Skip to main content
Device management (MDM) covers the state of a device, not the activity of the person using it. This guide sets out exactly where that line falls: what the agent reports continuously, what the product never collects, what an administrator can trigger deliberately, and the legal framework around each. In several countries, deploying an MDM on employee devices also requires involving employee representatives beforehand — a works council consultation in France, a works agreement in Germany. The tables below are written to be copied into that file. For the message sent to employees once that step is settled, see Communication resources; for what employees do on their side, see the Employee guide & FAQ.

What changes with device management

Each security objective appears twice below: as it stands today, and as it stands once device management is in place.
These controls cover the state of the device — is it encrypted, up to date, protected. They do not cover the activity of the employee using it.

What the agent reports

The agent reports device metadata continuously and automatically. Nothing in this list requires an administrator to act.

What the tool never collects

Each of these is absent from the product, not simply disabled.

What an administrator can trigger

These actions are deliberate, taken one device at a time, and recorded in the audit log with the administrator, the action and its result.
A remote wipe is irreversible. Data on the device cannot be recovered afterwards.
A technical capability is not an authorization. Three requirements hold across every country below: a declared purpose with a lawful basis, information given to employees before the deployment starts, and proportionality between the control and the aim. What differs is who must be involved before deployment, and on what terms.
ResourceNote for a CSE consultation (PDF, in French). A two-page note covering the objectives of the deployment, what the agent reports, what it never collects, what an administrator can trigger and the legal framework, ready to hand out at the session.
The tool decides nothing. The capabilities listed above exist on every MDM on the market. What a company allows itself to do with them belongs to the framework above and to its own IT charter.

The IT charter, country by country

Every country in this list expects a written document naming the authorized uses of a company device, the controls applied to it, the cases in which IT intervenes, and how long data is kept. Only its name, its legal weight and the way it is adopted change.
This guide is an information summary, not legal advice. Requirements differ by country, and in the United States by state. Your legal team or local counsel remains the only authority on how your processing activities are qualified and on how your IT charter is drafted.