A working audit for legal and compliance teams who account for email and Slack but haven’t looked closely at what’s sitting on every employee’s personal phone.
Most compliance frameworks are built around the data sources IT already controls: corporate email, Slack, enterprise messaging. Mobile data from personal and BYOD devices rarely gets the same scrutiny. Not because it’s low-risk, but because it’s hard to reach, easy to defer, and nobody wants to be the one who has to ask for it.
The risk isn’t that you’ll be asked about mobile data in discovery. It’s that you won’t have an answer ready when you are.
Use this checklist to pressure-test your program across six areas. Where you can’t confidently check a box, that’s the gap opposing counsel or a regulator will find first.
