Skip to main content
Informationssicherheit / NIS2

Mobile device management

Mobile device management (MDM) is the central administration, configuration and protection of mobile devices such as smartphones, tablets and laptops – including the ability to lock and wipe a lost or stolen device remotely.

Mobile device management (MDM) is a combined technical and organisational approach that lets an organisation control mobile devices centrally across their entire lifecycle: from enrolment and automated baseline configuration, through day-to-day operation, to decommissioning. An MDM platform distributes security policies, certificates, Wi-Fi and VPN profiles and approved applications to every managed device, enforces screen lock, device passcode and full-device encryption, checks patch and operating-system levels, and flags non-compliant or compromised devices – for example those whose vendor protections have been removed (jailbreaking or rooting). Modern products are often branded unified endpoint management (UEM) because they manage laptops and IoT devices alongside smartphones and tablets from a single console.

From a security perspective, MDM closes the gap created by mobile working: corporate data leaves the protected company network and sits on devices that can be lost, stolen or used on untrusted networks. The core safeguards are therefore the separation of business and private data in a managed container or work profile, enforced encryption of device storage, control of data outflows (copying, backups to personal cloud accounts, sharing out of managed apps) and, above all, remote lock and remote wipe. It is essential to distinguish a full wipe of the entire device from a selective wipe that removes only the business container – on employee-owned devices (BYOD), only the selective variant is normally lawful and proportionate.

Legally and in terms of standards, MDM is not optional. Anyone processing personal data on mobile devices must implement appropriate technical and organisational measures under Article 32 GDPR; encryption and the ability to wipe remotely frequently determine whether a lost device creates a notifiable risk under Article 33 GDPR at all. Within the scope of the NIS2 Directive and the German BSIG, secure handling of endpoints, access control and cryptography are part of the required risk-management measures. ISO/IEC 27001 addresses the topic through Annex A controls 8.1 (user endpoint devices), 6.7 (remote working) and 8.24 (use of cryptography), while the German BSI IT-Grundschutz provides modules SYS.3.2.2 (mobile device management) and SYS.3.2.1 (general smartphones and tablets). Because an MDM is technically capable of monitoring employee behaviour and performance, its introduction in German companies with a works council also requires co-determination under Section 87(1) no. 6 of the Works Constitution Act; the extent of monitoring and the wipe permissions should be set out in a works agreement and an acceptable-use policy.

Legal Basis

Art. 32, Art. 33 GDPR; Art. 21(2) NIS2 Directive (EU) 2022/2555 in conjunction with Section 30 BSIG (German NIS2 transposition act); ISO/IEC 27001 Annex A 8.1, 6.7, 8.24; BSI IT-Grundschutz SYS.3.2.1 and SYS.3.2.2; Section 87(1) no. 6 BetrVG

Practical Example

A field engineer at an energy utility has his company smartphone stolen at a railway station. The information security officer checks the device status in the MDM console: the device is encrypted, protected by a six-digit PIN and biometric unlock, and all business email and documents live in the managed work profile. He first places the device in lost mode and, once the employee has formally reported the loss, triggers a wipe of the container; the MDM logs the timestamp, the administrator who initiated it and the confirmation of success. Together with the data protection officer he documents the assessment under Article 33 GDPR: because the data was encrypted, access was blocked by the device lock and the container was demonstrably wiped within 40 minutes, a risk to the rights and freedoms of the data subjects is unlikely. The assessment and the MDM log go into the internal incident register and later serve as evidence of control effectiveness for "user endpoint devices" in the next ISO 27001 audit.

FAQ

A full wipe of an employee-owned device is usually disproportionate because it also destroys private photos, messages and apps. The appropriate measure is a selective wipe of the business container or work profile. This requires a clear contractual basis – typically a usage agreement with the employee and, where a works council exists, a works agreement under Section 87(1) no. 6 BetrVG.
The loss is always a personal data breach and must be recorded in the internal register. Whether it has to be notified to the supervisory authority under Article 33 GDPR depends on the risk: if the data was effectively encrypted, the device was locked and the container was demonstrably wiped, a risk to the individuals concerned is often unlikely and notification can be dispensed with. That assessment must be documented and backed up with the MDM logs.
The baseline comprises device encryption, a sufficiently strong passcode with automatic screen lock, current operating-system and app versions, separation of business and private data, and blocking of tampered devices (jailbreak or rooting). In addition, remote lock and remote wipe, controlled app installation from a corporate catalogue and protected data transmission via VPN or certificates should be configured. The concrete requirements follow from the protection-needs assessment for the information being processed.

How preeco supports you

Learn how our software supports you with this topic.

Learn more