
The Scenario
Suresh is a mid-level manager at a logistics company in Chennai. His employer had implemented an IoT-enabled smart office system — access badges tracked movement across the building, smart cameras monitored workstations, occupancy sensors logged time at desk, and a connected printer recorded who printed what and when.
All of this data flowed into a workplace analytics platform that generated individual productivity scores. Suresh was placed on a performance improvement plan based partly on his occupancy metrics — he had spent less time at his desk during a period when he was, in fact, attending client meetings in the conference rooms.
He was never told that his movement and occupancy data were being collected and used for performance evaluation. He had signed a general IT usage policy when he joined — three years before this system was installed.
The DPDP Act Position
This scenario raises three compliance failures.
First — Absence of lawful consent for a new processing purpose. Section 6(1) of the DPDP Act requires consent for each specified purpose. A general IT usage policy signed three years earlier does not constitute valid consent for IoT-based occupancy tracking and performance scoring. The purposes are different, the data categories are different, and the consequences to the employee are materially different.
Section 5(1) of the Act requires that every request for consent be accompanied or preceded by a notice informing the Data Principal of the personal data to be processed and the purpose. No such notice was given when the IoT system was deployed. Consequently, all processing of Suresh’s location and occupancy data for performance evaluation was unlawful.
Second — Use of incomplete data to make decisions affecting the Data Principal. Section 8(3) requires that when personal data is likely to be used to make a decision that affects the Data Principal, the Data Fiduciary must ensure the completeness, accuracy, and consistency of that data. Suresh’s occupancy data was accurate — he was not at his desk — but it was incomplete, because the system had no mechanism to capture the reason. An employee attending client meetings generates the same occupancy reading as one who is absent without reason. Using this data for performance decisions without ensuring completeness is a direct violation of Section 8(3).
Third — Breach of proportionality under the Puttaswamy doctrine. The Supreme Court’s judgment in Puttaswamy v Union of India (2018) established that any encroachment on informational privacy must satisfy the proportionality test: there must be a lawful basis, a legitimate aim, and the measure must be proportionate to that aim. Continuous occupancy monitoring of every employee for the purpose of productivity scoring is disproportionate to any legitimate workplace management aim — particularly when other, less invasive means of performance assessment are readily available.
The IS Audit 3.0 Perspective
IS Audit 3.0 by ICAI identifies insufficient authentication and authorisation, insecure web interfaces, and lack of transport-level encryption as key IoT risks. In Suresh’s case, the workplace IoT system aggregated movement data with no individual access controls, no audit trail for the analytics platform, and no individual visibility into what data was being collected about each employee.
IS Audit 3.0 (Governance and Controls) is direct: IoT governance must define the lifecycle of IoT data, cover the changes to IT governance for distributed IoT architecture, and ensure that the principles for managing that architecture deliver on the stated business goals. A workplace analytics platform that generates employment consequences without a lawful consent framework is not a managed system — it is an uncontrolled compliance liability.
The Compliance Fix
Employers deploying workplace IoT systems must:
→ Issue a fresh, specific consent notice — separate from general IT policies — for each new IoT deployment that collects employee personal data. → Conduct a Data Protection Impact Assessment (DPIA) under Section 10 of the DPDP Act before deploying any system that collects employee movement, biometric, or occupancy data at scale. → Ensure that any data used to make employment decisions is complete, not merely accurate — which means building context-capture mechanisms alongside sensors. → Apply proportionality: if the legitimate aim is productivity management, the least invasive means of achieving that aim should be used. Continuous movement tracking is rarely the least invasive option. → Give employees visibility into what data is being collected about them, and provide a mechanism to raise corrections under Section 12(2) of the DPDP Act.
Suresh’s employer automated its surveillance. However, it did not automate its compliance.
Disclaimer
The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.
The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.
Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.
The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.
Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.
