The French data protection regulator's decision to fine Infosys Rs 2 crore is a necessary step to protect employee privacy in an era of pervasive workplace surveillance. Time-tracking systems, when designed without limits, can gather far more data than needed—such as keystrokes, idle times, and location—creating a culture of distrust.
By penalizing Infosys, the regulator sends a clear signal that even global tech firms must respect local data laws. The fine, though modest relative to Infosys's revenue, underscores that compliance is not optional. Employees have a right to know what data is collected and how it is used.
Supporters of the regulator argue that clear boundaries on monitoring actually benefit businesses by fostering transparency and worker morale. When staff feel watched excessively, productivity can suffer. The ruling encourages companies to adopt least-intrusive methods, like voluntary check-ins rather than constant tracking.
This decision aligns with GDPR's core principles of data minimization and consent. Other European regulators may follow suit, leading to a harmonized standard that protects workers across the EU. Infosys, as a major employer, should view this as an opportunity to lead by example in ethical data practice.