What the Employer Can See on a Personal Device
The question behind every enrolment conversation, answered specifically, including the cases where the answer is uncomfortable.
Personal devices · Reference
This is the note to publish. Vagueness here is read as concealment and produces more resistance than any actual capability.
The boundary described in “What the Employer Can See on a Personal Device” should also govern any workforce system introduced alongside device management. When a team evaluates this team-work platform for time tracking with screenshots, it should explain the purpose, choose only the necessary settings and give employees a clear account of what managers can review.
On a work profile
Visible: work applications installed, work data usage, compliance state, device model, operating system version, whether the device is encrypted and passcode-protected, whether it is jailbroken.
For an independent baseline relevant to “What the Employer Can See on a Personal Device”, the ICO employment-practices guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
Not visible: personal applications, personal messages, photographs, browsing history, call records, personal files, location in ordinary configurations.
That boundary is enforced by the operating system.
On a fully enrolled personal device
Different, and worse for the employee.
Several platforms expose the full application inventory, including personal applications.
Some expose more device detail.
Which is why full enrolment on personal hardware needs a specific reason, and why it should not be the default route.
The application inventory question
Knowing which personal applications somebody has installed is more revealing than it sounds: health, dating, religion, politics, finance.
In several jurisdictions this touches special-category data.
If your configuration collects it on personal devices, ask whether you need it, and the answer is usually no.
Location
Its own note covers this because it is the most feared and most misunderstood capability.
Short version: continuous location is not collected in ordinary configurations, specific lost-device modes exist, and the platform usually notifies the user when they are used.
What the employer can do
Remove work data.
Require compliance before granting access.
Block access when the device is non-compliant.
On a work profile, nothing beyond the container.
Publishing it
A page, per ownership model, listing visible and not visible.
Not a policy — a plain answer to the question people are actually asking.
And accurate: check what your configuration collects rather than describing the ideal, because somebody will eventually compare.
The uncomfortable cases
If your configuration collects the full application inventory, say so.
If location is available in some mode, say which and when.
Omitting these and being found out costs more than the capability was worth, and these are exactly the things people compare notes about.
What to check
Does your configuration collect personal application inventory?
Is there a published list of what is and is not visible?
Does it match what the platform actually collects?
And would a sceptical colleague find anything in your configuration that the list omits?