Skip to main content

Glossary

GDPR

The GDPR is regulation (EU) 2016/679, the European text on personal data protection that has applied since 25 May 2018. It sets the principles for processing personal data, requires security measures appropriate to the risk, and gives you 72 hours to notify your supervisory authority after a personal data breach.

How it works

Being a regulation and not a directive, the GDPR applies directly in every member state with no national transposition. Enforcement is national: the CNIL in France, the AEPD in Spain, the federal and state authorities in Germany, coordinated through the EDPB.

Article 5 holds the six principles that frame everything: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Article 6 sets the legal bases. Article 32 is the one IT teams live with daily: security appropriate to the risk, naming pseudonymisation and encryption, the ability to restore availability, and regular testing of the measures.

Two clocks start after an incident. Article 33 gives 72 hours to notify the supervisory authority of a personal data breach, counted from when you became aware. Article 34 adds telling the people affected when the risk to them is high, unless the data was encrypted in a way that leaves it unintelligible. Fines under article 83 reach 20 million euros or 4 % of worldwide annual turnover.

Why it matters for a fleet

A lost phone with a mail client, synced contacts and a cached CRM is a breach the moment you cannot show it was protected. The proof is a device record: storage encrypted, passcode enforced, wipe command issued and confirmed. Without it, the safe advice from your DPO is to notify, and you are doing that on a 72-hour deadline with no facts.

BYOD raises the harder question. The device belongs to the employee, so their photos and messages are their own personal data and a full wipe is out of bounds. The CNIL's BYOD guidance is blunt about it: the employer's control must stay limited to professional data. A work profile or a managed app container is what turns that limit into something technical instead of a sentence in a policy.

Then there are transfers. Since the Schrems II ruling of July 2020, sending personal data to a US-hosted service means documenting a transfer tool and a risk assessment. Data kept in the EU avoids that work entirely.

How Appaloosa handles it

Appaloosa acts as your processor under article 28 and holds no certification. It does not make you GDPR compliant: the controller duties remain yours. What it gives you is the technical half of article 32 on mobile, meaning enforced storage encryption and passcode, a compliance state per device, selective wipe that removes work data only, and logs of when each command was sent and applied.

The platform runs on infrastructure in France qualified SecNumCloud by ANSSI (version 3.2 of the framework, which covers immunity to non-European legislation), and customer data stays inside the EU, so you have no transfer mechanism to document. Minimisation is part of the design: the console collects inventory and compliance signals rather than location or browsing history, and your mobile device management record is where a DPO can read what happened to a given device.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

See the full platform Explore Appaloosa

Frequently asked questions

Is a lost company phone always a reportable breach?
No. If the device was encrypted, protected by a passcode and remotely wiped, many DPOs document it internally without notifying, because the data stays unintelligible. That reasoning only works if you can produce the evidence, which is why the device record matters more than the incident itself.
Can we wipe an employee's personal phone under GDPR?
Not entirely. A full wipe destroys the employee's own personal data, which you have no basis to process or erase. Use a selective wipe limited to the work profile or managed apps, state it in the BYOD policy, and keep the personal side untouched.
Does an MDM need a DPIA?
Often yes, because it processes employee data and can feel like monitoring. Document which fields you collect, why, and how long you keep them. A DPIA also forces the useful question of what you deliberately do not collect, such as location or browsing history.