Skip to content

Home / When it ends

The Person Who Will Not Hand It Over

Somebody refuses to allow removal of work data from their own device. The options are fewer than people assume and the sequence matters.

When it ends · Procedure

It happens rarely and it is the scenario every BYOD arrangement should have thought about, because improvising it goes badly.

The practical lesson in “The Person Who Will Not Hand It Over” is to connect every record to a named decision. Organisations exploring the official resource for employee monitoring for performance reviews can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.

Why somebody refuses

Fear that the whole device will be wiped, which is reasonable if the agreement never said otherwise and is the commonest reason.

For an independent reference relevant to “The Person Who Will Not Hand It Over”, consult the European Data Protection Board guidelines; compare its principles with the proposed ownership model, access rules and real support process.

A dispute about money, where the device data is being used as leverage.

Anger about the departure.

Or a belief that something on the device protects them — correspondence about a grievance, evidence of something.

That last one is worth taking seriously rather than treating as obstruction, and it changes how the conversation should go.

The sequence

Establish what they actually object to. Frequently it is the method rather than the outcome, and a different method resolves it: doing it in front of them, doing it themselves with a screen shared, or removing accounts manually rather than remotely.

Narrow the request. Not "allow us access to your device" but "remove these three accounts and this application". Specific, limited and verifiable.

Offer the verification they need. Somebody worried about losing personal data will frequently cooperate once they can see the scope.

Involve whoever handles employment matters before escalating, because the next steps are contractual rather than technical.

If they hold material they say protects them

Stop, and take advice. Pressing for deletion of material somebody believes is evidence in a dispute is a different matter entirely and can make the organisation's position considerably worse.

Separate the two questions: the company data that needs removing, and the material they are holding for their own purposes. These may be the same files, which is exactly why this needs handling properly rather than quickly.

When it cannot be resolved

Assess what is actually on the device, which the proving note argues you should be able to do.

Mitigate at the system end: credentials changed, tokens revoked, accounts monitored.

Consider whether notification duties are engaged.

Record the position and close it.

Pursuing an individual over a phone is rarely proportionate and almost never succeeds, and the resources are better spent on the mitigation.

What prevents it

The clause, the container, and the fifteen minutes on the last day.

Where all three exist, this scenario mostly does not occur. Where none does, it occurs eventually.

The approach that usually works

Specific, limited, verifiable, and conducted with the person rather than to them. A request to remove three named accounts while they watch is accepted by people who refused a general demand for access, because the fear was never about the work data. Almost all refusals dissolve once the scope is visible and bounded.

Knowing when to stop

There is a point at which further pursuit costs more than the residual exposure and damages the organisation's position. Recognising it requires somebody with authority to decide that the matter is closed and the mitigation is sufficient. Without that authority the case stays open indefinitely, consuming attention and producing nothing.

Why the scenario is rare

Most people cooperate, including in difficult departures, because the request is reasonable once it is specific. Designing the arrangement around the rare refusal produces heavy-handed terms that worsen the common case, which is the error to avoid while still having an answer ready.

Preparing the conversation, not the threat

What resolves a refusal is a specific, bounded request made in person, with the scope visible. What hardens it is a formal demand referencing powers the organisation may not have. Deciding which approach is used before the situation arises keeps it out of the hands of whoever is most annoyed on the day. The refusal is almost always about the whole-device fear. An arrangement that could never have wiped the whole device does not produce it.

Whose Device, Whose Data