ARTICLE
26 June 2025

Use Of Personal Mobile Phone For Work-Related Purposes

VK
G. Vrikis & Associates Ltd

Contributor

G. Vrikis & Associates LLC is a rapidly expanding and prominent law firm in Cyprus. Established in 2015 by its managing partner, Mr. George Vrikis, the firm has been focused in providing high-level legal advice to its clients and expanding its international profile and clientele, while at the same time maintaining a prompt, proactive and family office-approach for its clients. The Firm has expanded to a second location in Limassol in 2019, with the addition of Mrs Christiana Kouppi as a Partner.
The Commissioner for Personal Data Protection issued the Directive No 1/2025 in relation to the use of personal mobile phones for work purposes based on the guidelines given by the European Data Protection Supervisor...
Cyprus Privacy

The Commissioner for Personal Data Protection issued the Directive No 1/2025 in relation to the use of personal mobile phones for work purposes based on the guidelines given by the European Data Protection Supervisor, Opinion 2/2017 of the European Commission and the European Data Protection Board.

The practice of using personal mobile phones in the context of the employment relationship is quite widespread these days. However, "Bring Your Own Device" ("BYOD") practice may be associated with potential risks related to the monitoring of employees' privacy, while it is also related to potential risks to the security of data registered in the employer's systems and databases, to which the employee may have access through his personal device.

The main points of the Directive are the fact that employees are not obliged to use their personal mobile phone for work purposes, and that the use of a personal mobile phone for work purposes may be permissible when:

  1. the employee wishes to use their phone for such purposes
  2. such use facilitates the performance of their duties and
  3. it does not entail or involve the processing of the employee's personal data by their employer.

Furthermore, if the employee does not wish to use their personal mobile phone for work purposes, even when no data processing is taking place, the employer must:

  1. provide him/her with an alternative solution and
  2. ensure that the employee is not subject to adverse consequences if he/she chooses this alternative solution i.e. the provision of a company device or sponsoring for the purchase of such device, as well as reimbursement for usage costs, where applicable.

Where an employee's duties require occasional use of a personal mobile phone, e.g. to access documents by receiving a one-time password (OTP) and does not entail any processing of personal data by or on behalf of the employer, the use of personal mobile phone is permitted. The employer must in any case be able to adequately and appropriately document the absence of processing of personal data.

When the use of a personal mobile phone involves the processing of employee data by or on behalf of the employer, e.g. in the context of an application (app) to check working hours and/or remaining rest periods, the employer must ensure that:

  1. the basic principles of processing (Article 5 GDPR) are respected,
  2. the processing is based on one of the conditions of Article 6 GDPR, but not consent [Article 6(1)(a)], due to the employer's position of power,
  3. the transparency procedure is followed, and the employer informs employees in advance of the processing in question,
  4. where possible, an alternative, less intrusive measure is offered, e.g. swiping a card instead of a mobile app,
  5. employees who choose the alternative measure are not subject to adverse consequences or discrimination and that,
  6. all other GDPR obligations are met

In cases where the employee's duties require the use of a personal mobile phone on a systematic basis, whether or not their data is being processed, the employer must establish a policy and inform the employees of the same, which policy should regulate, among other things, what happens in the event that:

  1. the employee forgets the device at home,
  2. the device breaks down or malfunctions
  3. the employee no longer wishes to use the device for work-related purposes.

The Directive aims for a more uniform and consistent use of personal mobile phones, for the purposes of carrying out specific work tasks during working hours, in a manner that ensures the protection of personal data and the privacy of employees.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More