What changes with device management
Each security objective appears twice below: as it stands today, and as it stands once device management is in place.These controls cover the state of the device — is it encrypted, up to date, protected. They do not cover the activity of the employee using it.
What the agent reports
The agent reports device metadata continuously and automatically. Nothing in this list requires an administrator to act.What the tool never collects
Each of these is absent from the product, not simply disabled.What an administrator can trigger
These actions are deliberate, taken one device at a time, and recorded in the audit log with the administrator, the action and its result.The legal framework
A technical capability is not an authorization. Three requirements hold across every country below: a declared purpose with a lawful basis, information given to employees before the deployment starts, and proportionality between the control and the aim. What differs is who must be involved before deployment, and on what terms.- France
- Germany
- Spain
- United Kingdom
- United States
Resource — Note for a CSE consultation (PDF, in French). A two-page note covering the objectives of the deployment, what the agent reports, what it never collects, what an administrator can trigger and the legal framework, ready to hand out at the session.
The IT charter, country by country
Every country in this list expects a written document naming the authorized uses of a company device, the controls applied to it, the cases in which IT intervenes, and how long data is kept. Only its name, its legal weight and the way it is adopted change.This guide is an information summary, not legal advice. Requirements differ by country, and in the United States by state. Your legal team or local counsel remains the only authority on how your processing activities are qualified and on how your IT charter is drafted.