DV 54 - Specifying the Guidelines for Using Private IT Devices (BYOD) and Work IT Devices, Including Mobile IT Devices, at Technische Universität Braunschweig

DV 54 - Specifying the Guidelines for Using Private IT Devices (BYOD) and Work IT Devices, Including Mobile IT Devices, at Technische Universität Braunschweig

Historical books in the University Library
Unofficial Translation—the German original is legally binding

Between
Technische Universität Braunschweig
represented by the President

and the
Staff Council of Technische Universität Braunschweig
represented by the Chairperson

the following TU Braunschweig/Staff Council Agreement, hereinafter also referred to as staff council agreement, is concluded in accordance with § 78 NPersVG (Nieder-sächsisches Personalvertretungsgesetz [Lower Saxony Staff Representation Act]):

Preamble

This staff council agreement specifies the application of the guideline “Use of Private IT Devices (BYOD) and Work IT Devices, Including Mobile IT Devices, at TU Braunschweig” (Appendix 1). Binding regulations and responsibilities for compliance are established, particularly with regard to protecting the interests of employees and observing their rights.

§ 1 Objectives

With the increasing use of mobile IT devices and their ever deeper integration into the university's system landscape and business processes, their potential risk is growing. The aim is to meet the legal, regulatory, contractual, commercial, and other requirements identified by TU Braunschweig, for example in relation to risk management. Among other things, this means that all organizational units at TU Braunschweig use IT devices that are secured and maintained according to the state of the art and that data protection requirements are implemented for the data stored on these devices.

Privately purchased mobile IT devices may also be used for official work purposes. In this case, too, data security and data protection have to be guaranteed. Personal and professional applications and data have to be separated, and the availability of work-related data has to be ensured.

The basic principle to be observed here is that the use of private devices is voluntary and has to be approved by the supervisor of the organizational unit. In this case, a supplementary agreement governing the framework conditions has to be signed by both parties. However, the normal case is that an IT device is provided by TU Braunschweig.

Conversely, in practice, work devices are also used for private purposes (e.g., email correspondence). Since, in principle, the employer always has access to work devices, precautions have to be taken to ensure that the rights of the persons concerned under the EU GDPR (EU General Data Protection Regulation) are not violated. This also requires both parties to sign a supplementary agreement that, in addition to the framework conditions to be observed, also contains the approval of the organizational unit management for the private use of company IT equipment. Here, the recommendation to organizational unit supervisors is to be generous with their approvals.

§ 2 Scope of Application

This staff council agreement applies to all employees of TU Braunschweig who fall within the scope of the NPersVG.

§ 3 Legal Framework

The legal framework is based in particular on the following legal principles, which have to be observed in their currently valid versions: EU General Data Protection Regulation (EU GDPR), Niedersächsisches Datenschutzgesetz (NDSG [Lower Saxony Data Protection Act]), Tarifvertrag für den öffentlichen Dienst der Länder (TV-L [Collective Bar-gaining Agreement for the Public Service of States]), Informationssicherheitsordnung der TU Braunschweig [Information Security Regulations of Technische Universität Braunschweig] (Senate Resolution of March 16, 2022), Richtlinie “Umgang mit privaten IT-Geräten (BYOD und dienstlichen IT-Geräten einschließlich mobiler IT-Geräte der TU Braunschweig” [Guideline “Use of private IT devices (BYOD) and work IT devices, including mobile IT devices, at TU Braunschweig”].

§ 4 Specific Provisions Relating to Chapter 3 of the Guideline Use of Private IT Devices for Work Purposes

(1) An organizational unit (OE) in the meaning of this staff council agreement is a clearly defined and fixed area of activities within the structures of TU Braunschweig. In this self-contained work area, supervisors and their assigned employees continuously pursue specific work-related objectives. Organizational units include administrative divisions, designated offices, central facilities and offices for social activities, scientific institutions, institutes, and faculties.

(2) The signatures of supervisors and employees of an organizational unit on a supplementary agreement are a prerequisite for the use of private IT devices for official purposes. The approval has to be documented in the organizational unit, and the organizational unit also has to maintain and keep up to date a list of private IT devices used for work purposes. The use of private IT devices can only be voluntary. If the use of private devices is not desired, a work device has to be provided (standard case).

(3) The supplementary agreement has to refer to the mandatory compliance with the guideline “Use of private IT devices (BYOD) and work IT devices, including mobile IT devices” as well as to this staff council agreement (title and number). Unlike when using official IT devices, users of private devices are personally responsible for ensuring and implementing the provisions of chapters 5 and 6 of the guideline in particular.

(4) In addition, the following content is specifically highlighted in the supplementary agreement:

a) Users are required to comply with legal regulations regarding data protection and information security. This includes, in particular, the obligation to demonstrably implement the rights of data subjects under the EU GDPR (right to erasure, right to correction of incorrect data, right to information about stored personal data) on private IT devices as well. Furthermore, data protection has to be ensured through technical IT security. Operating systems and applications have to be updated regularly.

b) TU Braunschweig (leaders of organizational units) is responsible for ensuring compliance with data protection regulations on all IT devices used for work purposes. Similarly, in accordance with the information security regulations, TU Braunschweig (CISO team or GITZ) also has to be able to access these IT devices at short notice in the event of information security incidents for the purposes of hazard prevention and technical investigation.

c) Consequently, users have to allow the service to access private IT devices within a reasonable period of time (usually within five working days). For hazard prevention and technical investigation in the event of information security incidents, access has to be granted at very short notice if necessary. In addition, the data protection officer may monitor the processing of official personal data at any time and without cause (Art. 39(1) lit. (b) GDPR).

d) To protect their privacy, users have to make a clear distinction between workrelated and private data (e.g., by using two accounts).

e) Securing data: Officials of TU Braunschweig may not access private data on private IT devices without sufficient justification (e.g., when assisting law enforcement authorities). In such cases, access may only take place in accordance with the dual control principle and in the presence of the person concerned.

f) Users are obliged to regularly store and back up work-related data on the GITZ infrastructure (preferably using the TU Braunschweig cloud).

g) Before termination of employment or sale of the private device, the workrelated data have to be returned to TU Braunschweig. The data then have to be securely deleted from the private device before it is passed on to third parties.

§ 5 Specific provisions relating to Chapter 4 of the Guideline on the Use of Work IT Devices for Private Purposes

(1) The signatures of the supervisor of an organizational unit and the employee on a supplementary agreement are required in order to be permitted to use work IT devices for private purposes. The approval has to be documented in the organizational unit, and the organizational unit also has to maintain and keep up to date a list of work IT equipment used for private purposes.

(2) The supplementary agreement has to refer to the mandatory compliance with the guideline “Use of private IT devices (BYOD) and work IT devices, including mobile IT devices” as well as to this staff council agreement (title and number).

(3) In addition, the following content has to be specifically highlighted in the supplementary agreement:

a) Users are required to comply with legal regulations on data protection and information security. This includes, in particular, the obligation to demonstrably implement the rights of data subjects under the EU GDPR (right to erasure, right to correction of incorrect data, right to information about stored personal data).

b) TU Braunschweig (each leader of an organizational unit) is responsible for ensuring compliance with data protection regulations on all IT devices used for work purposes. Similarly, in accordance with the information security regulations, TU Braunschweig (CISO team or GITZ) also has to be able to access these IT devices at short notice in the event of information security incidents for the purposes of hazard prevention and technical investigation.

c) To protect their privacy, users have to make a clear distinction between work-related and private data.

d) Officials of TU Braunschweig may not access private data on the work IT device without sufficient justification (e.g., when assisting law enforcement authorities). In such cases, access may only take place in accordance with the dual control principle and in the presence of the person concerned. TU Braunschweig officials have unrestricted access to devices that are not approved for private use.

e) Upon termination of employment and when turning in the work IT device, it is the users’ responsibility to securely delete their private data.

§ 6 Specific Provisions Relating to Chapters 5 and 6 of the Guideline on Rules for all Users of the IT Infrastructure at TU Braunschweig and Rules for all Employees of TU Braunschweig

(1) In principle, the organizational units are responsible for ensuring compliance with the guideline on the official IT devices provided, with appropriate technical support. Only those points that can be influenced exclusively by employee behavior are the responsibility of the employee.

(2) Employees who use private IT devices for work purposes are individually responsible for implementing the guidelines. Special advice and, if necessary, technical support are required here, as the use of these devices for work purposes is often also in the interest of TU Braunschweig.

(3) All employees affected by the guidelines have to be informed about the BYOD policy through training and education.

(4) Employees are personally responsible for the following points of the guideline:

a) Under Chapter 5.

  • Mobile devices always have to be kept on the person or in a secure location to prevent theft or loss (for example, Kensington locks have proven effective in securing notebooks in the office or at conferences against opportunistic theft). The simplest measure is to lock the office.
  • Devices must never be left unattended in public spaces in order to prevent physical tampering and theft. (For example, devices that are visible in a locked vehicle are at increased risk of theft.)
  • Only trustworthy, state-of-the-art encrypted Wi-Fi access points may be used. If this cannot be guaranteed, the VPN connection provided by TU Braunschweig with encryption of all data traffic has to be used. Exceptions for problematic third countries are regulated in a work instruction. (For example, Wi-Fi access points must have at least WPA2-standard encryption. The TU VPN should be used with the “Tunnel All Traffic” setting. The usability of VPN in certain third countries may be problematic.
  • The use of compromised data carriers (e.g., USB sticks) is a known gateway for the introduction of malware. Therefore, the use and connecting of data carriers and (USB) devices from unknown or untrustworthy sources is not permitted. External data carriers and (USB) devices have to be checked for safety before use. This applies in particular to data carriers of unknown or problematic origin, which have to be checked be-forehand using a scanning program (e.g., Desinfect from Heise Verlag) or at scanning stations or data locks from well-known manufacturers before connecting to the IT infrastructure of TU Braunschweig.
  • Mobile devices should not be connected to external infrastructure without protective measures against attacks via USB/Lightning, not even to charge the device's battery. (For example, when charging at airports, hotels, ports of external devices such as power banks, etc., a USB data blocker should always be used to charge them. Using your own charger is the easiest way to protect yourself.)
  • Unnecessary interfaces and functions should only be activated when they are needed. This excludes them as potential targets for attack. (For example, Bluetooth, Apple AirDrop, Wi-Fi, NFC, developer modes, and USB development mode should be turned off when not in use.)

b) Under Chapter 6.

  • Mobile data carriers (USB sticks, SD cards, external SSD hard drives, etc.) have to be encrypted as soon as documents classified as TLP:AMBER, TLP:AMBER+STRICT, or TLP:RED (or a comparable classification from another classification system) or personal data with protection level D or E are stored on them. Encryption is also recommended for lower protection levels. In addition, the legal regulations governing secrecy apply.
  • Only by immediately reporting the loss of a device used for work (including private devices) can the associated liability issues be transferred to TU Braunschweig and, if applicable, personal liability be avoided. The published reporting process has to be followed for the report; in particular, the relevant authorities, such as the responsible IT administration or the superior authority, have to be informed, with the involvement of the information security officer and data protection management. The institutions can be reached at the following addresses:
    the information security officer soc(at)tu-braunschweig.de,
    the data protection management datenschutz-verstoss@tu-braunschweig.de.
  • Furthermore, all credentials (passwords, cryptographic keys, etc.) used on a lost device have to be changed immediately or the corresponding accesses deactivated in order to prevent unauthorized use. Device approvals based on certificates or hardware features have to be blocked immediately. If possible, initiate remote deletion of the device, e.g., via Active Sync, MDM (Mobile Device Management), the device manufacturer (Apple iCloud, Google Account), or the mobile phone provider. The consent of the employee is required for private devices or privately used work devices that are reset by TU Braunschweig.
  • Lost, misplaced, or compromised access data, credentials, and hardware tokens have to be reported immediately and blocked immediately by the personnel responsible for access to the IT infrastructure of TU Braunschweig. Passwords have to be changed immediately. Reasonable suspicion has to be reported. In all other respects, the above procedure applies.
  • If it cannot be ruled out that a mobile device has been accessed by an unauthorized person (with potential access to the data on the device), the same procedures have to be followed as for the loss of a mobile device. In individual cases, device deletion may be waived if manipulation of the device (e.g., installation of malware or hidden remote access) can be ruled out and the integrity of the stored data can be ensured.
  • Passing on an unlocked work device or privately owned device used for work purposes to third parties (or negligently allowing third parties to access data) is prohibited. The transfer of a work device or a private device used for work purposes to third parties is only permitted under the supervision of the employee if the employee ensures that no access to or insight into work-related data is possible.
  • Any modification or manipulation of the operating system to obtain administrative rights (known as “jailbreaking” or “rooting”) on devices used for work purposes is not permitted. After notification to the information security officer, devices whose work-related use requires administrative rights may be exempted from this requirement. The exception can be revoked at any time.

 

§ 7 Supplementary Agreements and Documentation

Standard forms are used for the supplementary agreements (sample attached to the staff council agreement). Contrary to the guideline, they are not an appendix to the employment contract and are kept by the supervisor of the respective organizational unit. The documentation of approvals and the lists of private IT devices used for work purposes and work IT devices used for private purposes also remain in the respective organizational unit.

Employees may declare in writing at any time that they no longer wish to use private devices for work purposes with immediate effect.

Likewise, TU Braunschweig may revoke the supplementary agreement with an employee at any time in writing, thereby prohibiting the use of private devices for work purposes or the partial use of work devices for private purposes.

In such cases, all work-related data on private devices and all private data on work devices have to be securely deleted immediately.

§ 8 Liability and Damages

In the event of damage, loss, or theft of the work equipment provided, including the loss of data or files, the respective statutory, collective agreement, and civil servants’ regulations apply. Employees are only liable for damages in cases of intentional or grossly negligent breach of their duties.

In the event of damage, loss, or theft of private devices used for work purposes, compensation may be claimed in accordance with the general compensation guidelines of the State of Lower Saxony.

§ 9 Exclusion of Behavior and Performance Monitoring

Performance and behavior monitoring does not take place either in the context of the official use of private devices or in the context of the private use of official devices.

§ 10 Severability Clause

Should one or more provisions of this staff council agreement be invalid, the remaining provisions will remain in force. The negotiating parties will immediately agree on a date to renegotiate the invalid passage.

§ 11 Entry Into Force and Termination

(1) This staff council agreement will enter into force on October 1, 2025. This staff council agreement may be supplemented and amended at any time by mutual agreement. Supplements and amendments have to be made in writing.

(2) The agreement may be terminated with four months' notice to the end of the year, at the earliest on December 31, 2027.

The President
of Technische Universität Braunschweig

Staff Council
of Technische Universität Braunschweig
the Chairperson