LABOUR LAW

Is Employee GPS Tracking Legal in India? What the DPDP Act Allows

India has no single employee-monitoring law, but location and biometric data are personal data under the DPDP Act 2023. Here is the lawful basis, the notice and proportionality tests, and a tracking design that stays on the right side of the line.

Employee marking GPS attendance on a phone at a work site

There Is No Single Employee-Monitoring Law, So Several Rules Apply Together

The short answer is yes: an employer in India can lawfully track an employee's location for attendance and work-related purposes. The longer answer is that the legality depends on how you do it, because no single statute says 'GPS tracking of staff is permitted' or 'prohibited'. Instead, four sources of law shape what is acceptable.

The first is the Digital Personal Data Protection Act 2023 (DPDP Act), which treats any data that identifies an individual, including their location and their face, as personal data and imposes duties on the organisation that decides how it is processed. The second is the constitutional right to privacy recognised by the Supreme Court in 2017, which requires any intrusion to be lawful, necessary and proportionate. The third is the Information Technology Act 2000 and its rules on reasonable security practices for sensitive personal data such as biometrics. The fourth is ordinary labour law: state Shops and Establishments Acts and the Factories Act require attendance and wage records, which gives you a legitimate reason to record when and where someone worked.

This guide is written for HR and operations managers, not lawyers, and it is not legal advice. Where your situation is unusual, such as tracking staff in another country or monitoring personal devices, take specific advice. For the common case of marking attendance with a phone at a work site, the rules below are enough to design something defensible.

  • DPDP Act 2023: governs collection, use, storage and deletion of location and biometric data
  • Right to privacy: tracking must be for a legitimate aim and proportionate to it
  • IT Act 2000 and SPDI Rules 2011: reasonable security practices for biometric information
  • State S&E Acts and Factories Act: the statutory duty to keep attendance records that justifies collecting the data at all

Lawful Basis: Consent or Legitimate Use for Employment

The DPDP Act allows personal data to be processed either with the individual's consent or for certain 'legitimate uses' listed in the Act. One of those legitimate uses is processing for the purposes of employment, including safeguarding the employer from loss or liability. Recording that an employee was present at a client site from 08:00 to 20:00 fits squarely within that employment purpose.

That does not mean you can skip consent altogether. Relying on legitimate use works for data you genuinely need to run the employment relationship. The moment you collect more than that, for example tracking a delivery executive's movements on a Sunday, or keeping a live location feed of a desk employee who is already inside the office, you are outside the employment purpose and back to needing free, specific and informed consent, which an employee can withdraw.

Practically, most employers do both: they document the employment purpose in the attendance policy and they take a signed acknowledgement from each employee. The acknowledgement is not what makes tracking legal; the necessity for attendance is. But the acknowledgement proves that the employee was told, which the DPDP Act requires. Our GPS attendance policy template contains the wording most SMEs need.

  • Attendance location captured at check-in and check-out is an employment purpose under the DPDP Act
  • Continuous tracking outside duty hours needs separate, withdrawable consent, and is rarely justifiable
  • Record the purpose in a written policy before you switch the feature on, not after a complaint
  • Keep the acknowledgement with the employee's personnel file or in the HR system

Notice, Purpose Limitation and Proportionality

The DPDP Act requires the organisation collecting personal data to give a notice that explains what is collected, why, and how the individual can exercise their rights or complain. For attendance tracking, the notice should say that location is captured when the employee marks attendance, that it is used to verify presence at the assigned site and to compute wages, that it is shared with client sites only as a presence record, and how long it is kept.

Purpose limitation means you cannot quietly reuse attendance location for something else. If the same data is later used to check whether a sales executive visited a competitor, that is a new purpose that was never disclosed. Decide the purposes at the design stage and write them down. Wage computation, presence verification, safety of lone workers and client billing are the four purposes most employers can justify.

Proportionality is the test courts apply to any intrusion on privacy: is the tracking necessary for the aim, and is there a less intrusive way to achieve it? Capturing a point location at check-in inside a geofence is proportionate to verifying attendance. Streaming location every 30 seconds for a warehouse worker who never leaves the premises is not. Field roles with a genuine safety or route-verification need can justify tracking during the shift, provided it stops when the shift ends or the employee checks out.

  • Notice must be in plain language and available in a language the employee understands
  • List every purpose you intend: attendance, wages, site safety, client billing
  • Match the intensity of tracking to the role: point-in-time for fixed sites, duty-hours only for field roles
  • Never track outside working hours, on leave days, or after check-out

Biometric Data Deserves Extra Care

Face and fingerprint data sit in a more sensitive category than location. Under the IT Act's SPDI Rules 2011, biometric information is expressly 'sensitive personal data', which means an organisation holding it must follow documented reasonable security practices, typically an information-security programme aligned with a recognised standard. The DPDP Act does not create a separate sensitive category, but its security and purpose-limitation duties apply with full force, and regulators will look hardest at biometric misuse.

The design choice that matters most is what the system stores. A product that keeps a gallery of employee photos and compares new selfies against them holds raw biometric images. A product that converts the enrolled face into an encrypted mathematical descriptor, discards the image, and compares descriptors holds far less usable data if breached. Ask any vendor which model they use. Attend Mitra stores encrypted face descriptors rather than photographs and adds a liveness check so a printed photo cannot be used to mark attendance.

Also decide who inside your company can see biometric or location data. A supervisor needs to know that a guard checked in at Gate 3 at 20:02. They do not need the raw face image or a map of the guard's movements for the last month. Role-based access that restricts these views is itself a security practice.

  • Prefer systems that store encrypted face descriptors, not photo galleries
  • Confirm the vendor's encryption at rest and in transit, and where the servers are located
  • Restrict raw biometric and location views to named administrators
  • Include biometric data in your breach-response plan; the DPDP Act requires notifying affected individuals and the Data Protection Board of a breach

Employee Rights and Your Security Duties

The DPDP Act gives employees, as data principals, the right to know what personal data you hold about them and how it has been processed, the right to have inaccurate data corrected, and the right to erasure once the purpose is served, where processing rests on consent. It also gives them a route to complain: first to your grievance officer, then to the Data Protection Board of India. Your attendance system should make these rights easy to honour rather than a scramble.

In practice this means an employee can ask for their attendance and location history, and you should be able to export it. It means the correction process for a wrong punch is not just a payroll convenience but a legal right, and it means when an employee leaves, you retain attendance and wage records for the period labour law requires (state S&E rules and the Code on Wages generally expect wage and attendance registers to be kept for several years) and then delete location and biometric data that no longer serves a purpose.

Security duties fall on you as the data fiduciary even when a vendor processes the data. Choose vendors who can show encryption, access logs and a breach process, and put those obligations in the contract. Attend Mitra publishes its security posture on its security page and maintains audit logs of who viewed or changed attendance records, which is the kind of evidence you need if an employee or a regulator asks how their data was handled.

  • Be able to export one employee's complete attendance and location history on request
  • Treat attendance correction as a data-accuracy right, with an approval trail
  • Set a retention schedule: wage-related records per labour law, biometric templates deleted at exit
  • Appoint a grievance officer and publish their contact in the notice

How to Design GPS Attendance That Stays Legal

The safest design collects location only at the moments attendance is marked, checks that moment against the assigned site's geofence, and stores the result as a presence record rather than a movement trail. This is what GPS attendance in most Indian attendance apps does by default, and it is exactly the level of intrusion labour law already justifies through the attendance-register requirement.

For field teams that need route verification, restrict tracking to the window between check-in and check-out, make it visible to the employee in the app when tracking is active, and let the employee end it by checking out. Never ask employees to install monitoring software on a personal device beyond the attendance app itself, and do not collect call logs, messages or app usage. If you supply company phones, say so in policy and limit monitoring to the same duty-hours principle.

Set the geofence radius honestly. A 100 to 200 metre radius around a factory gate reflects GPS accuracy and allows a check-in from the gate or the parking area. A 5 kilometre radius is not a geofence, it is a fig leaf. And because fake-GPS apps exist, use a system that flags mock locations on Android rather than relying on the coordinates alone; our guide on preventing GPS spoofing covers the detection methods. Attend Mitra's GPS attendance captures location at check-in and check-out, supports multiple geofences per company, and flags mock-location apps, with live tracking available as a separate, shift-bound option for field and security roles.

  • Default to point-in-time location at check-in and check-out, not continuous tracking
  • If continuous tracking is needed, bind it to the shift and show the employee when it is on
  • Use realistic geofence radii and mock-location detection instead of blind trust in coordinates
  • Keep the attendance app's permissions minimal: camera and location, nothing else
  • Do not monitor personal devices beyond the attendance function

Sample Notice Wording and a Compliance Checklist

A notice does not need to be long. Something like the following, translated into the working language of your staff, covers the DPDP Act's requirements: 'We record your location and verify your identity using your face when you mark attendance in the app. We use this to confirm you were present at your assigned site, to calculate your wages and overtime, and to provide presence records to the client at whose site you work. Location is captured only when you check in or out (and, for field roles, during your shift until you check out). Your face is stored as an encrypted code, not a photograph. Records are kept for the period required by labour law and then deleted. You may view or request correction of your attendance records through the app or by contacting our grievance officer at the address below.'

Pair the notice with a one-page policy that names the purposes, the retention period, who can access the data, and the correction process. Have every employee sign or digitally acknowledge it at onboarding, and re-issue it when you change what is collected. The checklist below is what an auditor or a Data Protection Board inquiry would expect to see.

  • Written attendance and tracking policy stating purposes, retention and access
  • Notice in plain language, acknowledged by each employee at onboarding
  • Tracking limited to duty hours; no tracking on leave days or after check-out
  • Biometric data stored as encrypted descriptors with restricted access
  • Vendor contract covering security, breach notification and data deletion at exit
  • Grievance officer appointed and contact published
  • Retention schedule documented; deletion of biometric templates on separation

Frequently Asked Questions

Can an employer track an employee's location in India without consent?
For attendance and other genuine employment purposes, the DPDP Act's legitimate-use ground allows processing without separate consent, but you must still give notice explaining what is collected and why. Tracking that goes beyond employment needs, such as after working hours or on leave days, requires explicit, withdrawable consent and is hard to justify.
Is 24x7 GPS tracking of employees legal?
It is very unlikely to pass the proportionality test. Tracking should stop when the shift ends or the employee checks out. Even for field roles with safety justification, tracking must be limited to duty hours, disclosed to the employee, and visible in the app while active. Off-duty tracking exposes the employer to privacy complaints and DPDP Act penalties.
Is face recognition attendance legal under the DPDP Act?
Yes, provided you give notice, limit the purpose to identity verification for attendance, secure the data, and restrict access. Prefer systems that store encrypted face descriptors instead of photos, and delete templates when an employee leaves. Biometric information is also sensitive personal data under the IT Act's SPDI Rules, so document your security practices.
Can employees refuse GPS attendance?
An employee can object, and you should have a grievance process to hear the objection. If the tracking is limited to attendance marking at the work site, it is a reasonable condition of employment linked to the statutory attendance record. Offer an alternative such as kiosk or QR check-in at the site if the employee's concern is about installing an app on a personal phone.
How long should attendance and location data be kept?
Keep attendance and wage records for the period your state Shops and Establishments Act or the Code on Wages rules require, since they support wage claims and inspections. Location coordinates beyond the presence record, and biometric templates, should be deleted once they no longer serve a purpose, typically at separation. Write the schedule into your policy.

Related guides

Ready to put this into practice?

Start your free trial or book a live demo with our team.