Free Bring Your Own Device policy

BYOD Policy Template for UK Businesses

A Bring Your Own Device policy defines when employees may use personal phones, tablets or laptops for work and the security conditions those devices must meet before they can access company email, files, applications or customer data.

Quick answer

What is this policy and why does it matter?

A BYOD policy helps a company control the security and data-protection risks created when business information is accessed from personally owned devices. It sets minimum device standards, access rules, privacy expectations, lost-device reporting, separation of business and personal data, and the circumstances in which access can be removed or business data wiped.

Business case

Why does a company need this policy?

A policy is not a substitute for technical controls, but it gives employees, managers and IT teams one written standard to work from.

Protect business data on personal devices

Without a policy, company email, files and customer information can end up on devices the organisation does not own, patch or fully control.

Set a minimum security standard

The policy can require supported operating systems, screen locks, encryption, MFA, automatic updates and approved security controls before access is granted.

Clarify privacy and selective wipe

Employees need to understand what the organisation can and cannot see on a personal device, what business data may be removed and what happens when the device is lost or employment ends.

Support GDPR accountability

Where personal data is processed on BYOD devices, the organisation remains responsible for appropriate security and data-protection controls. A written policy helps make responsibilities and restrictions clear.

Inside the template

What should the policy cover?

The downloadable template is designed to be edited around your organisation, technology and employment practices rather than published unchanged.

Eligible personal phones, tablets and laptops
Supported operating systems and security updates
Screen lock, encryption and device integrity
MFA and business-account security
MDM/MAM and application controls
Business and personal data separation
Local storage, backups and personal cloud services
Shared devices and family access
Lost, stolen or compromised devices
Privacy, monitoring and selective wipe
Leavers and removal of business access
Device approval, exceptions and regular review
Who should use it?

Designed for practical UK business use.

  • Businesses allowing Microsoft 365 or Google Workspace on personal devices
  • Employers with hybrid, mobile or home-working staff
  • Organisations considering BYOD to reduce hardware costs or improve flexibility
  • Companies that need a consistent approval process before personal devices access business information

Important: This is a practical template and should be adapted to your organisation. It is not legal or employment-law advice.

Implementation

How to put the policy into practice.

  1. 1

    Decide which roles and business systems are suitable for BYOD rather than assuming every user and application should be included.

  2. 2

    Set a minimum device-security baseline and block devices that cannot meet it.

  3. 3

    Choose how business data will be separated and controlled using platform, MDM or MAM capabilities where appropriate.

  4. 4

    Explain privacy, monitoring and selective-wipe arrangements before the employee enrols a personal device.

  5. 5

    Use the included 30-point approval checklist before granting access.

  6. 6

    Review devices periodically and remove access immediately when a device, role or employment relationship changes.

Free 39Security download

Get the BYOD policy and 30-point checklist.

Editable BYOD Policy Template, branded PDF and 30-point BYOD approval checklist.

  • Branded 39Security template
  • Editable Word document
  • 30-point BYOD approval checklist included
  • Secure email link - no attachment
  • © 2026 Matthew Southgate. All rights reserved.

Email me the download link

By requesting the resource you agree that the transactional delivery email can use a unique open pixel and secure link so 39Security can record delivery-email opens, link clicks and downloads. These measurements can be affected by mail-security scanners and privacy proxies. You will not be added to marketing by this form.

See the privacy notice.

Policy implementation support

Need help making the policy real?

39Security supports businesses in Essex, Kent, Hertfordshire and London with BYOD design, Microsoft 365 security, mobile-device controls, Cyber Essentials readiness and staff training. Remote advice is available across the UK.

Talk to 39Security
Frequently asked questions

10 practical answers.

Use these answers alongside your own risk assessment, technical controls and employment or legal advice where needed.

Does a UK company need a BYOD policy?

There is no single rule that says every employer must operate BYOD, but if staff are allowed to access business systems or personal data from their own devices, a written policy is a practical way to define the security, privacy and access conditions that apply.

Does GDPR still apply on an employee’s personal phone?

Yes. If the organisation is processing personal data for business purposes, using a personally owned device does not remove the organisation’s data-protection responsibilities.

Should every personal device be allowed?

No. The business should define which device types, operating-system versions, ownership situations and roles are eligible. Devices that cannot meet the security baseline should not receive access.

Can a company require MFA on a personal device?

Yes, where access to company systems is conditional on security requirements. The policy should explain the authentication method and any device-enrolment requirement before access is granted.

Can a company wipe an employee’s personal phone?

The preferred design is usually to remove business access or selectively wipe managed business data rather than erase unrelated personal content. The exact capability depends on the platform and management method, and the employee should be told clearly what actions are technically possible.

Should business data be backed up to the employee’s personal iCloud or Google account?

Normally not. Business information should stay within approved company-controlled storage and backup arrangements unless a specific exception has been assessed and approved.

What happens when an employee leaves?

Business accounts, tokens, applications and data access should be removed promptly. Managed business data should be removed according to the company’s process, and any company information stored outside approved systems should be addressed.

Can family members use the same BYOD device?

Shared personal devices create extra confidentiality and access risk. A business may prohibit shared devices or require strong user separation and other controls before approving them.

How often should BYOD approval be reviewed?

Review it when the operating system becomes unsupported, the device changes owner or user, security controls fail, a role changes, a serious incident occurs or at a regular interval set by the organisation.

What comes with the 39Security BYOD download?

The pack includes an editable BYOD Policy Template, branded PDF copy and a 30-point BYOD approval checklist that can be used before granting a personal device access to business systems.

Related guidance

Keep improving the control set.