Mobile Devices, BYOD, and the Workforce: Responsible Mobile Computing, AICP GREAT LAKES CHAPTER May 18, 2017 Dan Cotter, Butler Rubin Saltarelli & Boyd dcotter@butlerrubin.com 312-696-4497
DISCLAIMER The materials in this presentation are intended to provide a general overview of the issues contained herein and are not intended nor should they be construed to provide specific legal or regulatory guidance or advice. If you have any questions or issues of a specific nature, you should consult with appropriate legal or regulatory counsel to review the specific circumstances involved. Views expressed are those of the speaker and are not to be attributed to his firm or clients.
GOALS OF SESSION This session will discuss compliance issues and some best practices for addressing the increasing prevalence of BYOD. Learn what constitutes “your own device” (smartphones, tablets, laptops, desktops, others?) and opportunities and challenges permitting BYOD create, including use while in transit, overtime issues, and other things that compliance should be thinking about.
AGENDA Define BYOD Why does it matter? Labor and Employment Issues Cyber/Privacy Issues E-discovery/Due diligence issues
DEFINITION BRING YOUR OWN DEVICE
IBM DEFINITION Bring your own device (BYOD) is an IT policy where employees are allowed or encouraged to use their personal mobile devices—and, increasingly, notebook PCs—to access enterprise data and systems
DEFINITION (CONT’D) Easy, right?
STATISTICS 2013 – 181.4 million United States users 2017- was expected to climb to 222.4 million users
OR IS IT? What about:
OR THIS?
WHAT ABOUT THIS?
WATCH, ANYONE?
AND?
WHY DOES IT MATTER? Benefits: Ability to be productive everywhere Reduces costs for the employer Responsiveness Risks: Loss/theft Malware Other exposures
FORMS IT MIGHT TAKE Company owned, business only Bring your own device Choose your own device Company owned, personally enabled
HOW MANY OF YOUR ORGANIZATIONS HAVE A BYOD POLICY?
THE TRADITIONAL BYOD POLICY Acceptable Use Support business Nothing illegal Devices and Support Smart phones Tablets Reimbursement We do not reimburse ,or We will reimburse X Security Passwords Remote wipe ActiveSync
THE TRADITIONAL BYOD POLICY (CONT’D) Good start, but…. Not Complete.
WHAT IS MISSING? USE BY NON-EXEMPT? AFTER HOURS? USE IN TRANSIT? DRIVING CAR? ON PUBLIC TRANSPORTATION? PUBLIC PLACES? DEFINITION OF BYOD? WHAT DOES YOUR ORGANIZATION SUPPORT?
LABOR AND EMPLOYMENT ISSUES
SCOTUS and Independent Contractors (3) The amount of the worker's investment in facilities and equipment Examples: Is the worker reimbursed for any purchases or materials, supplies, etc.? Does the worker use his or her own tools or equipment?
The Continuing Debate
EMPLOYEE ISSUES (CONT’D) Exempt/Non-Exempt? Do you have non-exempt with access who can answer at all hours of day and night? Overtime? BYOD/Employee Handbook? Distracted driving/walking? Hours of Use? Ability to monitor? What happens when leave employment?
CYBER/PRIVACY ISSUES
APPLICABLE LAWS FTC Privacy Protections HIPAA Gramm-Leach-Bliley Computer Fraud & Abuse Act Stored Communications Act
WHAT PLATFORM ON? IOS Much safer if have a password vs. hacking What password protocol do you have? Android Need to install additional safeguards Such as DFNDR
WIFI? Public use? What access does one have on smartphone/other devices?
LOCAL ADMINISTRATOR RIGHTS?
PORTAL ACCESS? - Shutoff or on for laptops?
ENCRYPTION? - What protections does it afford?
E-DISCOVERY/DUE DILIGENCE ISSUES Does anyone remember when Outlook asked if you wanted to archive? Something like this? Or a shorter message?
E-DISCOVERY (CONT’D) If you said yes, you then saved to .pst files, right?
E-DISCOVERY (CONT’D) Know where those went? Personal drives, thumb drives, etc. Anyone ever have to sign off on a production response as it being “complete” and “producing all responsive documents and information?”
Questions
Mobile Devices, BYOD, and the Workforce: Responsible Mobile Computing, AICP GREAT LAKES CHAPTER May 18, 2017 Dan Cotter, Butler Rubin Saltarelli & Boyd