3월 21, 2022

Protecting your personal information and privacy on a company phone

Joel Snyder

When you use a new employer-issued smartphone, or you use your own phone to read your work email, you might ask yourself, “Wait, did I just let my employer look at everything on this phone? Did I just give up my privacy?”

Well, maybe some, but probably not anything that should be of concern. There are three things protecting your information: the technology itself, your employer’s device policy and the law (at both federal and state levels).

Here’s a look at all three — and exactly where you are and aren’t protected.

 

Technology

All smartphones have a number of built-in features that can help maintain the boundary between your work life and personal life. Some of these features are for you to use just to keep things organized on your own phone. Samsung’s Dual Messenger capability, for example, lets Android phone users create two different accounts, such as a work account and personal account, in chat apps such as WhatsApp and Facebook Messenger. But these boundaries are more intended for organization than for actual privacy.

To really isolate things so that your employer can’t access personal data, you need Android’s Work Profile feature — a capability that doesn’t exist in iOS. When you establish a Work Profile on your Android phone, there’s true isolation between this profile and the rest of your smartphone.

In terms of privacy, if your employer has control of your Work Profile — which is how things are normally set up — then the information outside of that profile is absolutely off limits to them. They can’t see any of your private data, contacts, calendar events, messages, emails or camera roll. (Which means that you’ll need to back up these items yourself.)

But from a technological point of view, there are some things your employer can control outside of your Work Profile. For example, your employer may be able to keep you from installing certain apps, even on the personal side of your phone. They can also remotely lock your phone or erase it if necessary.

Your employer’s exact capabilities will depend on how your phone is set up. For example, many employers use a Bring Your Own Device (BYOD) approach to let you use your own phone for work but give them a little piece of the phone that they can protect for work purposes. In a BYOD environment, your employer may be even more limited in what they can do. On the other hand, some organizations use a Company Owned, Personally Enabled (COPE) approach. In a COPE environment, your employer still can’t reach into your private data, but they do have more control over the device settings, such as requiring a passcode to unlock your phone or tracking the device’s location.

 

Company policy and its affect on privacy

Your employer’s specific BYOD or COPE policy is also an important part of keeping your personal data private. In the U.S., employers have tremendous flexibility in what they can regulate. While the employer has the advantage in writing the policy that the employee has to agree with, these policies still have to be very specific in what types of information your employer can look at. If the policy doesn’t address a particular issue, then employers don’t have permission to overstep any privacy boundaries.

For employees, this means their employer’s BYOD or COPE policy must define all of the rules for data privacy. And if your employer says the information on your phone is considered private, then they cannot legally violate their own policy.

In the U.S., employees traditionally haven’t expected much privacy in employer-provided IT systems, such as company email — but that’s changing rapidly. When privacy issues have gone to court in the past, employers have usually won, because employer policies used to say, in effect, “You have no reasonable expectation of privacy on anything you do on our network.” In other words, if the policy says that particular information isn’t considered private, then you’ve been given notice that your employer can look at that type of data on your smartphone. This is true whether the device is personally owned (BYOD) or owned by the employer (COPE); U.S. law allows employers to enforce their device policies as long as the policies are clear and agreed to by the employee.

This imbalance in favor of employer access has changed as more people have started to bring their own smartphones and other personal computing devices to work. People have become much more sensitive to privacy issues, and policies have changed accordingly, giving greater respect to employee privacy and reassuring people that their private information will stay private.

The gray area emerges when an employer’s device policy doesn’t say anything about privacy. If there’s a question in court about what the policy says, the judges will likely ask, “Is there a reasonable expectation of privacy for this kind of information?” Employers can’t easily justify peeking into your smartphone for information that would normally be considered private. But a “reasonable expectation of privacy” can be interpreted very differently in different courtrooms.

 

Legal

Laws and regulations are third in this list because in the U.S. there are very few laws that directly protect your privacy, especially at the federal level. The Constitution doesn’t explicitly list privacy as a right, but the Supreme Court has stated that there are “penumbras” (shadows) within the Bill of Rights that give us a general right to privacy. These penumbras are generally cited when a law goes too far and invades our privacy rights — which is very different from protecting an employee’s right to privacy on their smartphone, no matter who paid for it or who manages it.

Since the federal government offers few protections, privacy rights are now determined state by state. Traditionally, California state law advances these protections faster than other states, but other states are also legislating in this area. The general direction across most of the U.S. is for state legislatures to increase privacy rights, but these rights remain very uneven.

 

Following the rules

Most of us think about privacy as personal protection, but it’s important to remember that we can forfeit our privacy if we don’t follow the established rules. Most BYOD/COPE policies, for example, say that certain device uses and apps are work-specific, and that’s where the employer is allowed to look; everything else on the device should not be used for work and is off limits to the employer.

To stay within the policy limits, you have to only do work within the apps that are controlled by your employer. For example, if policy states that all of your work chats must be in Microsoft Teams, choosing to have those conversations in WhatsApp or Facebook Messenger could cause you to lose some privacy rights to other software or data on your phone.

At the end of the day, your best phone privacy protections come from technology that partitions your work data and employer access from everything else on the device. At the same time, a clear and fair BYOD/COPE policy also helps protect employees’ privacy and sets the limits of what is and isn’t allowed.

 

An aside for HR and IT

To avoid problems with your company’s BYOD/COPE policy, make sure the policy is clear and understandable to your employees, and that employees are trained on the policy; that the policy is certified, even annually, to ensure that employees understand it; and that the policy is consistently enforced across the organization.

 

For more mobile security solutions, discover the array of tools in Knox Suite, Samsung’s end-to-end set of device management tools.

[아이콘] 닫기

삼성 Knox 시작하기

[아이콘] 여행가방
리셀러, 솔루션 공급업체 또는 서비스 공급업체이신가요?

지금 Knox 파트너가 되어 비즈니스 성장을 도모하세요.

[아이콘] 정보

시작할 Knox 제품 선택:

올인원 번들
Knox Suite
리브랜딩 및 맞춤 설정
Knox Configure
사기 및 도난 방지
Knox Guard
디바이스 보호 플랜
Samsung Care+ for Business
기타 제품 및 서비스

시작하기

[이미지] Knox Suite

기업용 모바일을 위한 일체형 솔루션 번들

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 회사 디바이스를 안전하게 보호, 배포, 관리 및 분석할 수 있는 완벽한 툴 모음입니다.
  • Knox Suite와 함께 제공되는 강력한 기능을 사용해 보세요.

Knox Suite에는 다음이 포함됩니다.:

Knox Mobile Enrollment 무료
Knox Manage
Knox E-FOTA
Knox Asset Intelligence
Knox Platform for Enterprise 무료
Knox Remote Support
Knox Capture
Knox Authentication Manager

시작하기

[이미지] Knox Configure 로고

삼성 디바이스를 리브랜딩하고 맞춤 설정하세요.

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 삼성 디바이스를 대량으로 구매하는 즉시 원격으로 구성하고 특정 요구 사항을 충족하도록 맞춤 구성합니다.
  • 디바이스를 일회성 배포를 위해 설정하거나 원하는 만큼 업데이트할 수 있습니다.

시작하기

[아이콘] Knox Guard 로고

삼성 디바이스를 위한 사기 및 도난 방지

  • 최대 30대의 디바이스에 제공되는 90일 무료 평가판을 사용해 보세요.
  • 원격으로 삼성 디바이스를 제어하여 금융 관련 위험성을 줄이고 자산을 보호하세요.
  • SIM 제어 및 디바이스 잠금 기능을 포함한 Knox Guard의 모든 기능을 사용해 보세요.

시작하기

[이미지] Samsung Care Plus For Business 로고

삼성 디바이스를 위한 디바이스 보호 플랜

  • 빠른 디바이스 수리 및 교체로 업무 중단을 최소화합니다. 시작하려면 삼성 영업팀에 문의하세요.
  • 한 곳에서 모든 디바이스 보증 범위 및 청구 정보를 확인하세요.
  • 이미 Samsung Care+ for Business를 구매하셨나요? Samsung Care+ for Business 콘솔에서 계정을 만들고 플랜을 활성화하세요.

기타 제품 및 서비스

[이미지] 기타 로고

고객의 고유한 요구 사항을 해결하는 최신 솔루션입니다.

  • Enterprise Tech Support를 통해 전담 계정 관리자로부터 효율적인 기술 지원을 받아보세요.
  • 삼성 소프트웨어 맞춤 설정 서비스를 사용하여 귀사를 위한 맞춤형 디바이스를 만들어 보십시오.
영업 팀에 문의