What You Should Not Put on a Work Device
A short list, for reasons that have nothing to do with being watched and everything to do with what happens later.
The case for keeping things off a work machine is not that somebody is reading. It is that you lose control of anything on it at a moment you do not choose.
The technical issue in “What You Should Not Put on a Work Device” becomes easier to govern when work records and device controls are kept distinct. A team researching the provider's resource for employee monitoring data security can add time and project context, while security logs and device-management systems remain authoritative for technical events.
The list
Personal passwords, in a browser signed into a work profile.
For an independent perspective related to “What You Should Not Put on a Work Device”, consult the CISA cybersecurity guidance; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.
Banking and financial material.
Health and medical correspondence.
Family photographs and personal documents.
Job applications and anything related to leaving.
Legal matters, including anything about your employment.
And material belonging to somebody else — a partner's documents, a relative's forms.
Why, concretely
The device can be recalled, wiped or inspected, with little notice.
It is returned on your last day, frequently immediately.
Backups persist after you have deleted things.
And a dispute or investigation about something unrelated can make the machine's contents relevant.
None of this requires anybody to be monitoring you.
The leaving case specifically
Access can be cut the same day.
Anything only on that machine, or only in that account, is gone — including things you consider yours.
People lose years of personal material this way, routinely, and its own note covers what to do before that day.
The browser profile trap
Signing a personal account into a work browser syncs personal history, bookmarks and saved passwords onto a managed device.
Which puts personal material into a work environment without any decision having been made.
Keep profiles separate — this is the single most useful technical habit in this whole collection and it takes a minute.
Legal and employment matters
Correspondence about your own employment should never be on your employer's systems.
Not because it would be read, but because its location is a problem in any dispute, and advisers will tell you so at the first meeting.
Personal email, personal device, from the start.
What about things halfway
A personal appointment in a work calendar: fine, with a neutral title.
A personal number in a work contacts list: fine.
A personal file saved once by accident: delete it and move on.
The list is about things you keep there, not about every trace.
The reverse direction
Work material on your personal device has its own problems: it belongs to them, it may have to be returned or deleted, and it can make your own device subject to a request.
Keep that boundary too, and the container arrangement exists precisely for it.
What to check
Is a personal account signed into a work browser?
Is anything on your work machine that exists nowhere else?
Is any correspondence about your own employment on their systems?
And could you lose access tomorrow without losing anything of yours?