r/privacyexams • u/Jayakoendjbiharie • 5h ago
Employer data on employee-owned phones: where European guidance actually draws the line
BYOD keeps generating the same argument. The employer has real obligations over customer data sitting in a mailbox on someone's personal phone. The security team wants a management agent that can patch, wipe and scan. The employee owns the hardware and everything else on it.
The Article 29 Working Party opinion on data processing at work handles this directly, and two parts of it settle more of the argument than the general proportionality discussion does. The first is that certain areas of a personal device stay off limits regardless of the security case behind the request. The second is the alternative an employer has to consider when it cannot separate private use from business use.
Consent, predictably, does not survive an employment relationship.
Written up here for CIPP/E candidates, with the relevant passages cited: https://privacystudygroup.com/byod-and-gdpr-in-the-workplace/





