When tax season arrives, a lot of people do the same thing: they open their work laptop to scan a document, download a bank statement, or pull up a form. It feels harmless. The work laptop is right there, it’s convenient, and it’s just for a minute.
A Forbes report published at the start of this year made the point directly in its headline: your workplace devices aren’t private. Not in the way most employees assume. Not in the way that would hold up if an employer decided to look.
This isn’t about surveillance dystopias or unusually intrusive companies. It’s a straightforward legal and technical reality: if your employer owns the device, they generally control what can be monitored, accessed, and retained on it. Most people have never read the policy that governs exactly what that means.
Who Owns the Device, Owns the Data
The foundational rule of work device privacy is simple: company-owned hardware operates under company rules. That applies to laptops, desktop computers, phones provided by an employer, and any device where IT has installed endpoint management software.
Under U.S. law, employers have both the technical ability and the legal right to access data on company-owned devices. Courts have consistently held that employees have a low expectation of privacy when using employer-owned hardware, particularly when a written policy — even one buried in an employee handbook — establishes that monitoring may occur.
You don’t need to receive a specific warning before monitoring begins. A handbook clause noting that company devices may be subject to review is typically sufficient notice. The absence of a prominent pop-up saying “you’re being watched” doesn’t mean you’re not.
The legal framework in the EU is somewhat more protective under GDPR — employers must establish a legitimate purpose for monitoring and apply proportionality — but the practical reality is still that the device itself is the employer’s asset, and employees have limited control over what happens to data on it.
What Employers Can Actually See
Monitoring software on work devices varies widely in what it captures, but the technical capabilities that exist — and are deployed — include:
Screen captures and screen recording. Some endpoint management systems take periodic screenshots of activity or allow IT to view screens in real time. This can include anything visible on screen: personal email opened in a browser tab, a banking dashboard, photos pulled up for quick reference.
Keystroke logging. Some monitoring tools record keystrokes, which includes passwords entered into personal accounts, private messages typed in a browser-based chat, or drafts of personal documents. The application logging the keystrokes doesn’t distinguish between work typing and personal typing.
File access and storage. IT departments can audit which files exist on a device, when they were created or accessed, and often what they contain. A personal tax document saved to the desktop is not shielded from this visibility.
Network traffic. Many corporate networks route traffic through inspection proxies, meaning even “private” browsing may not be private if you’re on a corporate Wi-Fi network or if the corporate laptop is configured to use the corporate DNS. This includes traffic from personal accounts accessed through company browsers.
Cloud sync. If a work laptop is configured to sync its Desktop or Documents folder to a corporate cloud account — OneDrive for Business, Google Workspace Drive, Box — personal files saved there may flow directly into employer-accessible storage. This is a common enterprise configuration, and many employees aren’t aware their local folders are actively syncing upward.
The “It’s Fine, Nothing Will Happen” Problem
Most people who keep personal files on work devices are right that nothing will happen — most of the time. Companies typically don’t have staff dedicated to reviewing random employees’ desktops. Day-to-day, the monitoring capability sits in the background.
The problem is the circumstances where it stops being background.
Termination. When employment ends — voluntarily or otherwise — devices are commonly wiped or retained and reviewed as part of offboarding. This is standard IT procedure, not a response to suspected wrongdoing.
Internal investigations. If there’s a HR investigation or audit that touches anything near your role, IT may pull device logs, file histories, and communication records. Scope can expand beyond the original subject.
Litigation. If your company faces a lawsuit, legal holds can capture device contents companywide. “Companywide” includes your device. Personal files stored on it are now part of a legal process you have no control over, in the hands of lawyers and forensic analysts you’ve never met.
Acquisition or merger. When companies change ownership, device inventories and data repositories change hands too. A personal file sitting on a work laptop can outlast the company that employed you.
In any of these scenarios, personal files you stored on a work device are now part of a process with its own timeline and scope. Tax documents, medical records, personal photos, private correspondence — anything stored on that hardware is in the employer’s possession, full stop.
None of this requires malice. It’s often the routine operation of legal and HR processes applied to hardware the company owns.
What the Law Does and Doesn’t Protect
There’s a persistent belief that employees have stronger privacy rights on company devices than the law actually provides. Some clarifications:
There’s no general right to personal privacy on company hardware. Courts have repeatedly found that employees who use company devices for personal purposes do so at their own risk, particularly when a written policy reserves the right to monitor.
Personal device monitoring is different. Employers generally cannot require employees to install monitoring software on their personal phones or computers without consent. The legal protection strengthens considerably when you move to devices you own.
BYOD programs occupy a middle ground. If your personal phone or tablet is enrolled in a work MDM (mobile device management) system, your employer may have visibility into some device functions — installed apps, email configuration, potentially remote wipe capability. What they can access depends on the MDM configuration and platform, but enrollment means some corporate visibility exists whether or not you’ve thought about it.
Incognito mode and private browsing don’t help. These features prevent local browser history from being saved. They don’t prevent the corporate network, the MDM software, or the keyboard logger from recording your activity. “Incognito” addresses one specific data-retention mechanism; it doesn’t affect the others.
Remote Work Has Blurred the Physical Boundary
For most of modern history, the separation between work and personal life was enforced partly by physical space. You left the office, you left the work computer behind. Your personal files were at home on a machine you owned.
Remote work removed that boundary. The work laptop is now in the same room as everything else — the tax files, the family photos, the personal email. The temptation to use one device for everything is structural: it’s the most convenient device available, it’s always charged, and reaching for a second device takes deliberate effort.
That convenience has a cost. What used to be a natural physical separation now requires an active habit: keeping work hardware for work use, and keeping personal files on hardware you own.
Hybrid work environments compound this. Employees who spend part of their week in the office and part at home may be using work hardware in personal spaces in ways that didn’t exist before distributed work became the norm.
Practical Steps to Keep Personal Files Off Work Hardware
Use your personal phone for personal documents. A photo of a document taken on your personal phone, uploaded to a personal storage account from your personal phone, keeps it entirely outside the work device chain.
Access personal accounts on a personal device. Even checking personal email on a work laptop routes that activity through employer hardware. Use a separate device where possible for anything you consider personal.
Be especially careful with sensitive documents. Tax records, medical information, financial statements, and personal correspondence are the files most worth protecting. They’re also the categories most likely to cause real harm if reviewed or exposed.
Check what’s syncing. If you’ve ever saved something to a Desktop, Documents, or Downloads folder on a work machine, check whether those folders are configured to sync to corporate cloud storage. Anything synced may already exist in the employer’s cloud, not just on your local device.
Build a clean separation going forward. A dedicated personal storage account — entirely separate from your work ecosystem, tied to a personal email address, accessed only from personal devices — creates a clear bright line. What goes there is personal. What stays on work hardware is work.
What to Do If You’ve Already Accumulated Personal Files on Work Hardware
If personal files have built up on a work device over time, the practical steps are:
Move them off while you still have access. If employment ends, you may lose access to the device immediately and without warning. Retrieve personal files proactively rather than reactively.
Check what’s already synced to corporate storage. Anything in a work cloud folder may already exist in an employer-accessible location. Deleting it from the local device doesn’t necessarily remove the synced copy.
Establish a clean-slate habit going forward. Clearing out past accumulation is a one-time effort; keeping personal files off work hardware from here is a policy you maintain.
Know that file deletion has limits. IT systems that logged file activity or synced contents to corporate cloud storage retain those records even after local deletion. Deleting a personal tax document from a work laptop doesn’t necessarily remove it from the places it’s already been copied.
The Broader Point: Convenience Isn’t Free
Using work hardware for personal files feels free because there’s no obvious immediate cost. The convenience is real — the work laptop is fast, it’s charged, it’s available.
The hidden cost is the loss of control over files that are genuinely private. Tax records document your income. Medical files document your health. Personal correspondence reflects your relationships and your private thoughts. These aren’t files that belong on hardware someone else owns.
A personal storage account that’s accessible from your phone — easy to use, always available, unconnected to any work system — eliminates the reason to reach for the work laptop for personal tasks. The convenience gap disappears; the separation stays.
daftei provides 5 GB free, with unlimited storage on Pro for $5.99/month or $44.99/year ($89.99 lifetime). Files are encrypted in transit with TLS 1.3 and at rest with AES-256. daftei doesn’t run ads, doesn’t sell data, and doesn’t share your files with third parties. It’s available on iOS, Android, and the web at /app — which means the personal storage option is always on the device in your pocket, making the alternative to work hardware a single tap away.
The moment worth protecting against isn’t the big dramatic one. It’s the quiet Tuesday afternoon when it would be slightly more convenient to save something to the work laptop instead.