Legal Risks of Using Personal Devices for Work
In the modern working environment employees often run business activity on their own laptops, phones and tablets, which is convenient for the company but turns into a serious legal risk when clear rules are absent: both corporate communications and business information, and data about employees and their contacts, migrate to personal devices. Such processing falls within the scope of the personal data protection legislation of Georgia, so the organisation must know in advance which principles and which legal bases apply to this process. This is precisely why a bring-your-own-device policy is written — a document that gives the regulation a practical shape and avoids conflicting situations in advance, before an incident or a regulator's question makes the gaps visible.
Data Processing Principles as the Foundation of the Policy
The principles established by law form the skeleton of any policy: data must be processed lawfully, fairly, transparently for the data subject and without violating the subject's dignity; collected only for specific, clearly defined and legitimate purposes; processed only to the extent necessary and proportionate to the aim; kept accurate, with inaccurate data corrected or erased without unjustified delay; and stored only for the period necessary for the legitimate purpose, after which the data must be erased, destroyed or kept in depersonalised form. A separate emphasis lies on security: for the purpose of data protection, such technical and organisational measures must be taken as adequately ensure the protection of data, including from unauthorised or unlawful processing, accidental loss, destruction or damage. For personal devices this requirement is particularly strict, because the device escapes the company's direct control and travels into every environment of the employee's life.
Legal Bases of Processing in the Employment Context
Processing is admissible only where a basis provided by law exists, and this list must be analysed when drafting the policy: the data subject's consent; performance of an obligation under a contract with the data subject or steps preparatory to such a contract; processing provided for by law; performance of duties imposed on the controller by legislation; public availability of the data; protection of vital interests; significant public interest; tasks of a sphere of public interest; legitimate interests of the controller or a third party; and processing necessary for considering the data subject's application. In the context of personal devices the boundary between consent and legitimate interest arises most often: what the employer may do under its own interest and what requires the employee's separate consent. Selecting and substantiating the basis falls on the controller, which is why this step is the principal filter against unlawful processing.
Video Monitoring and Control of the Work Process
Where a company controls the work process through video monitoring, the law imposes strict rules: video monitoring of an employee's work process or space is admissible only as an exception, where achieving the permitted aims by other means is impossible or requires disproportionately great effort. Video monitoring is impermissible in changing rooms, in places designated for hygiene, or in any space where a person has a reasonable expectation of privacy. The law requires a warning sign to be placed conspicuously, containing a corresponding inscription, an easily perceivable image about the ongoing monitoring, and the name and contact details of the controller; in the case of workplace monitoring, the employee must additionally be warned in writing about the specific purpose. Each instance of access to the recordings is logged, including the time of access and the username of the person accessing.
The Employee's Right to Information and Its Support
The policy must also serve the realisation of the employee's rights: the data subject is entitled to request from the controller confirmation of whether data about the subject are being processed and, corresponding to the request, to receive free of charge information about the data, the basis and purpose of processing, the source of collection, the storage period, the subject's rights, and any transfers of the data. This information must be provided no later than within ten working days of the request; in special cases, with appropriate substantiation, the period may be extended by no more than a further ten working days, about which the subject is notified immediately. The organisation should describe this procedure in the policy in advance, because a breach of these deadlines itself becomes a ground for legal liability.
Frequently Asked Questions About a Personal Device Policy
Is a written policy mandatory?
The law requires that the purpose, scope, duration, storage period of recordings and access rules for video monitoring be defined in writing. For personal devices, a written policy is the practical implementation of the transparency requirement.
May an employee's device be inspected in full?
The volume of data must not exceed the frame of necessity: processing is admissible only to the extent needed to achieve the legitimate purpose. The boundaries of what belongs to the employer depend on the concrete purpose and must be defined in advance.
What about video monitoring of the workplace?
It is admissible only as an exception, where achieving the purpose by other means is impossible or requires disproportionate effort, and the employee must be warned in writing about the specific purpose.
Within what period must the employee receive the information?
No later than within ten working days of the request; in special cases the period may be extended, with substantiation, by a further ten working days, of which the data subject is notified immediately.
How We Help on Legal.ge
The lawyers of Legal.ge will prepare your personal device policy in full compliance with the law: we generalise the data flows, select the processing bases, describe the rules of video monitoring and access logging, and draft the agreements needed with employees. Contact us — we will assess your processes and plan the deployment of the document.
