Tata Consultancy Services (TCS) has deployed a Digital User Experience Monitoring tool on some company-issued employee laptops, raising questions about whether the technology is primarily being used to strengthen data security and IT infrastructure or could also enable closer monitoring of employee activity. According to sources cited by Moneycontrol, the tool can provide visibility into applications accessed on employee devices and the amount of time spent on them.

The deployment has reportedly created an internal debate around two competing objectives: protecting sensitive client and company information from data leaks while maintaining appropriate boundaries around workplace surveillance. TCS has not formally disclosed the name of the software, its vendor, the precise categories of employee information collected or which teams within the company can access the data.

What Is TCS Monitoring On Employee Laptops?

The monitoring technology reportedly deployed by TCS is described as a Digital User Experience Monitoring tool. Such tools are generally designed to help IT teams understand whether employee devices, applications and digital workplace systems are functioning properly.

According to the Moneycontrol report, the tool installed on some TCS company-issued laptops allows the company to see applications accessed by employees and the amount of time spent on those applications. The report does not establish that TCS is using the system specifically to evaluate employee productivity or take disciplinary action.

That distinction is important because digital experience monitoring and employee surveillance can involve overlapping technical capabilities while serving different purposes.

What The Report Says About The Tool

Monitoring AreaWhat Has Been Reported
DeviceCompany-issued employee laptops
Tool typeDigital User Experience Monitoring
ApplicationsApplications accessed can reportedly be viewed
Time informationTime spent on applications can reportedly be viewed
VendorNot disclosed by TCS
Software nameNot disclosed by TCS
Exact data collectedNot disclosed
Internal data accessNot disclosed
Formal employee communicationNot reported by TCS
Primary stated purposeNot formally clarified by TCS

The absence of these details is central to the current discussion. Without knowing the software’s complete capabilities, it is difficult to determine exactly how extensive the monitoring is.

Why Companies Use Digital Experience Monitoring

Digital experience monitoring is not inherently an employee-surveillance technology.

Large organisations operate thousands or even hundreds of thousands of laptops and software applications. IT teams need visibility into problems such as applications freezing, slow systems, connectivity issues and performance bottlenecks.

Pareekh Jain, CEO of EIIRTrend, told Moneycontrol that monitoring application usage and time spent can help organisations understand whether applications are working properly or hanging, particularly when a company manages infrastructure for a client. He also noted that the same capabilities can potentially be used for surveillance.

This creates a technical overlap between legitimate IT monitoring and employee monitoring.

Security And IT Uses

A monitoring platform can potentially help organisations:

  • Identify malfunctioning applications
  • Detect unusual device behaviour
  • Investigate potential security incidents
  • Understand application performance
  • Identify software or infrastructure bottlenecks
  • Improve digital workplace performance
  • Detect suspicious activity on endpoints
  • Support IT troubleshooting

The key issue is therefore not simply whether monitoring exists, but what information is collected, why it is collected, how long it is retained and who can access it.

Security Is A Major Concern For TCS

TCS handles sensitive information belonging to large global clients, making endpoint security an important part of its operating environment.

The company’s published security policy says TCS has security controls covering physical, logical, personnel and information security, including cybersecurity. It also says the company maintains a framework for identifying weaknesses, protecting against exploitation, detecting violations and responding to security incidents.

TCS has also publicly described endpoint-monitoring solutions in its cybersecurity work. In one case study, the company said it monitored more than 7,500 devices to analyse, detect, report and respond to suspicious activity. The system included behaviour analysis and threat-hunting capabilities.

Why Endpoint Visibility Matters

Security ChallengeHow Endpoint Monitoring Can Help
MalwareIdentify suspicious behaviour
Data leakageDetect unusual activity
Unauthorised softwareIdentify applications running on devices
Security incidentsProvide investigation data
Vulnerable endpointsImprove device visibility
ComplianceSupport security controls and audits
Insider threatsDetect unusual patterns

For an IT services company working with sensitive client systems, endpoint visibility can therefore be an important component of cybersecurity.

However, security monitoring needs to be carefully separated from unnecessary employee surveillance.

Where Security Monitoring Can Become Employee Surveillance

The same technical information that helps an IT department troubleshoot a laptop can potentially provide detailed information about an employee’s working patterns.

For example, application-level data can reveal which software a person uses, how frequently they use it and how long the application remains active. Depending on the system’s capabilities, additional monitoring could potentially extend to websites, files, network activity or other device events.

The Moneycontrol report specifically identifies applications accessed and time spent as information reportedly visible through the tool. It does not establish that TCS is collecting all of these additional categories.

This distinction should be maintained when assessing the issue.

The Core Privacy Questions

QuestionWhy It Matters
What data is collected?Determines the level of employee visibility
Why is it collected?Separates security from productivity surveillance
Who can access it?Limits potential misuse
How long is it retained?Determines long-term privacy exposure
Is monitoring disclosed?Employees need transparency
Is data aggregated?Aggregation can reduce individual surveillance
Can employees challenge misuse?Provides accountability

Until TCS provides further information, several of these questions remain unanswered.

Lack Of Formal Communication Adds To Concerns

The controversy has been intensified by the reported lack of formal communication about the deployment.

Moneycontrol reported that TCS had not formally responded to questions about the software’s identity, vendor, capabilities, data collected or internal access. The report also noted that IT and business-process-management companies have been using employee-monitoring tools for years, but said the absence of formal communication around the TCS deployment had contributed to speculation.

Transparency is particularly important when monitoring software is installed on employee devices because employees may reasonably want to know what information is being collected about them.

A clear policy can explain the purpose of monitoring, categories of information collected, retention periods and circumstances in which individual-level data can be reviewed.

TCS Already Has A Broader Security And Privacy Framework

TCS’s published policies indicate that information security and privacy are already formal components of its corporate framework.

Its security policy says the company has an independent security organisation led by a Chief Information Security Officer and that its security-management system is periodically reviewed. The policy also covers employees, business associates and external parties with access to TCS infrastructure and information resources.

TCS’s annual report also states that the company has an information-security policy covering cybersecurity, a cybersecurity framework aligned with the NIST Cybersecurity Framework and a global privacy policy covering employees, applicants, customers, partners and other stakeholders whose personal data is processed.

This existing framework makes the current question more specific: how does the newly reported laptop-monitoring deployment fit within those established security and privacy controls?

How The IT Industry Is Handling Employee Monitoring

Employee-monitoring technology is not unique to TCS.

Large IT and business-process companies have increasingly relied on endpoint-management, cybersecurity, digital-experience and workforce-management technologies as employees work across offices, homes and client environments.

The distinction between these systems can sometimes become difficult for employees because several tools can collect overlapping technical information.

The debate has also surfaced elsewhere in India’s technology sector. Moneycontrol previously reported online discussion around employee activity-tracking tools at technology companies, including concerns about pressure created by constant monitoring.

That broader debate means companies increasingly have to balance cybersecurity requirements with employee expectations around privacy and autonomy.

Security Monitoring Vs Employee Surveillance

Security MonitoringEmployee Surveillance
Focuses on protecting systemsFocuses on observing individuals
Detects security threatsTracks behaviour or activity
Usually tied to defined security risksCan extend to productivity measurement
Uses access controlsRequires strong governance
Should have a defined purposeCan become intrusive without safeguards
Often monitored by security teamsMay involve managers or HR

In practice, a single technology can potentially support both types of activity. Governance and purpose therefore become as important as the technology itself.

What TCS Employees And Clients May Watch Next

For employees, the most important information would be an official explanation of what the software does and what data it collects.

For clients, the issue is also relevant because TCS manages sensitive information and technology infrastructure for businesses across industries. Any endpoint-monitoring system must be governed in a way that protects both employee information and client data.

TCS’s existing security policy emphasises protection of information and assets, compliance with legal and regulatory requirements and third-party and supply-chain risk management.

The reported deployment could ultimately strengthen security if it is narrowly configured for that purpose. Conversely, insufficient transparency could create unnecessary employee concerns even if the underlying technology is legitimate.

The Bigger Picture

The TCS monitoring debate reflects a broader challenge facing large technology companies: the same digital tools that provide better cybersecurity and IT visibility can also create unprecedented visibility into employee behaviour. As companies expand endpoint security, zero-trust architectures and digital workplace analytics, the boundaries between protecting a device and monitoring its user are becoming increasingly important.

For TCS, the immediate issue is less about whether monitoring technology should exist and more about transparency and governance. The company has publicly documented cybersecurity and privacy frameworks, but the specific capabilities and governance arrangements surrounding the newly reported tool have not been publicly clarified. That leaves room for legitimate questions about data collection, access and purpose.

Looking Ahead

TCS may face increasing pressure to explain the scope and purpose of the monitoring deployment, particularly if the technology is installed broadly across company-issued laptops. Clear communication covering the software vendor, data categories, access rights, retention policies and permitted uses would help distinguish security monitoring from employee surveillance and reduce uncertainty among workers.

The broader IT industry is likely to face the same challenge as workplace technology becomes more sophisticated. Cybersecurity teams need detailed visibility to protect corporate and client environments, but employees also need reasonable expectations about how their digital activity is observed. The companies that establish clear boundaries, strong access controls and transparent policies will be better positioned to use monitoring technology without undermining workplace trust.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.