BYOD And Disclosure
17 pages · 23 min read
This guide for UK lawyers explains how to handle work data on personal devices, covering control, collection routes, and privacy.
- Mobile and messaging evidence
This guide addresses how to manage the collection and disclosure of work data residing on employees' personal devices.
Guide · 17 pages · 23 min read · Published 2026-08-30
Aimed at UK legal practitioners navigating complex litigation and investigations, the text addresses the challenges surrounding corporate evidence stored on personal smartphones and hardware. It sets out the legal framework governing when work data falls under company control, examining the distinct routes of consent, contract, and compulsion alongside privacy rights under GDPR. On the technical side, it details targeted, privacy-scoped extraction protocols that isolate disclosable material while protecting personal data, addressing MDM, cloud backups, corporate tenancy profiles, and recoverable deleted files. Special focus is given to hard cases such as uncooperative custodians, former employees, and exit-wiped devices, illustrated through practical worked examples. The text equips solicitors with drafting aids, suggested interrogatories, custodian consent protocols, and checklists to spot red flags and determine when to instruct a CPR Part 35 expert. By bridging legal obligations with digital forensics, it provides actionable guidance on collecting data from WhatsApp and counterpart systems while maintaining full chain-of-custody documentation and strict proportionality.
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
17 pages · 23 min read
This guide for UK lawyers explains how to handle work data on personal devices, covering control, collection routes, and privacy.
Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. See every guide's author and source.
Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the current wording of the guide, including any later corrections.
BYOD & DISCLOSURE · A GUIDE FOR UK LAWYERS BYOD and Disclosure Personal Devices, Work Data and the Collection Nobody Signed Up For COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM PRIVACY-SCOPED EXTRACTION PROTOCOLS CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the company's evidence on the employee's phone 03 Control: when personal-device data is disclosable 04 The routes: consent, contract, compulsion 05 Targeted collection: taking the work, leaving the life 06 Privacy, proportionality and the device owner's rights 07 Leavers, refusers and wiped devices 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: WORKDATAONPERSONALDEVICESISUSUALLYDISCLOSABLE, RARELYSEIZABLE, ANDALWAYSCOLLECTABLEWITHTHERIGHTPROTOCOL: THECRAFT IS THE PROTOCOL
§ 02 · FIRST PRINCIPLES The problem in plain English: the company's evidence on the employee's phone
§ 03 · CONTROL Control: when personal-device data is disclosable
§ 04 · THEROUTES The routes: consent, contract, compulsion
§ 05 · THESCALPEL Targeted collection: taking the work, leaving the life
§ 06 · RIGHTS Privacy, proportionality and the device owner's rights
§ 07 · THE HARD CASES Leavers, refusers and wiped devices
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE DEVICE SYSTEM S / WORK COMPUTER PERSONAL CORPORATE MDM / CLOUD & (TARGETED) TENANCY PROFILE BACKUPS COUNTERPART DELETED / DEVICES RECOVERABLE
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEPROTOCOLTHATTURNEDAREFUSALINTOAYES EXAMPLE2 · THEDISCLOSURESTATEMENTTHATFORGOTTHEPHONES EXAMPLE3 · THEEXITWIPEANDTHECONTAINERTHATLOGGEDIT
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · CUSTODIANCONSENTPROTOCOL ( CORETERMS )
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The BYOD checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions Can my client require an employee to hand over their personal phone? Is Whats App on a director's personal phone within the company's control? What if the custodian's phone also holds another employer's confidential data? Our custodian left the company last year and will not cooperate. Options? Does GDPR prevent BYOD collection? What should a BYOD policy say to make disclosure workable?
§ 14 · REFERENCE Glossary BYOD MDM Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
19 pages · 25 min read
This guide for UK lawyers explains how iOS devices can be compromised by spyware, stalkerware, or misused features.
18 pages · 26 min read
Android app data forensics requires understanding an open ecosystem, where each app is its own world.
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.