GDPR and End Point Security in 2026: What you need to know

Last updated on 9 October 2026

The General Data Protection Regulation has applied since May 2018, and the supervisory authorities have spent the years since building a detailed body of enforcement around it. For anyone responsible for mobile security, the practical question is whether your security architecture passes the tests regulators now apply, and whether it holds up against the newer rules arriving alongside it.

Does GDPR apply to endpoint security?

Yes. GDPR applies to endpoint security because security tools on laptops and phones process employees’ personal data, such as device identifiers, network activity and app usage. That processing needs a lawful basis, usually legitimate interest, and must be proportionate to the security benefit. Tools that analyse data on the device and collect less of it carry a smaller compliance burden.

GDPR applies when an organisation is established in the EU, or when it offers goods or services to people in the EU or monitors their behaviour there. It covers the personal data of customers, and of employees in the EU whatever their nationality. Two things have changed since 2018. Member states have used their powers under Article 88 to set their own, often stricter, rules on workplace monitoring. The EU AI Act has also added a second layer of obligations.

Endpoint security remains a critical part of any organisation’s information security stack. Anti-malware tools, secure web gateways and endpoint management systems all work to keep desktops, laptops and mobile devices from being compromised. These systems involve, to a greater or lesser extent, monitoring employees’ personal data and internet activity. That tension is sharpest on smartphones and tablets, which people routinely use for both personal and business purposes.

When is monitoring employee devices allowed under GDPR?

GDPR allows employee monitoring, but it sets conditions on how far that monitoring can go and how the resulting data is handled. The key principle is proportionality: the security benefit must clearly outweigh the reduction in employee privacy. If a measure cannot be shown to deliver a real security gain, it cannot lawfully be deployed. This applies across desktops, laptops and mobile devices.

Businesses can still monitor device usage. If a proposed measure passes the proportionality test, the organisation is entitled to monitor and to maintain a safe working environment. Where the monitoring is systematic, the organisation will usually need to complete a Data Protection Impact Assessment to confirm it has sufficient grounds. This is assessed case by case, so the answer can vary by industry and by the type of organisation involved.

One point has hardened since 2018. Employers used to rely on employee consent as a basis for monitoring. Regulators now treat consent as rarely valid in the employment context, because the imbalance of power between employer and employee means an employee cannot freely refuse. For workplace monitoring, the usual defensible basis is legitimate interest under Article 6(1)(f). It should be supported by a documented assessment covering purpose, necessity and proportionality.

Why do businesses monitor employees’ mobile devices?

Monitoring employee devices helps detect and prevent the loss of personal data and the loss or theft of intellectual and physical property, and it supports the security of company systems. These are recognised as valid reasons, but the test does not end there.

Where two measures deliver the same or a similar result, the least invasive one must be chosen. This requirement is central to how authorities such as the French CNIL and the Dutch Data Protection Authority assess monitoring tools, and both treat continuous or highly intrusive monitoring as disproportionate in most circumstances.

Failure to comply with GDPR can lead to fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher.

How do national rules on workplace monitoring differ across the EU?

A single EU approach no longer describes reality. At EU level, the Article 29 Working Party’s 2017 opinion on data processing at work already said that logging remote workers’ keystrokes or capturing screenshots is highly unlikely to be justified as a legitimate interest. Member states have built stricter national rules on top of that:

  • Germany: where a works council exists, it has a right of co-determination under Section 87(1) no. 6 of the Works Constitution Act over any technical system capable of monitoring employees’ behaviour or performance. Monitoring tools are therefore normally introduced through a works agreement. The Federal Labour Court has also held that monitoring employees with keylogger software, without a concrete suspicion of a criminal offence or serious breach of duty, is disproportionate.
  • France: the CNIL treats keyloggers as excessive without a strong justification. In July 2026, following several fines in 2025 over non-compliant monitoring tools, it reminded employers that monitoring must be legitimate and proportionate, that the works council must be consulted and each employee informed beforehand, and that a Data Protection Impact Assessment may be required.
  • The Netherlands: the Dutch Data Protection Authority regards permanent or covert monitoring, such as screenshots and keystroke logging, as almost always disproportionate, and does not accept consent as a basis for it. Employers must also ask the works council for its consent before introducing a staff monitoring system.

For a business operating across several member states, the safe approach is to default to the strictest applicable rule and relax only where local law clearly allows.

Does GDPR apply to endpoint security in the UK?

Yes, through its UK equivalent. Since the end of the Brexit transition period, the UK has applied its own UK GDPR alongside the Data Protection Act 2018, with the same core principles of lawful basis, proportionality and transparency.

The Information Commissioner’s Office set out how those principles apply at work in its guidance on monitoring workers, published in October 2023. Its position is that data protection law does not prevent monitoring, but monitoring must be necessary and proportionate and must respect workers’ rights. In practice, that means:

  • telling workers about monitoring in a way they can understand;
  • choosing the least intrusive method that achieves the purpose;
  • completing a Data Protection Impact Assessment where monitoring is likely to pose a high risk to workers.

For organisations operating in both Ireland and the UK, the same device estate is assessed under two closely related regimes. An architecture that collects less personal data makes both easier to satisfy.

How does the EU AI Act affect security monitoring?

The EU AI Act adds a second axis of regulation that did not exist when this article was first written. GDPR governs how personal data is processed. The AI Act governs how the AI system itself behaves: whether it is transparent, whether a human can oversee it, and whether its outputs are accurate and fair. The two apply in parallel, and compliance with one does not satisfy the other.

This matters for security teams because employment and worker management is one of the high-risk categories under the Act, so AI systems used to evaluate, score or make decisions about workers fall into scope. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the obligations for these systems from August 2026 to 2 December 2027.

The Act’s Article 50 transparency obligations were not deferred, and have applied since 2 August 2026. These include the duty to tell people when they are interacting with an AI system. The one change there is a grace period, until 2 December 2026, for the machine-readable marking of AI-generated content from systems already on the market.

The practical lesson is the same one that has held since 2018, with more regulation behind it. The less personal data a security tool collects, and the fewer automated judgements it makes about individual employees, the smaller its regulatory footprint under both GDPR and the AI Act.

We explored this shift in our webinar, Mobile Device Security Re-imagined for the AI Era, which looks at what changes for mobile security as AI moves into both the threat landscape and the defensive stack.

How does mobile endpoint security support GDPR compliance?

For information security and compliance leaders in regulated industries, mobile endpoint security is a privacy question to manage. It can also be one of the more direct ways to meet GDPR obligations. The regulation requires organisations to protect personal data with appropriate technical measures, to detect breaches quickly, and to demonstrate that they did so. Mobile devices are where a growing share of that personal data now lives and moves, and they are also where the weakest controls often sit.

The most immediate contribution is phishing protection. Mobile phishing, delivered through SMS, messaging apps, QR codes and personal email, is a leading route to credential theft and account compromise, and it frequently bypasses the email filtering that protects the desktop. When a mobile endpoint security tool blocks a phishing link before the user reaches it, it prevents the chain of events that leads to a reportable personal data breach. The same applies to malware protection: catching a malicious app or connection on the device stops data exfiltration at source, rather than discovering it in an audit months later.

Beyond prevention, GDPR compliance rests heavily on being able to detect and evidence what happened, which is where integration matters:

  • MDM integration, so that a device found to be non-compliant can be brought back into line or have its access restricted.
  • SIEM integration, so that mobile events sit alongside the rest of your security telemetry and feed your incident response and reporting.

For a data protection officer assembling the facts after an incident, a clear, time-stamped record of which device did what makes the difference between a defensible breach response and a scramble.

For organisations in regulated industries such as healthcare, financial services, government and their suppliers, the obligations are stricter and the penalties larger. Frameworks such as NIS2 and DORA also reach phones through their rules on the wider ICT estate. The practical question for an enterprise buyer is whether a mobile endpoint security tool reduces three risks at once:

  1. the phishing and malware risk to the data itself;
  2. the compliance risk of not being able to evidence protection;
  3. the integration risk of a tool that does not fit the MDM and SIEM stack you already run.

How should corporate-owned devices be secured under GDPR?

GDPR also affects how companies secure corporate-owned mobile devices, and businesses running enterprise mobility management and other mobile security products may need to adapt their chosen solutions. Where consent is the basis relied on, a record should be kept of how and when each employee gave it. The organisation also needs to record where employee data came from and any parties it was shared with. An information audit supports the transparency and accountability the regulation expects, and helps if unauthorised access to employee data ever occurs.

Mobile security solutions should help businesses move towards their compliance objectives. In the event of a data breach, a mobile security solution can provide a clear log of the events leading up to it, drawn from pre-agreed access to corporate-owned devices. The administrator can then see which devices and apps accessed which business services, and the data protection officer can make a better-informed decision on next steps.

Mobile security solutions can also help separate personal and business data. The device controller should not be able to reach an employee’s personal apps or email. This minimises the invasiveness of the security solution, increases the organisation’s security, and indirectly supports employee morale and productivity. Our post on mobile content filtering covers why a well-judged filter can lead to a better, more productive working environment.

How does Corrata approach GDPR?

Corrata is GDPR compliant by design. Its patented on-device technology inspects traffic on the device itself, without the need to track employee location, scan files or record browsing history. This keeps the personal data involved to a minimum and removes the need for the organisation to log device usage. Our product privacy statement sets out what the app does collect.

This matters most on personal and BYOD devices, where regulators across the EU apply a very high proportionality bar to monitoring. Mobile security providers using the traditional VPN gateway or proxy approach must route and inspect employees’ internet usage for their controls to work. With Corrata, employee internet activity does not need to be viewed by any system outside the device, and the app protects the device from web-based threats as a filter rather than a supervisor.

If a device tries to connect to a malicious host, the app blocks access, and that attempt can be reported to the security team. A limited, security-specific record of this kind is far easier to justify under the proportionality test than general monitoring, and the employee’s private activity stays private.

Conclusion

GDPR forced changes to endpoint security, particularly for mobile devices, and the obligations to protect personal data and detect when it has been compromised have only grown more important. The EU AI Act now adds a second set of expectations. Solutions whose architecture depends on continuous external monitoring of device activity sit awkwardly against both.

When we founded Corrata in 2016, it was with exactly this challenge in mind: to deliver strong mobile security without compromising employee privacy. The job for every security architect remains the same, with more regulation behind it: strike the right balance between employee privacy and effective information security.

To find out more about Corrata, get in touch, and for more industry news and analysis, follow us on LinkedIn.

Frequently Asked Questions

How does mobile endpoint security support GDPR compliance?
It helps on three fronts the regulation cares about: preventing breaches through phishing and malware protection, detecting incidents quickly, and evidencing what happened. Blocking a malicious link or app on the device stops the chain of events that leads to a reportable personal data breach. A clear log of device activity gives your data protection officer the facts needed for a defensible breach response.
Is monitoring employees' personal or BYOD devices allowed under GDPR?
It is held to a very high bar. Regulators across the EU set a strict proportionality test for monitoring private and BYOD devices, because the intrusion into personal life is hard to justify against the security benefit. An on-device approach that inspects nothing outside the device is far easier to justify, since it protects the device without viewing the employee’s private activity.
Do the same monitoring rules apply across all EU countries?
No. Member states have used GDPR Article 88 to set their own, often stricter, national rules. In Germany, a works council where one exists has a co-determination right over monitoring tools. France requires the works council to be consulted and treats keyloggers as excessive without strong justification. The Netherlands regards permanent or covert monitoring as almost always disproportionate. A business operating across several member states should default to the strictest applicable rule.
How does the EU AI Act affect mobile security and employee monitoring?
The AI Act regulates how an AI system behaves, including whether it is transparent, overseeable and fair, and it runs in parallel to GDPR. Systems used to evaluate or make decisions about workers fall into the high-risk category, with obligations applying from 2 December 2027. Compliance with GDPR does not satisfy the AI Act, so both need to be considered when a security tool uses AI to make judgements about individuals.
What should a regulated organisation look for when choosing a mobile endpoint security tool?
Look for a tool that reduces three risks at once: the phishing and malware risk to the data itself, the compliance risk of not being able to evidence protection, and the integration risk of a product that does not fit your existing stack. That means effective on-device threat prevention, a clear audit trail, and MDM and SIEM integration, so mobile events sit alongside the rest of your security telemetry.
Is consent a valid basis for monitoring employees?
Rarely. Regulators treat consent as unreliable in the employment context, because the imbalance of power means an employee cannot freely refuse. The usual basis for workplace security monitoring is legitimate interest under Article 6(1)(f), supported by a documented assessment of purpose, necessity and proportionality.

Keep reading

See Corrata on your own devices

A short call, a live look at the product, and a straight answer on whether it fits your estate.

Corrata
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.