Is device monitoring legal? A 2026 guide
SentinelMDM Team · Updated August 2026 · ~6 min read
Whether you're a parent supervising a child's phone, an employer managing company-issued devices, or an administrator running a small fleet — the legality question comes up fast. The short answer: in most cases, the person or organisation that owns the device and discloses the monitoring has broad authority to monitor it. But the details vary by context, age, jurisdiction, and what exactly you're capturing. Here's the plain-English version.
Key takeaways
- Device ownership is the biggest factor — the owner of a device generally has broad authority to manage and monitor it.
- Monitoring a minor child on a device you own is generally lawful for a parent or legal guardian.
- Monitoring employees on company-owned devices is broadly lawful, especially with notice and a written policy — personal devices and off-hours vary more.
- The picture changes sharply once the person is an adult (18+) on their own device — even your own child.
- Disclosure (telling the user they're monitored) reduces legal risk and is required for many tools, workplaces, and jurisdictions.
- Call/ambient audio recording is governed by separate consent laws that vary by state and country.
1. Who owns the device?
Ownership is the single biggest factor. Courts and regulators generally treat the owner of a device as having authority to manage and monitor it — the same principle that lets an employer manage a company-owned work phone or a parent administer a phone they bought for their child.
Company-owned devices: If the employer bought and owns the hardware, the employer has broad latitude to monitor it — especially when the employee has been given notice and agreed to an acceptable-use policy. This covers phones, laptops, and tablets that stay on company premises or go home with the employee.
Parent-owned devices: When a parent buys and provides a phone to a minor child, the parent generally has authority to supervise that device. The child's own purchase of a device — or an adult's personal device — weakens that authority considerably.
BYOD (personal devices): When the employee or family member owns the device, your legal right to monitor it is much narrower. Employers can often require management software as a condition of connecting to company resources, but can't freely read personal data. Parents generally can't install monitoring software on an adult child's own phone without consent.
2. How old is the person you're monitoring?
Minors are the clearest case. As a parent or legal guardian you're responsible for your minor child's safety and you exercise legal authority over their activities, which extends to a device you provide. In the U.S., the Children's Online Privacy Protection Act (COPPA) is built around the idea that a parent provides consent for a child's data — it assumes the parent is in the loop, not excluded.
Adults (18+) have full privacy rights regardless of who pays the phone bill. Secretly monitoring an adult child's personal phone, a spouse's device, or an employee's personal laptop can cross into illegal interception or stalking territory. If you want visibility into an adult's device, you need their genuine, informed consent.
Employees are adults, so the same adult-privacy principles apply — but the workplace context adds structure. In most U.S. states an employer can monitor company-owned devices used by employees, especially with a clear written policy the employee has acknowledged. Monitoring extends less cleanly to personal devices, off-duty hours, or personal accounts — there, state and national privacy laws start to bite.
3. Disclosure and notice
There's a meaningful legal and practical difference between monitoring where the device user knows it's happening and covert surveillance. Many anti-stalkerware laws and computer-misuse statutes specifically target software that hides itself and intercepts communications without the user's knowledge.
For employers: most jurisdictions require or strongly favour notice. A written acceptable-use policy, an employee acknowledgement, and a visible management agent keep you on the right side of that line. Some jurisdictions (notably parts of the EU and several U.S. states) require explicit consent, not just notice.
For parents: disclosure isn't always legally required for a minor, but it's strongly recommended — it builds trust, reduces conflict, and avoids the legal ambiguity of "secret" software on a device another person uses daily. Many child-safety professionals recommend an open conversation about monitoring as part of digital literacy.
A Device Owner app on Android makes the arrangement visible by default — the OS itself shows a "This device is managed by your organization" notice in Settings. That built-in transparency is a feature, not a limitation.
4. Recording calls and audio: a separate rulebook
Even where general device monitoring is fine, recording conversations is governed by its own wiretap and consent laws that are often stricter. In the U.S., some states are "one-party consent" (only one participant needs to know) and others are "two-party (all-party) consent" — and several other countries are stricter still.
This matters for both parents and employers. Ambient audio recording from a device microphone — even from a child's phone or a company-owned phone on a desk — can trigger recording-consent statutes. Treat call and ambient-audio recording as a higher-risk feature and check the law where you live or operate before enabling it.
5. A practical, low-risk checklist
- Monitor a device you own and administer — whether as a parent providing a phone to a child or an employer issuing devices to staff.
- Tell the user the device is monitored. For employees, put it in a written policy. For children, have an age-appropriate conversation.
- Be cautious with call/audio recording; check your jurisdiction's consent law first — this applies equally in family and workplace contexts.
- Choose a tool that minimizes and protects data — short retention and encryption no one but you can read.
That last point is where the technology choice matters. A monitoring tool that the vendor can read is itself a privacy risk. On Android, SentinelMDM keeps captured data on a 30-day auto-purge and encrypts it so that only you — not even us — can read it. How zero-knowledge monitoring works →
This is general information, not legal advice.
Laws vary by jurisdiction and change over time. For a specific situation — especially anything involving an adult, a shared device, workplace policy, or recording — consult a qualified attorney in your area.
Keep reading