> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What an MDM can and cannot do

> What an MDM reports, what it never collects, and what an administrator can trigger — with the legal framework that applies in France, Germany, Spain, the UK and the US.

Device management (MDM) covers the state of a device, not the activity of the person using it. This guide sets out exactly where that line falls: what the agent reports continuously, what the product never collects, what an administrator can trigger deliberately, and the legal framework around each. In several countries, deploying an MDM on employee devices also requires involving employee representatives beforehand — a works council consultation in France, a works agreement in Germany. The tables below are written to be copied into that file.

For the message sent to employees once that step is settled, see [Communication resources](/guides/device-management/mdm-rollout-resources); for what employees do on their side, see the [Employee guide & FAQ](/guides/device-management/employee-enrollment-guide).

## What changes with device management

Each security objective appears twice below: as it stands today, and as it stands once device management is in place.

| Objective                                   | Today                                                                             | With device management                                                                                                                                 |
| ------------------------------------------- | --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Encrypt the fleet                           | FileVault is enabled device by device, with no visibility on the rest             | Encryption is enforced and its status reported. The recovery key is escrowed by the company. See [Disk encryption](/mdm/policies/disk-encryption)      |
| Keep devices up to date                     | Each employee updates when they think of it, and known flaws stay open for months | A minimum OS version is required, and the gap is visible and correctable. See [Enforce a minimum OS version](/mdm/policies/enforce-minimum-os-version) |
| Cover the fleet with antivirus              | The agent is installed manually, with no view of which devices lack it            | The antivirus is deployed by the MDM and coverage is read on a single page. See [Endpoint protection](/mdm/endpoint-protection/crowdstrike-falcon)     |
| Spot a vulnerability before it is exploited | No inventory of the software installed across the fleet                           | Installed applications and their known vulnerabilities are reported                                                                                    |
| Frame sensitive software                    | Nothing prevents the installation of unauthorized software                        | Application blocking on macOS, in Monitor mode first, then Lockdown. See [App blocking](/mdm/policies/app-blocking)                                    |
| Answer an audit or a customer               | Security evidence is rebuilt by hand before each deadline                         | Controls run continuously and evidence comes out of the platform. See [Compliance overview](/mdm/compliance/overview)                                  |

<Info>
  These controls cover the state of the device — is it encrypted, up to date, protected. They do not cover the activity of the employee using it.
</Info>

## What the agent reports

The agent reports device metadata continuously and automatically. Nothing in this list requires an administrator to act.

| Data                                 | Frequency  | What it is for                                                  |
| ------------------------------------ | ---------- | --------------------------------------------------------------- |
| Model, serial number, OS and version | Continuous | Know which devices are managed and up to date                   |
| Disk encryption status               | Continuous | Verify that nothing is readable if a device is stolen           |
| Disk recovery key                    | Continuous | Escrowed automatically. The company can reopen a company device |
| Device security settings             | Continuous | Screen lock delay, firewall, password policy                    |
| Disk, memory and processor usage     | Continuous | Diagnose a slow device or a saturated disk                      |
| IP address                           | Continuous | Identify the device on the company network                      |
| Installed applications               | Continuous | Names and versions only, never their content                    |
| Software vulnerabilities             | Continuous | Fix a flaw before it is exploited                               |

## What the tool never collects

Each of these is absent from the product, not simply disabled.

| Data                        | Status | Detail                                                               |
| --------------------------- | ------ | -------------------------------------------------------------------- |
| Keystrokes                  | Never  | No keylogger exists in the product                                   |
| Browsing history            | Never  | Not reported by the agent. See the script execution row below        |
| Email and messaging content | Never  | The MDM is not connected to messaging systems                        |
| Webcam and microphone       | Never  | No image or sound capture                                            |
| Personal passwords          | Never  | No access to password managers                                       |
| File content                | Never  | The presence and name of a file can be known, never what it contains |

## What an administrator can trigger

These actions are deliberate, taken one device at a time, and recorded in the [audit log](/mdm/audit-logs) with the administrator, the action and its result.

| Action                            | Detail                                                                                                                                                                                                    |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Remote control and screen sharing | For troubleshooting. On macOS, the employee grants screen sharing permission on first use, and that approval cannot be pushed by MDM. See [Remote access](/mdm/policies/remote-management)                |
| Script execution on the device    | On macOS, Windows and Linux. A script can technically read the disk, as on any administration tool. Every execution is traced: who, what, which result. See [Script library](/mdm/scripts/script-library) |
| Locating an iPhone or iPad        | Only in Lost Mode, after a loss or theft is declared. No continuous geolocation, and no equivalent on Mac. See [Locking devices](/mdm/guides/locking-devices)                                             |
| Remote lock or wipe               | For a lost or stolen device, and for departures. See [Wiping devices](/mdm/guides/wiping-devices)                                                                                                         |

<Warning>
  A remote wipe is irreversible. Data on the device cannot be recovered afterwards.
</Warning>

## The legal framework

A technical capability is not an authorization. Three requirements hold across every country below: a declared purpose with a lawful basis, information given to employees before the deployment starts, and proportionality between the control and the aim. What differs is who must be involved before deployment, and on what terms.

<Tabs>
  <Tab title="France">
    | What the law says                                                     | What it requires here                                                                                                                                                                                                 |
    | --------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | **Works council consultation** — French Labour Code, art. L2312-38    | The CSE is informed and consulted prior to the implementation of means enabling the monitoring of employee activity                                                                                                   |
    | **Prior information of employees** — French Labour Code, art. L1222-4 | No information concerning an employee personally may be collected by a device that has not been brought to their knowledge beforehand. Hence the communication sent before deployment                                 |
    | **Proportionality** — French Labour Code, art. L1121-1                | A restriction must be justified by the nature of the task and proportionate to the aim pursued. Controlling the security state of a device, yes. Monitoring the activity of the person using it, no                   |
    | **Minimization and transparency** — GDPR art. 5 and 13                | Only the data necessary for the declared purpose, with a defined retention period and an entry in the record of processing activities                                                                                 |
    | **Files identified as personal** — French Supreme Court case law      | Files created on a company device are presumed professional. Those the employee has identified as personal, for example in a folder named "Personal", may only be opened in their presence or with them duly summoned |

    **Resource** — [Note for a CSE consultation](/images/resources/primo-note-cse-mdm-fr.pdf) (PDF, in French). A two-page note covering the objectives of the deployment, what the agent reports, what it never collects, what an administrator can trigger and the legal framework, ready to hand out at the session.
  </Tab>

  <Tab title="Germany">
    | What the law says                                                                         | What it requires here                                                                                                                                                                                                                                                                               |
    | ----------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | **Co-determination** — Works Constitution Act (BetrVG), § 87(1) no. 6                     | Where a works council exists, it co-decides on the introduction and use of technical devices capable of monitoring employee behavior or performance. Co-determination, not consultation: without its agreement — in practice a works agreement (Betriebsvereinbarung) — the tool cannot be deployed |
    | **Works council information** — BetrVG, § 80(2)                                           | The works council receives the documentation it needs to assess what the tool collects and what it can trigger                                                                                                                                                                                      |
    | **Employee data processing** — Federal Data Protection Act (BDSG), § 26, and GDPR art. 88 | Processing must be necessary for the employment relationship. A works agreement can itself carry the legal basis, within the limits set by the GDPR                                                                                                                                                 |
    | **Proportionality** — Federal Labour Court case law                                       | Continuous or covert monitoring is rarely proportionate, and evidence collected outside these limits can be excluded in proceedings                                                                                                                                                                 |
    | **Private use of the device**                                                             | Where private use of a company device is permitted, access to what it contains faces additional restrictions. Set the rule on private use explicitly in the works agreement                                                                                                                         |
    | **Impact assessment** — GDPR art. 35                                                      | A DPIA is expected where the deployment is likely to result in a high risk to employees                                                                                                                                                                                                             |
  </Tab>

  <Tab title="Spain">
    | What the law says                                                     | What it requires here                                                                                                                                                            |
    | --------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | **Employer control powers** — Workers' Statute, art. 20.3             | The employer may adopt the measures it deems appropriate to verify compliance with work duties, with due regard for the employee's dignity                                       |
    | **Criteria for the use of digital devices** — LOPDGDD, art. 87        | Employees have a right to privacy in the use of devices provided by the employer. The employer sets the criteria of use, and workers' representatives take part in drafting them |
    | **Geolocation** — LOPDGDD, art. 90                                    | Employees and their representatives must be informed expressly, clearly and unequivocally about the existence and the characteristics of any geolocation device                  |
    | **Prior report of the works committee** — Workers' Statute, art. 64.5 | The works committee issues a prior report on the implementation or revision of work organization and control systems                                                             |
    | **Minimization and transparency** — GDPR art. 5 and 13                | Only the data necessary for the declared purpose, with a defined retention period and an entry in the record of processing activities                                            |
  </Tab>

  <Tab title="United Kingdom">
    | What the law says                                                                                             | What it requires here                                                                                                                |
    | ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
    | **Lawful basis and transparency** — UK GDPR art. 6 and 13, Data Protection Act 2018                           | A declared purpose and a lawful basis, with employees told what is collected and why before deployment                               |
    | **Impact assessment** — UK GDPR art. 35                                                                       | A DPIA where monitoring is likely to result in a high risk. Art. 35(9) invites seeking the views of workers or their representatives |
    | **Monitoring workers** — ICO employment practices guidance                                                    | Monitoring must be necessary and proportionate to the stated purpose, and the least intrusive means available                        |
    | **Interception of communications** — Investigatory Powers Act 2016 and the 2018 business practice regulations | Frames any interception of the content of communications. The controls in this guide do not collect message content                  |
    | **Expectation of privacy** — Human Rights Act 1998, art. 8 ECHR                                               | Employees keep a reasonable expectation of privacy at work, including on company devices                                             |
    | **Employee representatives**                                                                                  | No statutory works council consultation applies. Where a union is recognized, a collective agreement may still require consultation  |
  </Tab>

  <Tab title="United States">
    | What the law says                                                                                                                            | What it requires here                                                                                                                                 |
    | -------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
    | **Company-owned devices**                                                                                                                    | Monitoring devices owned by the company is generally lawful, and notice is what makes it defensible                                                   |
    | **Interception of communications** — Electronic Communications Privacy Act, 18 U.S.C. § 2510 et seq.                                         | Frames the interception of communications in transit, with consent and provider exceptions. The controls in this guide do not collect message content |
    | **Written monitoring notice by state** — e.g. New York Civil Rights Law § 52-c, Connecticut Gen. Stat. § 31-48d, Delaware Code tit. 19 § 705 | Written notice of electronic monitoring to employees, at hire or before monitoring starts, depending on the state                                     |
    | **California employee data** — CCPA as amended by the CPRA                                                                                   | A notice at collection listing the categories collected, the purposes and the retention periods, plus handling of employee rights requests            |
    | **Unionized workforces** — National Labor Relations Act, § 8(a)(5)                                                                           | Introducing new monitoring may be a mandatory subject of bargaining                                                                                   |
    | **Federal works council**                                                                                                                    | None exists. Employee representatives are involved only where a union contract requires it                                                            |
  </Tab>
</Tabs>

The tool decides nothing. The capabilities listed above exist on every MDM on the market. What a company allows itself to do with them belongs to the framework above and to its own IT charter.

## The IT charter, country by country

Every country in this list expects a written document naming the authorized uses of a company device, the controls applied to it, the cases in which IT intervenes, and how long data is kept. Only its name, its legal weight and the way it is adopted change.

| Country        | Instrument                                                                                  | How it is adopted                                                                                                          |
| -------------- | ------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| France         | IT charter (charte informatique), annexed to the internal rules (règlement intérieur)       | CSE consultation, filing with the labour court registry, transmission to the labour inspectorate                           |
| Germany        | Works agreement (Betriebsvereinbarung), or an IT usage policy where no works council exists | Negotiated and signed with the works council, binding on both sides                                                        |
| Spain          | Criteria for the use of digital devices (LOPDGDD, art. 87)                                  | Drafted with the participation of workers' representatives, then communicated to employees                                 |
| United Kingdom | Acceptable use policy in the staff handbook                                                 | Issued by the employer, backed by a DPIA and a privacy notice. Consultation only where a collective agreement requires it  |
| United States  | Acceptable use and electronic monitoring policy                                             | Acknowledged in writing at hire, with state-specific notice where required and bargaining where the workforce is unionized |

<Note>
  This guide is an information summary, not legal advice. Requirements differ by country, and in the United States by state. Your legal team or local counsel remains the only authority on how your processing activities are qualified and on how your IT charter is drafted.
</Note>

## Related articles

* [Employee guide & FAQ](/guides/device-management/employee-enrollment-guide)
* [Communication resources](/guides/device-management/mdm-rollout-resources)
* [Data wiping compliance](/guides/compliance/data-erasure)
