Recordkeeping for testing programs.

Recordkeeping for Testing Programs

1. Meaning

Recordkeeping for testing programs refers to the systematic creation, maintenance, protection, retention, retrieval and eventual disposal of records generated through workplace testing programmes.

In an employment context, testing programmes may include:

  • Drug and alcohol testing
  • Medical fitness testing
  • Occupational-health examinations
  • Safety and competency testing
  • Skill or certification tests
  • Background and integrity verification
  • Random compliance testing
  • Workplace exposure or health monitoring
  • Fitness-for-duty examinations
  • Psychological or aptitude assessments where legally permissible

Recordkeeping is important because testing records can affect employment, disciplinary action, promotion, termination, compensation, workplace safety and litigation.

The employer must therefore maintain records in a manner that preserves accuracy, confidentiality, authenticity and procedural fairness.

2. Objectives of Recordkeeping

A proper testing-record system serves several purposes.

A. Proof that testing actually occurred

The employer should be able to establish:

  • Who was tested
  • When the test occurred
  • Why the employee was tested
  • What procedure was followed
  • Who conducted the test
  • What result was obtained

This becomes particularly important where an employee challenges disciplinary action.

B. Evidence of procedural compliance

Records can demonstrate whether the employer followed:

  • The employment contract
  • Standing orders
  • HR policies
  • Safety rules
  • Applicable legislation
  • Testing protocols
  • Collective agreements
  • Due-process requirements

C. Protection against arbitrary decisions

A documented testing system reduces the possibility that an employer will rely on an undocumented or selectively applied testing process.

D. Litigation preparedness

Testing records may subsequently become relevant in:

  • Domestic enquiries
  • Labour disputes
  • Industrial tribunals
  • Civil litigation
  • Writ proceedings
  • Criminal proceedings
  • Arbitration
  • Regulatory investigations

3. Types of Records

A comprehensive testing programme can generate several categories of records.

RecordTypical contents
Testing policyPurpose, scope and procedure
Employee consentConsent/acknowledgment where required
Test requestReason and authority for testing
Chain-of-custody recordHandling and transfer of specimen
Laboratory reportTest methodology and result
Medical reportFitness/occupational-health findings
Retest recordIndependent confirmation or challenge
Incident reportCircumstances leading to testing
Disciplinary recordAction based on verified results
Appeal recordEmployee's challenge and response
Retention logRetention and destruction dates
Access logPersons who accessed confidential records

4. Confidentiality of Testing Records

Testing records may contain highly sensitive personal information.

For example, medical testing can reveal:

  • Health conditions
  • Medication
  • Substance use
  • Disability
  • Reproductive information
  • Genetic information
  • Mental-health information
  • Other sensitive medical information

Consequently, unrestricted circulation of testing reports within an organisation is problematic.

The principle should generally be:

Access should be limited to persons who genuinely require the information for a legitimate employment, safety, medical, legal or compliance purpose.

A manager who merely needs to know whether an employee is fit for a particular task may not necessarily need access to the employee's complete medical report.

5. Accuracy and Integrity of Records

Testing records should be capable of demonstrating that the recorded result corresponds to the actual test.

Important safeguards include:

  1. Unique employee/test identification
  2. Date and time stamping
  3. Identification of the testing facility
  4. Identification of the testing professional
  5. Proper specimen identification
  6. Chain-of-custody documentation
  7. Secure storage
  8. Audit trails for electronic records
  9. Controlled alteration rights
  10. Preservation of original records

An electronically altered testing record can become highly problematic in litigation.

Where electronic evidence is relied upon, the organisation should also be able to establish its source, authenticity and integrity.

6. Chain of Custody

Chain of custody is particularly important in drug, alcohol, forensic and other specimen-based testing.

It establishes the history of the specimen from collection through final analysis.

A proper chain-of-custody record should identify:

  • Person collecting the specimen
  • Date and time of collection
  • Specimen identification number
  • Packaging
  • Seal
  • Person receiving the specimen
  • Laboratory transfer
  • Testing procedure
  • Storage
  • Disposal

Why it matters

Suppose an employee is dismissed because of a positive substance test.

If the employer cannot establish that the specimen tested by the laboratory was actually the employee's specimen, the reliability of the disciplinary case may be seriously undermined.

7. Positive Results and Confirmatory Testing

A preliminary or screening result should not automatically be treated as conclusive where the testing methodology requires confirmation.

A robust policy should distinguish between:

Screening test → confirmatory test → final determination → disciplinary/administrative decision

The records should therefore show:

  • Initial result
  • Confirmatory result
  • Testing methodology
  • Laboratory details
  • Relevant quality-control information
  • Any employee request for retesting
  • Final decision

This is particularly important because a testing programme may produce false positives, false negatives or inconclusive results.

8. Employee Access and Opportunity to Challenge

Fair testing systems should provide an appropriate mechanism for an employee to challenge a result.

Depending on the circumstances, this may include:

  • Requesting a copy of the report
  • Seeking an independent retest
  • Producing contrary medical evidence
  • Challenging the chain of custody
  • Challenging the testing methodology
  • Challenging procedural irregularities
  • Raising the issue in disciplinary proceedings

The existence of an appeal/retest mechanism should itself be recorded.

9. Retention Period

There is no single universal retention period applicable to every workplace testing record in India.

The appropriate period depends upon:

  • Nature of the test
  • Applicable labour legislation
  • Occupational-safety requirements
  • Medical-record obligations
  • Sector-specific regulation
  • Contractual requirements
  • Litigation limitation periods
  • Regulatory requirements
  • Internal retention policy

The employer should therefore create a documented retention schedule rather than retaining everything indefinitely.

A retention policy can specify:

Creation → Active use → Restricted archival → Litigation hold → Secure destruction.

10. Litigation Hold

If litigation, investigation or a disciplinary dispute is reasonably anticipated, routine destruction should be suspended for relevant records.

For example, if an employee challenges termination based upon a failed drug test, the employer should preserve:

  • Original test result
  • Laboratory report
  • Chain-of-custody documentation
  • Testing policy
  • Consent/acknowledgment
  • Communications concerning the test
  • Retest documentation
  • Disciplinary proceedings
  • Relevant electronic records

Failure to preserve relevant evidence can adversely affect the employer's case.

11. Privacy and Proportionality

Testing programmes must be balanced against employee privacy.

The Supreme Court's constitutional privacy jurisprudence recognises privacy as a fundamental right.

Therefore, employers should consider:

Purpose limitation

Collect information for a legitimate employment or safety purpose.

Data minimisation

Collect only information reasonably necessary for that purpose.

Restricted access

Limit access to authorised personnel.

Security

Protect records against unauthorised disclosure.

Retention limitation

Do not retain sensitive records indefinitely without justification.

Transparency

Employees should ordinarily understand the nature and purpose of the testing programme.

12. Testing Records and Disciplinary Proceedings

Testing evidence does not automatically establish misconduct merely because a report exists.

The employer may need to establish:

  1. Authority for the test
  2. Applicability of the testing policy
  3. Proper notice
  4. Valid testing procedure
  5. Authenticity of the report
  6. Reliability of the testing method
  7. Chain of custody
  8. Opportunity for challenge
  9. Connection between the result and alleged misconduct
  10. Proportionality of disciplinary action

A disciplinary authority should therefore distinguish between:

"The test report exists"

and

"The misconduct has been established through a procedurally reliable process."

13. Important Indian Case Laws

1. K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1

The Supreme Court recognised privacy as a fundamental right under Article 21.

The judgment is foundational for workplace testing because testing programmes may involve collection and processing of highly personal information.

Principle

Any testing programme involving personal or medical information should consider:

  • Legality
  • Legitimate purpose
  • Necessity
  • Proportionality
  • Procedural safeguards

Relevance

Employers should not treat employee testing records as ordinary administrative documents where the information implicates personal privacy.

2. District Registrar and Collector, Hyderabad v. Canara Bank, (2005) 1 SCC 496

The Supreme Court examined privacy in relation to access to personal and financial records.

Principle

The Court recognised that individuals have legitimate privacy interests in personal information and records.

Relevance

The case supports the broader principle that access to personal records should not be treated as unrestricted merely because the information exists within an institutional environment.

For HR testing systems, this reinforces the importance of controlled access to sensitive employee records.

3. People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301

The Supreme Court considered privacy concerns in the context of telephone interception.

Principle

Interference with privacy requires procedural safeguards.

Relevance

Although the case did not concern workplace testing, its reasoning is relevant to organisational surveillance and collection of personal information.

A testing programme should therefore operate through a defined procedure rather than unrestricted managerial discretion.

4. Selvi v. State of Karnataka, (2010) 7 SCC 263

The Supreme Court considered involuntary administration of scientific techniques such as narco-analysis, polygraph examination and brain-mapping.

Principle

The Court emphasised the constitutional significance of personal autonomy and protection against involuntary intrusion.

Relevance to employment testing

The case is relevant where employers consider intrusive testing methods. It demonstrates that the mere availability of a scientific technique does not automatically make its involuntary use legally permissible.

Testing policies must therefore distinguish between:

  • voluntary consent,
  • legally authorised testing, and
  • coercive testing.

5. State of Bombay v. Kathi Kalu Oghad, AIR 1961 SC 1808

The Supreme Court examined the scope of protection against testimonial compulsion under Article 20(3).

Principle

The Court distinguished between testimonial evidence and physical evidence.

Relevance

The case is important when analysing different forms of employee testing because not every form of physical evidence is legally equivalent to compelled testimony.

However, the constitutional analysis must depend upon the nature of the particular test and the circumstances in which it is conducted.

6. R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632

The Supreme Court recognised significant privacy protections relating to personal information and publication.

Principle

Individuals possess privacy interests in matters concerning their personal lives, subject to recognised legal limitations.

Relevance

Medical and testing information should not ordinarily be circulated or publicly disclosed merely because an employer possesses it.

The case supports careful handling of confidential employee information and restrictions on unnecessary disclosure.

14. Recordkeeping Failures That Create Legal Risk

Failure 1 — No written testing policy

If testing occurs without a documented policy, employees may challenge the employer's authority and procedure.

Failure 2 — Missing chain-of-custody documentation

This can undermine the reliability of specimen-based testing.

Failure 3 — No confirmation of positive results

Treating an initial screening result as final may create evidentiary problems.

Failure 4 — Excessive access

Circulating medical or testing results to unnecessary personnel can create privacy concerns.

Failure 5 — Inconsistent application

Testing one employee while ignoring similarly situated employees can create questions about fairness and selective enforcement.

Failure 6 — Poor electronic security

Sensitive testing records stored without appropriate access controls may be exposed to unauthorised persons.

Failure 7 — Destruction during litigation

Destroying relevant testing records after a dispute has arisen can seriously prejudice the employer's evidentiary position.

15. Recommended Recordkeeping Framework

An employer can structure its testing-record system around the following model:

1. Policy

Define when and why testing may occur.

2. Notice/Consent

Document the applicable employee acknowledgment or consent.

3. Test Request

Record the authority, reason and date.

4. Collection

Document specimen collection and identification.

5. Chain of Custody

Record every significant transfer.

6. Laboratory Analysis

Preserve the original laboratory documentation.

7. Confirmation

Record confirmatory testing where applicable.

8. Result

Classify the result appropriately—negative, positive, inconclusive, invalid, etc.

9. Employee Challenge

Preserve requests for retesting and responses.

10. Decision

Record the administrative or disciplinary decision and its reasons.

11. Secure Retention

Apply the applicable retention schedule.

12. Litigation Hold

Suspend destruction when legally required.

13. Secure Disposal

Destroy records securely when the lawful retention period ends.

16. HR Compliance Checklist

AreaGood practice
Testing policyWritten and accessible
PurposeClearly defined
Employee noticeDocumented
ConsentObtained where required
CollectionStandardised
Chain of custodyComplete
LaboratoryQualified/appropriate
ConfirmationUsed where necessary
ResultsAccurately recorded
AccessNeed-to-know
SecurityStrong technical and organisational safeguards
AppealsDocumented
RetentionDefined schedule
Litigation holdImplemented when necessary
DestructionSecure and documented
AuditPeriodic review

17. Conclusion

Recordkeeping is not merely an administrative aspect of workplace testing; it is part of the evidentiary and governance structure of the testing programme.

A legally defensible system should establish why testing was conducted, who authorised it, how it was performed, how the specimen or information was handled, how the result was verified, who accessed the information, how the employee could challenge it, and why any resulting employment action was taken.

In India, privacy jurisprudence—particularly K.S. Puttaswamy, together with the principles emerging from Canara Bank, PUCL, Selvi and Rajagopal—makes confidentiality, procedural safeguards and proportionality particularly important when testing involves sensitive personal information.

For HR purposes, the central principle can be stated simply:

A testing result should be treated as sensitive evidence requiring controlled collection, reliable verification, secure recordkeeping and fair use—not merely as an ordinary HR data point.

LEAVE A COMMENT