Work That Lives in a Personal Account
What to do about company work held in personal email, drives, phones and messaging apps when somebody leaves, and why asking is more effective than demanding.
Ask, specifically and early, what company material sits in personal accounts, drives, phones and messaging apps — because none of it is reachable by anything IT can switch off, and after the last day the organisation's only route to it is a request the person may or may not act on.
The handover issue in “Work That Lives in a Personal Account” is easier to manage when current projects, recorded time and unfinished work can be reviewed before access closes. A team evaluating Monitask resources for attendance point system for attendance point system should set a clear cutoff, export what is genuinely required and avoid retaining unnecessary activity data after the departure workflow is complete.
This is the category that has grown fastest and is managed least. It exists because work happens on phones, because people forward documents to themselves to read on a train, and because a messaging group with a supplier has been running for three years on an app nobody in the organisation administers.
For an independent reference relevant to “Work That Lives in a Personal Account”, consult the NSA cybersecurity guidance. Use it to test record quality, access, retention, fair process and exception handling against the organisation’s real departure workflow.
What is actually in scope
- Company documents in a personal email account or personal cloud storage.
- Work on a personal laptop, tablet or phone, including offline copies.
- Messaging threads with colleagues, clients or suppliers on personal apps.
- Photographs of whiteboards, screens, documents or sites.
- Accounts with third-party services registered to a personal address.
- Contact details for clients and suppliers held only in a personal phone.
The last two are where most of the practical value sits and where the legal position is least obvious. A contact list built over seven years is not obviously the organisation's and not obviously the person's.
Asking rather than demanding
Framed as an accusation, this produces denial. Framed as part of the handover — what have you got that we would not know about, so we can make sure it is where it needs to be — it produces a list.
The difference matters because the organisation has no way to verify the answer. There is no scan that finds a document in somebody's personal drive. Cooperation is the only mechanism, and cooperation is a function of how the rest of the exit has been handled.
What to ask for
Three things, in order: that company material is returned or copied back to where it belongs, that it is then deleted from personal accounts, and that the person confirms in writing that they have done so.
The confirmation is not proof and is worth having anyway. It records what was asked, when, and what the person said — which is the difference between an organisation that addressed the issue and one that did not think about it.
The parts that are not simple
Deleting company material from a personal device may require the person to hand over or allow access to something personal, and that raises its own questions. A demand to inspect a personal phone is a serious step, and whether it can be made at all, and on what basis, is a question for somebody qualified in the place concerned.
The same applies to recovering a messaging thread that contains both work and private conversation, and to anything involving a device the organisation did not supply. These are not problems to improvise on a last day.
Why it is cheaper to prevent
Every item on this page exists because there was no sanctioned way to do the thing people needed to do. Somebody forwards a document to a personal address because the file-sharing is awkward. A supplier group runs on a consumer app because the organisation never set one up.
The exit is where that surfaces, and the exit cannot fix it. What the exit can produce is a list of the specific gaps that caused it, which is the input to a project worth doing once rather than discovering repeatedly.
The policy that should already exist
A short, readable statement of what may be kept where, issued in a way that produces a record, is the thing that makes every conversation above easier. It gives the request at exit something to rest on other than goodwill.
It also has to be realistic. A policy prohibiting all use of personal devices, in an organisation where everybody reads mail on their phone, is a policy that will be ignored and that makes the organisation's position worse rather than better. What the rule should be is a question worth asking once, with advice, and then writing down in a form people will actually follow.
Contacts, which nobody agrees about
A professional network built over several years, held in a personal account on a platform the organisation does not control, is the item in this category most likely to be argued about and least likely to be resolved.
Whether connections made during employment belong to anybody, and what can be asked of somebody who leaves, differs and is contested. What an organisation can do is decide its position in advance, write it into the contract rather than raising it at the exit, and be realistic about what is enforceable. Raising it for the first time on a last day achieves nothing except making the last day worse.
On the day itself
Put it on the checklist as a line of its own, with a named owner, and record the answer. "Asked and confirmed nothing held" is a record. An unticked box is a record of a different kind, and it is the one that reads badly when somebody asks about it eighteen months later.