Skip to content

Home / When it ends

Records, Retention and Someone Else's Phone

Obligations to keep records, and obligations to produce them, do not pause because the data is on hardware the organisation cannot reach.

When it ends · Analysis

General orientation, not legal advice; retention and disclosure duties differ substantially by sector and jurisdiction.

The practical lesson in “Records, Retention and Someone Else's Phone” is to connect every record to a named decision. Organisations exploring reducing key-person dependency risk for key person dependency can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.

An organisation's duties regarding its records are unaffected by where the records happen to sit. BYOD distributes them onto devices the organisation does not own and cannot search, which is a problem for compliance rather than for IT.

For an independent reference relevant to “Records, Retention and Someone Else's Phone”, consult the European Data Protection Board guidelines; compare its principles with the proposed ownership model, access rules and real support process.

The duties that do not move

Retention. Where a rule requires records to be kept for a period, messages and documents created on a personal device are still records.

Disclosure. In litigation or a regulatory request, relevant material must be identified and produced wherever it is. A device the organisation cannot search is not therefore out of scope; it is simply harder.

Access requests. Somebody asking what personal data the organisation holds about them is asking about all of it, including anything on an employee's phone.

And deletion. A commitment to delete somebody's data after a period cannot be honoured on devices nobody can reach.

Why this is the strongest argument for not storing locally

Every one of the above becomes straightforward if work material lives in company systems and personal devices only display it.

An employee who accesses mail through a browser creates no local record to retain, disclose, search or delete. One who synchronises a mailbox creates a copy the organisation is answerable for and cannot see.

That distinction is worth more than any policy, and it is a configuration choice rather than a rule people have to follow.

The departing employee's copy

When somebody leaves with synchronised work mail on their phone, the organisation has lost control of records it is obliged to control.

Not because they will do anything with it — most people will not — but because the duty is about control rather than about outcome.

Which is why the removal confirmation from the previous note is a compliance matter and not merely tidiness.

The regulated sectors

Financial services, healthcare, legal and parts of the public sector have specific recording and retention duties, and some have requirements about the systems communications must pass through.

In those settings a personal device holding regulated communications may be a breach regardless of how carefully the arrangement is otherwise run, which the earlier note on suitability flags.

The usual answer is that the work channel is the company system and personal devices access it without retaining anything.

What to establish

Which of your records duties could be engaged by material on a personal device.

Whether any of that material is actually resident rather than merely accessed.

And whether you could identify it if asked.

Most organisations discover the answer to the third is no, which is the finding that drives the configuration change.

Whose Device, Whose Data