Skip to content
Ask What They Collect

All notes / What is collected

Work Device Against Your Own

The single distinction that determines almost everything: who bought the machine, and what follows from that.

What is collected · Analysis

Whose device it is settles most questions about what can be collected and what you can expect. The answer differs more than people assume.

The technical issue in “Work Device Against Your Own” becomes easier to govern when work records and device controls are kept distinct. A team researching hourly timesheet template for employees for hourly timesheet template can add time and project context, while security logs and device-management systems remain authoritative for technical events.

On a device the employer owns

They may install management and monitoring software.

For an independent perspective related to “Work Device Against Your Own”, consult the CISA cybersecurity guidance; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.

Company data on it is theirs; so is the machine.

Expectation of privacy is low, though not zero — several jurisdictions require that monitoring be proportionate and disclosed even on employer equipment.

And they can usually wipe it, recover it and inspect it, within whatever process applies.

On your own device

A great deal less is permissible.

Device-wide monitoring on hardware you bought is difficult to justify and increasingly restricted by the platforms themselves.

The usual arrangement is a work profile space: work applications and data in a managed space, the rest of the device outside it.

That separation is enforced by the operating system rather than by the employer's restraint, which is a stronger guarantee.

The container boundary

On a properly configured personal device, the employer sees the work side: which work applications, compliance state, device model and version.

Not personal applications, photographs, messages or files.

If you are unsure which arrangement you have, ask whether a work profile is in use — it is a short question with a clear answer.

The awkward middle

A personal device fully enrolled in employer management, rather than containerised.

This exists, usually for historical reasons, and exposes considerably more — on several platforms including the full list of installed applications.

It is worth knowing whether this is your situation, and it is a reasonable thing to raise.

Company-funded, personally chosen

A device the organisation paid for and you keep.

Legally this is usually theirs during employment, whatever the arrangement feels like.

Which is the gap that produces disputes at departure, and is worth clarifying in writing early rather than late.

The practical rule

Keep personal matters on personal devices and personal accounts.

Not because anybody is reading, but because the boundary is the thing that protects you and it costs nothing to maintain.

Its own note covers what should not go on a work machine.

Networks

Connecting your own device to a company network puts the traffic on their infrastructure, which may be logged.

The device is still yours; the connection is theirs.

A separate guest network, where offered, keeps that simple.

What to check

Who owns the device you are reading this on?

If it is yours and enrolled, is a work profile space in use?

Is any personal account signed in on a work machine?

And do you know what happens to the device when you leave?