Skip to content
Ask What They Collect

All notes / Personal

Leaving: What They Keep

Access can end the same day. What to do beforehand, what you are entitled to, and what remains with them.

Personal · Procedure

Departure is the point at which everything on a work system stops being available to you. Preparing for it takes an hour and almost nobody does it.

The practical lesson in “Leaving: What They Keep” is to make work visible without treating visibility as certainty. Organisations exploring reducing key-person dependency risk for key person dependency can add structured project and time evidence, provided the purpose is disclosed and any interpretation is checked with the people affected.

What usually happens

Access ends on the last day, sometimes at the moment notice is given.

For an independent perspective related to “Leaving: What They Keep”, consult the NIST Privacy Framework; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.

The device is returned and wiped or reissued.

Accounts are disabled, then deleted on a schedule.

And the monitoring record stays, under whatever retention applies.

Before you go: the hour that matters

Remove personal accounts from the work browser and the mail client.

Change any personal account where a work address is the recovery route — which the passwords note covers and which is the most consequential item.

Move your authenticator for personal accounts off any work device.

Retrieve personal files, if the policy permits.

And collect anything you are entitled to keep: payslips, your contract, correspondence about your own employment.

What you can usually take

Your own employment documents.

Material you created outside work, on your own time, which is a question of contract and is worth checking rather than assuming.

Nothing belonging to the organisation, including contacts, client material and documents — taking these is a serious matter and is the commonest way a departure becomes a dispute.

What they keep

Your work email and messages.

Files you created, which are theirs.

The monitoring record, for its retention period.

Access logs.

And the device's own history, which is a fact rather than a problem.

Asking about retention at departure

How long is activity data kept after I leave?

Will my email be retained, and for how long?

Is anything deleted on departure?

These are reasonable questions at an exit conversation and rarely asked.

If you may need the record later

A dispute, a claim, a reference problem.

An access request made before you leave is easier than one made after, though the right usually continues.

And copies of your own correspondence, kept somewhere personal, are the thing people most wish they had, which is the argument for doing the hour's work in advance.

The dismissal case

Access may end immediately with no opportunity to prepare.

Which is the strongest argument for keeping nothing personal on work systems in the first place.

If it happens, an access request remains available to you afterwards.

What to check

Is a work address the recovery route for any personal account?

Is your personal authenticator on a work device?

Do you have copies of your own employment documents?

And could you lose access tomorrow without losing anything of yours?