If you run a field sales team in India and you are considering GPS tracking, the question you actually need answered is not “is this allowed.” It is “what do I have to do so that this is allowed.”
The short version: employee location tracking is not banned in India, and for most field sales operations it is straightforwardly lawful. But the Digital Personal Data Protection Act has changed what is expected of you as an employer, and a lot of businesses are still operating on assumptions formed before it existed.
Here is what an owner needs to understand.
There is no single law that governs workplace monitoring
The first thing to know is that India does not have one dedicated statute on employee monitoring. What you are actually dealing with is a combination of your employment contract, the Information Technology Act, the constitutional right to privacy as developed by the Supreme Court, and now the DPDP Act 2023 and the rules made under it.
This matters practically. It means there is no single clause you can point to that makes everything fine, and it means your own documentation — your contract, your policy, your notice to staff — is doing more of the work than most owners realise.
Under DPDP, you are a data fiduciary
The moment you start collecting and processing information about identifiable employees — location, attendance, expense records, visit history — you are handling personal data, and the law treats you as responsible for it.
That responsibility does not depend on your size. A twelve-person distribution business collecting check-in locations is in the same category as a large enterprise, even though the practical burden is smaller.
The employment-purpose ground, and its limits
DPDP recognises certain “legitimate uses” where personal data can be processed without obtaining separate consent. One of these covers processing for purposes of employment, and for protecting the employer from loss or liability.
For a field sales business this is the relevant ground, and it is genuinely helpful. Recording where a rep checked in, on a working day, on a company-issued device, disclosed in your policy, for the purpose of verifying visits and settling expenses, is the kind of processing this provision is designed to accommodate. You do not need to collect a separate consent form for it.
But — and this is the part that gets missed — that ground removes the consent requirement, not the rest of your obligations. You are still expected to:
- Give clear notice of what you are collecting and why
- Collect only what you actually need for that purpose
- Keep it secure
- Not keep it indefinitely
- Be able to respond when an employee asks what you hold about them
An employer who assumes “employment purpose” is a blanket permission and then tracks continuously, keeps everything forever, and never tells anyone, has not actually met the standard.
The three areas where it gets risky
Personal devices
The employment-purpose ground is a much weaker footing when the device belongs to the employee. Most SMBs in India install on personal phones because buying handsets is not realistic, and that is workable — but it needs genuine, specific, informed agreement from the individual, given in advance, not a line buried in an appointment letter.
We have written separately about how to handle this well without buying phones for everyone.
Outside working hours
Tracking a person’s location when they are not working is very hard to justify as an employment purpose, whatever device it is on. If your app can be bounded to the period between login and logout on a working day, bound it. If it cannot, that is worth knowing before you deploy it rather than after someone asks.
Anything biometric
Face data, fingerprints and similar identifiers sit in a more sensitive category and attract a higher standard. If you are considering biometric attendance alongside location, treat it as a separate decision requiring separate and explicit agreement, not as an extension of what you are already doing.
The consent problem nobody talks about
DPDP expects consent to be freely given. There is an obvious tension between that and consent obtained from someone whose job depends on giving it.
This does not mean employee consent is worthless. It means you should not build your entire position on it. The stronger structure for a field sales business is:
- Rely on the employment-purpose ground for work-hours tracking on work activity
- Meet the notice, minimisation, security and retention obligations properly
- Use consent as an additional layer for the genuinely optional parts, with a real ability to decline
An employee who could have said no and chose not to is a far more comfortable position than one who was told to sign.
What to actually do — a six-point checklist
- Write a monitoring policy and publish it before you install anything. One page. What is recorded, when, why, who can see it, how long it is kept, and who to contact with a concern.
- Get a written acknowledgement from each person. Not a signature buried in an offer letter — a separate acknowledgement of this policy.
- Bound tracking to working hours and be able to demonstrate it. If someone asks whether you can see them on a Sunday, you should be able to show them, not just assert it.
- Set a retention period and actually apply it. Six or twelve months is a defensible range for field activity data. Indefinite retention is not.
- Restrict who can see the data to the smallest set of people who genuinely need it, and use role-based access rather than giving everyone the admin login.
- Give employees access to their own record. This is both a likely expectation under the law and the single most effective thing you can do to reduce suspicion.
None of this requires a compliance department. It requires one page of writing and a couple of settings configured correctly.
Common questions
Can I track my field employees without telling them?
No. Covert monitoring is the weakest position available to you under every part of the framework, and it is also the fastest way to lose your team’s trust. Notice is not optional.
Do I need each employee to sign a consent form?
For work-hours tracking of work activity on a company device, disclosed in policy, generally no — that is what the employment-purpose ground is for. For personal devices, off-hours, or biometric data, you should be obtaining specific agreement.
Can an employee refuse?
On a company-issued device, refusing to follow a lawful, disclosed work policy is an employment matter like any other. On a personal device the position is considerably less clear-cut, and pushing it to a disciplinary conclusion is both legally weaker and practically worse than solving the underlying objection.
How long can I keep the data?
Only as long as you need it for the stated purpose. Set a defined period, write it in your policy, and delete on schedule.
What if the GPS is wrong?
Location accuracy varies with device, network and surroundings, and it will sometimes be wrong. Have a correction process, and never take an adverse decision against an employee on an uncorroborated location reading.
This article is general information for business owners, not legal advice. India’s data protection framework is still phasing in and the position may have changed since publication. Have your monitoring policy reviewed by a qualified professional before you roll it out.
Setting this up? Our field app rollout guide includes a one-page policy template you can adapt, plus announcement messages in English, Hindi and Bengali to send your team before installation. https://twib.online/field-app-rollout-guide/
