Personally I think it's much cleaner to keep work stuff on your work device(s) and personal stuff on personal devices. The only place that gets sticky is where companies don't provide the device but want you to have work information on it (e.g. mobile phones)
And if you don't want to use BYOD we are required to supply a phone if we require employees to use one (which we do, for MFA).
However they can not reduce private social life to zero at work [1]. And there the employees are guaranteed privacy. NB: This was pre GDPR.
This however does not go so far, that people must be allowed private chatting apps on work phones. They can and should use their private phones.
[1]https://www.jacksonboyd.co.uk/barbulescu-v-romania-work-rela...
I've been in a lawsuit with Oracle (as engineer, not direct). And their discovery hit EVERYTHING.
If I used work devices for personal messages, my personal messages would absolutely been in scope.
Or if I used personal devices for work, my personal devices are now in scope. Hell NO!
My work laptop is on my personal network. Its also on its own vlan and can only talk to the imternet, and not fellow devices. And I can attest to that as much if I'm ever called in for a discovery hearing.
Some of our antimalware like SentinelOne actually does this by default though we have switched it off for privacy reasons (EU)
When we get requests to "legal hold" an account for discovery, this is always coming from the US.
In Europe, unless it's a criminal investigation, which this wouldn't be, there is no way a lawsuit would touch your personal devices if you didn't agree (and mostly also nobody would care I think).
And GDPR explicitly forbids personal items to be released during discovery even to jurisdictions that require that.