The iPhone Duo Doesn’t Change Canadian Employment Law — But It Should Trigger a BYOD Policy Review
The iPhone Duo creates no new Canadian employment-law obligation. Review seven BYOD, privacy, electronic-monitoring and device-security policy checks.
The iPhone Duo does not change Canadian employment law. Apple announced its first foldable iPhone on September 9, 2026. That product announcement creates no new Canadian workplace-policy deadline. New phones enter workplaces every year. The useful question for employers is whether their bring-your-own-device (BYOD) rules still match how employees actually work. A BYOD policy in Canada should explain when personally owned devices may access company systems or information, and the conditions attached to that access. A manager opening a confidential employee file on a personal phone presents a familiar policy issue, regardless of the device's shape. The same applies when someone saves a workplace screenshot to a personal photo library or replaces a phone without removing company information. For Canada Policy Manual readers, the announcement is therefore a timely reason to review BYOD, acceptable-use, privacy, electronic-monitoring and information-security policies together. The objective is a usable employee policy manual that reflects today's working arrangements. No Apple-specific compliance change: review existing obligations and practices. Regulator guidance: federal, Alberta and British Columbia privacy commissioners jointly recommend addressing monitoring, acceptable use, approved technology, security, employee departures and information separation. Ontario: covered employers with at least 25 Ontario employees on January 1 must have an electronic-monitoring policy before March 1. The joint BYOD guidance dates from 2015; it is established guidance, not a new 2026 law. The seven checks below combine that guidance with practical implementation suggestions. Canada does not have one employee-privacy rule for every workplace. PIPEDA applies to employee information in federally regulated businesses. Alberta, British Columbia and Quebec have their own private-sector privacy legislation; public-sector and sector-specific requirements may also apply. This article focuses on general policy planning and Ontario's disclosure requirement, rather than providing a Quebec compliance guide. Identify the applicable laws and any collective-agreement commitments before deciding what the employer may collect, inspect or erase. An employee's agreement to BYOD is not a substitute for that analysis. Use technology-neutral scope: personally owned devices that access, process or store company information. Examples can help, but a closed list of phones, tablets and laptops can become dated. Keep an accompanying approval standard for operating systems, supported versions and security settings. Assign IT responsibility for assessing a new device before access is granted. Set clear expectations for updates, screen locks, encryption and authentication. A newly purchased device should still pass the employer's approval process. Define access by role and information sensitivity. Reading a shift schedule and downloading payroll, accommodation records or investigation notes should not automatically receive the same permission. State which records must stay in approved company systems, whether offline copies are permitted, and who can authorize exceptions. HR should identify sensitive records; IT should implement the corresponding access restrictions. Consider company-issued equipment when the work cannot be supported appropriately on a personal device. Make acceptable-use rules concrete. Address copying into personal messages, screenshots, downloads, file sharing and moving information between work and personal apps. Example: a supervisor screenshots an accommodation email to remember a scheduling restriction. That creates another copy of sensitive information outside the approved HR record. The policy should direct the supervisor to an authorized workflow instead. Ask IT which restrictions can actually be enforced. Do not promise that screenshots or transfers are technically impossible without testing the relevant apps and devices. Explain the information collected, monitoring circumstances, purposes, authorized viewers and retention practices. Distinguish work-account logs from access to personal messages, photos or location information. Avoid a blanket statement that employees have no privacy on their own devices. Ontario's existing rule: employers covered by the ESA requirement with 25 or more Ontario employees on January 1 must have a written policy before March 1 that year. It must state whether monitoring occurs; if it does, explain how, when and for what purposes the information may be used. Include preparation and revision dates. Ontario expressly includes monitoring through an employee's personal computer used for work, including remote and hybrid arrangements. The rule is not confined to company equipment. Provide employees with the policy within the applicable 30-day deadlines, including after changes; special timing applies to new hires and assignment employees. Retain required policies for three years after they cease to app