A managed phone answers to two owners.
A phone issued and paid for by an employer usually runs mobile device management software, installed for entirely reasonable reasons: security patches, lost device wipes, compliance with the company's own policies. The trade is that the same software gives the IT department a genuine, if usually limited, view into the device it manages, which makes a work phone a different kind of object from a personal one, even when it feels identical in the hand.
None of this implies anyone is actively reading a specific employee's messages. It means the capability sits there, administered by policy rather than by curiosity, and a sensible line for personal use should be drawn from that fact rather than from how the phone happens to feel day to day, since the two rarely match: a company phone that feels entirely ordinary in daily use can still sit inside a system built to be reviewed at any point.
What device management can typically see.
The honest answer varies by company and by the specific software in use, which makes a general rule more useful than a precise one: assume an IT department can see which apps are installed, general compliance status, and the device's approximate location if that feature is enabled, and cannot usually read the content of a personal message inside an end to end encrypted app unless something more invasive has been installed beyond standard management software.
The word usually is doing real work in that sentence. Company policy documents, not guesswork, are the only reliable source for what a specific employer's software actually monitors, and it is worth reading that document once rather than assuming either the most alarming or the most reassuring version.
The simplest fix, a second device or number.
The cleanest line is the simplest one: keep personal messaging apps, and any account that matters to you privately, off a company-managed phone entirely, and use a personal device or a separate line for everything else. A second number on an eSIM makes this genuinely easy without carrying two physical phones, since a single device can hold both a work profile and a private one without either seeing the other's content.
Where carrying two devices is unavoidable, at minimum keep the personal messaging apps used for anything sensitive off the company device, even if this means a slightly less convenient habit of checking two phones rather than one.
Wi-Fi, browsers and the company network.
Beyond the device itself, a company Wi-Fi network or VPN can, depending on how it is configured, see which sites a connected device visits, separate from anything the device management software reports directly. This applies to a personal phone connected to office Wi-Fi just as much as to a company-issued one, worth remembering on days spent working from an office in the Zuidas rather than only when the phone itself belongs to the employer. A VPN required for work email specifically often routes far more than that one app's traffic once switched on, so check what the client actually tunnels before assuming only email is affected.
Using mobile data instead of the office network for anything genuinely personal, even for a few minutes, sidesteps this entirely and costs little in an era of generous data plans.
Itemised bills, a paper trail of their own.
A company phone plan often produces an itemised bill listing every number called or texted, sometimes reviewed automatically by finance for cost allocation or an expense audit rather than by anyone with any particular curiosity, which makes it a paper trail worth remembering exists independently of any device management software. This is a carrier level record rather than a phone setting, so no privacy adjustment on the device itself changes what the bill shows.
A personal line kept separate, set up as an eSIM rather than a second physical phone, sidesteps this cleanly for anything you would rather never appear on a document someone else in the company routinely reviews.
When the phone changes hands.
Leaving a role or returning a company device is the moment this all matters most concretely, since a returned phone is typically wiped and reissued, but only after whatever was on it has already been visible to the systems managing it up to that point. Treating the device as company property throughout, rather than only at the moment of handover, avoids any awkward surprise about what a departing employee assumed was private turning out not to have been. A short check the week before handover, personal accounts signed out, photos moved elsewhere, the second line already carrying anything that matters, turns the handover itself into a formality rather than a scramble.
Keeping a booking off the work line.
This is exactly why an evening built around the business events format, a reception among the towers of the Zuidas among them, is arranged through your own line rather than the one issued at work, and why a companion filed under tall or aged 30 and over is confirmed there regardless of which phone happens to be in your other pocket that day. The booking page assumes exactly this kind of separation, since the whole arrangement only works if the thread stays somewhere only you can see it.