Privacy concerns in surveillance.

Privacy Concerns in Surveillance 

Privacy concerns in surveillance arise when an employer, government authority, platform, or other organisation collects, monitors, records, analyses, or shares information about individuals or their activities. In employment law, surveillance can include CCTV, email monitoring, internet monitoring, GPS/location tracking, biometric attendance, device monitoring, call recording, productivity tracking, facial recognition, and monitoring of employees working remotely.

In India, the constitutional foundation of privacy is Article 21, read with the guarantees of dignity, liberty and, in appropriate circumstances, equality under Article 14. For private employment, contractual obligations, labour legislation, the Information Technology Act framework, applicable data-protection law, and common-law principles may additionally become relevant.

1. Meaning of Surveillance

Surveillance involves systematic observation or collection of information about a person.

Examples include:

  • CCTV monitoring;
  • employee attendance systems;
  • biometric identification;
  • facial-recognition systems;
  • GPS tracking of company vehicles;
  • monitoring company laptops;
  • recording emails;
  • monitoring browsing history;
  • recording telephone calls;
  • keystroke monitoring;
  • screenshots;
  • location tracking;
  • monitoring social-media activity;
  • remote-work productivity software;
  • automated behavioural profiling.

The legal question is not simply whether surveillance exists, but whether the surveillance is lawful, necessary, proportionate, transparent and appropriately limited.

2. Constitutional Right to Privacy

The most important Indian constitutional authority is:

K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1

A nine-judge Constitution Bench unanimously recognised privacy as a constitutionally protected right arising primarily from Article 21 and the broader guarantees of Part III of the Constitution.

The Court rejected the proposition that privacy is merely a common-law or statutory right.

The judgment recognised several dimensions of privacy, including:

  • bodily privacy;
  • informational privacy;
  • decisional autonomy;
  • protection of personal information;
  • dignity and individual liberty.

Importance for surveillance

Surveillance that collects personal information potentially interferes with informational privacy.

However, the existence of a privacy interest does not mean that all surveillance is automatically unconstitutional. The legality of a particular surveillance measure depends upon its purpose, legal basis, extent and safeguards.

3. The Proportionality Requirement

Indian privacy jurisprudence generally requires restrictions on fundamental privacy interests to satisfy constitutional standards.

The principal considerations include:

1. Legality

There should be a valid legal basis for the interference.

2. Legitimate State or institutional objective

The surveillance must pursue a legitimate objective.

Examples:

  • national security;
  • crime prevention;
  • workplace safety;
  • protection of confidential information;
  • prevention of fraud;
  • investigation of misconduct.

3. Necessity

The surveillance should have a rational connection with the legitimate objective.

4. Proportionality

The method should not unnecessarily intrude into privacy when a less intrusive alternative could achieve substantially the same objective.

This is particularly important for workplace surveillance.

4. Six Important Case Laws

1. K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1

This is the foundational Indian privacy judgment.

The Supreme Court held that privacy is a fundamental right protected by the Constitution.

The judgment recognised that privacy encompasses protection against inappropriate interference with a person's:

  • personal autonomy;
  • dignity;
  • bodily integrity;
  • personal information;
  • choices and relationships.

Relevance to surveillance

Surveillance involves collecting information about a person's behaviour or activities.

Therefore, systems such as:

  • facial recognition;
  • GPS tracking;
  • biometric databases;
  • electronic communications monitoring;
  • extensive employee profiling

can implicate informational privacy.

Principle

Privacy is a constitutionally protected right, and surveillance that interferes with privacy must satisfy constitutional requirements.

5. People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301

This case concerned telephone tapping.

The Supreme Court recognised that telephone conversations are an important aspect of an individual's privacy and that telephone tapping constitutes an invasion of privacy.

The Court laid down procedural safeguards concerning telephone interception.

These included requirements relating to:

  • authorisation;
  • necessity;
  • duration;
  • review;
  • record keeping;
  • destruction of intercepted material.

Relevance to surveillance

The case established an important principle:

Surveillance powers cannot be exercised without procedural safeguards.

This principle has broader relevance to modern surveillance technologies such as:

  • call recording;
  • electronic communications monitoring;
  • interception;
  • digital communications surveillance.

Principle

Even where surveillance serves a legitimate governmental objective, procedural safeguards are necessary to prevent arbitrary intrusion.

6. Selvi v. State of Karnataka, (2010) 7 SCC 263

The Supreme Court considered the legality of involuntary:

  • narco-analysis;
  • polygraph examinations;
  • Brain Electrical Activation Profile tests.

The Court emphasised individual autonomy, mental privacy and protection against involuntary intrusion into a person's mind.

Relevance to surveillance

Modern surveillance increasingly involves not merely observing conduct but analysing behaviour.

Examples include:

  • emotion recognition;
  • behavioural profiling;
  • AI-based employee monitoring;
  • predictive analytics;
  • psychological profiling.

The reasoning in Selvi demonstrates that privacy can extend beyond physical spaces to mental autonomy and personal decision-making.

Principle

Technological capacity to obtain information does not itself establish legal authority to obtain it without respecting autonomy and constitutional protections.

7. K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar), (2018) 1 SCC 809

The Supreme Court considered the constitutional validity of the Aadhaar framework.

The judgment examined extensive collection and processing of personal and biometric information.

The Court considered:

  • purpose limitation;
  • data security;
  • proportionality;
  • informational privacy;
  • authentication;
  • potential misuse of personal data.

Relevance to surveillance

Biometric systems create particular privacy concerns because biometric information is intrinsically connected to the individual.

Examples include:

  • fingerprints;
  • iris scans;
  • facial recognition;
  • voice recognition.

Unlike a password, biometric characteristics generally cannot simply be replaced after compromise.

Principle

Large-scale collection and processing of personal information require safeguards against misuse, excessive collection and disproportionate interference with privacy.

8. Anuradha Bhasin v. Union of India, (2020) 3 SCC 637

The Supreme Court considered restrictions on internet access in Jammu and Kashmir.

The Court recognised the importance of the internet in exercising constitutional freedoms and examined restrictions through the principle of proportionality.

The judgment required restrictions to satisfy standards concerning:

  • legality;
  • necessity;
  • proportionality;
  • publication and review of orders.

Relevance to surveillance

Digital surveillance frequently operates through restrictions or monitoring of communications infrastructure.

The case is therefore important for understanding how constitutional rights apply in the digital environment.

Principle

Technological measures affecting digital communications must remain subject to constitutional standards of legality and proportionality.

9. Vinit Kumar v. Central Bureau of Investigation, 2019 SCC OnLine Bom 3151

The Bombay High Court dealt with interception of telephone conversations and examined the statutory safeguards governing interception.

The Court emphasised the importance of compliance with the legal framework governing interception and considered the consequences of interception carried out without proper legal authority.

Relevance

The case demonstrates that unauthorised interception cannot be justified merely because the information obtained may be useful.

This principle is particularly relevant where surveillance evidence is subsequently sought to be used in:

  • disciplinary proceedings;
  • criminal proceedings;
  • employment disputes;
  • regulatory investigations.

Principle

Evidence obtained through legally defective interception can face serious judicial scrutiny.

10. R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632

This is another foundational Indian privacy case.

The Supreme Court recognised the individual's right to privacy and considered publication of information concerning a person's private life.

The Court distinguished between information legitimately available from public records and genuinely private information.

Relevance to surveillance

Surveillance frequently produces information that is not ordinarily public.

For example:

  • employee movements;
  • private communications;
  • personal relationships;
  • medical information;
  • private photographs;
  • personal browsing activity.

The fact that an organisation possesses such information does not necessarily mean that it has unlimited authority to disclose or use it.

Principle

Possession of personal information does not eliminate the individual's privacy interest in that information.

11. Workplace Surveillance

Workplace surveillance creates a particularly difficult balance.

An employer may have legitimate reasons to monitor employees.

For example:

Security

Monitoring may protect:

  • employees;
  • customers;
  • premises;
  • confidential information.

Fraud prevention

Financial institutions may need monitoring systems to identify:

  • unauthorised transactions;
  • unusual access;
  • insider misconduct.

Productivity

An employer may legitimately monitor certain aspects of work performance.

Compliance

Regulated organisations may have statutory obligations to maintain records or monitor particular activities.

However, legitimate business interests do not automatically justify unlimited employee surveillance.

12. Excessive Employee Surveillance

Examples of potentially excessive surveillance include:

  • recording employees continuously without a clear purpose;
  • monitoring personal devices without adequate legal basis;
  • tracking employees outside working hours;
  • monitoring private communications;
  • collecting biometric data unnecessarily;
  • retaining surveillance data indefinitely;
  • monitoring family members or visitors;
  • using facial recognition without adequate safeguards;
  • analysing employees' emotions without a clearly defined necessity;
  • monitoring remote employees continuously through webcams.

The greater the intrusion, the stronger the justification and safeguards ordinarily required.

13. CCTV Surveillance

CCTV is one of the most common forms of workplace surveillance.

CCTV can be legitimate for:

  • security;
  • prevention of theft;
  • workplace safety;
  • investigation of incidents.

However, cameras should not ordinarily be placed in locations where individuals have an especially strong expectation of privacy.

Particular caution is required concerning:

  • bathrooms;
  • changing rooms;
  • rest areas;
  • private medical areas.

The employer should also consider:

  • purpose;
  • notice;
  • access controls;
  • retention period;
  • deletion;
  • disclosure;
  • security.

14. Email and Internet Monitoring

Employers may have legitimate interests in monitoring activity occurring on company systems.

However, an important distinction exists between:

company-system monitoring and unrestricted surveillance of personal communications.

For example, an employer may have stronger justification for monitoring:

  • malware;
  • data leakage;
  • unauthorised downloads;
  • corporate email security.

But monitoring an employee's private Gmail account or personal WhatsApp conversations raises substantially greater privacy concerns.

15. GPS and Location Surveillance

GPS tracking can be particularly intrusive.

During working hours, tracking a delivery employee or company vehicle may have an obvious operational purpose.

The privacy issue becomes substantially more complicated if tracking continues:

  • after working hours;
  • during leave;
  • during weekends;
  • while the employee is at home.

The employer should therefore consider whether continuous location tracking is actually necessary.

16. Biometric Surveillance

Biometric systems may include:

  • fingerprints;
  • facial recognition;
  • iris recognition;
  • voice recognition.

Biometrics raise special concerns because they are closely linked to the individual's identity.

Potential risks include:

  • identity theft;
  • unauthorised profiling;
  • function creep;
  • data breaches;
  • permanent consequences of biometric compromise.

A company should therefore avoid collecting biometric information merely because the technology is available.

17. Remote-Work Surveillance

Remote work has introduced new forms of monitoring.

Examples include:

  • webcam monitoring;
  • screenshots;
  • keystroke logging;
  • mouse movement tracking;
  • application monitoring;
  • productivity scores;
  • periodic screenshots;
  • automated activity scoring.

The central legal question is:

Does the monitoring measure work, or does it continuously observe the worker?

A system that measures completed work may be considerably less intrusive than continuous observation of an employee's home environment.

18. AI-Based Surveillance

Artificial intelligence creates additional privacy issues.

An AI system can potentially:

  • classify employee behaviour;
  • infer productivity;
  • identify unusual behaviour;
  • recognise faces;
  • analyse communications;
  • generate risk scores;
  • predict employee attrition;
  • detect "anomalies."

This creates the possibility of surveillance without meaningful human understanding of how the conclusion was generated.

Important safeguards include:

  • purpose limitation;
  • data minimisation;
  • accuracy;
  • human review;
  • access controls;
  • auditability;
  • explainability where appropriate;
  • retention limits.

19. Purpose Limitation

Information collected for one purpose should not automatically be repurposed for another unrelated purpose.

For example:

An employer installs CCTV for physical security.

It subsequently uses the footage to create automated employee-performance scores.

That secondary use raises a separate privacy and governance question.

The organisation should ask:

  1. Why was the information initially collected?
  2. What is the proposed new purpose?
  3. Was the new use reasonably foreseeable?
  4. Is the new use necessary?
  5. Is additional notice required?
  6. Is there a less intrusive alternative?

20. Data Minimisation

An organisation should collect only information reasonably necessary for the stated objective.

For example:

If an employer needs to know whether an employee entered a secure facility, it may not need to maintain a detailed minute-by-minute location history for months.

More data does not automatically mean better security or better management.

Excessive collection increases:

  • breach risk;
  • misuse risk;
  • insider-access risk;
  • compliance burden;
  • employee privacy intrusion.

21. Retention of Surveillance Data

Retention is an often-overlooked issue.

An organisation should establish:

  • how long CCTV footage is retained;
  • how long GPS data is retained;
  • how long employee emails are retained;
  • when biometric information is deleted;
  • who may access surveillance records.

Keeping information indefinitely creates unnecessary privacy and cybersecurity risks.

22. Employee Notice

A strong workplace surveillance framework should clearly communicate:

  • what is monitored;
  • why it is monitored;
  • when monitoring occurs;
  • what data is collected;
  • who can access it;
  • how long it is retained;
  • whether it is shared with third parties;
  • how employees can raise concerns.

A vague statement such as "the company may monitor employees at any time" creates substantially greater uncertainty than a specific monitoring policy.

23. Proportionality in Workplace Surveillance

A useful framework is:

QuestionIssue
PurposeWhy is surveillance necessary?
Legal basisWhat law/policy authorises it?
NecessityIs monitoring actually required?
ScopeWhat information is collected?
DurationHow long does monitoring continue?
IntrusivenessHow deeply does it interfere with privacy?
AlternativesCould a less intrusive method work?
AccessWho can see the information?
RetentionWhen is it deleted?
SecurityHow is it protected?
ReviewIs the system periodically reassessed?

24. Surveillance Evidence in Disciplinary Proceedings

Suppose an employer obtains:

  • CCTV footage;
  • email records;
  • access logs;
  • GPS information;
  • computer activity records.

The employer may seek to rely on this material in disciplinary proceedings.

The privacy question and the evidentiary question are related but distinct.

The organisation should examine:

  1. whether the monitoring was authorised;
  2. whether the employee received appropriate notice;
  3. whether the information was lawfully obtained;
  4. whether the record is authentic;
  5. whether it has been altered;
  6. whether relevant procedural safeguards were followed.

A privacy violation does not necessarily answer every question concerning admissibility, but it can significantly affect the legality and reliability of the surveillance process.

25. Employer's Legitimate Interests vs Employee Privacy

The appropriate approach is not:

"Employee privacy always wins."

Nor is it:

"The employer owns the computer, therefore the employer can monitor everything."

The legally significant question is whether the surveillance is justified and proportionate in the circumstances.

For example:

SurveillancePotential justificationPrivacy concern
CCTV at entranceSecurityModerate
CCTV in bathroomGenerally difficult to justifyVery high
GPS during deliveryOperational managementModerate
GPS 24/7Weakens necessityHigh
Corporate email malware scanningCybersecurityLower
Reading personal emailsUsually much more intrusiveHigh
Fingerprint attendanceAttendance verificationContext dependent
Continuous webcamProductivity/securityHigh
Security loggingCybersecurityContext dependent
Keystroke surveillanceProductivity/securityPotentially high

26. Six Core Legal Principles from the Case Law

The cases collectively establish several important principles:

1. Privacy is a fundamental right

K.S. Puttaswamy established the constitutional foundation.

2. Telephone communications have privacy protection

PUCL v. Union of India recognised privacy concerns surrounding interception.

3. Mental autonomy also matters

Selvi demonstrates that intrusive technology cannot be justified solely because it can extract information.

4. Biometric information requires safeguards

The Aadhaar judgment illustrates the constitutional concerns surrounding large-scale biometric information processing.

5. Digital restrictions must satisfy proportionality

Anuradha Bhasin reinforces constitutional scrutiny of measures affecting digital communications.

6. Private information remains protected against unjustified disclosure

R. Rajagopal establishes the importance of the individual's privacy interest in personal information.

27. Practical Compliance Framework for Employers

An employer implementing surveillance should ideally adopt a documented Surveillance and Employee Privacy Policy containing:

  1. defined surveillance purposes;
  2. categories of monitored data;
  3. lawful authority/justification;
  4. employee notice;
  5. access restrictions;
  6. retention periods;
  7. deletion procedures;
  8. third-party controls;
  9. cybersecurity safeguards;
  10. employee complaint mechanism;
  11. periodic proportionality review;
  12. restrictions on off-duty monitoring;
  13. special safeguards for biometric data;
  14. human review of automated decisions;
  15. disciplinary consequences for misuse of surveillance data.

Conclusion

Privacy concerns in surveillance are fundamentally about balancing legitimate security, operational and regulatory objectives against individual autonomy, dignity and informational privacy.

The Indian Supreme Court's privacy jurisprudence, particularly K.S. Puttaswamy, establishes that privacy is a fundamental constitutional right. PUCL, Selvi, Puttaswamy (Aadhaar), Anuradha Bhasin, Vinit Kumar, and R. Rajagopal demonstrate different dimensions of protection against intrusive information collection, interception and monitoring.

For employment surveillance, the most important practical principle is proportionality: an employer should be able to explain why the surveillance is necessary, what information is being collected, why that amount of information is required, who can access it, how long it will be retained, and why a less intrusive alternative would not adequately achieve the legitimate objective.

 

LEAVE A COMMENT