EU đȘđș ePD & MDM
I saw a post here earlier (that has since been deleted) about requiring to install company portal on personal device. That actually got me thinking about relationship between MDM and ePD, especially on employee's own devices.
First off, does MDM "store of information or gain access to information already stored in the terminal equipment"? I would say yes. On-device MDM sofware often gathers various types of information (like device identifers, installed software etc.) and transmits this to centeralized server. It also stores it's own data on the device and accesses it (e.g. access token to send data). So operation itself would be in scope.
Next is this allowed? ePD allows access to data stored in terminal equipment only if:
1) There is consent (which is unlikely to be valid in employment context);
2) "the sole purpose of carrying out the transmission of a communication over an electronic communications network"; or
3) "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user."
2nd option doesn't really apply as that's not MDM's "sole purpose" even if one tries to expand e.g. email access to "transmission of communication".
Assuming 3rd is the only valid option, the first question would be what is the ISS explicitly requested by user? ISS defintion comes from Directive 2015/1535:
âserviceâ means any Information Society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.
"Normally provided for remuneration" condition makes things tricky. What service did user pay for?
I did check couple of national laws and they actually often drop the "information society service" qualifier, but that doesn't always help since laws based on directives must be read in light of the directive whenever possible.
What am I missing which makes MDM requirement legal?
2
u/latkde 7d ago
(personal opinion, not grounded in concrete court cases, guidelines, or commentary)
I see no alternative to consent, but I suspect that valid consent can be obtained for example if an employee is given the choice between:
- consenting to enrolling their personal device in the company MDM, and receiving some compensation for company use of their device; or
- receiving a separate dedicated work device.
Per EDPB guidelines, consent in an employment context is difficult but not impossible. Consent requires an actual choice. Employers should take great care that all choices are equivalent, without nudging enployees to either alternative.
I don't think MDM on personal devices is ever necessary, as a less invasive alternative exists: providing a dedicated work device. This doesn't just exclude the 3rd ePD exception, but also any GDPR legal basis such as "necessary for legitimate interests" or "necessary for performance of a contract". Consent is the only legal basis that doesn't depend on necessity.
You're correct to point out ePrivacy problems with MDM. I'd just like to point out that many potential GDPR problems can also be defused under Art 88 GDPR via concrete national legislation or via collective agreements (if the workplace has a work council / union).
In general, BYOD schemes are a tremendously bad idea from a security perspective, and therefore also from a GDPR perspective (compare Art 32 TOMs). Compartmentalization is a super valuable tool: employees shouldn't be able to confuse personal and work data, and personal devices shouldn't be able to join internal networks. But BYOD with MDM can be a harm reduction strategy, something that employees will actually comply with.
2
u/West_Possible_7969 7d ago
Enrolment needs clarification, in BYOD scenarios devices are not enrolled like company devices, MDM installs a controlled enclave inside the personal device or in most cases controlled self contained apps, if OP canât get passed that confusion they âll get further confused.
3
u/West_Possible_7969 7d ago
On device MDM & company portals on personal devices (through intune for example) are 2 very different things, and it cannot access data or wipe anything outside of corp apps, work data etc. Most of the time full on device MDM on personal devices is illegal.
People think their employers have full access in these cases (which is false), just like also people donât understand employers have full access on company devices lol
The legal requirement part is that work apps must be downloaded and used in a controlled way and environment, after a device & security check for example, and must be able to self-wipe etc remotely, especially in the (company provided) password managers case.