This guide is about the data and the device: email, documents, records systems and apps on hardware the organisation does not own. When staff may use their phones around pupils or residents is covered in the personal mobile phone policy guide, and work messages on personal phones have their own guide. Here the questions are security, data protection and the owner’s privacy, which is what the ICO and the National Cyber Security Centre write about.
The rule: the organisation stays responsible, whoever owns the device
Under UK GDPR the organisation is responsible for the security of its personal data on a member of staff’s own device in the same way as on its own equipment. Article 32 requires the controller to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk”, taking account in particular of the risk of “accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data” (UK GDPR Article 32). The National Cyber Security Centre puts the BYOD consequence in a sentence: “the responsibility for protecting information rests with the data controller, not the device owner.”
The ICO’s guidance Bring your own device – what should we consider? sets out three approaches, from safest to riskiest:
- Company issued devices. “This is generally the most secure option, but it is also the most expensive.”
- Use your own device, but access company software. “This is a more cost-effective option, but comes with some security risks.” Here “The device owner’s data and the organisation’s data should be separate. Staff should not be able to inadvertently or deliberately move the organisation’s data into their personal storage on the device or onto separate personally-owned devices.”
- Use your own device, with no separation. “This approach has the most security risks and should be avoided for all but the smallest organisations with an immediate need to work remotely with no other remote working capability.”
What is “appropriate to the risk” depends on the data. Health information about residents and service users, and safeguarding information about children, are among the most sensitive personal data an organisation holds; health data is special category data under UK GDPR. The more sensitive the data a personal device can reach, the stronger the controls the policy has to require, and the more carefully the organisation should record the risk assessment behind its choice. For higher-risk processing that may mean a data protection impact assessment.
Most schools, charities and care providers that allow BYOD are, in practice, somewhere between the second and third, and the policy’s first job is to say which. The ICO page carries a notice that, because of the Data (Use and Access) Act 2025, the guidance “is under review and may be subject to change”, so check its date before relying on it.
What BYOD covers, and the ways of allowing it
BYOD covers every device the organisation does not own that touches its data: phones and tablets, and also home laptops and family PCs used to open work email or the records system. The NCSC’s Bring your own device (BYOD) guidance defines it as employees using “their personally owned device(s) for work purposes”, where “an organisation has ownership of the corporate data and resources that may be accessed or stored on a device, but the device itself is the property of the user.”
The NCSC is straightforward about why organisations allow it. BYOD aims to “Give end-users the ability to use IT they feel comfortable with”, “Reduce overheads for the organisation in terms of procurement and provisioning of corporate devices”, “Enable flexible (including remote) working” and “Increase productivity”. For a charity whose volunteers have no work laptop, or a care provider whose carers need the rota on the move, those benefits are real. The same guidance lists the challenges, including “Protecting corporate data”, “Protecting the personal privacy of the end-user/device owner” and “Ensuring legal compliance and meeting contractual obligations”, and the policy exists to manage them. The NCSC’s deployment approaches are the practical choices:
- Web browser access to cloud services such as work email. The simplest, and the weakest: “There are no technical controls that you can reliably enforce to prevent data loss”, and “Some corporate data will be stored and vulnerable on the device”.
- Remote desktop or remote apps, where the user sees a managed environment and “minimal amounts of corporate data are cached on the user device”, so loss or theft of the device is less problematic.
- Mobile application management (MAM), which protects the organisation’s data inside approved apps without managing the whole device: the organisation should be able to “remotely remove access to corporate applications and associated data” and “Restrict the ability to copy data from corporate apps to non-corporate apps.”
- Mobile device management (MDM), where the personal device is enrolled and “partly managed”. It gives more assurance, but “the level of control over a device can be concerning to the owner, making this a less popular solution.”
For a small organisation running Microsoft 365 (Outlook and Teams on staff phones) or Google Workspace, app-level protection on phones and browser access with multi-factor authentication on laptops is the common pattern, and the policy should name which applies to which device. Whatever the model, the NCSC’s first rule holds: “Only present the minimum set of services and data required to BYOD users.”
The security controls a BYOD policy should require
The policy should state the minimum standard a personal device must meet before it is allowed near work data, and the organisation should enforce as much of it technically as it can, because the NCSC is blunt that otherwise “You will be reliant on procedural controls”. Drawing on the NCSC and on Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026):
- Multi-factor authentication on every work account reached from a personal device: the NCSC says “MFA should be enforced as a minimum”. For schools, the Department for Education’s cyber security core standard says “MFA must be enabled for all” staff accounts with access to cloud services or remote access to on-site systems.
- A locked device. Cyber Essentials requires a biometric, password or PIN before the device can be used, protected against brute-force guessing, and “a minimum password or PIN length of at least 6 characters” where the credential only unlocks the device. The NCSC adds that staff “should be advised to use different passwords for unlocking the device and accessing corporate services and data.”
- Supported, updated software. Under Cyber Essentials, software on in-scope devices must be “licensed and supported” and updated “within 14 days” of release where the update fixes critical or high-risk vulnerabilities. A phone that no longer receives operating system updates should lose access.
- Separation. Work data stays in the approved apps or the browser session; no saving to the personal photo library, personal cloud storage, USB sticks or personal email. Among the risks of staff using their own devices, the ICO lists data being moved to “other insecure storage (personally-owned USB sticks and external hard drives)” and the use of “personal email accounts”.
- No modified devices. The NCSC’s training topics include “not using jailbroken or rooted devices”.
- No shared use. “If for any reason an employee is unable to abide by your policies (for example, an inability to separate users on a device used for BYOD that is shared amongst family members), then BYOD access should not be permitted.”
- Network connections. Cyber Essentials treats home routers the organisation did not supply as out of scope, “which means you need to apply Cyber Essentials firewall controls (such as a software firewall) on user devices”. The NCSC warns that a full-device VPN enabled for personal use may give “the users’ personal applications … a direct network connection to your enterprise services”.
- Minimum data on the device. Prefer a remote view to a local copy: the NCSC says organisations should, where reasonable, “provide staff with a remote ‘view’ of information from their device, rather than allowing data to persist locally”.
Cyber Essentials matters even to organisations that never think of themselves as having BYOD. Its requirements say “user-owned devices which access organisational data or services (as defined above) are in scope”, apart from devices used only for native voice, native text and multi-factor authentication apps, and that “all corporate or BYOD home/remote working devices used for your organisation’s business are in scope”. A charity or academy trust that holds or is seeking the certificate has to bring staff-owned devices that open work email up to the same standard, or keep them away from work data.
The owner’s privacy: what the organisation will and will not do
A BYOD policy is also a promise to the device owner, and it fails if staff do not trust it. The NCSC warns that a scheme which “makes life difficult” can lead employees to reject it and use “shadow IT”. The ICO’s guidance on monitoring workers notes that monitoring tools “can be particularly intrusive if workers are using their own devices”, and says “You should ensure that when workers are using their own personal devices for work, you are not capturing their private use of their device.” The policy should therefore say, in plain words:
- what the management tool can see – the NCSC lists that an MDM can report, among other things, “A list of apps installed on the device” – and what it cannot, such as personal messages, photographs and browsing;
- that the organisation will remove its own apps and data, not wipe the whole device, unless the owner agrees, and how the owner is told before either happens;
- that the organisation will not ask to inspect a personal device as a matter of routine, and what happens instead when work information on it is needed for a request or an investigation;
- who pays for what: data, repairs and replacement, and whether the organisation contributes;
- that BYOD is optional where it can be, with an alternative for anyone who does not want work data on their own device.
That last point matters in law as well as in trust. No general rule of UK employment law requires staff to supply their own phone or laptop for work; whether a particular instruction to do so is reasonable depends on the contract and the circumstances, so take HR advice before making BYOD compulsory or treating a refusal as misconduct.

Joining, losing, repairing and leaving
Most BYOD incidents happen at the edges of a device’s working life, so the policy should walk through each one.
- Joining. The device is checked against the minimum standard, enrolled or given the approved apps, and the owner signs the policy. The NCSC suggests requiring training “before users are added to a BYOD-allow list”.
- Loss or theft. Reported to the named contact the same day, so that access can be revoked and work data removed. A lost device with work data on it is a possible personal data breach: UK GDPR Article 33 requires the organisation to report a breach to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of it unless it is unlikely to result in a risk to people, and to document every breach whether reported or not. The school data breach guide works through that test.
- Repair. The NCSC asks how the organisation will “manage the risk of potential unauthorised access to corporate data by the repair service”, and suggests wiping corporate data before a device goes for repair, with “a plan for when this isn’t possible, as when the device’s battery is not chargeable.”
- Replacement. The old device has work access removed before it is sold, traded in or handed to a child.
- Leaving. “When staff leave your organisation or replace their device, you should ensure all business data is removed and credentials to access business systems are revoked.” Removing the account and the managed apps is the method; asking to see the phone is not.
The NCSC also recommends “regular audits of the business data stored on, or accessible from, personal devices”. In a small organisation that can be as simple as a list of who has BYOD access to what, reviewed each term or quarter against the staff list.
The work data that never reaches the managed apps
A well-run BYOD scheme protects the work data that lives in the apps the organisation manages: the email app, the document store, the records system. The difficulty is the work that happens on the same device outside them. A senior carer photographs a resident’s skin tear with the phone’s own camera to show the nurse, and the photograph sits in her personal photo library and, if her phone backs up photographs, in her personal cloud storage too. A teacher’s personal number is in a parent’s contacts, and the parent’s messages about a child arrive by text. The volunteer coordinator’s rota group is a consumer app on her own phone, end-to-end encrypted so that only the people in it can read it.
None of that is touched by the BYOD controls, because none of it is in a managed app. App protection can stop a document being copied out of the work email; it cannot reach a photograph that never went into the work email, or a conversation that was never in a work app. The organisation is still the controller of that personal data, and still answerable for it in a breach or a subject access request, but it holds no copy and cannot remove it when the member of staff leaves.
That is the gap a BYOD policy should name rather than leave implicit: which kinds of work are allowed only inside managed apps, and which have no approved route at all and therefore end up in personal ones. The question for the next leadership or trustee meeting is a direct one: which of our work conversations and photographs happen on staff’s own devices in apps our BYOD controls never touch, and what would we hold if we were asked for them?
Questions people ask
What is the bring your own device policy?
A bring your own device (BYOD) policy is an organisation’s written rules for staff who use their own phones, tablets or laptops for work: which devices and data are allowed, the minimum security (such as multi-factor authentication, a locked screen and current updates), how work data is kept separate from personal data, what the organisation can and cannot see, and what happens when a device is lost or its owner leaves.
What are the risks of BYOD?
The ICO lists the main ones for unmanaged personal devices: out-of-date software that “may be vulnerable to exploitation”, devices “shared between family members”, data that is “unlikely to be encrypted on the device”, weak access control, data moved to “other insecure storage”, and staff using insecure methods such as personal email. The NCSC adds the risk to the owner’s privacy and the cost of supporting many device types.
Is bring your own device a good idea?
It can be, for a limited set of tasks with the right controls. The NCSC says “BYOD should be used for a limited set of defined tasks that are acceptable to your risk appetite”, with anything else handled on organisation-managed devices, and the ICO describes company-issued devices as “generally the most secure option, but … also the most expensive”.
Can I refuse to use my personal phone for work?
Often, yes in practice, but it depends on your contract. No general rule of UK employment law requires staff to supply their own device; whether an instruction to use one is reasonable depends on the employment terms and circumstances. Good BYOD policies make it optional where possible and provide an alternative, and the NCSC says BYOD access should not be permitted where an employee cannot meet the policy.
Does GDPR apply to personal devices used for work?
Yes. UK GDPR applies to the organisation’s personal data wherever it is processed, including on a member of staff’s own phone or laptop, and Article 32 requires the organisation to ensure “a level of security appropriate to the risk”. The ICO’s monitoring guidance also protects the owner: the organisation should ensure it is “not capturing their private use of their device”.
Where to read the official guidance, and your next step
Start with the ICO’s Bring your own device – what should we consider?, then the NCSC’s five-part BYOD guidance, written mainly for medium and large organisations but useful to any. Cyber Essentials requirements v3.3 sets the minimum technical standard, and schools should read the Department for Education’s cyber security core standard. Quotations are from those pages as read on 3 October 2026.
This guide is a summary for organisations in the UK, not legal or technical advice. Choose controls with your IT support, and take HR advice before changing what staff are required to provide.
Then do one thing: list every member of staff, trustee and volunteer who opens work email or a records system on a device the organisation does not own, and what each can reach. That list is the scope of your policy.
We build ComplyChat for the work conversations organisations need to keep. A BYOD policy protects the apps the organisation manages; the conversations staff have in consumer apps on their own phones stay outside it. ComplyChat gives those conversations a channel the organisation owns, usable on a compatible phone including a personal one, where everyone is told the channel is on the record; on paid plans the lasting record files into the organisation’s own Microsoft 365 once its tenant is connected. It is not device management software. Free is personal messaging with three calendar months of recent history and no archive, so it does not meet a retention duty.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- UK GDPR Article 32 legislation.gov.uk
- Bring your own device – what should we consider? ico.org.uk
- Bring your own device (BYOD) ncsc.gov.uk
- Deployment approaches ncsc.gov.uk
- Cyber Essentials: Requirements for IT Infrastructure v3.3 ncsc.gov.uk
- Cyber security core standard gov.uk
- Monitoring workers ico.org.uk





