Skip to content

Home / When it ends

What Gets Wiped and What Should Not

The difference between removing a work profile space and erasing a device is the difference between an administrative step and a serious wrong.

When it ends · Reference

Two actions are available at the end of a BYOD arrangement and they are not alternatives. One removes the employer's data; the other destroys somebody's property.

The privacy boundary in “What Gets Wiped and What Should Not” should also govern workforce records created on a personal device. When a team evaluates ethical employee monitoring practices for ethical employee monitoring, it should disclose the purpose, limit manager access and retention, and give each person a practical correction route.

Selective removal

The work profile space and its contents: company applications, work mail, work files, certificates, configuration profiles.

For an independent reference relevant to “What Gets Wiped and What Should Not”, consult the ICO employment-practices guidance; compare its principles with the proposed ownership model, access rules and real support process.

Everything else untouched. Photographs, personal applications, personal accounts, the operating system, personal files.

This is the normal action, it is what the agreement should authorise, and under a container arrangement it is the only action technically available — which is the strongest argument for containers.

Full device wipe

Everything erased and the device returned to factory state.

Appropriate for a company-owned device being reissued. Not appropriate for a personal device in any ordinary circumstance, and the fact that it is technically possible in many configurations is a defect rather than a feature.

The cases where it happens anyway

A departing employee's device is wiped completely because the administrator used the wrong option in a hurry.

A lost device is wiped as a precaution without anyone considering that recovery was still possible.

A full-enrolment arrangement offers no selective option, so the only available action is the destructive one.

Each of these has produced real disputes, and in each the employer was acting within what the agreement permitted and had not thought about what it permitted.

Removing the capability

The most reliable protection is not having the power. Where the platform allows disabling whole-device erase for personal devices, disable it.

A capability that exists will eventually be used by somebody in a hurry, which is an argument that recurs throughout this subject.

What to tell the employee in advance

Exactly which of the two applies to them, in the agreement, in plain terms.

"We will remove the work space and its contents. We cannot and will not remove anything else" is a sentence that can be written and kept under a container arrangement, and it does more for the arrangement than any other single line.

Where a whole-device erase is genuinely required

A serious security incident involving a device holding sensitive material, where selective removal has failed and the risk is material.

Rare, and it should require a named approver, a written reason, and an attempt at the selective option first.

Not a decision for whoever happens to be at the console.

Who holds the button

Where a destructive capability exists, the question of who may use it and under what approval should be answered before anybody needs to. In practice it is frequently available to anybody with administrative access to the platform, including people who have never considered what the action does to a person. Restricting it to named individuals is a configuration change and it takes minutes.

The mistake that cannot be undone

A selective removal applied wrongly can be redone. A whole-device erase cannot be reversed and the data is gone. That asymmetry alone justifies treating the two actions differently in every respect: different permissions, different approval, different confirmation step. Most platforms present them as adjacent options in the same menu, which is how the accident happens.

Say which one applies

Employees assume the destructive option because nobody told them otherwise. A single sentence in the agreement naming which action the employer can take, backed by a configuration that cannot do more, removes the largest fear in this subject at no cost.

Removing the option entirely

Where the platform allows, disabling whole-device erase for personal devices is a ten-minute change that eliminates the worst outcome in this collection permanently. It also converts the reassurance in the agreement from a promise into a statement of fact, which is the difference between being believed and not.

Two actions, two permissions

Selective removal is routine and should be available to anybody running the platform. A whole-device erase is destructive and irreversible and should require a named approver and a written reason. Presenting them as adjacent menu options with identical permissions is how the serious mistake eventually happens.

If your configuration offers a whole-device erase for personal devices, somebody will use it one day on somebody's family photographs. Turn it off.

Whose Device, Whose Data