BYOD, GDPR and ICO FAQ for UK businesses
Allowing staff to use their own phones, tablets or laptops for work can be convenient, but it changes the organisation’s security and data-protection risk. These 30 questions explain the practical controls to consider before granting access.
Download the free BYOD policy pack
Enter your email address to receive a secure link to the branded 39Security BYOD Policy Template, a PDF copy and the 30-point approval checklist. The files are not attached to the email.
Get the BYOD policy and 30-point checklist.
Editable BYOD Policy Template, branded PDF and 30-point BYOD approval checklist.
- Branded 39Security template
- Editable Word document
- Secure email link - no attachment
- © 2026 Matthew Southgate. All rights reserved.
30 practical answers.
What does BYOD mean?
BYOD means Bring Your Own Device: allowing workers to use a personally owned phone, tablet or computer to access organisational systems or information. The organisation still needs to control how business information is protected.
Does UK GDPR apply when staff use their own devices?
Yes where personal data is processed on or through the device. Using a worker-owned device does not remove the organisation’s data-protection responsibilities.
Does the ICO ban BYOD?
No. BYOD can be used, but it needs appropriate technical and organisational controls. A company-issued and managed device will often be easier to secure and govern.
Is a company-issued device safer than BYOD?
Usually it gives the organisation more control over security configuration, updates, applications, encryption, monitoring and removal of business data. BYOD should therefore be a deliberate risk decision rather than the default because it appears cheaper.
Do we need a written BYOD policy?
A written policy is strongly recommended. It should define who may use BYOD, which systems and data are permitted, minimum device security, monitoring, lost-device reporting, remote removal of work data and what happens when somebody leaves.
Should we carry out a BYOD risk assessment?
Yes. Consider the devices, information, users, applications, threats, business need and the impact if the device is lost, compromised or shared. Record the controls and any accepted residual risk.
Do we need a DPIA for BYOD?
A DPIA should be considered where the proposed processing is likely to create a high risk to people’s rights and freedoms, especially where intrusive monitoring, sensitive data or new technology is involved.
Can we require staff to install MDM or MAM on a personal device?
You can make approved device-management or application-management controls a condition of using BYOD, but the policy and privacy information should clearly explain what the organisation can see, control or remove.
Can the company remotely wipe an employee’s personal phone?
A full-device wipe can create obvious privacy and ownership problems. Where possible, design BYOD so organisational data can be selectively removed from a managed work profile or approved application without deleting personal content.
What is selective wipe?
Selective wipe removes organisational accounts, keys, applications or work data while leaving the user’s personal data intact. It is normally preferable to an unrestricted full-device wipe for BYOD.
Should a BYOD device be encrypted?
Yes where the device and operating system support it. Encryption reduces the risk of business data being read if the device is lost, stolen or removed from the organisation’s control.
Can old phones and laptops be used for BYOD?
Only if they still receive appropriate security updates and meet the organisation’s minimum supported operating-system and device-security requirements. Unsupported devices should not be approved.
How quickly should BYOD devices install security updates?
The organisation should define a reasonable patching requirement based on risk and available device-management controls. Critical security updates should not be postponed indefinitely.
Should MFA be mandatory for BYOD?
Yes for important business services where supported. Strong authentication is particularly important because the organisation has less control over a personally owned device.
Should administrators be allowed to use personal devices?
Privileged administration from personal devices should normally be prohibited or subject to a much stricter approval process because compromise could give an attacker broad control of business systems.
Can a family-shared computer be approved for BYOD?
This is high risk. Other household users must not be able to access business sessions, cached files, browser profiles or credentials. A shared device may be refused where adequate separation cannot be demonstrated.
Can personal cloud backup copy company information?
It can. Personal iCloud, Google Drive, Dropbox, browser sync, device backup and similar services may copy business information outside approved systems. The BYOD design should prevent or limit this where necessary.
Can staff use personal email for company information?
Normally no. Business records should remain in approved organisational systems so access, retention, deletion, security and legal requests can be managed consistently.
How should work and personal data be separated?
Use managed work profiles, approved applications, containerisation or browser controls where practical. Limit downloads and copy/paste routes so work information does not spill into personal apps and storage.
Can staff use public Wi-Fi on a BYOD device?
Only in line with the organisation’s remote-working rules. Use approved secure access or VPN where required, keep devices patched and avoid exposing confidential information in public places.
What should happen if a BYOD device is lost or stolen?
The user should report it immediately. The organisation should revoke sessions and credentials where necessary, selectively remove business data where possible, investigate exposure and follow the incident process.
Is a lost personal device automatically a personal data breach?
Not automatically. The organisation should assess what personal data was accessible, the security controls in place, the likelihood of unauthorised access and the potential consequences, then follow its breach-assessment process.
Can BYOD affect subject access requests and legal holds?
Yes. Business records may need to be found, preserved or disclosed. Keeping work information inside approved organisational systems makes these obligations much easier to manage.
Can a company monitor a worker’s personal device?
Monitoring must have a defined purpose and should be necessary, proportionate and transparent. BYOD privacy information should explain what security or compliance information is collected and avoid unnecessary access to private content.
What happens to BYOD access when an employee leaves?
Revoke business accounts and sessions promptly, remove managed work data or profiles where possible, recover organisational information and confirm that business records remain in approved systems.
Should rooted or jailbroken devices be allowed?
Normally no. Rooting or jailbreaking can weaken platform security controls and should usually make a device ineligible for business access.
Do BYOD devices need endpoint security?
Use the level of anti-malware, EDR, device management or platform security appropriate to the device and information risk. The requirement should be defined before approval.
Do staff need cyber security training before using BYOD?
Yes. Staff should understand phishing, passwords and MFA, updates, approved storage, public Wi-Fi, lost-device reporting, privacy expectations and the boundary between personal and business use.
Who should approve a BYOD exception?
The organisation should name an accountable role. Exceptions should be documented, time-limited where practical and reviewed when the user, device, access or risk changes.
What should we check before allowing a staff member to use their own device?
Use a documented approval checklist covering business need, supported software, encryption, device lock, MFA, least privilege, data separation, cloud backups, endpoint protection, lost-device response, leaver controls and a review date. The free 39Security pack includes a 30-point approval checklist and editable BYOD policy template.