Recordkeeping for testing programs.
Recordkeeping for Testing Programs
1. Meaning
Recordkeeping for testing programs refers to the systematic creation, maintenance, protection, retention, retrieval and eventual disposal of records generated through workplace testing programmes.
In an employment context, testing programmes may include:
- Drug and alcohol testing
- Medical fitness testing
- Occupational-health examinations
- Safety and competency testing
- Skill or certification tests
- Background and integrity verification
- Random compliance testing
- Workplace exposure or health monitoring
- Fitness-for-duty examinations
- Psychological or aptitude assessments where legally permissible
Recordkeeping is important because testing records can affect employment, disciplinary action, promotion, termination, compensation, workplace safety and litigation.
The employer must therefore maintain records in a manner that preserves accuracy, confidentiality, authenticity and procedural fairness.
2. Objectives of Recordkeeping
A proper testing-record system serves several purposes.
A. Proof that testing actually occurred
The employer should be able to establish:
- Who was tested
- When the test occurred
- Why the employee was tested
- What procedure was followed
- Who conducted the test
- What result was obtained
This becomes particularly important where an employee challenges disciplinary action.
B. Evidence of procedural compliance
Records can demonstrate whether the employer followed:
- The employment contract
- Standing orders
- HR policies
- Safety rules
- Applicable legislation
- Testing protocols
- Collective agreements
- Due-process requirements
C. Protection against arbitrary decisions
A documented testing system reduces the possibility that an employer will rely on an undocumented or selectively applied testing process.
D. Litigation preparedness
Testing records may subsequently become relevant in:
- Domestic enquiries
- Labour disputes
- Industrial tribunals
- Civil litigation
- Writ proceedings
- Criminal proceedings
- Arbitration
- Regulatory investigations
3. Types of Records
A comprehensive testing programme can generate several categories of records.
| Record | Typical contents |
|---|---|
| Testing policy | Purpose, scope and procedure |
| Employee consent | Consent/acknowledgment where required |
| Test request | Reason and authority for testing |
| Chain-of-custody record | Handling and transfer of specimen |
| Laboratory report | Test methodology and result |
| Medical report | Fitness/occupational-health findings |
| Retest record | Independent confirmation or challenge |
| Incident report | Circumstances leading to testing |
| Disciplinary record | Action based on verified results |
| Appeal record | Employee's challenge and response |
| Retention log | Retention and destruction dates |
| Access log | Persons who accessed confidential records |
4. Confidentiality of Testing Records
Testing records may contain highly sensitive personal information.
For example, medical testing can reveal:
- Health conditions
- Medication
- Substance use
- Disability
- Reproductive information
- Genetic information
- Mental-health information
- Other sensitive medical information
Consequently, unrestricted circulation of testing reports within an organisation is problematic.
The principle should generally be:
Access should be limited to persons who genuinely require the information for a legitimate employment, safety, medical, legal or compliance purpose.
A manager who merely needs to know whether an employee is fit for a particular task may not necessarily need access to the employee's complete medical report.
5. Accuracy and Integrity of Records
Testing records should be capable of demonstrating that the recorded result corresponds to the actual test.
Important safeguards include:
- Unique employee/test identification
- Date and time stamping
- Identification of the testing facility
- Identification of the testing professional
- Proper specimen identification
- Chain-of-custody documentation
- Secure storage
- Audit trails for electronic records
- Controlled alteration rights
- Preservation of original records
An electronically altered testing record can become highly problematic in litigation.
Where electronic evidence is relied upon, the organisation should also be able to establish its source, authenticity and integrity.
6. Chain of Custody
Chain of custody is particularly important in drug, alcohol, forensic and other specimen-based testing.
It establishes the history of the specimen from collection through final analysis.
A proper chain-of-custody record should identify:
- Person collecting the specimen
- Date and time of collection
- Specimen identification number
- Packaging
- Seal
- Person receiving the specimen
- Laboratory transfer
- Testing procedure
- Storage
- Disposal
Why it matters
Suppose an employee is dismissed because of a positive substance test.
If the employer cannot establish that the specimen tested by the laboratory was actually the employee's specimen, the reliability of the disciplinary case may be seriously undermined.
7. Positive Results and Confirmatory Testing
A preliminary or screening result should not automatically be treated as conclusive where the testing methodology requires confirmation.
A robust policy should distinguish between:
Screening test → confirmatory test → final determination → disciplinary/administrative decision
The records should therefore show:
- Initial result
- Confirmatory result
- Testing methodology
- Laboratory details
- Relevant quality-control information
- Any employee request for retesting
- Final decision
This is particularly important because a testing programme may produce false positives, false negatives or inconclusive results.
8. Employee Access and Opportunity to Challenge
Fair testing systems should provide an appropriate mechanism for an employee to challenge a result.
Depending on the circumstances, this may include:
- Requesting a copy of the report
- Seeking an independent retest
- Producing contrary medical evidence
- Challenging the chain of custody
- Challenging the testing methodology
- Challenging procedural irregularities
- Raising the issue in disciplinary proceedings
The existence of an appeal/retest mechanism should itself be recorded.
9. Retention Period
There is no single universal retention period applicable to every workplace testing record in India.
The appropriate period depends upon:
- Nature of the test
- Applicable labour legislation
- Occupational-safety requirements
- Medical-record obligations
- Sector-specific regulation
- Contractual requirements
- Litigation limitation periods
- Regulatory requirements
- Internal retention policy
The employer should therefore create a documented retention schedule rather than retaining everything indefinitely.
A retention policy can specify:
Creation → Active use → Restricted archival → Litigation hold → Secure destruction.
10. Litigation Hold
If litigation, investigation or a disciplinary dispute is reasonably anticipated, routine destruction should be suspended for relevant records.
For example, if an employee challenges termination based upon a failed drug test, the employer should preserve:
- Original test result
- Laboratory report
- Chain-of-custody documentation
- Testing policy
- Consent/acknowledgment
- Communications concerning the test
- Retest documentation
- Disciplinary proceedings
- Relevant electronic records
Failure to preserve relevant evidence can adversely affect the employer's case.
11. Privacy and Proportionality
Testing programmes must be balanced against employee privacy.
The Supreme Court's constitutional privacy jurisprudence recognises privacy as a fundamental right.
Therefore, employers should consider:
Purpose limitation
Collect information for a legitimate employment or safety purpose.
Data minimisation
Collect only information reasonably necessary for that purpose.
Restricted access
Limit access to authorised personnel.
Security
Protect records against unauthorised disclosure.
Retention limitation
Do not retain sensitive records indefinitely without justification.
Transparency
Employees should ordinarily understand the nature and purpose of the testing programme.
12. Testing Records and Disciplinary Proceedings
Testing evidence does not automatically establish misconduct merely because a report exists.
The employer may need to establish:
- Authority for the test
- Applicability of the testing policy
- Proper notice
- Valid testing procedure
- Authenticity of the report
- Reliability of the testing method
- Chain of custody
- Opportunity for challenge
- Connection between the result and alleged misconduct
- Proportionality of disciplinary action
A disciplinary authority should therefore distinguish between:
"The test report exists"
and
"The misconduct has been established through a procedurally reliable process."
13. Important Indian Case Laws
1. K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1
The Supreme Court recognised privacy as a fundamental right under Article 21.
The judgment is foundational for workplace testing because testing programmes may involve collection and processing of highly personal information.
Principle
Any testing programme involving personal or medical information should consider:
- Legality
- Legitimate purpose
- Necessity
- Proportionality
- Procedural safeguards
Relevance
Employers should not treat employee testing records as ordinary administrative documents where the information implicates personal privacy.
2. District Registrar and Collector, Hyderabad v. Canara Bank, (2005) 1 SCC 496
The Supreme Court examined privacy in relation to access to personal and financial records.
Principle
The Court recognised that individuals have legitimate privacy interests in personal information and records.
Relevance
The case supports the broader principle that access to personal records should not be treated as unrestricted merely because the information exists within an institutional environment.
For HR testing systems, this reinforces the importance of controlled access to sensitive employee records.
3. People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301
The Supreme Court considered privacy concerns in the context of telephone interception.
Principle
Interference with privacy requires procedural safeguards.
Relevance
Although the case did not concern workplace testing, its reasoning is relevant to organisational surveillance and collection of personal information.
A testing programme should therefore operate through a defined procedure rather than unrestricted managerial discretion.
4. Selvi v. State of Karnataka, (2010) 7 SCC 263
The Supreme Court considered involuntary administration of scientific techniques such as narco-analysis, polygraph examination and brain-mapping.
Principle
The Court emphasised the constitutional significance of personal autonomy and protection against involuntary intrusion.
Relevance to employment testing
The case is relevant where employers consider intrusive testing methods. It demonstrates that the mere availability of a scientific technique does not automatically make its involuntary use legally permissible.
Testing policies must therefore distinguish between:
- voluntary consent,
- legally authorised testing, and
- coercive testing.
5. State of Bombay v. Kathi Kalu Oghad, AIR 1961 SC 1808
The Supreme Court examined the scope of protection against testimonial compulsion under Article 20(3).
Principle
The Court distinguished between testimonial evidence and physical evidence.
Relevance
The case is important when analysing different forms of employee testing because not every form of physical evidence is legally equivalent to compelled testimony.
However, the constitutional analysis must depend upon the nature of the particular test and the circumstances in which it is conducted.
6. R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632
The Supreme Court recognised significant privacy protections relating to personal information and publication.
Principle
Individuals possess privacy interests in matters concerning their personal lives, subject to recognised legal limitations.
Relevance
Medical and testing information should not ordinarily be circulated or publicly disclosed merely because an employer possesses it.
The case supports careful handling of confidential employee information and restrictions on unnecessary disclosure.
14. Recordkeeping Failures That Create Legal Risk
Failure 1 — No written testing policy
If testing occurs without a documented policy, employees may challenge the employer's authority and procedure.
Failure 2 — Missing chain-of-custody documentation
This can undermine the reliability of specimen-based testing.
Failure 3 — No confirmation of positive results
Treating an initial screening result as final may create evidentiary problems.
Failure 4 — Excessive access
Circulating medical or testing results to unnecessary personnel can create privacy concerns.
Failure 5 — Inconsistent application
Testing one employee while ignoring similarly situated employees can create questions about fairness and selective enforcement.
Failure 6 — Poor electronic security
Sensitive testing records stored without appropriate access controls may be exposed to unauthorised persons.
Failure 7 — Destruction during litigation
Destroying relevant testing records after a dispute has arisen can seriously prejudice the employer's evidentiary position.
15. Recommended Recordkeeping Framework
An employer can structure its testing-record system around the following model:
1. Policy
Define when and why testing may occur.
↓
2. Notice/Consent
Document the applicable employee acknowledgment or consent.
↓
3. Test Request
Record the authority, reason and date.
↓
4. Collection
Document specimen collection and identification.
↓
5. Chain of Custody
Record every significant transfer.
↓
6. Laboratory Analysis
Preserve the original laboratory documentation.
↓
7. Confirmation
Record confirmatory testing where applicable.
↓
8. Result
Classify the result appropriately—negative, positive, inconclusive, invalid, etc.
↓
9. Employee Challenge
Preserve requests for retesting and responses.
↓
10. Decision
Record the administrative or disciplinary decision and its reasons.
↓
11. Secure Retention
Apply the applicable retention schedule.
↓
12. Litigation Hold
Suspend destruction when legally required.
↓
13. Secure Disposal
Destroy records securely when the lawful retention period ends.
16. HR Compliance Checklist
| Area | Good practice |
|---|---|
| Testing policy | Written and accessible |
| Purpose | Clearly defined |
| Employee notice | Documented |
| Consent | Obtained where required |
| Collection | Standardised |
| Chain of custody | Complete |
| Laboratory | Qualified/appropriate |
| Confirmation | Used where necessary |
| Results | Accurately recorded |
| Access | Need-to-know |
| Security | Strong technical and organisational safeguards |
| Appeals | Documented |
| Retention | Defined schedule |
| Litigation hold | Implemented when necessary |
| Destruction | Secure and documented |
| Audit | Periodic review |
17. Conclusion
Recordkeeping is not merely an administrative aspect of workplace testing; it is part of the evidentiary and governance structure of the testing programme.
A legally defensible system should establish why testing was conducted, who authorised it, how it was performed, how the specimen or information was handled, how the result was verified, who accessed the information, how the employee could challenge it, and why any resulting employment action was taken.
In India, privacy jurisprudence—particularly K.S. Puttaswamy, together with the principles emerging from Canara Bank, PUCL, Selvi and Rajagopal—makes confidentiality, procedural safeguards and proportionality particularly important when testing involves sensitive personal information.
For HR purposes, the central principle can be stated simply:
A testing result should be treated as sensitive evidence requiring controlled collection, reliable verification, secure recordkeeping and fair use—not merely as an ordinary HR data point.

comments