Expert Advice Community

Guest

MDM

  Quote
Guest
Guest user Created:   Jul 23, 2018 Last commented:   Jul 23, 2018

MDM

We are working to be compliant with ISO 27001 in information security, and after a risk assessment we agreed that there is a risk of not having MDM on employee mobile phones when they have access to sensitive information on both email and other application.
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Jul 23, 2018

Employees are using their private devices for work purpose.
My question is if it is legal to use google's MDM solution on private phones in regards to GDPR? If not, could you please provide advise on how to approach this? What options do we have?

Answer:

You can use such monitoring software based on legitimate interest and this is lawful provided that:

The employee is properly informed on the amount of processing as well as the purpose ( art. 12 of the EU GDPR - “Transparent information, communication and modalities for the exercise of the rights of the data subject” (https://advisera.com/eugdpracademy/gdpr/transparent-information-communication-and-modalities-for-the-exercise-of-the-rights-of-the-data-subject/)
The monitoring is strictly limited to the company communications. Usua lly sandboxing technology software is used to distinguish between private and company storage.

To learn more about the EU GDPR check out our “EU GDPR Foundations course” (https://advisera.com/training/eu-gdpr-foundations-course//).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 23, 2018

Jul 23, 2018