Shadow IT by employees.
Shadow IT by Employees
1. Meaning
Shadow IT refers to the use of software, cloud services, applications, devices, storage platforms, messaging tools, or other technology by employees without the knowledge, approval, or authorization of the employer's IT or security function.
Examples include:
- An employee uploading company files to a personal Google Drive/Dropbox account.
- Using personal Gmail to send confidential work documents.
- Installing unauthorized software on a company laptop.
- Using ChatGPT or another AI tool with confidential company information without authorization.
- Saving customer information on a personal USB drive.
- Using an unapproved SaaS application to process company data.
- Creating a private WhatsApp/Telegram group for transferring sensitive work information.
- Using personal devices to access company systems contrary to company policy.
Shadow IT is not automatically unlawful merely because an employee uses an unapproved application. The legal consequences depend on what was accessed, copied, disclosed, or used, the employee's authorization, contractual obligations, company policies, applicable data-protection law, and whether confidential information or intellectual property was compromised.
2. Legal Issues Created by Shadow IT
A. Unauthorized access to company data
An employee may legitimately have access to company information for work purposes but exceed that authorization by copying or transferring it to an unauthorized location.
Under India's Information Technology Act, 2000, unauthorized access, downloading, copying or extraction of computer data can attract liability depending upon the circumstances.
In Awadhesh Kumar Paras Nath Pathak v. State of Maharashtra, the Bombay High Court considered allegations involving employees accessing and taking company computer data. The Court explained that unauthorized access or downloading of data can fall within Section 43 of the IT Act and that dishonest or fraudulent conduct can attract Section 66.
B. Confidentiality and trade secrets
Shadow IT can expose:
- customer databases;
- pricing information;
- business plans;
- source code;
- technical information;
- employee records;
- research material;
- intellectual property.
An employee's employment agreement, confidentiality agreement, IT policy, NDA, or code of conduct may prohibit such unauthorized disclosure or use.
C. Data protection and privacy
Personal information transferred through unauthorized applications may create privacy and compliance risks.
For example, uploading employee Aadhaar information, salary records, medical information, customer information, or financial details to an unapproved cloud service may create significant compliance issues.
D. Intellectual property
Installing unauthorized software can also create copyright/licensing problems. An employee who downloads or installs unlicensed software on company systems may expose the employer to infringement claims or contractual penalties.
E. Employment disciplinary action
Where company policies clearly prohibit unauthorized applications, external storage, personal email, or unauthorized data transfer, shadow IT may constitute misconduct.
Possible consequences include:
- warning;
- suspension;
- disciplinary proceedings;
- termination, subject to applicable employment law and contractual/statutory requirements;
- recovery of losses where legally permissible;
- civil injunctions;
- criminal proceedings in serious cases.
3. Important Indian Case Laws
1. Awadhesh Kumar Paras Nath Pathak v. State of Maharashtra (2020)
This case involved allegations concerning company computer data and unauthorized access/copying. The Bombay High Court considered Sections 43 and 66 of the Information Technology Act.
The Court observed that accessing or securing access to computer resources without permission, or downloading data without authorization, can fall within Section 43; dishonest or fraudulent conduct can bring Section 66 into operation.
Relevance to Shadow IT:
An employee who transfers company data to a personal computer, cloud account, or external device without authorization may face legal consequences where the statutory requirements are satisfied.
2. V. Narendra Babu v. State of Andhra Pradesh (2022)
The Andhra Pradesh High Court dealt with allegations that persons who had been entrusted with company computers and data accessed and transferred company information to another organization.
The Court noted allegations that company data had been copied from laptops and transferred to computers/hard disks of another institution without permission, and considered the applicability of Sections 43 and 66 of the IT Act.
Relevance:
The case demonstrates the distinction between authorized possession of a computer and authorized use of the data contained in it. An employee may possess a company laptop legitimately but still exceed authorization by transferring confidential data elsewhere.
3. Abhinav Goyal v. Greyb Consultancy Service Ltd. (2013)
The Punjab and Haryana High Court considered allegations that employees with authorized access to a confidential company database downloaded and transferred database information to pen drives and through email.
The employees had confidentiality and invention agreements governing confidential information. The allegations included copying company database information for their own benefit and establishing a competing business.
Relevance:
This is particularly relevant to shadow IT because it illustrates how an employee's legitimate access to an employer's database does not necessarily authorize copying the information to personal storage or email accounts.
4. Hi-Tech Systems & Services Ltd. v. Suprabhat Ray (2015)
The Calcutta High Court dealt with former employees allegedly possessing and using confidential business information and databases obtained during employment.
The company's code of conduct required employees to keep confidential information relating to the company and its clients confidential, including after employment.
Relevance:
Shadow IT can create evidence of unauthorized retention or dissemination of confidential information, particularly where an employee moves company information to personal devices or accounts.
5. Sri Sita Rama Balaji Maganti v. GE India Industrial Pvt. Ltd. (2022)
The case involved allegations that an employee transferred company information from a company laptop to a personal email address and external storage devices. The employer's investigation generated a data-movement report showing files and folders accessed and transferred.
Relevance:
This case closely resembles modern shadow-IT scenarios. Personal email and external storage can create an audit trail showing movement of employer information outside approved systems.
It also demonstrates why companies commonly use:
- Data Loss Prevention (DLP);
- access logs;
- endpoint monitoring;
- file-transfer records;
- device-management systems.
6. M/s Stellar Information Technology Pvt. Ltd. v. Rakesh Kumar (2016)
The Delhi High Court considered a dispute involving former employees accused of misusing confidential information and client information obtained during employment. The employer relied upon confidentiality and invention-assignment agreements and sought injunctions concerning the alleged misuse of confidential information.
Relevance:
Where shadow IT results in company information being retained or used after an employee leaves, confidentiality obligations and contractual restrictions can become important in civil proceedings.
7. SAP Aktiengesellschaft v. Appsone Consulting India (P) Ltd. (2015)
The Delhi High Court dealt with unauthorized use of SAP software. The Court recognized that unauthorized use of computer programs can involve unauthorized reproduction, including temporary copies generated during computer operation, under copyright law.
Relevance:
Shadow IT is not limited to data theft. An employee installing unauthorized or unlicensed software can create software copyright and licensing exposure for an organization.
8. M/s Webkul Software Pvt. Ltd. v. Anand Kumar Prajapati (2026)
In this recent Delhi High Court matter, the plaintiff alleged that a former employee had misused confidential information and source code obtained during employment and had used substantially similar software code in products sold independently. The employment relationship included confidentiality obligations.
Relevance:
The case demonstrates the connection between employee access, confidential technical information, source code and subsequent unauthorized use. In a modern workplace, unauthorized external development environments or personal repositories can create similar risks.
4. Shadow IT and Employee Misconduct
The important distinction is:
Authorized technology use ≠ unauthorized data use.
For example:
Employee uses personal Gmail for a routine, non-confidential communication contrary to company policy.
This may primarily be an internal policy violation.
But:
Employee sends a confidential customer database to personal Gmail and uploads it to personal cloud storage.
This can potentially involve:
- breach of confidentiality;
- violation of employment obligations;
- unauthorized transfer of data;
- IT Act implications;
- privacy/data-protection issues;
- intellectual-property issues;
- disciplinary misconduct;
- possible civil claims.
Therefore, employers should assess the nature of the information and conduct, rather than treating every instance of shadow IT as equivalent.
5. Employer Policies Against Shadow IT
A comprehensive IT/employee policy should clearly regulate:
- Approved software
- Personal email
- Cloud-storage services
- USB/external storage
- Personal laptops and mobile phones
- AI tools and generative AI
- Messaging applications
- Remote-access software
- Password sharing
- Downloading company information
- Data transfer outside the corporate network
- Use of open-source software
- Software installation rights
- Monitoring and logging
- Incident reporting
- Exit/termination procedures
The policy should clearly state what constitutes authorized and unauthorized access.
6. AI Tools as Modern Shadow IT
A particularly important form of shadow IT is unauthorized employee use of generative AI.
For example, an employee may copy:
"Here is our company's customer database and internal contract. Please summarize it."
into an external AI platform.
Potential issues include:
- confidential-information disclosure;
- client confidentiality;
- personal-data exposure;
- intellectual-property concerns;
- contractual confidentiality obligations;
- loss of control over company information.
Companies therefore increasingly create separate AI acceptable-use policies specifying what information employees may and may not submit to external AI systems.
7. Employer Monitoring and Privacy
There is also an important counterbalance.
An employer cannot necessarily assume that everything found on an employee's company device can be freely examined without regard to privacy and applicable law.
In Vikram Khurana v. M/s Kaapi Machines (India) Pvt. Ltd., the Madras High Court considered allegations concerning forensic extraction of deleted files from a company-issued computer, including personal information such as bank-account information and browsing history. The case illustrates the tension between an employer's legitimate investigation interests and an employee's privacy interests.
Therefore, companies investigating shadow IT should have appropriate:
- monitoring policies;
- employee notice;
- proportionality;
- access controls;
- forensic procedures;
- evidence-preservation procedures.
8. Employer's Compliance Strategy
A practical shadow-IT compliance framework can be divided into four stages.
Prevention
- Maintain an approved-software list.
- Restrict unauthorized installations.
- Implement access controls.
- Use DLP systems.
- Block unauthorized cloud-storage services where appropriate.
- Train employees.
- Establish an AI-use policy.
Detection
Employers can monitor, subject to applicable law and policy:
- unusual downloads;
- mass file transfers;
- external USB usage;
- personal-email transfers;
- unauthorized applications;
- unusual cloud uploads;
- access outside normal business requirements.
Investigation
When suspicious activity is identified:
- Preserve logs.
- Identify the relevant employee/account.
- Determine what information was accessed.
- Determine whether access was authorized.
- Preserve electronic evidence.
- Follow applicable disciplinary procedures.
- Assess privacy and data-protection implications.
Response
Depending on the facts:
- revoke access;
- secure affected accounts;
- preserve evidence;
- notify affected parties where legally required;
- commence disciplinary proceedings;
- seek an injunction where appropriate;
- pursue civil or criminal remedies where applicable.
9. Key Legal Principle
The central legal issue in shadow IT cases is usually not simply whether the employee used an unauthorized application.
The more important questions are:
Was the employee authorized to access the information?
Was the employee authorized to copy or transfer it?
Was the information confidential or personal?
Was the external system approved?
Did the employee disclose or misuse the information?
Did the conduct violate an employment agreement or company policy?
What monitoring and investigation methods did the employer use?
The Indian cases above demonstrate that courts have considered unauthorized copying, transfer and use of company data, confidential information and software in different factual contexts.
Conclusion
Shadow IT by employees creates a combination of employment, confidentiality, cybersecurity, intellectual-property, privacy and data-protection risks. Mere use of an unapproved technology does not automatically establish criminal or civil liability. However, when unauthorized technology is used to copy, transfer, disclose, retain or exploit confidential company data, the legal consequences can become substantially more serious. Employers should therefore combine clear IT policies, technical controls, employee training, proportionate monitoring and legally compliant investigation procedures.

comments