TCS Employee Monitoring Tool: Laptop Tracking Raises Privacy Concerns, Here’s What We Know

TCS Employee Monitoring Tool: Laptop Tracking Raises Privacy Concerns, Here’s What We Know

How Many TCS Employees Could Be Affected?

The scale of the reported deployment is one reason the story has attracted significant attention. TCS had a total workforce of 593,798 employees as of June 30, 2026, after adding 9,279 employees during the first quarter of FY27.

Media reports have therefore described the potential reach of the laptop-monitoring rollout as close to six lakh employees. However, this number should be treated as the approximate size of TCS’s workforce rather than proof that the monitoring software has been installed on every employee laptop.

What has been reported is that a Digital User Experience Monitoring tool has been deployed on company-issued devices. TCS has not publicly disclosed a device-by-device rollout figure.

Key scale facts

  • TCS workforce stood at 593,798 employees as of June 30, 2026.
  • Reports describe deployment on company-issued laptops.
  • The exact number of devices running the tool has not been publicly confirmed.
  • TCS has denied using the technology to track individual employee activity.
  • The software vendor and complete technical capabilities have not been publicly disclosed.

TCS Monitoring Controversy: What Is Confirmed and What Is Still Unclear?

A major problem with the discussion around the TCS employee monitoring tool is that confirmed facts, media reports and speculation are often being mixed together.

The available information can be separated more carefully:

QuestionCurrent Status
Has a DEX-type monitoring tool reportedly been deployed?Reported by multiple publications
Is it installed on company-issued laptops?Yes, according to reports
Can it provide information about applications accessed and time spent?Reported by Moneycontrol
Does TCS admit tracking individual employees?No
Does TCS say the tools are for network/security purposes?Yes
Is individual productivity scoring confirmed?No
Are screenshots or keystrokes being recorded?No verified evidence
Is the software vendor publicly confirmed?No
Is the exact data-retention period known?No
Who can access employee-level data?Not publicly established
Is every TCS laptop covered?Not publicly confirmed

This distinction is important. The existence of telemetry or Digital Experience Monitoring software does not automatically prove that an employer is using it for individual performance surveillance.

Recent TCS Cybersecurity Context

The monitoring discussion has also emerged shortly after a separate cybersecurity development involving TCS employee information.

On August 10, 2026, TCS said it had received threat-intelligence alerts alleging possible exposure of certain employee-related data. The company said its investigation found no credible evidence of a breach of TCS systems or customer environments.

According to TCS, the information referenced in that incident appeared to be more than four years old and limited to basic employee information. The company also said it had safeguards against the password-spray and MFA-fatigue techniques allegedly claimed by the attacker.

However, there is currently no verified evidence establishing that this security incident caused or triggered the reported DEX-tool deployment. The two developments should therefore not be presented as directly connected unless TCS confirms such a link.

This context is nevertheless relevant because it shows why cybersecurity, endpoint visibility and data-loss prevention are major priorities for a company handling sensitive enterprise and client information.

Why Would a Company Use a Digital Experience Monitoring Tool?

Digital Experience Monitoring is broader than simply checking whether an employee is working.

Enterprise IT teams can use endpoint and network telemetry to identify problems such as:

  • Applications repeatedly crashing
  • Slow login or boot times
  • Network connectivity problems
  • Poor application performance
  • Device-health issues
  • Security incidents
  • Unusual system behaviour
  • Availability problems affecting employees

This can help an IT department identify whether a problem is affecting one device, a group of users or the wider corporate network.

The controversy begins when technical telemetry can also reveal information about how a person uses the device. Application-usage information, for example, may be useful for troubleshooting but can potentially become sensitive when linked to a specific employee and interpreted as a measure of productivity.

That is why the crucial question is not simply “Does monitoring exist?” but “What data is collected, at what level, for what purpose and who can access it?”

Company Laptop vs Personal Laptop: Is There a Difference?

Another important distinction is that the reports concern TCS-issued corporate laptops, not employees’ personal computers.

Company devices are normally subject to enterprise security controls because they can contain corporate information, credentials, customer data and access to internal systems. Organizations commonly use endpoint-security, network-management and device-management software on such systems.

That does not mean every form of monitoring is automatically appropriate.

The privacy impact depends on factors such as:

  • What information is collected
  • Whether data identifies an individual employee
  • Whether monitoring continues outside working hours
  • Whether employees have been informed
  • How long information is retained
  • Who can access the information
  • Whether it is used for cybersecurity or performance evaluation

The fact that a device belongs to an employer therefore explains why security monitoring may exist, but it does not answer every privacy question surrounding the collection and use of employee data.

What Does India’s DPDP Law Say About Employee Data?

The Digital Personal Data Protection Act, 2023 specifically recognises employment-related processing as a possible legitimate use of personal data.

Section 7 of the Act includes processing for employment purposes and for safeguarding an employer from loss or liability, including areas such as prevention of corporate espionage and protection of trade secrets, intellectual property and classified information.

However, an important timing point needs to be understood.

As of August 2026, the DPDP framework is being brought into force in phases. The government notified the Digital Personal Data Protection Rules, 2025 and an implementation timeline in November 2025. Key provisions covering grounds for processing, notice, consent, legitimate uses, Data Fiduciary obligations and individual rights are scheduled to commence 18 months from November 13, 2025.

Therefore, it would be inaccurate to claim that all of these DPDP obligations already fully govern this particular TCS monitoring controversy today.

The Act nevertheless provides an important indication of how India’s developing data-protection framework approaches employee data: employers may have legitimate reasons to process information for employment and security, while the broader framework also establishes obligations around responsible handling and protection of personal data.

What Does TCS’s Own Privacy Framework Say?

TCS’s public privacy policy states that the company is committed to applicable data-protection and privacy requirements in the countries and regions where it operates.

The company also says it uses technical, organisational and security measures to prevent personal information from being lost, improperly accessed, altered or disclosed, and that access should be limited to people who have a business need to know.

There is an important distinction for employees. TCS’s public privacy notice says a separate Employee Privacy Notice applies to the employment relationship. TCS employees can access employee-specific privacy information through the company’s Ultimatix platform.

This makes the Employee Privacy Notice particularly relevant for workers who want to understand what information may be collected from company devices and the purposes for which that information can be processed.

What Should TCS Employees Check?

Employees concerned about the reported tool should avoid assuming that every device action is being secretly recorded. Instead, they can focus on the policies and information actually available to them.

Useful questions include:

  1. Check the Employee Privacy Notice: Review the current notice available through Ultimatix.
  2. Review acceptable-use policies: Company-issued laptops may have specific security and usage policies.
  3. Understand what software is installed: Do not disable corporate security or monitoring software without authorization.
  4. Separate personal and professional activity: Avoid storing unnecessary personal information on corporate devices.
  5. Ask how data is used: Employees can seek clarification about whether telemetry is aggregated, identifiable or used in performance decisions.
  6. Check data retention: Find out, where disclosed, how long endpoint or application-usage information is retained.
  7. Use official channels: Privacy, HR, information-security or compliance teams are more reliable sources than social-media speculation.

Could the Tool Be Used for Employee Performance Reviews?

At present, there is no verified public evidence that TCS is using the reported tool to score employees or make individual performance decisions.

The reported ability to identify applications and time spent does not by itself establish that these metrics are being fed into performance reviews.

This distinction matters because application time can be a poor standalone measure of productivity. Different jobs require different workflows, and an employee may spend substantial time in meetings, development environments, browsers, communication platforms, remote systems or other tools depending on the nature of their work.

Until TCS discloses additional information, claims that the DEX tool is directly being used for appraisals, promotions, terminations or productivity scoring should be treated as unverified.

Why Transparency Matters More Than the Software Name

The identity of the monitoring platform has not been publicly established, but knowing the product name alone would not resolve the privacy debate.

The more important questions are about configuration and governance.

The same enterprise technology can potentially be configured to collect limited technical performance data in one organization and more detailed endpoint information in another.

For employees, the critical questions therefore remain:

  • What telemetry is enabled?
  • Is information aggregated or linked to individuals?
  • Can managers access it, or only IT/security teams?
  • Is employee activity used in HR decisions?
  • How long is the information retained?
  • Can data be exported or shared with third parties?
  • What safeguards prevent misuse?

Clear answers to these questions would make it easier to distinguish legitimate Digital Experience Monitoring from employee surveillance.

Updated Bottom Line

The TCS laptop-monitoring controversy currently contains two different sets of claims that should not be confused.

Media reports say a Digital User Experience Monitoring tool deployed on company-issued laptops can provide visibility into applications accessed and time spent on them. TCS, however, has categorically denied tracking individual employee activity and says its tools operate at a macro level to support network performance, security, availability and employee experience.

There is currently no verified public evidence that TCS is recording employee keystrokes, taking screenshots, scoring individual productivity or using the reported DEX data in performance appraisals.

The biggest unanswered questions concern the precise data collected, whether it can be associated with individual workers, its retention period, who can access it and the exact governance controls surrounding the system.

Until those details are publicly established, the most accurate description is a reported enterprise-monitoring deployment that has generated employee-privacy questions—not confirmed evidence of individual employee surveillance.

More From Author

TCS laptop monitoring and employee device tracking on a company laptop

TCS Laptop Monitoring: What Employees Should Know About Tracking, Privacy and Work Activity

Mumbai vada pav stalls

Mumbai Vada Pav Stalls See Hygiene Changes Amid Maharashtra FDA Crackdown