There is a line that used to be simple: the company owned the computer, the employee owned the phone, and discovery followed ownership. Bring-your-own-device (BYOD) policies erased that line without replacing it with a clear rule. The phone in an employee's pocket may now hold the text thread that decides a harassment claim, the calendar entry that fixes a termination timeline, or the app data that contradicts a declaration. Whether an employer can be made to produce any of it, and whether the employer can lawfully reach in and collect it in the first place, resolves into a single doctrinal question: does the employer have “possession, custody, or control” of that data under Federal Rule of Civil Procedure 34(a)(1)? This article examines how the control test applies when the device sits outside the company's four walls, what mobile device management (MDM) technology actually grants an employer, and how a forensic expert scopes a collection that satisfies discovery without over-collecting an employee's personal data.
The Governing Standard: Possession, Custody, or Control
Fed. R. Civ. P. 34(a)(1) requires a party to produce electronically stored information (ESI), the texts, photos, app data, and metadata that reside on a device, when that information is within the party's “possession, custody, or control.” Possession and custody are the easy cases: a document sitting on a company-issued laptop is plainly within the company's control. Control is the harder question, and it is the one BYOD disputes turn on, because the device itself belongs to someone else.
Courts applying Rule 34 have long recognized that control does not require actual possession. The widely applied formulation asks whether the responding party has the practical ability to obtain the material from the party who holds it, not merely a fully enforceable legal right to demand it. That test is what allows a litigant to reach data sitting with a third-party vendor, an affiliate, or, increasingly, an employee's personal phone.
Flagg and the Practical-Ability Test
The leading illustration of that logic is Flagg v. City of Detroit, 252 F.R.D. 346 (E.D. Mich. 2008). There, the City of Detroit argued that text messages sent by its employees and archived by a third-party wireless carrier were outside its control. Courts have held otherwise: because the City had a contractual and practical relationship with the carrier that allowed it to obtain the archived messages, the messages were within the City's control for Rule 34 purposes, and the Stored Communications Act did not excuse production. The point of the case is not that the City physically held the text messages. It is that the City had the practical means to get them, and that was enough.
Flagg addressed a carrier holding an employer's data, not an employee's own device, but the underlying test travels well. If practical ability to obtain is what matters, then the question in a BYOD dispute is not who owns the phone. It is what practical and contractual reach the employer actually has into that phone, and that reach is defined almost entirely by the technical architecture of the deployment, not by the fact of personal ownership standing alone.
What BYOD and MDM Actually Grant
Mobile device management (MDM), and the broader category of enterprise mobility management (EMM), is the technology employers use to secure and administer devices that access company data, including personally owned devices enrolled under a BYOD program. According to the National Institute of Standards and Technology's Special Publication 800-124 Revision 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise (2023), a properly configured deployment separates organizational data from personal data, commonly through a “container” or work profile that isolates corporate email, messaging, and documents from the rest of the device. Within that container, the employer typically retains rights to enforce security policy, audit access, and remotely wipe the organizational data, sometimes without touching anything outside it.
That architecture matters because it converts an abstract policy statement into something a court can actually evaluate. A BYOD policy that merely tells employees to expect monitoring, with no signed enrollment agreement and no MDM software actually installed, gives the employer very little practical ability to obtain anything from the device. An enrolled device, with a signed EMM agreement granting audit and remote-wipe rights over a defined container, gives the employer exactly the kind of contractual and practical reach that Flagg-style control analysis looks for. The technical fact of enrollment is evidence for or against the legal element.
The Investigatory Reality on the Ground
The doctrine assumes a clean fact pattern that litigation rarely delivers. Scholarship examining BYOD from the investigator's side has cataloged the recurring failure points: inconsistent or absent employee consent, chain-of-custody complications that arise because the organization never possessed the device to begin with, and BYOD policies so thin or unenforced that the organization has no practical way to compel an employee's cooperation once litigation arrives. Carla J. Utter & Alan Rea, The “Bring Your Own Device” Conundrum for Organizations and Investigators: An Examination of the Policy and Legal Concerns in Light of Investigatory Challenges, 10 J. Digital Forensics, Security & L. 55 (2015). An employer that adopted BYOD for cost and convenience, without building the enrollment and consent architecture to back it up, may discover during litigation that it has neither the device nor a documented right to reach it, which does not eliminate a discovery obligation so much as convert it into a harder fight over what “control” can mean without practical means.
The Proportionality Counterweight
Establishing control does not end the inquiry. Fed. R. Civ. P. 26(b)(1) limits discovery to what is proportional to the needs of the case, and a personal smartphone carries an obvious privacy interest that a company laptop does not: photographs, health data, financial accounts, and communications with family and counsel that have nothing to do with the dispute. Scholarship on this tension argues that courts should, and increasingly do, respond to that asymmetry by narrowing the scope of collection rather than narrowing the finding of control itself. Agnieszka McPeak, Social Media, Smartphones, and Proportional Privacy in Civil Discovery, 64 U. Kan. L. Rev. 235 (2015). Under that framework, even where an employer can reach data on an enrolled personal device, proportionality and the employee's privacy interest counsel toward a targeted extraction of the corporate container, filtered by date range and keyword, rather than a full forensic image of the phone.
That distinction is not merely a defense-side talking point. A party moving to compel BYOD data should expect a court to ask why the corporate container will not suffice before it authorizes anything broader, and a party resisting production should expect that a documented, narrowly scoped MDM architecture, not a blanket privacy objection, is what actually persuades a court to limit the request.
Why a Well-Scoped Policy Helps Both Sides
Organizational-behavior research on BYOD offers a complementary insight from outside the courtroom: employees perceive employer control mechanisms, such as MDM monitoring and remote wipe, as more legitimate when they are paired with procedural fairness, meaning a clear policy that defines in advance what the employer can see and do. Helen Lam, Terry Beckman, Mark Harcourt & Sandra Shanmugam, Bring Your Own Device (BYOD): Organizational Control and Justice Perspectives, Emp. Resps. & Rts. J. (2024) (advance online publication). A narrowly scoped, clearly communicated BYOD policy is not only the more discovery-defensible design; it is also the design least likely to be challenged internally as overreaching, which reduces the odds that the policy itself becomes a subject of dispute once litigation begins.
How a Forensic Expert Scopes the Collection
The practitioner task that follows from all of this is not abstract. Counsel confronting a BYOD discovery dispute, on either side, needs a collection protocol that maps to the actual technical boundary of the employer's control, not to the device as a whole. That protocol should:
- Confirm whether the device is enrolled in MDM or EMM, and obtain the enrollment agreement defining what the employer can access, audit, or wipe.
- Identify the organizational container's actual contents before collection begins, distinguishing corporate email, messaging, and app data from personal content on the same device.
- Propose extraction limited to the container, or to app-specific data the enrollment agreement covers, rather than a full-device physical or file-system image.
- Apply date-range and keyword filtering consistent with the claims at issue, and document why the scope was drawn where it was.
- Preserve a chain-of-custody record for the collection even though the underlying device was never in the employer's physical possession.
A collection built this way answers the control question and the proportionality question at the same time. It shows a court exactly what the employer could reach and did reach, and it avoids creating spoliation exposure for personal data that was never within the scope of the request in the first place.
Engaging an Expert Before the Dispute Hardens
BYOD discovery disputes are won or lost on facts that exist before the motion is filed: what the enrollment agreement says, what the MDM container actually contains, and whether a targeted collection was technically feasible. Counsel who wait until a motion to compel is pending have already lost the ability to shape those facts. Engaging a mobile forensics expert early, to assess the deployment, document what is technically retrievable from the corporate container, and propose a scoped protocol before a dispute over an employee's personal phone escalates, gives both the control argument and the proportionality argument the factual record they need to succeed.
Authorities & further reading
- Fed. R. Civ. P. 34(a)(1)
- Flagg v. City of Detroit, 252 F.R.D. 346 (E.D. Mich. 2008)
- Carla J. Utter & Alan Rea, The "Bring Your Own Device" Conundrum for Organizations and Investigators: An Examination of the Policy and Legal Concerns in Light of Investigatory Challenges, 10 J. Digital Forensics, Security & L. 55 (2015)
- Agnieszka McPeak, Social Media, Smartphones, and Proportional Privacy in Civil Discovery, 64 U. Kan. L. Rev. 235 (2015)
- Helen Lam, Terry Beckman, Mark Harcourt & Sandra Shanmugam, Bring Your Own Device (BYOD): Organizational Control and Justice Perspectives, Emp. Resps. & Rts. J. (2024) (advance online publication)
- Nat'l Inst. of Standards & Tech., Special Publication 800-124 Rev. 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise (2023)
Adapted from Law & Forensics continuing-legal-education and seminar materials (2025–2026). This article is general information for attorneys and is not legal advice; it does not create an attorney-client, expert, or consulting relationship.