At a company like the one I work for, it's a hill noone can afford to die on. PCI-DSS demands at least some control over employee laptops to ensure that certain secure configuration standards are met. That entails dropping command and control agents on machines. Say what you will about PCI and credit card cartels, but no accreditation, no business. That said, as I work from home, my work laptop lid remains closed for…
How does PCI-DSS compliance work in European countries, with GDPR and actual employee rights with teeth and serious fines at play?