and what conclusions can be drawn from it. Until TCS provides clarity on those questions, the reported deployment of monitoring software across a workforce approaching 600,000 people will inevitably raise concerns that a tool introduced in the name of digital security could evolve into a powerful system of workplace surveillance.
