By Lauren E. Douglas

The year 2021 marks the forty-eighth anniversary of the mobile phone[1] and the eighty-third anniversary of the programmable computer.[2]  It is no secret that mobile devices are significantly more powerful than their inventors could have ever predicted.[3]  What started as clunky, cumbersome machinery has transformed into the backbone of society as we know it.[4]

Many aspects of corporate success are rooted in the evolution of the mobile device.[5]  To aid in their success, the majority of employers now permit the cross-use of electronic devices for personal and professional purposes—a movement known as “Bring Your Own Device” and lovingly referred to as “BYOD” for short.[6]  More specifically, the BYOD phenomenon is a practice whereby employees[7] use their own electronic devices[8] to do their jobs on the employers’ platforms.[9]  The BYOD practice is loved by employees and employers alike[10] and drives corporate activity in ways nearly unimaginable even ten years ago.[11]  In fact, in 2018, the BYOD market was predicted to reach nearly $367 billion by 2022.[12]  In the wake of the COVID-19 pandemic, the true number is likely even higher.[13]  Pandemic or no pandemic, it is clear that the BYOD era is here to stay.[14]

Despite the rising popularity of the BYOD workstyle, very few businesses actually enforce formal BYOD policies and instead simply allow employees to access corporate data on their own devices free of internal regulation.[15]  A study conducted in 2016 revealed that, even though roughly 70 percent of employees conduct work-related activities on their personal devices, only 39 percent of companies have a formal BYOD policy in place.[16]  This is dangerous; if companies do not regulate their BYOD practices, they risk breaches of sensitive corporate data and violations of federal privacy laws.[17]

The Tension Between Privacy Interests and Data Protection

Perhaps the most problematic issue that comes with implementing a BYOD policy is determining to what extent an employer can legally monitor and access its employee’s personal devices.[18]  The American Bar Association describes balancing the employers’ interests in data security with the employees’ rights of privacy as “the single greatest challenge” to a successful BYOD program.[19]  With that said, it must be recognized that employees enjoy a heightened right to privacy regarding information stored on their own personal devices as compared to employer-provided devices.[20]  Such protection may be found in both statutory and common law.

Specifically, the Computer Fraud and Abuse Act of 1986 (“CFAA”)[21] imposes criminal and civil penalties on individuals and companies that “intentionally access a computer without authorization or exceeds authorized access” to obtain “information from any protected computer.”[22]  The CFAA began as a means to protect government computers from hackers, but today the law reaches every computer connected to the internet.[23]  Of course, in 2021, computers are not the only devices used to conduct work.  Luckily, federal case law establishes that, in addition to desktop and laptop computers, the CFAA protects devices such as cell phones,[24] tablet devices, and even videogame systems.[25]  To supplement the CFAA, employees might also claim a violation of the Electronic Communications Privacy Act (“ECPA”), a subsection of the Stored Communications Act (“SCA”) that protects the privacy of electronic communications in electronic storage.[26]

So far, courts addressing the new BYOD privacy dichotomy seem reluctant to construe statutory protection broadly in favor of plaintiff-employees who had their personal devices wiped clean of all information.  For instance, in Rajaee v. Design Tech Homes, Ltd.,[27] a company remotely deleted all of an employee’s work and personal files from his mobile device after he resigned.[28]  The device was connected to the employer’s data server, allowing for remote access to email and calendar platforms.[29]  The employee sued for damages under the ECPA and the CFAA, but the court rejected both claims, reasoning that the personal data lost was not “electronic storage” as defined under the ECPA and was not a qualified “loss” under the CFAA.[30]  Such stringent readings of these statutes makes asserting a viable claim for lost personal data caused by the employer a very difficult feat for employees.[31]

Because technology moves light-years faster than the development of law,[32] the CFAA and ECPA are two of the closest statutes to the BYOD issue; there is currently no federal or state legislation directly addressing BYOD policies.[33]  Similarly, the relevant case law is negligible.[34]  It is thus vital for employers to create and implement comprehensive, transparent, and officially documented BYOD programs.  Thorough BYOD policies are important because, with the lack of statutory law on point, courts in many cases will look directly to the provisions in the BYOD policy to “determine the bounds of permissible employer conduct.”[35]

Private employees generally retain privacy interests in common law so long as their expectations are “reasonable.”[36]  When considering whether an employee has a reasonable expectation of privacy in electronic communications, courts tend to balance the following factors: (1) account ownership;[37] (2) device ownership;[38] (3) the security level of the communication;[39] and (4) published employer policies and whether they were routinely enforced.[40]  No one factor is dispositive and different courts may weigh factors differently.[41]  Because two of the four factors essentially look for whether a BYOD program exists, employers can cover a significant number of bases simply by drafting a formal policy.[42]

Best Practices for Employers

Despite the lack of concrete legal guidelines surrounding the BYOD phenomenon, an employer can mitigate the majority of its concerns by implementing a formal BYOD policy.  An effective policy should “emphasize security and contain clear instructions” regarding acceptable and unacceptable activities on personally owned devices that have access to corporate information systems.[43]  Additionally, an employer’s BYOD policy should make clear that “any and all company information and emails” on all personal devices remain “the sole property” of the company, and that the employer “in its sole discretion” may access and delete any company data that “may be in jeopardy.”[44]  No threat is too small when it comes to business use of personal devices, and providing express notice to employees is the very best way to mitigate legal liability surrounding BYOD policies.[45]

In addition to implementing a comprehensive, written BYOD policy, many companies—especially those that handle sensitive information—are utilizing Mobile Device Management (“MDM”) service providers to help mitigate the technical risks associated with allowing employees to access company data on their own devices.[46]  In essence, MDM broadens the scope of BYOD protection and is “designed to fill security gaps” in employee use of personal devices.[47]  MDM allows employers to exercise control over the device, monitor applications, and remotely wipe the device if it is lost or stolen—clearly a worthwhile addition to any BYOD policy.[48]

The Bottom Line

An astonishing number of employees and employers engage in the BYOD workstyle.  While BYOD practices often increase employee satisfaction and performance, and decrease employer costs, they come with inherent risks that cannot be ignored, such as data breaches and violations of federal privacy law.  Employers can mitigate many of these risks by implementing a strong written BYOD policy that clearly delineates the employers’ rights of access to each device.  Now more than ever, actively and uniformly enforcing a BYOD policy is the best mechanism to alleviate legal risks while the law plays catch-up with the modern technological workplace.

Post Image by Ryan Adams on Flickr.