Bring your own device policy

A bring your own device policy reconciling the employer's security and data obligations with the employee's ownership of the device, part of the £995 handbook and core policies, five working days.

Share

Bring your own device policy

A bring your own device policy, drafted for the employer, covering which devices may be used for what, the security the employer requires on a device it does not own, the employer's access, remote wipe and the employee's privacy, personal data on personal devices and the employer's obligations, costs, support and the device that breaks, and leaving, loss and the end of the arrangement. £995 as part of the handbook and core policies, delivered in five working days.

Buy now, £995

When employees use their own phones and laptops for work, the employer's data sits on devices it does not own, cannot inspect and cannot be sure are secure, and the employee's personal data sits alongside the employer's with the employer's management software watching both. The policy has to say which devices may be used for what, what security the employer requires, what access and remote wipe the employee agrees to and what privacy they keep, who pays for what, and what happens when the device is lost or the employee leaves. I draft the policy for the employer as part of the handbook and core policies for a fixed fee of £995, delivered in five working days.

Who this is for

Employers in England and Wales whose staff use personal phones, tablets or laptops for email, messaging, documents or systems, whether by design or because nobody said otherwise.

What matters in a bring your own device policy

Which devices may be used for what

The policy should state which personal devices may be used (phones, tablets, laptops), for which purposes (email and calendar, messaging, documents, access to named systems) and which are prohibited (production systems, special category data, client data where the client's contract forbids it), which applications may be used and which are prohibited (consumer messaging apps for client communications, personal cloud storage for work documents), and the employee's obligation to register the device with the employer before using it for work; a policy that permits everything on any device has no control, and one that permits nothing is ignored.

The security the employer requires on a device it does not own

The policy should set the minimum security (a supported operating system kept updated, a passcode or biometric lock, encryption, automatic locking, no jailbroken or rooted devices, approved security software), the employer's mobile device management or application management software that the employee must install and keep, the separation of work data in a managed container where the employer uses one, the prohibition on storing work data outside the managed applications, and the obligation to report a lost or stolen device immediately; the employer's obligation under Article 32 of the UK GDPR to keep personal data secure does not stop at devices it does not own.

The employer's access, remote wipe and the employee's privacy

The policy should state what the employer's management software can see and do (the managed container and the applications in it, the device's compliance status, remote wiping of the work data or, in the last resort, the whole device), what it cannot see (personal messages, photographs, browsing outside the container, where the software is configured that way), the circumstances in which a wipe is used (loss, theft, a security incident, leaving, a breach of the policy), the employee's consent to it, and the employee's responsibility for backing up their own data because a full wipe removes it; the Information Commissioner's guidance expects the employer to tell the employee exactly this, and the policy is where it is told.

Personal data on personal devices and the employer's obligations

The employer remains the controller of the personal data its staff process on their own devices, so the policy should require compliance with the data protection policy for staff, the handling of personal data only within the managed applications, no local copies, the reporting of breaches within the time the employer needs to meet the seventy-two hour notification under Article 33 of the UK GDPR, and the employee's cooperation with subject access requests that may extend to work data on their device; the employer should also address the risk of the employee's own personal data being seen by the employer, with the software configured to minimise it.

Costs, support and the device that breaks

The policy should say whether the employer contributes to the cost of the device or the contract (a stipend, a proportion, nothing), who pays for the management software, what support the employer provides (for the work applications only, not the device), the position where the device breaks (the employee's responsibility, with a loan device where the employer can provide one), and the tax treatment of any contribution, which the accountants confirm; an employee who cannot work because their own laptop has failed is a situation the policy should anticipate.

Leaving, loss and the end of the arrangement

The policy should set the leaver process (removal of the managed applications and work data, confirmation that no work data remains, the deregistration of the device, the surrender of any employer-funded accessories), the process on loss or theft (immediate reporting, remote wipe, a police report where required, the breach assessment), and the employer's right to end the arrangement and require the use of its own devices for a role or for everyone; the policy should be acknowledged on issue with the consents it contains recorded, because the remote wipe is the step the employee will object to if they did not agree it.

What it costs

Staff handbook and core policies, £995. Five working days.

Employment contract, £595. One template you can reuse for a grade of staff. Five working days.

Buying online forms the engagement on payment. The scope is what the employment contracts and handbooks page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how you employ people
  • Restrictive covenants drafted at a scope a court will uphold
  • Confidentiality and intellectual property provisions that put ownership where it belongs
  • The statutory particulars, so the document does the job section 1 of the Employment Rights Act 1996 requires it to do
  • Flexibility clauses where you genuinely need them, drafted to survive challenge
  • Core policies: disciplinary, grievance, sickness absence, equal opportunities, data protection and, increasingly, AI use
  • One round of amendments

What is not included

  • Acting for employees
  • Employment tribunal representation
  • Payroll, pensions auto-enrolment and tax
  • Immigration and sponsor licence work
  • Day to day HR handling, disciplinaries, grievances and redundancy processes

Questions I am often asked

Can we wipe an employee's personal phone if they leave?

The work data and applications, yes, under the consent the policy records; the whole device only where the policy says so and the circumstances justify it. The employee is told to back up their own data for that reason.

Can we see an employee's personal messages on a managed device?

The policy and the software configuration should mean the employer sees only the managed container and the device's compliance status. The regulator expects the employee to be told exactly what the employer can see.

Do we have to pay towards the device?

Not unless the policy promises it. Many employers contribute to the contract or provide the management software; the policy states the position and the accountants confirm the tax treatment of any contribution.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.