Data on personal phones and laptops nobody controls
- Aug 29
- 3 min read
Updated: 2 days ago
Introduction
Staff use their own phones for work email, their own laptops when working from home, and a messaging application to coordinate with customers. Customer names, addresses, order details and photographs of jobs are spread across half a dozen personal devices.
The business has no idea what is on any of them, no way to remove anything, and no control over whether they are encrypted, shared with family members or sold when replaced. This is simultaneously the most common working arrangement in small businesses and the largest unmanaged data risk most of them carry. It is also the one least likely to appear in any policy the business holds.
1. Data on personal phones and laptops is still your responsibility
The point that changes the framing.
Where somebody processes your customer data, the obligations remain yours regardless of who owns the device. Not controlling it does not transfer the responsibility, it simply removes your ability to meet it.
2. Find out what is actually on them
Start with a question.
Which applications people use for work, what is stored locally, whether photographs of jobs are in personal camera rolls, and what messaging platforms carry customer conversations. The answers are generally worse than expected. Photographs of jobs in personal camera rolls are almost universal in the trades.
3. Decide whether to permit personal devices at all
A genuine choice.
Providing equipment for anybody handling significant customer data removes most of the problem. For small businesses this is frequently cheaper than the alternative once the risk is priced properly.
4. Set basic requirements where you do permit them
Minimum controls.
Device passcode or biometric lock, automatic screen lock, encryption where available, current operating system, and no shared use with family members. These are simple and rarely stated anywhere. None of them costs anything and none is difficult to comply with.
5. Keep work data inside managed applications
Rather than on the device.
Accessing systems through an application, or through a browser, keeps data in a controlled place rather than in a local download or a camera roll. This is the single most effective practical control.
6. Deal with messaging applications explicitly
Where policy is usually silent.
Customer conversations on a personal messaging account are records the business cannot access, cannot retain properly and cannot produce in response to a request. Decide whether it is permitted and, if so, how those records are captured.
7. Have a policy people have actually read
Short and specific.
What may be used, what may be stored, what happens if a device is lost, and what happens when somebody leaves. A page that everybody has seen is worth more than a section in a handbook nobody has opened.
8. Plan for a lost or stolen device
Before it happens.
Who to tell, how quickly, whether remote wiping is possible, and how to assess whether it constitutes a breach. A personal device with no remote wipe capability and unencrypted customer data is a notifiable incident waiting to occur.
9. Remove access when people leave
The most commonly missed step.
Email, systems, shared drives and messaging groups, revoked on the day. Former employees retaining access on personal devices for years afterwards is extremely common and entirely preventable.
Consider what happens when somebody replaces or sells their phone. Work data on a device passed on or disposed of without wiping is a real and frequent exposure, and it is worth including specifically in whatever you agree with staff.
Conclusion
Recognise that the obligation follows the data rather than the device.
Establish what is actually stored on personal equipment, decide whether to provide devices for anybody handling significant data, set minimum requirements for locking, encryption and updates where personal devices are permitted, keep work data inside managed applications rather than local storage, address messaging applications explicitly, publish a short policy people have read, plan the response to a lost device, revoke access on the day somebody leaves, and cover disposal and replacement of devices.
.png)



Comments