ComplyChat Start free

Guide · Work messaging

Work messages on personal phones

Most work conversations in a school, a charity or a care service now happen on phones the organisation does not own. A teaching assistant texts the class teacher about a child; a care worker messages the senior on shift about a fall; a fundraiser replies to a donor from the number in her own contacts; trustees keep a group chat. The organisation did not set any of that up and cannot see it, but the law treats it as the organisation’s: the ICO says staff holding personal information on their own devices “may be holding it on your behalf”, so it is within scope of a subject access request, and the Cabinet Office tells civil servants that messages about government business in WhatsApp or private email are held “on behalf of your department” and engage “your recordkeeping responsibilities”. At the same time the organisation cannot simply look. The ICO is equally clear that an employer must tell workers about any checking of their communications, and must not capture the private use of a personal device. This guide sets out what the organisation answers for, what it can and cannot see, what the guidance says a policy has to cover, and the record that, on a personal phone, never reaches the file.

13 minute read

A care worker in a plain tunic reads a message on her own phone in the doorway of a resident’s room at the end of a corridor, the screen turned away from the camera
01

Whose messages they are

The starting point is the controller, not the device. Under UK GDPR the organisation that decides why and how personal information is used is responsible for it wherever it sits, and the ICO’s right of access guidance applies that to staff phones in terms: “In most cases, you do not have to supply personal information if someone else is storing it on their own computer systems (except where that person is your processor or if your staff have stored the requester’s personal information on their personal devices).” It then says what it thinks of the practice: “It is not usually appropriate for your staff to hold information about customers, contacts or other employees on their personal devices (eg in private email accounts, smartphones, home computers or private instant messaging applications). You should have a policy which makes this clear, particularly as there may be security risks if staff keep information on devices that you do not control.” And it draws the consequence: “If you do permit staff to hold personal information on their own devices, they may be holding it on your behalf. This means that this information may be within scope if you receive a SAR.”

The public sector has written the same rule down as policy. The Cabinet Office’s guidance on non-corporate communication channels (WhatsApp, Signal, private email, private messaging on social media, SMS) starts from ownership: “Government communications belong to the Crown and must be handled lawfully. If you hold such communications in NCCCs you do so on behalf of your department.” Its definition is the useful one for any organisation: a non-corporate channel is “a communication channel that does not provide corporate access to information”, as against government systems, which are “corporately-overseen systems providing corporate access to the information held in them”. The test is not whether the app is respectable but whether the organisation can get at what is in it. Then: “In general, it is expected that you use government systems for government business. Any use of NCCCs for significant government business engages your recordkeeping responsibilities”, where significant information is “information that materially impacts the direction of a piece of work or that gives evidence of a material change to a situation.”

The sector regimes assume the same. Keeping children safe in education 2026 requires every school’s staff behaviour policy to include “acceptable use of technologies (including the use of mobile devices), staff/pupil relationships and communications including the use of social media”. CQC’s Regulation 17 requires a care provider to “maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken”, and a decision taken by message between two carers is a decision taken. Charity trustees answer to the Commission for decisions however they were made. None of these regimes asks whose phone the message was on.

02

What that reaches in practice

Read together, the organisation is responsible for, and may be asked to produce:

  • messages between colleagues about pupils, residents, service users, donors, parents or other staff, whatever app carried them;
  • messages to and from the people the organisation serves, sent from a member of staff’s own number or account;
  • group chats for a team, a shift, a class, a project or a board, including the ones a member of staff set up unasked;
  • photographs and voice notes sent in the same conversations, which are personal data like the text;
  • the contact details themselves: a parent’s or resident’s number saved in a personal phone is the organisation’s personal data held on a device it does not control;
  • decisions taken in those messages that the records the regime requires (a care record, a safeguarding chronology, a set of minutes) are supposed to show.

What it does not reach is the rest of the phone. The messages the organisation answers for are the work-related ones; a worker’s private conversations on the same device are the worker’s, and the next section is about the line between them.

03

What the organisation can and cannot see

Responsibility for the messages does not bring a right to read the phone. The ICO’s employment guidance on monitoring workers sets the terms, and they are strict. “Workers have the right to be informed about the collection and use of their information, and you must tell workers about monitoring in a way that is accessible and easy to understand.” “Monitoring conducted without transparency is unfair and could negatively impact trust relationships.” “Apart from in very exceptional circumstances where covert monitoring is justified, you must inform workers about any monitoring”, and the specific considerations add that an employer is “unlikely to be able to justify covert monitoring in usual circumstances”. On personal devices the guidance is specific: “Some workers may also use personal devices for work.” “This can be particularly intrusive if workers are using their own devices.” “You should ensure that when workers are using their own personal devices for work, you are not capturing their private use of their device.”

So the organisation is in a position the law creates and does not resolve: it answers for the work messages and must not look at the private ones, on a device where the two sit in the same app. Three things follow. The organisation cannot install anything on a personal phone, read it, or require it to be handed over, outside a lawful process such as a court order or a properly justified investigation the worker has been told about in advance. It can ask: the ICO’s right of access guidance says that where “you have a good reason to think your staff are holding personal information about the requester on their personal devices, you should ask them to search their private emails, devices or instant messaging applications, as appropriate.” And it can decide, in advance and in writing, what work may and may not be done on a personal device at all, which is the policy.

The practical consequence is that the organisation’s control over these messages is exercised through the worker, never around them. What the worker searches for, exports and hands over is what the organisation has. When the worker has left, deleted the conversation, changed phone or simply cannot find it, the organisation has nothing, and “we could not obtain it” is the answer it gives to the requester, the tribunal or the inspector.

04

What the policy has to say

The ICO’s advice is the shortest statement of the first rule: “You should have a policy which makes this clear”. The Cabinet Office guidance is the best published model of what a complete one contains, because it had to be written for people who were already doing the thing it regulates. Its structure transfers directly:

  1. A default. “In general, it is expected that you use government systems for government business.” The organisation’s own channels are the default for work conversations; anything else is the exception and needs a reason.
  2. A classification of what may go where. The guidance distinguishes “significant” information from “logistical or other non-significant information”, and a corporately managed device from “a privately owned and managed device”. On a private device, significant information needs “exceptional circumstances” and “any use in these circumstances should be reported”; logistics are “permitted with due regard to your security responsibilities”. A school can say the same in its own words: swapping a duty is logistics; anything about a named child is not.
  3. A record-keeping rule for the exceptions. “Any use of NCCCs for significant government business engages your recordkeeping responsibilities.” If a decision or a concern has to be dealt with by message on a personal phone, the policy says how and when it is transferred to the record the regime requires.
  4. What must never be on a personal device, which the guidance handles by classification (“must not use”) and a school, charity or care service handles by category: images of children or residents, safeguarding detail, medical information, bank details.
  5. What happens to work information when the worker leaves, and the expectation that it is returned or deleted, with the honest acknowledgement that the organisation cannot verify either.
  6. How the organisation will and will not look, in the ICO’s terms: what is checked, why, how workers are told, and the statement that private use of a personal device is not captured.
  7. How a subject access request or a disclosure order reaches the phone: the duty on staff to search their own devices and accounts when asked, and to preserve rather than delete once a request or a dispute exists.

Behind the policy sits a decision most organisations never take in terms: whether to issue a work phone or to let employees use their personal phone for work. The first costs money and puts the calls and texts, the work emails and the number the families have on one device the organisation owns, can manage with mobile device management, and takes back when someone leaves. The second costs nothing and puts work and personal life on one device the organisation cannot touch: the personal number becomes the work number, personal calls and work calls share a bill the worker pays, customer data and personal photographs share a backup, and the question of what happens to the messages when the worker leaves the organisation has no good answer. BYOD is a legitimate choice for some roles, and the policy is where it is made deliberately, with the business use defined, the phone bill and any allowance settled, work hours and working from home covered, and the disciplinary consequences of a breach stated in the same place as the rules.

For schools the policy sits inside the staff behaviour policy KCSIE requires; for care providers it is part of the governance CQC tests under Regulation 17; for charities it is a trustee decision that belongs in the minutes. In every case it is a policy about the organisation’s information, not about the worker’s phone, and it reads better and works better when it is written that way round.

Two teaching assistants on a school playground bench at break, one showing the other something on a phone held between them, screen away from the camera
05

How long, and where the record has to end up

A message on a personal phone has whatever retention the app and the phone give it, which is none the organisation controls: disappearing-message settings, a factory reset, a lost handset or a leaving date end it. Every regime above assumes a different clock. A care record must be “accurate, complete and contemporaneous” and kept for the periods CQC and the provider’s own schedule set; a safeguarding chronology in a school is kept for the child’s lifetime in practice; a charity’s decisions are needed for as long as the accounts they explain; an employment dispute can reach back years. None of those periods can be met by a message the organisation does not hold.

The policy therefore needs one more rule, and it is the one most policies leave out: the point at which a work conversation on a personal phone becomes part of the organisation’s record, and who moves it. The Cabinet Office puts that duty on the individual (“you do so on behalf of your department”). A workable version for a smaller organisation is a short list of triggers, a concern about a person, a decision, an instruction, a complaint, anything a regulator could ask about, and a rule that the message is copied into the system of record the same day, with its time and sender, by the person who received it.

The honest limit is that this is a duty of memory and diligence placed on the busiest people in the organisation at the worst moments, and it will be met unevenly. The alternative is to reduce how often the trigger fires, by giving the conversations that matter a channel the organisation owns in the first place.

06

The conversations that never reach the record

Everything above is written from the organisation’s side, and it describes a gap the organisation cannot close by policy alone. The message in which the concern was first raised, the reply that decided what to do, the photograph of the bruise, the donor’s change of mind, the trustee’s yes: these are the records the regimes require and the evidence a tribunal, an inspector or a requester asks for first, and they are on a device the organisation cannot read, under a retention it does not set, held by a person who may have left.

When the question comes, the organisation asks the worker to search their phone. Sometimes the conversation is there and exported; often it is partial, or deleted, or on the last handset, or the worker has gone. The file then begins with the entry that was typed up afterwards, and the timing that decides whether the organisation acted promptly, or knew, or was told, is the part it cannot produce. The policy did everything a policy can do, and the record still has a hole where the first message was.

The fix is not to forbid staff from messaging about work on their own phones; that is the concern being raised, the shift being covered, the decision being taken, and a ban moves it rather than stopping it. It is to give the work conversations a channel the organisation owns, on any phone including a personal one, so that the message is on the record with its time as it is sent, the reply is next to it, and the worker’s private conversations stay where they are: in the worker’s own apps, which nothing lawful can read. Two limits, stated plainly and including for products like ours: no channel can reach conversations that have already happened elsewhere, and no channel is a care record, a safeguarding file or a minute; it is the place those records point at.

A question for the next leadership or trustees’ meeting: take the last thing that went wrong. Where was the first message about it, and could the organisation produce it today without asking anyone to search their own phone?

07

Official guidance and your next step

The primary sources are the ICO’s right of access guidance on finding and retrieving information (the passage on personal computer equipment and personal devices) and its employment guidance on data protection and monitoring workers with the specific considerations for different methods; the Cabinet Office’s Non-corporate communication channels for government business (March 2023), which applies to central government and is quoted here as the best published model of the policy; Keeping children safe in education 2026 on the staff behaviour policy; and CQC’s guidance on Regulation 17. The ICO’s guidance is written for UK GDPR and the Data Protection Act 2018 and applies to every organisation that is a controller, whether or not it is public.

This guide is a summary of published guidance for the United Kingdom, not a substitute for it and not legal advice. Whether a particular message is within scope of a request, and what an employer may lawfully do about a particular worker’s device, depends on the facts; take advice before acting on either.

Then do one thing: ask five members of staff, in confidence, what the last work message on their own phone was about. If any of the five answers is a person the organisation is responsible for, the policy is needed this term, not next year.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. Work messages on staff’s own phones are the whole problem in one sentence: the organisation answers for them, cannot read them, and needs them. ComplyChat gives those conversations a channel your organisation does own, on any phone, on the record from the first message, filing into your own Microsoft 365 once your tenant is connected and kept under your own retention rules; a member of staff’s private messages stay in their own apps, where nothing lawful can read them, and everyone in a channel is told it is on the record. There is no WhatsApp, Signal or Meta anything in the path, and we cannot see a personal phone. It is not a policy and it does not replace one; it is what the policy can point staff at when it says “use the organisation’s channel”.

How it works · Why us · Pricing · FAQ