Template

US BYOD Policy Template (Bring Your Own Device)

About this template

Crafted by
Whale logo
US BYOD Policy Template (Bring Your Own Device)

Purpose and Scope

This policy sets the rules for using personal devices, including mobile phones, tablets, and laptops, to access [Organisation Name] systems or data. This includes email, messaging platforms, scheduling tools, customer relationship management systems, and operational files.

Using a personal device for work is optional. Access depends on strict compliance with this policy. These rules protect company and customer data while respecting owner privacy. This document is not an employment contract and does not change at-will employment status.

Working through related paperwork at the same time? See also our UK BYOD Policy Template, UK Data Breach Response Procedure Template and US Data Breach Response Procedure Template.

Policy Statement

Staff may use personal devices for work only with prior approval, through approved access channels, and while maintaining all security standards. [Organisation Name] may revoke device access at any time. We will not monitor or access personal content. Nothing in this policy restricts employees’ legal rights to discuss working conditions.

Approval and Eligible Devices

  1. Request approval from [Role] before connecting any personal device to company systems.
  2. [Role] records approved devices, device types, and access permissions in the BYOD register.
  3. Confirm the device actively receives manufacturer security updates. Devices past end-of-life support are ineligible.
  4. Personnel handling sensitive data (such as health or payment records) cannot use personal devices and must use company-issued hardware. Excluded roles include: [List Roles].

Security Requirements

  • Lock the device with a PIN, password, or biometrics that triggers automatically after inactivity.
  • Keep the operating system and applications updated. Stop using any device for work as soon as it loses update support.
  • Turn on device encryption if it is off by default.
  • Never use jailbroken or rooted devices to access company systems.
  • Install required mobile device management software or approved security applications when mandated for your access level.

Use our templates to fast-track your documentation

Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.

Operational Requirements

  • Access company systems only through approved applications or web portals. Never forward work emails to personal accounts.
  • Save work files exclusively in designated company cloud storage. Do not store company files locally or on personal cloud accounts.
  • Nonexempt (overtime-eligible) employees must not check or respond to work messages outside scheduled hours unless directed by a manager. Record all off-the-clock work time.
  • Keep unauthorized individuals, including family members, from using the device while logged into work systems.
  • Avoid public Wi-Fi networks for work tasks. Use an approved Virtual Private Network (VPN) or secure access tool if public Wi-Fi is unavoidable.
  • Do not take photos or recordings of customer or employee personal data unless an approved work process requires it.

Privacy and Data Access

[Organisation Name] accesses and manages work-related data only. This includes work accounts, business application data, and system access logs. [Organisation Name] will never inspect personal photos, personal messages, browsing history, location data, or personal passwords.

Where remote wipe features are active, actions target work data and work applications whenever technically possible. A full-device wipe is a last resort if a lost device cannot be wiped selectively. Unless immediate action is critical to prevent material risk, the company will notify the device owner before executing a full wipe. Users must sign a written authorization for these terms before receiving access.

Incidents, Lost Devices, and Offboarding

  1. Report a lost, stolen, or compromised device with work access to [Role] immediately.
  2. [Role] revokes system access rights for the device and remote-wipes all work data.
  3. If personal data exposure is suspected, follow the data breach response procedure. [Role] checks applicable state and local breach notification laws.
  4. When an employee leaves [Organisation Name] or exits the BYOD program, IT removes all work accounts and data on or before their final day. The employee must confirm in writing that no company data remains on the device.

Financials, Support, Records, and Review

  • Financial Terms: [Organisation Name] [contributes [Amount] per month for approved regular users / reimburses work calls and data through the expense reimbursement policy / offers no contribution for optional BYOD participation]. Expense claims must comply with local and state reimbursement laws for required business use.
  • Support Limits: Technical support covers work applications and connection setups only. [Organisation Name] does not repair, maintain, or service personal hardware.
  • Records Management: The BYOD register, approval logs, and signed acknowledgments are stored in [System/Location].
  • Review Cycle: This policy is reviewed [Frequency] and updated whenever connected systems or legal requirements change.

Policy Owner: [Role] Next Review Date: [Date]

FAQs on a BYOD policy

A BYOD policy sets the rules for using personal devices, including mobile phones, tablets, and laptops, to access your organisation’s systems or data. This includes email, messaging platforms, scheduling tools, customer relationship management systems, and operational files.

Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.

This template covers approval and eligible devices, security requirements, operational requirements and privacy and data access.

Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.

Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.

Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.

Use our templates to fast-track your documentation

Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.