top of page
Search

WhatsApp, Teams and personal cell phones: what can companies really demand after the Constitutional Chamber's vote?

  • EAS LATAM
  • Aug 14
  • 5 min read

By Kimberly Esquivel, Esq.

Work Area | EAS LATAM Group


The scope of vote No. 32917-2025 for business management, cybersecurity and the use of personal devices


Digital transformation has made tools like WhatsApp, Teams, Outlook, and authentication applications essential for the operation of many organizations. However, in many cases, technology has advanced faster than the internal policies needed to regulate its use.


The recent ruling No. 32917-2025 by the Constitutional Chamber provides important criteria for organizations seeking to strengthen their cybersecurity measures, especially in teleworking arrangements. At the same time, it raises a question that many companies have yet to answer:


How far can a company go in requiring the installation of corporate applications on the personal devices of its employees?


The answer has implications for labor, technology, operations and personal data protection.


What did the Constitutional Chamber decide?


The Constitutional Chamber heard the appeal filed by an official of the Superintendency of Telecommunications (SUTEL), who questioned the obligation to install a two-factor authentication application on his personal phone as a requirement to perform teleworking.


The court dismissed the appeal, finding that, according to the technical evidence presented, the application only performed authentication functions and did not access the employee's private information, track their location, or interfere with their device. Furthermore, it concluded that the measure served a legitimate purpose: protecting institutional systems and information from cybersecurity risks.


This criterion confirms that IT security measures can be valid when they respond to a real need, have technical support, and respect the rights of workers.


What this vote does not mean


It would be a mistake to interpret this resolution as a general authorization for companies to require the installation of any application on the personal devices of their employees.


The Court's decision was based on specific circumstances:


  • There was a legitimate need for cybersecurity.

  • The institution technically certified the operation of the application.

  • No access to the official's private information was demonstrated.

  • The measure was directly linked to the teleworking modality.

  • There were internal policies and regulations that supported the technological requirement.


Therefore, organizations should not assume that simply invoking this vote is enough to impose new technological tools. Each measure must be evaluated according to its purpose, proportionality, impact on privacy, and supporting documentation.


The main lesson for organizations


Beyond the legal debate, this vote leaves a clear lesson: cybersecurity should not be managed through improvised instructions.


Companies should have internal policies that regulate aspects such as:


  • The use of corporate devices.

  • The use of personal devices for work purposes.

  • The installation of corporate applications.

  • The protection of business information.

  • The processing of personal data.

  • Digital disconnection.


In the absence of clear policies, even a technically justified measure can generate labor disputes, questions about data protection, or legal risks for the organization.


When the device is owned by the company


If the cell phone is provided by the organization, the organization has greater leeway to define the technological and security controls it deems necessary. These may include:


  • Mandatory use of corporate applications such as Teams or Outlook.

  • Multi-factor authentication.

  • Password policies.

  • Security updates.

  • Remote device management.

  • Procedures for returning equipment at the end of the employment relationship.


Even in these cases, it is advisable to document these conditions through internal policies that clearly define the scope of controls and reasonable expectations of privacy.


Use of personal devices: aspects that the company must document


The scenario changes when the company allows or requires employees to use their own phones to access corporate resources.


The Law Regulating Teleworking establishes, as a general rule, that it is the employer's responsibility to provide the equipment and software necessary for the performance of work. Therefore, when an organization implements schemes for the use of personal devices, it is advisable to document them beforehand.


  • The business need for the tool.

  • The permissions that the application requires.

  • The data you will have access to.

  • The terms of use of the personal device.

  • Applicable security measures.

  • The available alternatives.


The clearer and more documented the process, the less exposure there will be to labor contingencies or questions related to data protection.


The business risk of using personal WhatsApp


One of the most common scenarios in organizations is the use of personal phones to serve clients, suppliers, or manage internal processes through applications like WhatsApp. While this often seems like a practical solution, it also generates significant risks for the company, such as:


  • Commercial information is linked to a number that belongs to the collaborator.

  • Personal and work-related conversations are mixed together.

  • The traceability of important decisions can be lost.

  • Customers continue to contact the employee after the employment relationship has ended.

  • The organization may lose access to the conversation history.


For this reason, when WhatsApp is part of a business process, the safest practice is usually to use accounts and numbers managed by the organization. Likewise, important decisions should not only be documented in a chat but also recorded in the company's official systems.


Teams and Outlook: advantages and limitations


In the case of tools like Teams and Outlook, operating through corporate accounts managed by the organization offers greater control. However, when used on personal devices, internal policies should clearly establish:


  • What corporate information can be stored locally?

  • What technological controls are applied?

  • What permissions do the applications require?

  • How to remove corporate access when the employment relationship ends.


The goal should be to protect business information without unnecessarily affecting the private sphere of the collaborating individual.


Data protection: a business obligation that cannot be ignored


Organizations must also consider the obligations arising from Law No. 8968 on the Protection of the Person against the Processing of their Personal Data.


Not all apps pose the same level of risk. There's a significant difference between a tool that only generates authentication codes and one that requests access to contacts, location, camera, microphone, or files stored on the device.


Therefore, before implementing any technological solution, it is advisable to evaluate the need, proportionality, and permissions it actually requires, limiting access only to what is essential to fulfill the corporate purpose.


Reflection for organizations


The real debate isn't simply about whether a company can require the installation of a corporate application on a personal device. The fundamental question is whether the organization can demonstrate that this measure addresses a legitimate need, is proportionate, has technical support, and has been properly documented.


This analysis will enable the implementation of technological controls with greater legal certainty, strengthen information protection, and reduce labor and compliance risks.


Ruling No. 32917-2025 provides relevant guidance for organizations seeking to strengthen their cybersecurity programs. However, it should not be interpreted as authorizing the installation of any application on personal devices.


The main lesson is that technological measures must respond to a legitimate need, be proportionate, have technical support, and be properly documented.


Rather than expanding employer powers, this resolution emphasizes that technology management, data protection, and labor relations must advance in a coordinated manner. Organizations that develop clear policies on the use of devices, corporate applications, and cybersecurity will be better prepared to protect their information, reduce legal risks, and strengthen a culture of compliance.


Bibliographic references

Constitutional Chamber of Costa Rica. Vote No. 32917-2025.

Office of the Attorney General of the Republic. Law No. 9738, Law to Regulate Teleworking.

Office of the Attorney General of the Republic. Law No. 8968, Law on the Protection of the Person against the Processing of their Personal Data.

Editorial note: Internal policies on personal devices must be coordinated with labor, technical and data protection criteria.

 
 
 

Comments


bottom of page