Confidentiality is not a peripheral courtesy in POSH proceedings — it is a distinct statutory obligation with its own penalty provision, and one of the most frequently violated aspects of the Act in practice. Loose office gossip, a poorly worded internal email, or a well-meaning but careless HR update can each constitute an actionable breach.
What Section 16 actually says
Section 16 of the POSH Act prohibits the employer, Internal Committee, or Local Committee from making known to the public, press, and media in any manner: the contents of the complaint, the identity and addresses of the complainant, respondent, and witnesses, any information relating to conciliation and inquiry proceedings, recommendations of the Committee, and the action taken by the employer — except where information regarding the justice secured to any victim, without disclosing her name, address, identity, or particulars, needs to be disseminated.
This is a broad prohibition, deliberately so. It covers not just the identity of the parties but the substance of proceedings, findings, and recommendations.
Who exactly is bound by this obligation
The confidentiality duty binds the employer, every member of the Internal Committee or Local Committee, and — by clear implication and reinforced through the associated Rules — anyone who comes to know the details through their role in the process, including HR personnel supporting the inquiry, witnesses who are examined, and administrative staff who might handle related paperwork or scheduling.
A common misconception is that confidentiality only binds the formal Committee members. In practice, if an HR business partner mentions to a manager "so-and-so filed a complaint against someone on your team," that is very likely a Section 16 breach, even though the HR partner isn't formally an IC member.
What counts as a breach in practice
Based on the kinds of situations we see referred to us, common breaches include:
- Informal disclosure within teams — a manager mentioning to colleagues that "there's an inquiry going on" about a specific person.
- Overly detailed communications to the wider organisation about the outcome of a case, even where names are omitted but details make identification easy (e.g., "the senior manager on the western region sales team").
- Committee members discussing case specifics with people outside the Committee, including spouses, friends, or unrelated colleagues.
- Poor document hygiene — case files, statements, or draft reports left accessible on shared drives without access controls.
- Leaks to media or public forums, particularly in cases involving well-known individuals or companies, which have become an increasingly visible risk in the era of social media call-outs.
The penalty for breach
Rule 12 of the POSH Rules, 2013 prescribes the consequence for breach of Section 16's confidentiality requirement: it constitutes a violation attracting a penalty as per the service rules of the organisation applicable to the person committing the breach, or, where no such service rules exist, a fine of ₹5,000. This is separate from and in addition to the broader employer penalties under Section 26 for non-compliance with the Act generally, which we cover in our post on penalties for POSH non-compliance.
Employers should note that the ₹5,000 figure, while modest on paper, is only the statutory floor — internal disciplinary action under the organisation's own service rules (which can include termination for serious breaches) often carries far greater practical consequences, and reputational damage from a leak can dwarf both.
Exceptions built into the provision
Section 16's proviso permits disclosure of information regarding the justice secured to a victim, without revealing her name, address, identity, or particulars — this allows organisations to communicate, in appropriately anonymised terms, that action was taken on a complaint, which supports organisational transparency about taking harassment seriously without compromising individual confidentiality.
Practical safeguards employers should build in
- Restrict case files to a defined, small circle — Committee members and essential administrative support only, with access logged.
- Brief every witness, at the start of their statement, on their own confidentiality obligation — witnesses are often the weakest link, since they aren't always as formally briefed as Committee members.
- Standardise any organisation-wide communication about outcomes to a pre-approved, genuinely anonymised template, rather than leaving individual managers to describe outcomes in their own words.
- Train Committee members specifically on Section 16 as part of onboarding, not just general inquiry procedure — see our post on POSH training frequency and best practices.
- Apply the same discipline in remote/virtual proceedings, where recorded hearings and shared documents create additional leak points — our guide on running an Internal Committee for remote and WFH teams covers secure handling of virtual case materials.
Key takeaway
Confidentiality under the POSH Act isn't a soft best-practice recommendation — it's a specific, enforceable obligation with its own penalty, and breaches are disturbingly easy to commit through ordinary workplace carelessness rather than deliberate wrongdoing. Treating confidentiality training and access controls as seriously as the inquiry process itself is one of the highest-leverage things an employer can do to reduce real legal and reputational risk.
Need expert POSH guidance?
Book a free consultation with Kanika Rao — call +91 9990107803 or
send your enquiry.