Rolling out an MDM in Europe means answering to two audiences at once. NIS2 pushes you to bring every device that touches company data under management, while your works council, your DPO and the GDPR limit what you're allowed to see on those devices. The two are compatible, as long as you configure the MDM for security evidence and not for employee monitoring, and you put that in writing.
Two obligations that pull in opposite directions
Start with the security side. Directive (EU) 2022/2555, better known as NIS2, requires essential and important entities to take "appropriate and proportionate technical, operational and organisational measures". Article 21(2) lists ten areas, from incident handling to cryptography, access control and asset management. Germany transposed it with the NIS2UmsuCG, published in the Federal Law Gazette on 5 December 2025 and in force since 6 December 2025,. The ten measures now sit in §30 BSIG, and the BSI has published guidance on them. France is slower: the "Résilience" bill that transposes NIS2 was adopted by the Senate in March 2025 but had not been promulgated when we checked in September 2026. ANSSI tracks the progress here.
None of these texts mention MDM by name. But try proving asset management, encryption and patching on 800 smartphones with a spreadsheet. A mobile device management tool is how you produce that evidence. The security mapping is detailed in our NIS2 and DORA guide. This article stays on the other side of the table.
That other side is employee representation. In Germany, §87(1) no. 6 BetrVG gives the Betriebsrat a co-determination right over the "introduction and use of technical equipment designed to monitor the behavior or performance of employees". Read the word "designed" with care. The Federal Labour Court confirmed in its decision of 13 December 2016 (1 ABR 7/15), that equipment falls under this rule when it is objectively suitable for collecting information about behavior or performance. Your intentions don't matter. An MDM records which user holds which device, when it last checked in and which apps are installed. So it qualifies. If you can't agree, §87(2) BetrVG sends the matter to a conciliation board, whose ruling replaces the agreement.
France uses consultation instead of co-determination. Under Article L2312-38 of the Code du travail, the CSE (in companies with at least 50 employees) must be informed and consulted before any decision to implement means or techniques that allow employee activity to be monitored. Article L1222-4 adds that no information about an employee may be collected through a system that wasn't brought to their knowledge beforehand, and Article L1121-1 requires any restriction of individual rights to be justified and proportionate. Skip these steps and you risk seeing evidence drawn from the tool rejected in court, on top of a dispute with the CSE.
Above both sits the GDPR, with data minimization in Article 5(1)(c) and national employment rules under Article 88.
What an MDM can and cannot see
Most works council discussions go wrong because nobody in the room knows what the tool technically sees. The answer depends on the enrollment mode. Bring a table like this one to the first meeting.
| Enrollment mode | Visible to IT | Not visible to IT |
|---|---|---|
| Android work profile on a personal device (BYOD) | Device model, OS version and patch level, compliance state, apps and data inside the work profile | Personal apps, personal data, personal usage. Google states that the organization has no visibility or access to the personal profile |
| iOS or iPadOS personal device enrolled through an enrollment link | Device model, OS version, managed apps, managed accounts, installed configuration profiles | Messages, photos, personal mail, browsing history, content of personal apps. The user can remove the management profile at any time, which removes managed apps and settings with it |
| Company-owned, fully managed or supervised device | Full hardware and software inventory, all installed apps, compliance state, location if the feature is switched on | Content of messages, calls, photos and app data. |
On Android, the work profile does most of the privacy work for you: the separation is enforced by the operating system, not by a vendor promise. That matches what the CNIL asks for in its BYOD guidance: the employer may remotely erase the professional part of a personal device, never the whole device, and may not access personal elements such as photos, contacts, calendar or browsing history.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →Features to switch off, or to fence in
Data minimization is a configuration exercise. A feature that isn't needed for a security purpose you can name should be off, and the works agreement should say so.
- Location tracking. Off by default. On personal devices, never. On company devices, keep it only for a lost or stolen device, triggered on request, with the employee informed. Continuous location history supports no NIS2 Article 21 measure. That's how Appaloosa works: location is limited to lost mode, on company-managed devices only, never on BYOD. Real-time geolocation of managed devices is only activated on request, once the customer has provided evidence such as user consent or the employment contract clause.
- App inventory on the personal side. A list of personal apps can reveal health, religion or union membership. On an Android work profile the personal list is out of reach anyway. On iOS BYOD and on company devices where private use is allowed, limit inventory to managed apps, and commit to it in writing. On an iPhone enrolled as BYOD, the Appaloosa console only lists managed apps.
- Full device wipe on personal devices. Restrict helpdesk roles to removing the work profile or the managed apps and accounts.
- Per-user reports and last check-in data. Compliance dashboards are fine. Exporting one employee's device activity to settle an HR dispute is not. Limit admin roles and log admin actions.
The fewer optional features you enable at launch, the faster the agreement gets signed.
What to put in the works agreement
In Germany the natural instrument is a Betriebsvereinbarung. §26(4) BDSG and Article 88 GDPR allow collective agreements to serve as a basis for processing employee data. But the Court of Justice made clear in case C-65/23 (19 December 2024) that a works agreement must still comply with Articles 5, 6 and 9 GDPR, and courts can review it in full. An agreement can't authorize what the GDPR forbids.
A workable agreement covers these points:
- Purpose: security of devices and company data, with an explicit statement that the MDM is not used for behavior or performance monitoring.
- Scope: which device categories, which enrollment mode for each (work profile, enrollment link, fully managed).
- A closed list of data fields collected per mode. Attach the table above, adapted to your setup.
- Disabled features, named one by one, and the rule that turning one on requires the works council's consent.
- Admin roles, who can trigger lock and wipe, and logging of admin actions.
- Retention periods for inventory and logs, and deletion when a device or employee leaves.
- Ban on using MDM data as evidence in disciplinary matters, outside of clearly defined security incidents.
- A right for the works council to inspect the console configuration, plus a change procedure for new features after product updates.
In France there's no co-signed document, but the same content belongs in the CSE consultation file, the IT charter and the employee information notice. Our article on the acceptable use policy for mobile devices covers the employee-facing side. Involve the DPO early and check whether a data protection impact assessment under Article 35 GDPR is needed.
NIS2 Article 21 measures mapped to MDM controls
This table shows a works council that every security requirement is met with device data, not people data. An MDM supports these measures. It won't make you compliant alone.
| Article 21(2) measure | MDM control that supports it | Employee data needed |
|---|---|---|
| (i) Asset management | Device inventory with model, OS version, owner, exportable for audits | Name and device assignment |
| (i) Access control, (j) multi-factor authentication | Passcode enforcement, SSO with Microsoft 365, Google Workspace or Okta, blocking non-compliant devices | Work account identifier |
| (h) Cryptography and encryption | Encryption enforcement and reporting | None beyond device state |
| (e) Vulnerability handling | OS update enforcement, patch level reporting | None beyond device state |
| (b) Incident handling | Remote lock, wipe of the work profile or the device, revoking access after loss or theft | Loss report from the user |
| (g) Basic cyber hygiene | Managed app distribution through a private app store, blocking unknown sources in the work profile | Managed app list only |
| (d) Supply chain security | Your MDM vendor is a supplier: check hosting location, certifications of the hosting, contract terms | None |
Look at the third column. Nothing in Article 21 requires location, personal app lists or usage data. That's your strongest argument in the room. A European vendor with a short data flow is also easier to defend: Appaloosa, for instance, is a French company and hosts in France on infrastructure qualified SecNumCloud by ANSSI. We compared the options in our review of MDMs for NIS2 and BYOD in Europe.
A rollout sequence that works
The order matters more than the speed.
- Decide enrollment modes per population. Work profile or enrollment link for BYOD, fully managed for corporate phones, kiosk for shared devices.
- Build the data inventory. One page per mode: what's collected, why, who sees it, how long it's kept.
- Go to the works council or CSE before buying at scale. Show the console in a trial tenant. A live look at what the admin screen shows for a BYOD phone defuses most objections.
- Sign the agreement or close the consultation. In Germany, no production enrollment before signature. In France, consultation comes before the decision to deploy.
- Inform employees individually. A short notice at enrollment on what IT sees and doesn't see.
- Pilot with 20 to 50 users, including a works council member. Then roll out in waves.
- Review every year. Check new product features against the agreement before enabling them.
Employees enroll more willingly when someone they trust has checked the settings. If you want to see what the admin console shows for each enrollment mode, book a demo and bring your DPO along.
This article is general information, not legal advice. Check your situation with your counsel and your data protection officer.
FAQ
Does the works council have to approve an MDM rollout in Germany?
Yes. Under §87(1) no. 6 of the Works Constitution Act (BetrVG), the Betriebsrat has a co-determination right over the introduction and use of technical equipment that can monitor employee behavior or performance. The Federal Labour Court applies an objective test (for example in decision 1 ABR 7/15 of 13 December 2016): it is enough that the system is technically able to collect such data, whatever the employer intends. An MDM records device, user and app information, so it falls under this rule.
Does NIS2 override works council or employee privacy rights?
No. NIS2 (Directive (EU) 2022/2555) and its national transpositions, such as §30 BSIG in Germany, require appropriate and proportionate risk-management measures, but they don't prescribe a specific tool or configuration and they don't suspend the GDPR or labour law. The measures listed in Article 21(2), such as asset management, encryption, access control and incident handling, can be met with device-level data. NIS2 requires neither location tracking nor personal app inventories.
Can an employer see personal data on a BYOD phone managed by an MDM?
No, not when the device is enrolled correctly. On Android, the work profile separates work and personal data at the operating system level, and Google documents that the organization has no visibility or access to the personal profile. On an iPhone enrolled through an enrollment link, IT manages the work apps and accounts it deployed and cannot read messages, photos, personal mail or browsing history. The French CNIL adds that an employer may remotely erase only the professional part of a personal device.
Does a French employer need to consult the CSE before deploying an MDM?
Yes, in companies with at least 50 employees. Article L2312-38 of the Code du travail requires the CSE to be informed and consulted before the decision to implement means or techniques that allow employee activity to be monitored. Article L1222-4 also requires that each employee be informed before any system collects information about them, and Article L1121-1 requires the measures to be proportionate.
Ready to try Appaloosa? Start free