Purpose and Scope
This policy sets the rules for using personal devices, including mobile phones, tablets, and laptops, to access [Organisation Name] systems, platforms, and data (email, messaging, operations apps, and work files).
Using a personal device for work is optional and requires full compliance with this policy. This document protects company and customer data while establishing clear privacy safeguards for personal equipment.
Working through related paperwork at the same time? See also our US BYOD Policy Template, UK Data Breach Response Procedure Template and US Data Breach Response Procedure Template.
Legal and Compliance Framework
Under data protection laws, including UK GDPR and the Data Protection Act 2018, [Organisation Name] remains responsible for personal data processed on its behalf, regardless of device ownership.
We must apply proper technical and organizational security measures wherever work data lives. Losing an unencrypted personal device containing personal data is a security incident. It may require reporting to the supervisory authority within 72 hours of discovery.
Any action to monitor, access, or wipe data on personal devices must be proportionate, agreed upon in advance, and strictly limited to work data whenever technically possible.
Approval and Device Eligibility
- Get written authorization from [Role] before connecting any personal device to company systems.
- Record approved devices, owner details, device types, and permitted access levels in the [BYOD Register].
- Devices no longer receiving manufacturer security updates cannot use BYOD.
- Roles handling sensitive data (such as health or financial records) cannot use personal devices and must use organisation-issued hardware.
Security Requirements
- Lock the device automatically using a PIN, password, or biometric check.
- Keep operating systems and applications up to date. Stop accessing systems if the manufacturer drops security updates.
- Enable full-disk encryption where available.
- Do not use jailbroken or rooted devices with bypassed security controls.
- Install [Approved Security Application / Mobile Device Management Application] if your access level requires it.
Working Rules and Acceptable Use
- Access company systems only through approved applications or web portals. Never forward work emails to personal accounts.
- Store all work files in [Organisation Cloud System]. Saving work files to local drives or personal cloud accounts is prohibited.
- Prevent unauthorized third parties, including family members, from viewing or using the device while signed into work systems.
- Avoid unsecured public Wi-Fi networks. Use [Approved VPN / Secure Access Method] if public network access is unavoidable.
- Do not take photos or screenshots of customer or staff data unless an authorized process explicitly requires it.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
Privacy Boundaries and Monitoring Controls
- [Organisation Name] limits its visibility and control strictly to the work environment on your device. This includes work accounts, data within approved work apps, and access logs.
- [Organisation Name] will never monitor, access, or view personal content, such as private photos, personal messages, browsing history, or location data.
- Remote wipes clear only work data and applications whenever technically possible. We will execute a full-device wipe only as a last resort for a lost device that cannot be wiped selectively. We will notify the device owner before executing a full wipe unless immediate action is critical to stop a serious data breach.
Incident Management and Offboarding Procedure
- Report a lost, stolen, or compromised personal device to [Role] immediately.
- [Role] revokes system access for the device and runs a remote wipe of work data where applicable.
- If you suspect personal data was exposed, follow the internal data breach procedure to check if we must notify regulators within the mandatory 72-hour window.
- When leaving the company or exiting the BYOD program, [Role] removes all work accounts and data from the device on or before the final day. The employee must confirm in writing that no work data remains on the device.
Financial Terms and Technical Support
- Any stipends, reimbursements, or financial contributions for using a personal device must be agreed upon in writing before access is approved.
- [Organisation Name] IT support covers only work apps and network setup. Hardware repairs and general device maintenance remain the owner’s responsibility.
Records and Review
- Approvals, signed acknowledgments, and the [BYOD Register] live centrally in [System / Location].
- [Role] maintains this policy and reviews it [Review Frequency] or after major IT infrastructure changes.
Policy Owner: [Role] Last Reviewed: [Date] Next Review Date: [Date]
FAQs on a BYOD policy
What is a BYOD policy?
A BYOD policy sets the rules for using personal devices, including mobile phones, tablets, and laptops, to access your organisation’s systems, platforms, and data (email, messaging, operations apps, and work files).
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does a BYOD policy include?
This template covers legal and compliance framework, approval and device eligibility, security requirements and working rules and acceptable use.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement a BYOD policy with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.