First off, the article is about processing and metadata analysis, not just a mere "copy". Then, let's clarify: You legally stream a movie, you are also "copying" files to your computer, yet
keeping "a copy" of the entirety would be considered illegal. Pedantic, naive technicalities are a ill-advised legal defense, and so is the expectation of object-oriented jurisprudence. Not everything is categorically same, because of a shared attribute. Intent matters.
With your argument you are conflating intellectual property and business assets of your company, with privacy and informational self-determination of your colleagues. The latter isn't necessarily in the direct interest of your employer, but rather a right given by ethics, or governmental entities. Never mind metadata, a simple copy could mean transferring sensible information to a context where access control for unauthorized parties isn't implemented. Eg. you could have your take-home work laptop stolen, or compromised while watching porn. Legislative example: Under the GDPR, a doctor or therapist is not allowed to handle any patient data on private devices, which extends to contact information stored on their private phone. Context matters.
Not everything is about money, or monetary damage. Privacy rights are about freedom and self-determination of the individual.
Although, the organizational structure and history of a corporation certainly has implications for operational security as well. Try mapping and exfiltrating employment graphs and collected personal metadata at a defense contractor and see where that gets you. Mind you, OP's respective metadata analysis has little informational value in a ten peopled start-up, where you talk to everyone anyway. We're here considering corporations large enough for the individual employee to miss operational oversight by direct means. Corporations large enough, that meta-data would be valuable for third parties, too. Trust matters.