top of page

WhatsApp, Teams and personal cell phones: what can companies really require after the Constitutional Chamber’s ruling?

Aug 13, 2026

By Kimberly Esquivel


Digital transformation has turned tools such as WhatsApp, Teams, Outlook and authentication applications into essential elements for the operation of many organizations. However, in many cases technology has advanced faster than the internal policies needed to regulate its use.


The recent ruling No. 32917-2025 of the Constitutional Chamber provides important criteria for organizations seeking to strengthen their cybersecurity measures, especially in remote work arrangements. At the same time, it raises a question that many companies have not yet resolved: how far can a company require the installation of corporate applications on employees’ personal devices?


The answer has labor, technological, operational and personal data protection implications.


What did the Constitutional Chamber decide?

The Constitutional Chamber heard the appeal filed by an official of the Superintendency of Telecommunications (SUTEL), who questioned the obligation to install a two-factor authentication application on his personal phone as a requirement to perform remote work.


The Chamber dismissed the appeal, considering that, according to the technical evidence provided, the application only performed authentication functions and did not access the employee’s private information, did not track his location and did not interfere with his device. In addition, it concluded that the measure served a legitimate purpose: protecting institutional systems and information against cybersecurity risks.


This criterion confirms that information security measures may be valid when they respond to a real need, have technical support and respect workers’ rights.


What this ruling does not mean

It would be a mistake to interpret this decision as a general authorization for companies to require the installation of any application on employees’ personal devices. The Chamber’s decision was based on specific circumstances: there was a legitimate need for information security; the institution technically proved how the application worked; no access to the official’s private information was demonstrated; the measure was directly linked to the remote work modality; and there were internal policies and regulations supporting the technological requirement.


For this reason, organizations should not assume that invoking this ruling is enough to impose new technological tools. Each measure must be assessed according to its purpose, proportionality, impact on privacy and documentary support.


The main lesson for organizations

Beyond the legal debate, this ruling leaves a clear lesson: cybersecurity should not be managed through improvised instructions. Companies should have internal policies regulating aspects such as the use of corporate devices, the use of personal devices for work purposes, the installation of corporate applications, protection of business information, processing of personal data and digital disconnection.


In the absence of clear policies, even a technically justified measure may generate labor disputes, questions about data protection or legal risks for the organization. When the cell phone is provided by the organization, the company has a broader margin to define the technological and security controls it considers necessary, including mandatory use of corporate applications such as Teams or Outlook, multifactor authentication, password policies, security updates, remote device management and procedures for returning the equipment at the end of the employment relationship.


Even in these cases, it is advisable to document these conditions through internal policies that clearly define the scope of the controls and reasonable expectations of privacy. The situation changes when the company allows or requires employees to use their own phones to access corporate resources. The Law to Regulate Remote Work generally establishes that the employer must provide the equipment and programs necessary to perform the work. Therefore, when an organization implements personal-device-use schemes, it is advisable to document in advance the business need for the tool, the permissions required by the application, the data it will access, the conditions for using the personal device, the applicable security measures and the available alternatives.


One of the most frequent situations in organizations is the use of personal phones to communicate with clients, suppliers or internal teams through applications such as WhatsApp. Although this may seem practical, it also creates significant risks: business information remains tied to a number owned by the employee, personal and work conversations become mixed, traceability of important decisions may be lost, clients may continue contacting the employee after the employment relationship ends and the organization may lose access to the conversation history. For that reason, when WhatsApp is part of a business process, the safest practice is usually to use accounts and numbers administered by the organization. Relevant decisions should also be recorded in the company’s official systems, not only in chat messages.


Tools such as Teams and Outlook offer greater control because they operate through corporate accounts managed by the organization. However, when they are used on personal devices, internal policies should clearly establish what corporate information may be stored locally, what technological controls apply, what permissions the applications require and how corporate access is removed when the employment relationship ends. The objective should be to protect business information without unnecessarily affecting the employee’s private sphere.


Organizations must also consider the obligations derived from Law No. 8968 on Protection of Persons Regarding the Processing of Personal Data. Not all applications present the same level of risk. There is an important difference between a tool that only generates authentication codes and another that requests access to contacts, location, camera, microphone or files stored on the device. Before implementing any technological solution, it is advisable to assess need, proportionality and the permissions that are truly required, limiting access only to what is essential to fulfill the corporate purpose.


The real debate is not only whether a company may request the installation of a corporate application on a personal device. The underlying question is whether the organization can demonstrate that the measure responds to a legitimate need, is proportional, has technical support and has been properly documented. This analysis makes it possible to implement technological controls with greater legal certainty, strengthen information protection and reduce labor and compliance risks. Ruling No. 32917-2025 is relevant for organizations seeking to strengthen cybersecurity programs, but it should not be interpreted as authorization to require any application on personal devices.


References

The main lesson is that technological measures must respond to a legitimate need, be proportional, have technical support and be properly documented. More than expanding the employer’s powers, this ruling reminds organizations that technology management, data protection and labor relations must advance in a coordinated manner. Bibliographic references: Constitutional Chamber of Costa Rica, Ruling No. 32917-2025; Office of the Attorney General of the Republic, Law No. 9738, Law to Regulate Remote Work; Office of the Attorney General of the Republic, Law No. 8968, Law on Protection of Persons Regarding the Processing of Personal Data. Editorial note: Internal policies on personal devices should be coordinated with labor, technical and data-protection criteria.

bottom of page