You must find a new employer—preferably while you make public this repulsive behavior.
You must find a new employer—preferably while you make public this repulsive behavior.
Here’s the big issue I still have even with all of these ‘legal’ protections. The definitions are not highly technical and thus open to interpretation. Also, to my knowledge none of the clauses have been tested in the real world. How in the world am I supposed to feel secure that a legal agreement stops them from doing what is still technically possible? Even if they can’t use the data collected against me as admissible evidence in a disciplinary action what’s to stop them from collecting data anyway and then if they find something they don’t like they harass me in other ways?
The issue is in MDM systems. Until we design them in a way preventing access to certain classes of information through technical means then no type of agreement or ethical code is safe. The device must be treated as hostile. We can’t simply rely on ‘ethics’ because, as we’ve seen play out time after time in America, corporations lose no sleep over saying one thing and doing another.
I’ll take that kind of risk with i.e. Google employees and my Google searches, because it’s fundamentally necessary to provide me good search. There is just no reason to do it with my corporate security team and personal SMS.
Edit - looking at Settings->General->Profiles, there is one entry, which is for connecting to my Olympus camera. Nothing for the office.
During all communications, make it clear what your concerns are; perhaps even link to articles like this one.
Corporations that care about customer and employee privacy will take such inquiries seriously.
If it is your device, typically an employer will disclose in their policies what capabilities they use.
Now, does this prevent a rogue infosec person from deviating from the policy? No. Nor does it prevent the state from compelling the company to abuse their MDM technology. If these examples are part of your threat model, you should not use your personal device with your employer's infrastructure. I don't think this makes your employer's choice to use MDM a bad one, however. They are protecting the corporation, after all.
This is a good recommendation.
I personally was fine with this as I don't want to carry two devices, I like being able to check in via Slack (especially if I was on call), and we had several folks who had our security/IT team under a lot of scrutiny proving this wasn't overly invasive.
It helped that we were a small startup, so our IT and security teams were 20 feet away :)
Also found under Settings -> General -> Device Management.
GPS toggle isn't doing much of anything besides application permissions enforcement.
This article provides a summary of MDM User Enrollment, including details about how Apple separates personal and business data on separate APFS volumes.
https://simplemdm.com/apple-user-enrollment/
Before User Enrollment there wasn't a great Apple MDM enrollment option that struck this privacy balance for employee-owned devices. App data couldn't be viewed per-se, though a list of apps is certainly available (as mentioned by cannonedhamster). Some companies would skip MDM and essentially "wrap" individual apps in order to have the ability to encrypt the app data and have some control over the binary, but that's about it.
I'm not sure of the story with Android, though I'm under the impression that there is a similar "sandbox" option for MDM, albeit the implementation and user experience is rather messy and obtuse.
Full disclosure: I work for an MDM software producer.