Skip to content

Home / Two lives

One Device, Two Owners of the Data

The hardware belongs to one party and some of what is on it belongs to the other. Almost every difficulty in this subject comes from that single fact.

Two lives · Analysis

A company laptop holds company data on company hardware. A personal laptop under BYOD holds two sets of information with two owners, physically mixed, and no natural boundary between them.

The privacy boundary in “One Device, Two Owners of the Data” should also govern workforce records created on a personal device. When a team evaluates view the product overview for remote desktop monitoring software, it should disclose the purpose, limit manager access and retention, and give each person a practical correction route.

What each party owns

The employee owns the device, the operating system, their own files, their accounts, and the right to decide what happens to the object.

For an independent reference relevant to “One Device, Two Owners of the Data”, consult the ICO employment-practices guidance; compare its principles with the proposed ownership model, access rules and real support process.

The employer owns the work data, the documents, the messages sent through its systems, the customer information, and whatever obligations attach to that data under contract or law.

Neither claim is disputed. The difficulty is that they occupy the same storage and that acting on one usually means touching the other.

Where the conflict actually bites

At exit, which the final section covers: the employer needs its data gone, the employee needs their device intact.

During an investigation, where the employer may need to produce work communications and those live on hardware it has no right to seize.

In a records request, where someone asks what the organisation holds about them and part of the answer is on an employee's phone.

On loss or theft, where the employer wants the device wiped and the employee wants their photographs recovered first.

Each of these is a collision between two legitimate positions, and each is far easier when the two bodies of data were never actually mixed.

Which is why separation matters more than permission

The instinct is to solve this with agreements: the employee grants the employer rights over the work portion. That helps, and it depends on both parties identifying the work portion correctly at a difficult moment.

Technical separation solves it differently. Where work data lives in a container the operating system maintains, the boundary is enforced rather than agreed. The employer acts on the container; the personal side is not reachable, not by policy but by construction.

The next note examines what that separation actually delivers, including where it leaks.

The organisational obligation nobody considers

The employer's duties regarding the data do not stop at the edge of its own equipment. If customer records sit on an employee's phone, the organisation remains answerable for them.

That is worth stating because it reframes the arrangement: BYOD does not reduce the employer's data obligations, it distributes the places where those obligations must be met, onto hardware the organisation cannot inspect.

For some categories of data that is simply not an acceptable arrangement, which the earlier note on who it suits sets out.

The data nobody classified

Most organisations have never determined which categories of their data may rest on personal devices and which may not. Without that, every device holds whatever the person happens to work on, including the material that should never have left controlled systems. A short classification — these categories may, these may not — is the input the technical arrangement needs and is almost always missing.

Why agreements alone do not settle it

An agreement allocates rights over data that both parties can identify. At the moment of difficulty the identification is exactly what is contested: which file is work, which message is personal, what counts as company information. Technical separation removes the identification problem, which is why it does the work that the clause cannot.

The obligation that follows the data

Wherever company data sits, the duties attached to it travel with it. An organisation cannot discharge a retention, disclosure or deletion duty by pointing out that the copy is on hardware it does not own. Naming that plainly is what justifies the configuration decisions that follow. The question to hold throughout this section: if the two parties disagreed tomorrow, is the boundary between their data a technical fact or an interpretation?

Whose Device, Whose Data