Privacy concerns in surveillance.
Privacy Concerns in Surveillance
Privacy concerns in surveillance arise when an employer, government authority, platform, or other organisation collects, monitors, records, analyses, or shares information about individuals or their activities. In employment law, surveillance can include CCTV, email monitoring, internet monitoring, GPS/location tracking, biometric attendance, device monitoring, call recording, productivity tracking, facial recognition, and monitoring of employees working remotely.
In India, the constitutional foundation of privacy is Article 21, read with the guarantees of dignity, liberty and, in appropriate circumstances, equality under Article 14. For private employment, contractual obligations, labour legislation, the Information Technology Act framework, applicable data-protection law, and common-law principles may additionally become relevant.
1. Meaning of Surveillance
Surveillance involves systematic observation or collection of information about a person.
Examples include:
- CCTV monitoring;
- employee attendance systems;
- biometric identification;
- facial-recognition systems;
- GPS tracking of company vehicles;
- monitoring company laptops;
- recording emails;
- monitoring browsing history;
- recording telephone calls;
- keystroke monitoring;
- screenshots;
- location tracking;
- monitoring social-media activity;
- remote-work productivity software;
- automated behavioural profiling.
The legal question is not simply whether surveillance exists, but whether the surveillance is lawful, necessary, proportionate, transparent and appropriately limited.
2. Constitutional Right to Privacy
The most important Indian constitutional authority is:
K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1
A nine-judge Constitution Bench unanimously recognised privacy as a constitutionally protected right arising primarily from Article 21 and the broader guarantees of Part III of the Constitution.
The Court rejected the proposition that privacy is merely a common-law or statutory right.
The judgment recognised several dimensions of privacy, including:
- bodily privacy;
- informational privacy;
- decisional autonomy;
- protection of personal information;
- dignity and individual liberty.
Importance for surveillance
Surveillance that collects personal information potentially interferes with informational privacy.
However, the existence of a privacy interest does not mean that all surveillance is automatically unconstitutional. The legality of a particular surveillance measure depends upon its purpose, legal basis, extent and safeguards.
3. The Proportionality Requirement
Indian privacy jurisprudence generally requires restrictions on fundamental privacy interests to satisfy constitutional standards.
The principal considerations include:
1. Legality
There should be a valid legal basis for the interference.
2. Legitimate State or institutional objective
The surveillance must pursue a legitimate objective.
Examples:
- national security;
- crime prevention;
- workplace safety;
- protection of confidential information;
- prevention of fraud;
- investigation of misconduct.
3. Necessity
The surveillance should have a rational connection with the legitimate objective.
4. Proportionality
The method should not unnecessarily intrude into privacy when a less intrusive alternative could achieve substantially the same objective.
This is particularly important for workplace surveillance.
4. Six Important Case Laws
1. K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1
This is the foundational Indian privacy judgment.
The Supreme Court held that privacy is a fundamental right protected by the Constitution.
The judgment recognised that privacy encompasses protection against inappropriate interference with a person's:
- personal autonomy;
- dignity;
- bodily integrity;
- personal information;
- choices and relationships.
Relevance to surveillance
Surveillance involves collecting information about a person's behaviour or activities.
Therefore, systems such as:
- facial recognition;
- GPS tracking;
- biometric databases;
- electronic communications monitoring;
- extensive employee profiling
can implicate informational privacy.
Principle
Privacy is a constitutionally protected right, and surveillance that interferes with privacy must satisfy constitutional requirements.
5. People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301
This case concerned telephone tapping.
The Supreme Court recognised that telephone conversations are an important aspect of an individual's privacy and that telephone tapping constitutes an invasion of privacy.
The Court laid down procedural safeguards concerning telephone interception.
These included requirements relating to:
- authorisation;
- necessity;
- duration;
- review;
- record keeping;
- destruction of intercepted material.
Relevance to surveillance
The case established an important principle:
Surveillance powers cannot be exercised without procedural safeguards.
This principle has broader relevance to modern surveillance technologies such as:
- call recording;
- electronic communications monitoring;
- interception;
- digital communications surveillance.
Principle
Even where surveillance serves a legitimate governmental objective, procedural safeguards are necessary to prevent arbitrary intrusion.
6. Selvi v. State of Karnataka, (2010) 7 SCC 263
The Supreme Court considered the legality of involuntary:
- narco-analysis;
- polygraph examinations;
- Brain Electrical Activation Profile tests.
The Court emphasised individual autonomy, mental privacy and protection against involuntary intrusion into a person's mind.
Relevance to surveillance
Modern surveillance increasingly involves not merely observing conduct but analysing behaviour.
Examples include:
- emotion recognition;
- behavioural profiling;
- AI-based employee monitoring;
- predictive analytics;
- psychological profiling.
The reasoning in Selvi demonstrates that privacy can extend beyond physical spaces to mental autonomy and personal decision-making.
Principle
Technological capacity to obtain information does not itself establish legal authority to obtain it without respecting autonomy and constitutional protections.
7. K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar), (2018) 1 SCC 809
The Supreme Court considered the constitutional validity of the Aadhaar framework.
The judgment examined extensive collection and processing of personal and biometric information.
The Court considered:
- purpose limitation;
- data security;
- proportionality;
- informational privacy;
- authentication;
- potential misuse of personal data.
Relevance to surveillance
Biometric systems create particular privacy concerns because biometric information is intrinsically connected to the individual.
Examples include:
- fingerprints;
- iris scans;
- facial recognition;
- voice recognition.
Unlike a password, biometric characteristics generally cannot simply be replaced after compromise.
Principle
Large-scale collection and processing of personal information require safeguards against misuse, excessive collection and disproportionate interference with privacy.
8. Anuradha Bhasin v. Union of India, (2020) 3 SCC 637
The Supreme Court considered restrictions on internet access in Jammu and Kashmir.
The Court recognised the importance of the internet in exercising constitutional freedoms and examined restrictions through the principle of proportionality.
The judgment required restrictions to satisfy standards concerning:
- legality;
- necessity;
- proportionality;
- publication and review of orders.
Relevance to surveillance
Digital surveillance frequently operates through restrictions or monitoring of communications infrastructure.
The case is therefore important for understanding how constitutional rights apply in the digital environment.
Principle
Technological measures affecting digital communications must remain subject to constitutional standards of legality and proportionality.
9. Vinit Kumar v. Central Bureau of Investigation, 2019 SCC OnLine Bom 3151
The Bombay High Court dealt with interception of telephone conversations and examined the statutory safeguards governing interception.
The Court emphasised the importance of compliance with the legal framework governing interception and considered the consequences of interception carried out without proper legal authority.
Relevance
The case demonstrates that unauthorised interception cannot be justified merely because the information obtained may be useful.
This principle is particularly relevant where surveillance evidence is subsequently sought to be used in:
- disciplinary proceedings;
- criminal proceedings;
- employment disputes;
- regulatory investigations.
Principle
Evidence obtained through legally defective interception can face serious judicial scrutiny.
10. R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632
This is another foundational Indian privacy case.
The Supreme Court recognised the individual's right to privacy and considered publication of information concerning a person's private life.
The Court distinguished between information legitimately available from public records and genuinely private information.
Relevance to surveillance
Surveillance frequently produces information that is not ordinarily public.
For example:
- employee movements;
- private communications;
- personal relationships;
- medical information;
- private photographs;
- personal browsing activity.
The fact that an organisation possesses such information does not necessarily mean that it has unlimited authority to disclose or use it.
Principle
Possession of personal information does not eliminate the individual's privacy interest in that information.
11. Workplace Surveillance
Workplace surveillance creates a particularly difficult balance.
An employer may have legitimate reasons to monitor employees.
For example:
Security
Monitoring may protect:
- employees;
- customers;
- premises;
- confidential information.
Fraud prevention
Financial institutions may need monitoring systems to identify:
- unauthorised transactions;
- unusual access;
- insider misconduct.
Productivity
An employer may legitimately monitor certain aspects of work performance.
Compliance
Regulated organisations may have statutory obligations to maintain records or monitor particular activities.
However, legitimate business interests do not automatically justify unlimited employee surveillance.
12. Excessive Employee Surveillance
Examples of potentially excessive surveillance include:
- recording employees continuously without a clear purpose;
- monitoring personal devices without adequate legal basis;
- tracking employees outside working hours;
- monitoring private communications;
- collecting biometric data unnecessarily;
- retaining surveillance data indefinitely;
- monitoring family members or visitors;
- using facial recognition without adequate safeguards;
- analysing employees' emotions without a clearly defined necessity;
- monitoring remote employees continuously through webcams.
The greater the intrusion, the stronger the justification and safeguards ordinarily required.
13. CCTV Surveillance
CCTV is one of the most common forms of workplace surveillance.
CCTV can be legitimate for:
- security;
- prevention of theft;
- workplace safety;
- investigation of incidents.
However, cameras should not ordinarily be placed in locations where individuals have an especially strong expectation of privacy.
Particular caution is required concerning:
- bathrooms;
- changing rooms;
- rest areas;
- private medical areas.
The employer should also consider:
- purpose;
- notice;
- access controls;
- retention period;
- deletion;
- disclosure;
- security.
14. Email and Internet Monitoring
Employers may have legitimate interests in monitoring activity occurring on company systems.
However, an important distinction exists between:
company-system monitoring and unrestricted surveillance of personal communications.
For example, an employer may have stronger justification for monitoring:
- malware;
- data leakage;
- unauthorised downloads;
- corporate email security.
But monitoring an employee's private Gmail account or personal WhatsApp conversations raises substantially greater privacy concerns.
15. GPS and Location Surveillance
GPS tracking can be particularly intrusive.
During working hours, tracking a delivery employee or company vehicle may have an obvious operational purpose.
The privacy issue becomes substantially more complicated if tracking continues:
- after working hours;
- during leave;
- during weekends;
- while the employee is at home.
The employer should therefore consider whether continuous location tracking is actually necessary.
16. Biometric Surveillance
Biometric systems may include:
- fingerprints;
- facial recognition;
- iris recognition;
- voice recognition.
Biometrics raise special concerns because they are closely linked to the individual's identity.
Potential risks include:
- identity theft;
- unauthorised profiling;
- function creep;
- data breaches;
- permanent consequences of biometric compromise.
A company should therefore avoid collecting biometric information merely because the technology is available.
17. Remote-Work Surveillance
Remote work has introduced new forms of monitoring.
Examples include:
- webcam monitoring;
- screenshots;
- keystroke logging;
- mouse movement tracking;
- application monitoring;
- productivity scores;
- periodic screenshots;
- automated activity scoring.
The central legal question is:
Does the monitoring measure work, or does it continuously observe the worker?
A system that measures completed work may be considerably less intrusive than continuous observation of an employee's home environment.
18. AI-Based Surveillance
Artificial intelligence creates additional privacy issues.
An AI system can potentially:
- classify employee behaviour;
- infer productivity;
- identify unusual behaviour;
- recognise faces;
- analyse communications;
- generate risk scores;
- predict employee attrition;
- detect "anomalies."
This creates the possibility of surveillance without meaningful human understanding of how the conclusion was generated.
Important safeguards include:
- purpose limitation;
- data minimisation;
- accuracy;
- human review;
- access controls;
- auditability;
- explainability where appropriate;
- retention limits.
19. Purpose Limitation
Information collected for one purpose should not automatically be repurposed for another unrelated purpose.
For example:
An employer installs CCTV for physical security.
It subsequently uses the footage to create automated employee-performance scores.
That secondary use raises a separate privacy and governance question.
The organisation should ask:
- Why was the information initially collected?
- What is the proposed new purpose?
- Was the new use reasonably foreseeable?
- Is the new use necessary?
- Is additional notice required?
- Is there a less intrusive alternative?
20. Data Minimisation
An organisation should collect only information reasonably necessary for the stated objective.
For example:
If an employer needs to know whether an employee entered a secure facility, it may not need to maintain a detailed minute-by-minute location history for months.
More data does not automatically mean better security or better management.
Excessive collection increases:
- breach risk;
- misuse risk;
- insider-access risk;
- compliance burden;
- employee privacy intrusion.
21. Retention of Surveillance Data
Retention is an often-overlooked issue.
An organisation should establish:
- how long CCTV footage is retained;
- how long GPS data is retained;
- how long employee emails are retained;
- when biometric information is deleted;
- who may access surveillance records.
Keeping information indefinitely creates unnecessary privacy and cybersecurity risks.
22. Employee Notice
A strong workplace surveillance framework should clearly communicate:
- what is monitored;
- why it is monitored;
- when monitoring occurs;
- what data is collected;
- who can access it;
- how long it is retained;
- whether it is shared with third parties;
- how employees can raise concerns.
A vague statement such as "the company may monitor employees at any time" creates substantially greater uncertainty than a specific monitoring policy.
23. Proportionality in Workplace Surveillance
A useful framework is:
| Question | Issue |
|---|---|
| Purpose | Why is surveillance necessary? |
| Legal basis | What law/policy authorises it? |
| Necessity | Is monitoring actually required? |
| Scope | What information is collected? |
| Duration | How long does monitoring continue? |
| Intrusiveness | How deeply does it interfere with privacy? |
| Alternatives | Could a less intrusive method work? |
| Access | Who can see the information? |
| Retention | When is it deleted? |
| Security | How is it protected? |
| Review | Is the system periodically reassessed? |
24. Surveillance Evidence in Disciplinary Proceedings
Suppose an employer obtains:
- CCTV footage;
- email records;
- access logs;
- GPS information;
- computer activity records.
The employer may seek to rely on this material in disciplinary proceedings.
The privacy question and the evidentiary question are related but distinct.
The organisation should examine:
- whether the monitoring was authorised;
- whether the employee received appropriate notice;
- whether the information was lawfully obtained;
- whether the record is authentic;
- whether it has been altered;
- whether relevant procedural safeguards were followed.
A privacy violation does not necessarily answer every question concerning admissibility, but it can significantly affect the legality and reliability of the surveillance process.
25. Employer's Legitimate Interests vs Employee Privacy
The appropriate approach is not:
"Employee privacy always wins."
Nor is it:
"The employer owns the computer, therefore the employer can monitor everything."
The legally significant question is whether the surveillance is justified and proportionate in the circumstances.
For example:
| Surveillance | Potential justification | Privacy concern |
|---|---|---|
| CCTV at entrance | Security | Moderate |
| CCTV in bathroom | Generally difficult to justify | Very high |
| GPS during delivery | Operational management | Moderate |
| GPS 24/7 | Weakens necessity | High |
| Corporate email malware scanning | Cybersecurity | Lower |
| Reading personal emails | Usually much more intrusive | High |
| Fingerprint attendance | Attendance verification | Context dependent |
| Continuous webcam | Productivity/security | High |
| Security logging | Cybersecurity | Context dependent |
| Keystroke surveillance | Productivity/security | Potentially high |
26. Six Core Legal Principles from the Case Law
The cases collectively establish several important principles:
1. Privacy is a fundamental right
K.S. Puttaswamy established the constitutional foundation.
2. Telephone communications have privacy protection
PUCL v. Union of India recognised privacy concerns surrounding interception.
3. Mental autonomy also matters
Selvi demonstrates that intrusive technology cannot be justified solely because it can extract information.
4. Biometric information requires safeguards
The Aadhaar judgment illustrates the constitutional concerns surrounding large-scale biometric information processing.
5. Digital restrictions must satisfy proportionality
Anuradha Bhasin reinforces constitutional scrutiny of measures affecting digital communications.
6. Private information remains protected against unjustified disclosure
R. Rajagopal establishes the importance of the individual's privacy interest in personal information.
27. Practical Compliance Framework for Employers
An employer implementing surveillance should ideally adopt a documented Surveillance and Employee Privacy Policy containing:
- defined surveillance purposes;
- categories of monitored data;
- lawful authority/justification;
- employee notice;
- access restrictions;
- retention periods;
- deletion procedures;
- third-party controls;
- cybersecurity safeguards;
- employee complaint mechanism;
- periodic proportionality review;
- restrictions on off-duty monitoring;
- special safeguards for biometric data;
- human review of automated decisions;
- disciplinary consequences for misuse of surveillance data.
Conclusion
Privacy concerns in surveillance are fundamentally about balancing legitimate security, operational and regulatory objectives against individual autonomy, dignity and informational privacy.
The Indian Supreme Court's privacy jurisprudence, particularly K.S. Puttaswamy, establishes that privacy is a fundamental constitutional right. PUCL, Selvi, Puttaswamy (Aadhaar), Anuradha Bhasin, Vinit Kumar, and R. Rajagopal demonstrate different dimensions of protection against intrusive information collection, interception and monitoring.
For employment surveillance, the most important practical principle is proportionality: an employer should be able to explain why the surveillance is necessary, what information is being collected, why that amount of information is required, who can access it, how long it will be retained, and why a less intrusive alternative would not adequately achieve the legitimate objective.

comments