Apple’s integration of personal and work iCloud accounts has inadvertently allowed former employees to retain access to confidential company documents after their departure. This issue arises from Apple’s policy of encouraging staff to use their personal Apple IDs for work-related iCloud storage, offering a 2TB plan that can be merged with existing accounts. Consequently, work files often become intertwined with personal data.
Upon leaving the company, some ex-employees discovered that shared documents, including sensitive materials like product launch plans, continued to sync to their personal devices. In certain instances, they even received notifications about updates to these documents. This situation has left some individuals apprehensive about deleting the files, fearing it might draw unwanted attention from Apple.
Apple employs a managed folder system for workplace files, designed to revoke access when an employee departs. However, not all internal documents are automatically saved in this folder, leading to shared files being mixed with personal content. Additionally, access to iMessage chats and files shared via the Messages app can persist post-employment.
This lingering access has become a focal point in Apple’s lawsuit against OpenAI. The company alleges that former employee Chang Liu exploited a rare authentication bug to download files while employed at OpenAI. Apple clarified that this case is unrelated to any documents left accessible via iCloud and stated that it does not pursue legal action against former employees who inadvertently retain company documents in their personal iCloud accounts.
Former employees have expressed concerns that Apple does not thoroughly remove sensitive files stored in iCloud from personal devices upon an employee’s departure. In a now-settled legal dispute, chip company Rivos claimed that Apple intentionally allows former employees to retain access to files as part of a strategy to create a pretextual basis for legal action.
This situation underscores the complexities of managing data security in environments where personal and professional digital spaces overlap. It highlights the need for companies to implement clear policies and robust systems to ensure that sensitive information is adequately protected, even after an employee’s tenure ends.