The conference room where an off-colour remark once got made has moved. It now sits inside a Slack channel, a Microsoft Teams call, a late-night WhatsApp message, or an email thread that never really ends. For India’s growing base of remote and hybrid teams, the workplace is wherever the work happens. And the law that governs harassment at that workplace has had to stretch to keep up.
The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 was written for offices, factories, and client sites. Its architects assumed a physical space where people met face to face. That assumption no longer holds. Technology roles in India already show some of the highest flexible-work rates, with roughly 29% of technology employees working hybrid and 13% fully remote. When the desk moves home, the compliance obligation moves with it.
Here’s how digital work is reshaping what POSH compliance actually looks like on the ground.
1. The Definition of Workplace Now Reaches Your Home Office
The POSH Act’s definition of workplace was always broader than a single building. It covers any place an employee visits arising out of or during the course of employment. Courts have read that language generously for years, extending it to client sites, off-site meetings, and work-related travel.
Remote work pushed the boundary further. A home office, when used for work, now falls squarely within workplace jurisdiction. So does the co-working space or the café where an employee takes a client call. The employer’s duty to provide a safe environment doesn’t pause because the employee logged in from Bengaluru while the head office sits in Mumbai.
For HR teams, this is the foundational shift. Every other change on this list flows from it. If your POSH policy still describes the workplace as your registered office address, it’s already out of date.
2. Harassment Has Moved to Chat, Email, and Video Calls
The behaviour hasn’t disappeared. It has changed venue. Inappropriate comments that once happened in person now surface in direct messages, group chats, and video meetings.
Indian courts have kept pace. A 2022 Madras High Court ruling affirmed that harassment carried out through digital communication platforms falls within POSH Act jurisdiction. Tribunals have treated inappropriate emails and messages as actionable violations. As one legal analysis put it, the Internal Committee’s jurisdiction now extends to digital interactions even when the people involved are nowhere near the same location.
The platforms that now count as part of the virtual workplace include:
- Video conferencing tools like Zoom, Microsoft Teams, and Google Meet
- Official email and messaging apps used for professional purposes
- Collaboration platforms such as Slack and Teams
- Work-related social media interactions between colleagues
An offensive message sent at midnight from a personal device is still workplace harassment if it involves colleagues and arises from employment. The context of the interaction matters more than the platform it happened on. If you’re unsure where the line sits, TPB’s breakdown of what actually counts as sexual harassment under the POSH Act is a useful reference point.
3. Digital Evidence Is Now Central to Every Inquiry
An in-person complaint used to rest on testimony. A digital complaint rests on a record. Screenshots, chat exports, email trails, and call logs have become the raw material of many POSH inquiries.
That’s a double-edged development. Evidence is easier to preserve, but it’s also easier to alter, misread out of context, or lose. Internal Committees trained for verbal testimony now have to assess metadata, timestamps, and authenticity. The core guidance from practitioners is straightforward: keep records like screenshots and chat exports, and store them safely and privately for the duration of the investigation.
The process itself doesn’t change. Committees must follow the same POSH timelines and rules for a digital case as they would for an in-office one. What changes is the skill set required to run it well. Committee members who understand how to handle digital evidence responsibly are now essential, which raises the bar for who sits on the Internal Committee in the first place.
4. Cross-State Jurisdiction Complicates the Internal Committee’s Work
When a team is distributed across cities and states, a single complaint can involve a complainant in one location, a respondent in another, and an Internal Committee sitting in a third. The employer’s obligation doesn’t split across those geographies. It stays whole.
This creates real operational questions. Which IC handles the case? How does a virtual hearing protect confidentiality when participants join from home, sometimes with family nearby? How do you conduct a fair inquiry when nobody is in the same room? These aren’t hypotheticals for large employers running hybrid operations across India.
The practical answer most organisations are landing on is to build clear internal protocols that assign jurisdiction, standardise virtual hearing procedures, and protect privacy during remote proceedings. The complete POSH compliance framework offers the baseline that these protocols should sit on top of.
5. Complaints Are Rising as Reporting Becomes Easier
The numbers tell a clear story. Data compiled by Ashoka University’s Centre for Economic Data and Analysis with Business Standard, drawn from annual reports of 300 NSE-listed companies, shows that POSH complaints grew from 161 in FY14 to 1,729 in FY25, a rise of roughly 974% over the period.
Most experts read this as a healthy signal rather than an alarming one. Easier, more digital reporting channels lower the barrier to filing, and stronger awareness means more women recognise that a given behaviour is actionable. A KPMG analysis of India’s top 30 listed companies found a 6.2% increase in complaints in FY25, which it attributed to growing employee confidence in POSH mechanisms.
The same data carries a warning, though. That KPMG analysis also flagged a 21% rise in pending cases, pointing to strain on inquiry timelines. Rising complaints only reflect a healthier system if the resolution machinery can keep up. TPB’s deeper look at why POSH complaints in India stay under-reported puts these figures in fuller context.
| Metric | Figure | Source |
| POSH complaints, FY14 (300 NSE firms) | 161 | Ashoka CEDA / Business Standard |
| POSH complaints, FY25 (300 NSE firms) | 1,729 | Ashoka CEDA / Business Standard |
| Growth in reporting, FY14 to FY25 | ~974% | Ashoka CEDA / Business Standard |
| Complaint increase, top 30 firms, FY25 | 6.2% | KPMG India |
| Rise in pending cases, FY25 | 21% | KPMG India |
6. The SHe-Box Portal Has Taken Filing Fully Online
Digital work needed a digital reporting channel, and the government built one. The Ministry of Women and Child Development relaunched the SHe-Box portal on 29 August 2024, with the complaint registration feature going live on 19 October 2024.
SHe-Box is now the country’s central digital infrastructure for POSH compliance. It registers workplaces, captures Internal Committee details, accepts complaints from women across sectors, and routes each complaint to the correct IC or Local Committee for action. The portal also tracks the progress of an inquiry and updates the complainant on its status, all while maintaining confidentiality.
For employers, the portal isn’t optional background infrastructure. Following the Supreme Court’s directions in the Aureliano Fernandes v. State of Goa case, all workplaces, including private organisations, are expected to register their Internal Committees and workplace details on the platform. TPB’s full guide to the SHe-Box portal and how it works walks through what registration involves.
7. Data Privacy Now Collides With POSH Investigations
Digital evidence solves one problem and creates another. When an inquiry relies on chat logs, emails, and device records, the committee is handling large volumes of sensitive personal data. That responsibility now runs straight into India’s Digital Personal Data Protection Act, 2023.
An Internal Committee that pulls message histories, stores screenshots, and shares evidence among members is processing personal data. It has to do so lawfully, securely, and only to the extent the inquiry requires. The tension is real: POSH demands a thorough investigation, while data protection law demands restraint in how personal information is collected, stored, and shared.
Getting this balance right is now part of running a compliant inquiry. HR teams building digital POSH processes should understand how the DPDP Act reshapes their obligations before an incident forces the question.
In the End…
The POSH Act didn’t need rewriting to cover the digital workplace. Its language was broad enough, and India’s courts have interpreted it to reach home offices, video calls, and chat platforms without waiting for new legislation. What has changed is the practical work of compliance.
The policy that names only your office address, the Internal Committee that only knows how to run an in-person hearing, the process that ignores data protection while handling chat logs: each of these is now a gap. Closing them means updating your policy to name the virtual workplace explicitly, training your committee on digital evidence and remote hearings, registering on SHe-Box, and aligning your inquiry process with the DPDP Act.
Pull up your current POSH policy this week and read it against these seven shifts. If it still assumes everyone shares the same physical office, that’s the first thing to fix.

