India's DPDP Act permits employee monitoring — Section 7 treats employment-related processing as a "legitimate use," so you generally don't need separate consent. But you remain a Data Fiduciary with real duties: purpose limitation, data minimisation, security safeguards, breach notification and employee rights. The DPDP Rules 2025 were notified on 13 November 2025, with full compliance due by 13 May 2027.
That deadline is the thing most Indian employers are underestimating. If you monitor staff and haven't mapped what you collect, why, and for how long, you have roughly ten months to close the gap.
The timeline that matters
| Milestone | Date | What lands |
|---|---|---|
| Rules notified | 13 Nov 2025 | Framework operational; Data Protection Board established |
| +12 months | ~13 Nov 2026 | Consent-manager provisions take effect |
| +18 months | ~13 May 2027 | Full compliance: notice, consent, data-principal rights, grievance redressal |
The 18-month date is the one to plan against. Enforcement posture is expected to shift from awareness-building toward active supervision as the phases complete.
Where employee monitoring sits
The Act's key move for employers is Section 7's "legitimate uses." Employment-related processing is included, which covers purposes connected to employment — including safeguarding the employer from loss or liability and providing services or benefits to employees.
Practically, this means you are not dependent on employee consent to run workplace analytics. That's a meaningful difference from GDPR, where consent in an employment context is generally treated as weak because it can't be freely given, pushing employers toward legitimate interests. Under DPDP you have a cleaner statutory footing — see the GDPR checklist for the contrast if you employ across both regimes.
What legitimate use does not do is remove your other obligations. You still must:
- Limit the purpose. Collect for the employment purpose you identified — not "everything, in case it's useful later."
- Minimise. Only what's necessary for that purpose. This is where screenshot and keystroke capture gets hard to defend for ordinary productivity management.
- Secure it. Reasonable security safeguards are a standalone duty, and the breach penalty is the largest in the Act.
- Retain no longer than needed. Define a window and actually delete.
- Honour rights. Access, correction, erasure and grievance redressal.
Your duties as a Data Fiduciary
An employer determining the purpose and means of processing employee data is a Data Fiduciary, and employees are Data Principals. That relationship carries concrete work:
- Map what you collect. Every monitoring tool, every field. Most organisations discover they're collecting more than anyone can justify.
- Write the notice. Clear, plain-language, itemised. Our monitoring policy template covers the required ground.
- Appoint a grievance route. A named contact and a working process for employee complaints — this is explicitly required.
- Set retention and enforce it. Automated deletion beats a policy nobody runs.
- Prepare for breach notification. Know who reports, to whom, in what window.
- Check Significant Data Fiduciary status. Larger-volume or higher-risk processors face additional duties including a Data Protection Officer in India and periodic audits.
What this means for tool choice
Three questions to put to any vendor before you buy in India:
- What exactly is collected, field by field? If they can't produce a list, you can't write your notice.
- Where does the data reside, and what are the retention controls? You need configurable deletion, not "we keep it indefinitely."
- Can employees see their own data? Not strictly mandated, but it makes access requests trivial and demonstrates good faith to the Board.
Heavier collection models — keystroke logging, OCR, continuous recording — are not prohibited, but they raise your minimisation burden sharply and are hard to justify for ordinary productivity purposes. The collection-model breakdown and the UAM guide cover when the heavier tiers are genuinely warranted.
A ten-month plan
- Now: inventory every monitoring tool and data field. Delete what you can't justify.
- Next 60 days: publish the employee notice and stand up the grievance route.
- By end of 2026: retention automation live; breach-response runbook tested.
- Before May 2027: access/correction/erasure request handling working end to end, with evidence you can show.
For the wider Indian buying picture — INR pricing, native Linux, DPDP posture per vendor — see the India monitoring software comparison. BPO and call-centre operators have extra client-audit obligations covered in the BPO monitoring guide.
Where ProdView fits
ProdView is India-registered with INR billing, and built around minimisation: activity and app metadata only, never screen content, no keystroke logging, screenshots optional and off by default, configurable retention, and every employee sees the same dashboard their manager does. That makes the notice short, the access requests easy, and the breach surface small. SOC 2 Type II, ₹399/user/month, free for 3 seats.
When not to pick us: a regulatory or client mandate genuinely requires session recording or DLP — then you need a heavier tool and a correspondingly heavier compliance programme.
Try before you commit
Map your data first, then pick the tool that lets you keep the notice honest. Three seats are free forever — or model the payback with the ROI calculator.
Sources
- Digital Personal Data Protection Rules, 2025
- India's DPDP compliance timeline 2026–27 — India Briefing
- Data protection laws in India — DLA Piper
Reflects the position as of July 2026. The DPDP framework is phasing in — verify current requirements and dates with Indian counsel before acting.