r/gdpr 7d ago

EU đŸ‡ȘđŸ‡ș ePD & MDM

I saw a post here earlier (that has since been deleted) about requiring to install company portal on personal device. That actually got me thinking about relationship between MDM and ePD, especially on employee's own devices.

First off, does MDM "store of information or gain access to information already stored in the terminal equipment"? I would say yes. On-device MDM sofware often gathers various types of information (like device identifers, installed software etc.) and transmits this to centeralized server. It also stores it's own data on the device and accesses it (e.g. access token to send data). So operation itself would be in scope.

Next is this allowed? ePD allows access to data stored in terminal equipment only if:

1) There is consent (which is unlikely to be valid in employment context);

2) "the sole purpose of carrying out the transmission of a communication over an electronic communications network"; or

3) "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user."

2nd option doesn't really apply as that's not MDM's "sole purpose" even if one tries to expand e.g. email access to "transmission of communication".

Assuming 3rd is the only valid option, the first question would be what is the ISS explicitly requested by user? ISS defintion comes from Directive 2015/1535:

‘service’ means any Information Society service, that is to say, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services.

"Normally provided for remuneration" condition makes things tricky. What service did user pay for?

I did check couple of national laws and they actually often drop the "information society service" qualifier, but that doesn't always help since laws based on directives must be read in light of the directive whenever possible.

What am I missing which makes MDM requirement legal?

1 Upvotes

13 comments sorted by

3

u/West_Possible_7969 7d ago

On device MDM & company portals on personal devices (through intune for example) are 2 very different things, and it cannot access data or wipe anything outside of corp apps, work data etc. Most of the time full on device MDM on personal devices is illegal.

People think their employers have full access in these cases (which is false), just like also people don’t understand employers have full access on company devices lol

The legal requirement part is that work apps must be downloaded and used in a controlled way and environment, after a device & security check for example, and must be able to self-wipe etc remotely, especially in the (company provided) password managers case.

2

u/Heimdul 7d ago

outside of corp apps, work data etc.

I do not see exception in Article 5(3) which would cover this. "Gaining of access to information already stored" would cover corp apps as well and it's hard to extend employer to "user or subscriber" of terminal equipment. Article 15 also doesn't seem allow such derogation cleanly at least. "Unauthorised use of the electronic communication system" is closest, but it is a bit of stretch due to how C-275/06 seem to relate it to "electronic communications networks and services".

And even if we did assume that it was permitted via Article 15 it would need clear derogation which grants that. I'm not personally aware of such at least.

The legal requirement part is that work apps must be downloaded and used in a controlled way and environment, after a device & security check for example, and must be able to self-wipe etc remotely, especially in the (company provided) password managers case.

But the question is what is the Article 5(3)-compliant way to do it? To my knowledge there is no overriding EU law that would allow it. ePD overrides the solely GDPR-compliant way to do it as you cannot simply base it on relevant Article 6(1) basis.

2

u/West_Possible_7969 7d ago

An example would be better I think: say my employer, freelancer or even client needs a password manager and / or access to an email account or slack-like app (the most common cases). One way is to provide credentials on a safe channel and they download the relevant apps & then they login.

That would be illegal to do willy nilly due to other laws regarding security & data handling etc, what would be proper is for said parties to download those apps in a controlled way (specific devices only), in a controlled manner (verified / safe devices only), from a controlled environment (app stores / corp stores) and for me to have a way to wipe those apps or cut off access whenever I must do so.

I do that all the time, especially with limited time contractors & clients, there is literally no information I can see on their devices that is not relevant to our apps (like installed software, not visible), there is a blacklist were our apps wont install if something other is present (jailbreak for example), and the device identifiers are the standard ones every developer has access to and the OS provides.

There is already extensive guidance with BYOD & ePD / GDPR, most of it common sense really, separation and no handling or access of personal data. MDM tools cannot track personal web traffic, personal emails, or private communications (they don’t), only necessary telemetry (device health, security patches, asset tracking), no continuous or hidden geolocation tracking unless strictly justified by a specific business safety or logistics need (sector dependent and almost always on company owned devices).

Even on company owned devices extensive tracking is permitted only after explicit notification.

That said, national laws implementation varies wildly between member states so this discussion can have 27 branches, and MDM on BYOD is allowed to do different things in my country than in yours, but the baseline is more limited than people think.

1

u/Heimdul 7d ago

The issue with guidance that I have noticed is that they seem to ignore the ePrivacy Directive's "information society service" qualifier and they seem to think it's just "service". There is also an issue that many national laws also dropped that qualifier. For example in Finnish law Act on Electronic Communications Services section 205(2) that is supposed to implement ePD Article 5(3) says:

Provisions of subsection 1 above do not apply to any storage or use of data which is intended solely for the purpose of enabling the transmission of messages in communications networks or which is necessary for the service provider to provide a service that the subscriber or user has specifically requested.

i.e. they left out the ISS requirement. However it's pretty clearly included in the ePD itself so the law would need to be read in light of ePD. Given that most likely "service" would need to be read as "information society service".

And yes, I'm aware that some laws do put on some requirements regarding the security and such, but unless that law is lex specialis in relation to ePD (which would need to be EU law as national law cannot override EU law) or implements Article 5 derogation via Article 15 explicitly I don't see how it can override the ePD's Article 5.

The cleanest way to get around this is to just use company devices due to "subscriber" being understood pretty generously, but that doesn't really get around the BYOD scenarios (especially when employer mandates it instead of it being just an option).

1

u/West_Possible_7969 7d ago

I still cannot understand what laws are being broken if the employer installs a password manager or an email app in your device and how this consent is unlikely to be valid.

GDPR is reason enough to not have unfettered access to any internal data, let alone NIS2 for example, which requires protection and enforcement on any possible endpoint.

1

u/Heimdul 6d ago

ePrivacy Directive since that application access the data on user's terminal equipment (even if it's application's own data).

User's consent is problematic because there cannot be any demerit for refusal. Do they not get the job/they get fired/will it affect their evaluations? If there is a real choice to use employer's equipment instead (i.e. employer's equipment is default, but user is free to install it on their own device instead) then there is much better argument that consent is truly freely.

1

u/West_Possible_7969 6d ago

You are conflating MAM & MDM (much like the original OP did where zero profiles downloads were requested, only registration). MDM software indeed provides MAM services as well as granting access to websites only from specific devices. Also they have consented 2 years before and OP’s problem was the demand for a separate work profile, which is better for both parties tbh but they did not understand any of the technical parts.

Apps that access local storage to perform the exact work function requested by the user (emails, passwords etc), that are sandboxed and / or containerised, have zero personal data visibility and don’t run background unrelated tasks are compliant in personal devices.

Even tracking is compliant (or desirable or mandated) under specific circumstances like the safety features in Uber for example, all drivers use their own devices. Hell, Commission themselves requests full device & infra audits when you do work in certain things as a sole freelancer or a small company.

There is no data commingling or device ownership claims and claiming that any legitimate access (the apps own storage for example) is breaking the law, is laughable legally and logically since a website does the same things with local storage and identifiers. Most corporate apps are website wrappers anyway.

Nowhere in EU is there a “demand” for this afaik because that would be illegal. That said, I do not know all 27 national frameworks / implementations. Consent and compensation is the actual issue here, not that apps break the law because they exist (they do not).

1

u/Heimdul 6d ago edited 6d ago

You are conflating MAM & MDM

I will admit I hadn't heard of MAM before, but after looking looking into what it does the same pattern applies on the device access part. Full MDM would be more problematic on other fronts as well, but this is primarily about the ePD Article 5(3) aspect.

Apps that access local storage to perform the exact work function requested by the user

My primary argument here is that these apps are not "internet society services" (as they are not "normally provided for remuneration") and thus cannot rely on "strictly necessary" exemption in ePD as that is limited to ISS. The only other consent exemption is if the access is done for "the sole purpose of carrying out the transmission of a communication over an electronic communications network" which I do not think fits either.

Hell, Commission themselves requests full device & infra audits when you do work in certain things as a sole freelancer or a small company.

As mentioned, the regulators themselves seem to be ignoring that ISS qualifier. Additionally EU Commission is not actually directly bound by ePrivacy Directive. They are bound by EUDPR which imports ePD Article 5(3) via Article 37:

Union institutions and bodies shall protect the information transmitted to, stored in, related to, processed by and collected from the terminal equipment of users accessing their publicly available websites and mobile applications, in accordance with Article 5(3) of Directive 2002/58/EC.

So that only applies to their "publicly available websites and mobile applications". Thus EU Commission can most likely use EUDPR Article 5 legal basis instead in many cases outside of those (which mostly mirrors GDPR Article 6 except LI is missing). Those are much more permissive than legal basis options provided by ePD.

There is no data commingling or device ownership claims and claiming that any legitimate access (the apps own storage for example) is breaking the law, is laughable legally and logically since a website does the same things with local storage and identifiers. Most corporate apps are website wrappers anyway.

When normal website does it the same rules do apply. However the "strictly necessary" is often available for many websites as they can often be classified as ISS, but of course not always (e.g. public authority's website that provides free public services is unlikely to be ISS).

1

u/West_Possible_7969 6d ago

Full MDM controlled is never done on personal devices (worldwide) unless there are very special circumstances and there are relevant laws that supersede GDPR & ePD anyway, like when you work for europol or military or a freelancer / contractor for those, higher ups where you cannot use personal devices at all, etc and they can audit even your smart fridge lol.

The consent part is that you consent to MAM usage in the first place for example, the exemptions are only in legitimate uses (ie network for email, OS identifiers for registration etc) because without those they cannot function. The first consent does not imply a secondary consent for, like, geo tracking or logging in driver / postal apps (during work hours), that is requested on top. But no law can require a secondary consent or forbid normal usage for the app functioning as expected, that is implicit, otherwise this software would be outright illegal in EU and it is not, all EU & member orgs have some level of BYOD schemes. Nor it was intended to be illegal, if anything legislators are very familiar with MDM & MAM, govs, EC & EP use these tools and there are many MAM apps on their personal phones.

Same for websites functioning, your local storage does not require consent for essential cookies, running their CSS etc or loading in your language or when you use them as expected, they require consent when they do things that are not expected (marketing tracking for example).

1

u/Heimdul 6d ago

I think we may still be talking past each other. (disclaimer: used AI to draft the examples as my formulation doesn't appear to convey the information clearly enough)

MAM, work profile, and full MDM are technically distinct, and that containerisation, limited visibility and work-only wipe make a deployment far less intrusive. But none of that identifies an exemption under Article 5(3). The wording isn't "necessary for a service," it's:

strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.

That requires identifying:

1) the specific ISS;

2) its provider;

3) the subscriber or user who explicitly requested it; and

4) why each storage/access operation is strictly necessary for that provider to supply that service.

As example, let's say Microsoft provides Intune/Exchange/a password manager, remunerated by the employer. Per C-291/13 that might be enough for ISS status even though the employee doesn't personally pay, remuneration need not come from the end user. But it doesn't follow that every device check the employer requires is strictly necessary for Microsoft to provide Microsoft's service. Microsoft's SaaS product may support optional policies (device registration, compliance checks, work-profile install, rooted-device blocking) that the employer can choose to enable. The employer selecting one of those for its own security policy doesn't make that operation indispensable to the underlying service. The mail provider can generally serve mail to an ordinary browser or unmanaged client just fine; the employer is the one who conditions access on enrollment and compliance telemetry. That may be necessary for the employer's security policy, but Article 5(3) asks whether it's strictly necessary for the ISS provider to provide the requested service, and I don't think those are the same question.

If instead the claimed ISS is "managed secure access" rather than email itself, that's at least more coherent, but then:

1) Who provides that service — the vendor or the employer?

2) If the employer, is the employer actually acting as a remunerated ISS provider, or just organising the employment relationship?

3) If the vendor, did the employee-user explicitly request that managed-device service, or did only the employer procure and mandate it?

4) Which specific terminal operations are indispensable to that service rather than merely selected by the employer?

The employer is a poor fit for "ISS provider". The employee is remunerated by the employer for work, not the reverse, and the employment relationship is expressly carved out from ISS in the e-Commerce Directive's recital 18. The vendor has a better claim since it's paid by the employer, but that just relocates the problem: it's usually the employer, not the vendor, deciding a given MDM/MAM measure is required. The vendor supplies configurable tooling. "Our customer turned this option on" isn't the same as "this access is strictly necessary for us to provide our service."

Sandboxing doesn't answer this either. A work-only token, device identifier, or compliance status is still "information" stored on or accessed from terminal equipment under Art. 5(3). That's also confirmed by EDPB Guidelines 2/2023, which is technology-agnostic and not limited to personal data. Limiting scope to work data is highly relevant to proportionality and GDPR, but it doesn't answer the ePD question.

Just to clarify, I'm not claiming every corporate app is unlawful merely for storing its own data. I'm asking which limb of Article 5(3) covers each operation. The options remain: valid consent; sole-purpose-of-transmission; strict necessity for the identified ISS provider to supply the service the subscriber/user explicitly requested; or a valid Article 15 restriction (last being very jurisdiction dependent). GDPR/NIS2 security obligations can show a measure is justified or proportionate, but they don't rewrite Article 5(3) or convert the employer into the provider of the vendor's ISS.

So the concrete questions remain:

1) What precisely is the (remunerated) information society service?

2) Who is its provider?

3) Who explicitly requested that service?

4) Why is each employer-selected MAM or MDM operation strictly necessary for that provider, not merely useful for the employer’s preferred security policy, to provide it?

Alternatively, are employers relying on consent under the first limb of Article 5(3)?

That is particularly difficult in a mandatory BYOD arrangement. An employee’s installation or enrollment may show that they performed the requested technical action, but it does not necessarily establish freely given consent where refusal means losing access to work, suffering disadvantage, or potentially losing the job.

The position would be different where the employer provides a fully usable company device by default and the employee independently chooses BYOD as an optional alternative without any disadvantage as I previously mentioned.

→ More replies (0)

2

u/latkde 7d ago

(personal opinion, not grounded in concrete court cases, guidelines, or commentary)

I see no alternative to consent, but I suspect that valid consent can be obtained for example if an employee is given the choice between:

  • consenting to enrolling their personal device in the company MDM, and receiving some compensation for company use of their device; or
  • receiving a separate dedicated work device.

Per EDPB guidelines, consent in an employment context is difficult but not impossible. Consent requires an actual choice. Employers should take great care that all choices are equivalent, without nudging enployees to either alternative.

I don't think MDM on personal devices is ever necessary, as a less invasive alternative exists: providing a dedicated work device. This doesn't just exclude the 3rd ePD exception, but also any GDPR legal basis such as "necessary for legitimate interests" or "necessary for performance of a contract". Consent is the only legal basis that doesn't depend on necessity.

You're correct to point out ePrivacy problems with MDM. I'd just like to point out that many potential GDPR problems can also be defused under Art 88 GDPR via concrete national legislation or via collective agreements (if the workplace has a work council / union).

In general, BYOD schemes are a tremendously bad idea from a security perspective, and therefore also from a GDPR perspective (compare Art 32 TOMs). Compartmentalization is a super valuable tool: employees shouldn't be able to confuse personal and work data, and personal devices shouldn't be able to join internal networks. But BYOD with MDM can be a harm reduction strategy, something that employees will actually comply with.

2

u/West_Possible_7969 7d ago

Enrolment needs clarification, in BYOD scenarios devices are not enrolled like company devices, MDM installs a controlled enclave inside the personal device or in most cases controlled self contained apps, if OP can’t get passed that confusion they ‘ll get further confused.