YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Legal questions arise as employees use personal smartphones for work.
Legal questions arise as employees use personal smartphones for work.

Speed Bumps in the Mobile Office

Posted online
As smartphones, tablets, laptops and other personal electronic devices have permeated nearly all segments of society, PEDs also have begun showing up in the workplace. Last year, the Pew Research Center reported 56 percent of American adults own a smartphone and 43 percent of people older than 16 own a tablet computer. This proliferation of mobile devices, coupled with near perpetual wireless connectivity, has employers struggling to find the sweet spot between productivity and liability.

Known as BYOD – or bring your own device – the movement refers to any noncompany-issued device an employee brings into the workplace that can connect to the network or servers of the company.

But for all the increased productivity BYOD can offer in the workplace, it also presents many issues and risks companies are only just beginning to deal with.

Labor standards
The ability to remotely check email means many exempt – or salaried – employees start work before they reach the office and can continue well after traditional close-of-business. While the practice improves efficiencies and the company’s bottom line, when a nonexempt – or a nonsalaried – employee has the ability, it can potentially constitute a violation of the Fair Labor Standards Act.

Springfield attorney Jay Dade of Polisnelli PC said the root of the issue lies in the legal interpretation of de minimis, or the shortest amount of time a person can engage in work-related activity before it becomes significant enough to be tracked and recorded as part of the employee’s payroll record.

Currently, there’s no overarching benchmark decision or nationwide precedent in this context, but Dade has seen the wage and hour division of the U.S. Department of Labor take a very broad interpretation to allow for compensation. For exempt staff, the question comes when an employee is logging in remotely to check email.

“What constitutes ‘work’ for the purposes of compensation?” said Dade, who specializes in labor and employment issues, including federal and state wage-hour matters. “In some cases [of exempt employees], we have found as short a time as five minutes is enough for the interpretation to be made that that individual needs to be compensated for a full day, because that [five minutes] represents work that they have done on behalf of the employer.”

Citing the Fair Labor Standards Act, Dade asserts the employer is charged with maintaining accurate payroll records. But he also said the same technology that allows mobile access will usually allow an employer to monitor the digital activity of an employee to a close degree.

“A prudent employer will have in place policies and procedures that enable that employee to accurately record his or her time actually spent,” he said. “In the example of a nonexempt employee who checks email from home, they should be required to log in at the time they start and end, and then be compensated in whatever length of time the employer uses, which these days is usually increments of one-tenth of an hour.”

Husch Blackwell partner Paul Satterwhite works with health care, education and business clients on these issues regularly. “Many of the employers I work with are not allowing hourly workers to have access to email in off-hours because of these considerations,” he said. “It’s too hard to track, and they’ve determined that there’s too much risk.”

Additional BYOD issues include other usage of the device during work hours, such as unrelated texting, mobile Web browsing or gaming. While many workers believe there is an expectation of privacy or autonomy for the content on their own personal device, Dade said Internet access using company Wi-Fi should be covered by the same usage standards as outlined in the company’s policies and procedures.

Usage fees are another gray area companies must address – who pays the bill? Some companies offer a monthly stipend to cover usage costs while employees retain ownership of the device. In these cases, the owner remains liable for maintenance expenses.

Liability
Beyond labor violations, companies can face issues when PEDs are used for work functions because – whether it’s a text message, map search of a meeting location or work-related email – companies are increasingly being held fiscally accountable for employees’ actions. From a liability standpoint, Dade said there are a couple of factors colliding.

“When the employee is acting on behalf of the company, using company equipment on company business, an injured third party has cause for action against both the company and the individual at fault,” Dade said. “If the employee has engaged in personal activities instead of company business, that’s a more difficult call. But we have seen some courts that still find liability with that company.”

According to the National Safety Council, 1 in 4 auto crashes in 2010 involved cellphone usage, and costs from on-the-job vehicle accidents averaged nearly $25,000 per property damage crash and $150,000 per injury crash.

Most safety and risk experts advocate for clear policies that include total cellphone bans while operating a company vehicle or while engaged in company business in a personal vehicle.

A perceived loss in productivity is often given as the main argument against such policies. However, the NSC reports a survey of Fortune 500 companies with total cellphone bans showed productivity increases outpaced decreases by a margin of nearly 3 to 1.

Security
For many companies, the larger concern for employers is not just what is on an employee’s PED, but also who else might see it. Unauthorized access to privileged or confidential content creates an additional liability for employers – an especially daunting problem, given the average American loses their cellphone once a year and nearly half of information technology managers have experienced lost productivity as a result of a mobile security event, according to a report by Lookout Labs.

Attorney Satterwhite said there are alternatives to protect company data besides total cellphone bans. Most company-owned devices are equipped with a kill switch – the ability to remotely track and disable a unit if it’s lost or stolen – but software products exist that can easily apply the same functionality to PEDs.

“A better compromise in that situation is that – for employee-owned devices – the policy must be in place that they allow the IT department to install that software on their phone or tablet that contains company data,” he said. “It’s not to control content, but only to bring the unit up to the same security standards as company-owned devices.”

He points to the financial services, legal and health care industries as having particularly rigorous data security needs, mainly for regulatory compliance and confidentiality issues.

Solutions
Marc Moyer owns Premium Computers, an IT firm that provides security, mobile device management and cloud-based offerings to small businesses of typically around 100 employees or less. Moyer said the top three concerns his clients bring regarding BYOD are security of data, device interoperability and efficient information access.

“As far as data security, the biggest question with BYOD, as a company, is when does the data not become yours?” he said. “It comes down to the security of the device once it’s taken off-site, and is lost, stolen or gets hacked.”

Devices that operate both within the workplace and off-site are at the mercy of the security network they are connected to, be it at home, the library or a coffeehouse.

Other developments impacting business data security include cloud-based networking, which uses two-way security protocols to protect data moving between the device and the cloud.

Moyer said a particularly vulnerable area for small businesses is banking. Since mobile banking falls outside current Federal Deposit Insurance Corp. or other protections, if someone gains access to an online account password and withdraws money, “9 times out of 10, that small business is going to be liable for those losses.”

“The biggest issue is controlling the environment,” he said. “You need to maintain security in a way that keeps the information in you want to keep in, while at the same time making sure what needs to get out, can get out – regardless of the device being used.”

He said the highest-level security systems now require two-factor authentication, such as a traditional password that can only be used in concert with a physical key on a USB drive.

Even with all the increasing hazards in the wireless environment, for some of his clients, interoperability of devices still trumps data security interests.

“Some of them are not as concerned as they should be,” Moyer said.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences