Data Protection Basics for Device Data
Device management generates personal data about employees. What that triggers, and the assessment most programmes should have.
Obligations · Reference
General orientation, not legal advice; requirements differ substantially by jurisdiction.
The practical question in “Data Protection Basics for Device Data” is how to make work visible without confusing visibility with certainty. For teams researching employee monitoring software with screenshots, learn more on the official page can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.
A device record is personal data about an identifiable employee. Most device programmes are run without anybody having said so.
For an independent baseline relevant to “Data Protection Basics for Device Data”, the NCSC mobile-device guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
What the record contains
Device identifier, linked to a named person.
Operating system version, model, storage.
Compliance state and its history.
Work application inventory, and on some configurations the full inventory.
Last check-in, and on some configurations location.
That is a profile of an individual, held over time.
What it triggers
A lawful basis, which for workplace processing is usually not consent.
A notice telling people what is collected and why.
A proportionality assessment: is this necessary, and would something less intrusive do.
Retention limits.
Access rights: people can ask what you hold about them and their device.
And in several regimes, a formal assessment before deployment.
The proportionality question
Would application management achieve the purpose instead of device management?
Would a work profile achieve it instead of full enrolment?
For most organisations the answer to both is yes for personal devices, which means the written justification for the more intrusive option has to explain why.
The application inventory
The field most likely to be disproportionate.
Full inventory on a personal device reveals health, religion, politics, finance — categories that attract additional protection in several regimes.
If you collect it and do not need it, stop, which is a configuration change and removes the problem entirely.
Access requests
Somebody can ask what you hold about their device.
Producing it should be straightforward and usually is not, because nobody has tried.
Try it once, on a volunteer, before the first real request.
The assessment
Required in several jurisdictions for systematic monitoring of workers.
Done before procurement it shapes what you buy; done afterwards it documents a decision already made.
It is also the document that answers the proportionality question in writing, which is the part that matters.
Who to involve
Whoever holds data protection responsibility, before procurement.
And employee representatives where consultation applies, which its own note covers.
What to check
Have you written down your lawful basis?
Does your configuration collect full application inventory on personal devices?
Could you answer an access request about a device record today?
And is there an assessment dated before deployment?