Skip to content
Avanet

Sophos Mobile: Weigh Privacy Implications of Data Lake Uploads

Short answer: For Sophos Mobile Threat Defense, the documentation explicitly states that Data Lake uploads are off by default. For the device-management edition, Sophos Mobile, enabling Mobile uploads is described as a separate step, but the same initial state is not explicitly stated there. Before approving uploads, review privacy policies, the affected data and devices, permissions, and the required notice and legal basis, including consent where necessary. The global upload switch is not a single-device pilot. Network logging is an additional option that must be selected explicitly. The Mobile settings for device location and visibility of installed apps are separate; they do not provide a blanket deletion or anonymization function.

Before Approval: What Becomes Visible, and Where?

To query Sophos Mobile data in the Data Lake, the product documentation specifies a Sophos Mobile or Sophos Mobile Threat Defense license, plus an Endpoint, Server, or MDR license with Sophos XDR. The Mobile data path covers Android, iPhone, iPad, and Chromebook. What information is actually provided depends on the management mode: a fully managed Android Enterprise device provides different data from a device on which Mobile manages only Sophos Intercept X for Mobile. This does not establish a universal list of fields for all devices. The published xdr_mobile_data schema includes potential fields for user names and email addresses, device serial numbers and IMEI/MEID, device location, installed apps, certificate subjects, and network destinations. A schema field does not prove that every management mode supplies it or that uploading is enabled in your tenant.

App permission risks are a separate data category: The Android release notes reviewed on October 6, 2026 describe an extension of the Data Lake data in Intercept X for Mobile 9.7.3909 to include information about apps with sensitive and potentially dangerous permissions. These uploads require Sophos Mobile to manage the app and an administrator to enable uploading. Include this permission information in the privacy approval in addition to the app inventory. The earlier release entry establishes neither a uniform current field list nor actual transmission in your tenant. Nor does it establish that Hide installed apps excludes all permission information; clarify that effect separately before approval.

The editions also offer different privacy options:

  • Sophos Mobile (device management): Under My Products > Mobile > Setup > General > Privacy, Forbid admins to find devices blocks device searches in Mobile Admin, while Forbid users to find devices blocks device searches in the Self Service Portal. When device searches are forbidden, the last-known location is no longer shown in Google Maps, but remains visible in the Device location report. This does not demonstrably prevent location data from being collected. Hide installed apps hides the app list for an individual device and also excludes installed apps from the Mobile upload to the Data Lake. A consolidated app list remains available in app reports. None of these settings promises that previously stored data will disappear.
  • Sophos Mobile Threat Defense: Under My Products > Mobile > Setup > General > Privacy, Hide installed apps excludes the installed-app inventory from the device information uploaded to the Data Lake. Show installed apps includes this information again. Do not assume that the location controls documented for the device-management edition are available in this edition.

A portal user does not automatically have administrator rights. When setting up self-service access, check the enabled Mobile features separately from Mobile administrator rights. The Administrator, Helpdesk, and Read-only roles differ in their access to settings and actions; read-only access does not authorize changes to privacy controls. However, the Mobile role descriptions do not establish which role can change the separate tenant-wide Data Lake switch. Check who can change it in your own tenant.

Review and Control Before Any Upload

Before making a change, record the purpose, affected device types, responsible parties, and internal approval. Especially for privately owned devices, clarify visibility, notice to users, and any required valid consent before an upload. A UI switch neither obtains consent nor proves that processing is lawful.

Region and transfers before approval: In Sophos Fusion, open My Products > Mobile and record the tenant region shown in the browser URL after smc-user-if-cloudstation-. Sophos describes Mobile and XDR data as hosted in the region(s) selected when the account was created; this does not guarantee that every transfer, recipient, export, or downstream copy stays in that region. The data processing addendum allows international transfers subject to applicable safeguards regardless of the selected storage location. Before any upload, have the responsible privacy/legal team check the agreement applicable to this tenant, current subprocessors, intended recipients and transfer paths, and any residency requirements. Do not infer a Mobile-specific physical route or approve an upload from the region label alone.

  1. Before any upload, in the device-management edition Sophos Mobile, review the Privacy tab’s location restrictions and installed-app visibility; the device-location report and consolidated app reports can remain visible despite those restrictions. In Sophos Mobile Threat Defense, review the documented installed-app inventory setting on the Privacy tab, but do not assume the full edition’s location switches or reports exist there; verify any applicable location or report access separately through the relevant surfaces. Hide installed apps does not replace a review of Network logging.
  2. For the affected management modes and devices, review an approved list of data categories and recipients, access and retention rules, and the legal basis, including consent where required. A complete list of Mobile fields cannot be inferred from the published examples. Assess Network logging separately: this optional selection is part of the Mobile Upload to the Data Lake process, not an independently effective upload switch. When selected for Mobile uploads, network log data such as IP addresses, ports, timestamps, and apps involved may be transferred; these examples are not exhaustive. The option is documented for Android devices on which Mobile manages the Sophos Mobile Control app and for iPhones and iPads on which Mobile manages the Sophos Intercept X for Mobile app. Do not infer log availability from the platform alone.
  3. Only then, in Sophos Fusion, check the state of Upload to the Data Lake under Global Settings > Products and Services > Mobile and who has permission to change it in your own tenant, without enabling it during this check. This switch applies to Mobile and must not be confused with the Endpoint policy Data Collection and Investigation. Do not enable it in production on the basis of this article: The global switch does not limit uploads to a pilot device; per-device scoping of Mobile uploads is not documented. Before enabling it, you need either a separately approved isolated test tenant or independent evidence of every device that could be included in the upload in the real tenant, together with approval for that entire scope.
  4. Only in an environment approved and checked in this way, reread the switch state and edition after activation. If Live Discover is available in the tenant, use a suitable built-in Mobile Data Lake query under Threat Analysis Center > Live Discover with a short time range—but only if the query is within the approved privacy scope. In the UI, device selection for Data Lake queries cannot be narrowed to a pilot device: all devices are included. This does not mean every query returns rows for every device; query conditions may limit the rows returned. A short query time range determines only which historical data is searched; it does not limit the preceding upload. An empty result proves neither that no upload occurred nor that the switch is set incorrectly: first check the license, time range, management mode, query, and available fields. Do not generate sensitive records for an artificial test.

In the device-management edition, Sophos Mobile logs requests by admins and self-service users for a device’s location, as well as changes to the Privacy tab; the Threat Defense documentation mentions logging changes to privacy settings. This is a point to check during review, not proof that the affected person was notified or consented.

Do Not Overstate Retention or Reversibility

For the Data Lake, Sophos describes general upper limits: up to 90 days for XDR and, optionally, one year with the corresponding storage package. Storage limits may shorten the history available for queries. These statements do not establish the exact retention period of specific Mobile records or audit events, or immediate deletion of already uploaded data when the switch is turned off. The effects on reports, queries, exports, and downstream copies also remain unclear. For binding deletion, export, and retention processes, check the contract, data category, and current tenant state separately.

If approval is withdrawn, turn off Upload to the Data Lake under Global Settings > Products and Services > Mobile, check the optional Network logging selection within the Mobile upload settings, and review the Mobile Privacy settings and visible reports again. Verify the actual tenant state separately; the Network logging selection is not an independent upload path. This procedure is not evidence of retroactive removal of historical Data Lake entries, exported reports, or location data that was previously visible.