If you work at TCS or know someone who does, you've probably heard the news by now. Tata Consultancy Services has quietly deployed a Digital User Experience Monitoring (DUEM) tool on company-issued laptops used by close to 6 lakh employees across India and globally. No big announcement. No all-hands meeting. Reports from Times of India and Moneycontrol, plus Business Today, confirm this happened. And the lack of formal communication from TCS is precisely what's got people talking.
So what exactly does this software do? And should TCS employees be worried?
What the monitoring tool actually tracks
The tool TCS has rolled out is a Digital User Experience Monitoring solution. Based on reports, it gives the company visibility into two main things. Which applications an employee is running on their laptop. And how much time they are spending on each one.
Basically, think of it like your smartphone's Screen Time feature on iOS or Digital Wellbeing on Android. You know how your phone can show you that you spent 3 hours on Instagram yesterday? This is roughly the same concept. Except it's your employer doing the watching, not you. The software runs in the background on the company laptop. It sends usage data back to TCS's systems.
What it's not claimed to do, at least based on current reports, is take screenshots every few minutes or record your keystrokes. Or turn on your webcam. The monitoring is at the application and activity level. But honestly, the exact capabilities haven't been officially spelled out by TCS. I think this is part of why the monitoring has gotten so much attention.
Why TCS says it needs this
TCS hasn't issued a detailed public statement. But the general framing from the company is cybersecurity. And look, that's a legitimate concern. A company managing IT projects for banks and governments, as well as multinational corporations, has genuine reasons to want visibility into their devices.
Think about it from a security angle. If an employee's laptop gets compromised, knowing which applications were running can help security teams trace how a breach happened. If someone installs unauthorised software or connects to sketchy services, monitoring tools catch this early. Endpoint monitoring is a standard part of enterprise cybersecurity. Most large IT companies have had some form of it for years.
The Outlook Business piece and the OpIndia analysis both raise the same question. Where does cybersecurity end and workplace surveillance begin? That's not a rhetorical question. It's a mess to figure out (which makes sense, actually).
While IT and BPM companies have been using such tools for years, the lack of formal communication from TCS, which is expected for such changes, has triggered speculation. (Moneycontrol)
This isn't new for Indian IT — but TCS's scale is different
Here's something worth saying clearly. Employee monitoring software isn't new. Infosys, Wipro, HCL, Tech Mahindra, and most other large IT services companies use some form of endpoint monitoring or data loss prevention (DLP) tools on their machines. If you've ever worked at a large IT firm in India, your laptop almost certainly had security agents running on it.
What makes TCS different is the scale. We're talking about nearly 6 lakh employees. That isn't a pilot, it's a full deployment. When something touches that many people at once, it becomes news.
And then there's the timing. TCS, like most Indian IT majors, has been pushing hard for employees to return to office. There are attendance tracking systems and badge-based monitoring at campuses. Adding a software-based monitoring tool to the mix looks different in that context than it might have in 2019. I'm not sure exactly why they rolled it out right now, but the timing is interesting.
What Indian law actually says about workplace monitoring
This is where things get interesting. India doesn't have a specific law that governs employee monitoring in the workplace. The Digital Personal Data Protection Act (DPDPA) 2023 is now in force. It has obligations for organisations that process personal data. But workplace monitoring on company-owned devices occupies a grey zone.
On a company-issued laptop, TCS's legal position is fairly strong. The device belongs to the company. The network traffic passes through company systems. Most employment contracts in the IT sector include clauses saying that company devices may be monitored. Though, not everyone reads those carefully when they sign on Day 1 (annoying, I know).
That said, the DPDPA requires a "lawful purpose" for data processing. In many interpretations, it requires employees to be informed about what data is collected. TCS not making a formal announcement about this rollout could become a compliance question. It depends on how regulators interpret the Act as they apply it over the next few years.
There is no specific CERT-In advisory on this particular situation. But CERT-In has consistently encouraged organisations to implement endpoint monitoring as part of cybersecurity hygiene. This gives TCS cover on that front.
What TCS employees should practically do
If you're a TCS employee reading this, here's the practical reality:
- Assume the company laptop is monitored. It probably always was to some degree. Now there is a more structured tool in place.
- Don't use the company laptop for personal browsing or personal social media. Don't use it for anything you wouldn't want your employer seeing. This is just good practice regardless of any monitoring tool.
- Check your employment contract. There is almost certainly a clause about device monitoring. Read it.
- If you have concerns about what data is collected, you can raise a formal query with your HR or the data protection officer (DPO). Companies are required to designate a DPO under the DPDPA. That is your right.
- Personal devices are your own space. UPI transactions on your personal phone, your DigiLocker documents, or your Aadhaar-linked services. None of this is touched by software on a company-issued laptop.
That last point is worth stressing. A lot of people are anxious that their personal data is somehow at risk. It isn't. As long as you're keeping personal and professional devices separate. You should be doing that anyway.
The bigger picture: productivity monitoring is becoming normal
TCS isn't doing something unusual here. Even if the scale is unusual. Across the world, post-pandemic return-to-office pressure has accelerated the adoption of employee monitoring tools. Companies like Microsoft have built productivity scoring into their enterprise tools. Zoom and Teams have monitoring APIs. The direction of travel in corporate IT is more visibility.
In India specifically, the debate is only going to get louder. The IT sector employs millions of people. Most of them are in knowledge work that's hard to measure in traditional ways. Employers genuinely struggle to track productivity in hybrid and remote setups. Monitoring software is one answer to that problem. It's not the only answer, but it's the one a lot of companies are reaching for right now. In my experience, management always wants more data.
The concern from employee rights groups and privacy advocates is that this kind of monitoring can create a chilling effect. Employees self-censor their work habits. They avoid certain websites even for legitimate research. Or they feel constant low-grade anxiety about being watched. That is real. It is worth organisations thinking carefully about.
Honestly, the bigger issue here isn't whether TCS can legally do this. It probably can. The bigger issue is whether they communicated it transparently. Employees finding out about a monitoring rollout through news articles rather than an official HR communication is a trust issue. Trust in large organisations is harder to rebuild than it is to maintain. Workplace surveillance debates are becoming a recurring theme in Indian IT in 2026. And how companies handle transparency around these tools will matter a lot going forward.
For now, if you're on a TCS laptop, just proceed with the sensible assumption. Treat it like a company asset. It isn't a personal device. Because that's what it is.
If you want to understand more about how employee data and digital rights work in India, our guides section has a breakdown of the DPDPA and what it means for ordinary users.