Who needs one, and which rule says so
Schools and colleges. Keeping children safe in education 2026 requires governing bodies and proprietors to ensure there is a staff behaviour policy “(sometimes called the code of conduct) which should, amongst other things, include low-level concerns, allegations against staff and whistleblowing, plus acceptable use of technologies (including the use of mobile devices), staff/pupil relationships and communications including the use of social media”. That is the statutory home of a staff phone policy in a school. It is a different document from the pupils’ one: KCSIE’s mobile phone policy paragraphs say “All schools should be mobile phone-free environments by default; anything other than this should be by exception only”, and that the Department for Education’s guidance on mobile phones in schools “is clear that the department expects schools to implement a policy whereby pupils do not have access to their mobile phone throughout the school day”. Those paragraphs are about pupils. A school that answers the staff question with its pupils’ policy has not written the policy KCSIE asks for.
Every employer, under data protection law. The ICO’s right of access guidance says: “It is not usually appropriate for your staff to hold information about customers, contacts or other employees on their personal devices (eg in private email accounts, smartphones, home computers or private instant messaging applications). You should have a policy which makes this clear, particularly as there may be security risks if staff keep information on devices that you do not control.” And it says what follows if the organisation permits it anyway: “they may be holding it on your behalf. This means that this information may be within scope if you receive a SAR.” The ICO’s employment guidance on monitoring workers supplies the other half: “Some workers may also use personal devices for work”, and the employer “must tell workers about monitoring in a way that is accessible and easy to understand”.
Care providers. CQC’s Regulation 17 requires “an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided … and of decisions taken”. A handover done by text between two carers, or a photograph of a pressure sore taken on a personal phone to show the nurse, is care and treatment recorded on a device the provider does not hold. The policy is how the provider says where that record has to end up.
Charities. No charity-law rule names phones. The trustees’ duty to keep proper records and to protect the people the charity works with does the same work, and the Cabinet Office’s guidance on non-corporate communication channels is the clearest published model of the policy any charity can adapt: it expects staff to use the organisation’s systems for its business, treats WhatsApp, private email and SMS as channels that do “not provide corporate access to information”, and says that on “a privately owned and managed device” significant information needs “exceptional circumstances”.
The eight things the policy has to cover
A complete personal phone policy for staff answers the following, in whatever order suits the organisation. Most published templates on mobile phones in the workplace cover the first two, phone use and disciplinary action, and stop.
- Use at work. When personal phones may be used and where they must be out of sight: in classrooms and around pupils, in residents’ rooms and during personal care, in meetings, while driving on the organisation’s business. In a school this is where the staff policy meets the pupils’ one: a “mobile phone-free” school is one in which adults model the rule.
- Whether work may be done on a personal phone at all, and which work. The Cabinet Office’s distinction between logistics and significant information is the template: swapping a shift or a duty by text is one thing; anything about a named child, resident, donor or colleague is another, and the policy says which channel that belongs on.
- Personal numbers and accounts. Whether staff may give their own number to parents, families, service users or donors; whether the organisation’s contacts may be saved in a personal phone; what happens when a parent or resident already has the number.
- Images, video and voice notes. Whether any image of a pupil, resident or service user may be taken on a personal device, and if so how it is transferred and deleted the same day. For most schools and care services the answer is no, with the organisation’s own device or system as the route.
- Messaging apps and groups. Which apps and which groups are permitted for which purposes, who may set one up, who administers it, and what must never be posted in one. The staff WhatsApp group is the commonest breach of every other rule in this list.
- The organisation’s information on the phone. The ICO’s rule, stated as policy: personal information about the people the organisation serves and employs is not held on personal devices except as the policy allows, and where it is, it is held on the organisation’s behalf, it is searched on request, and it is deleted when the worker leaves.
- What the organisation will and will not look at, in the ICO’s terms: workers are told what is checked and why, and “when workers are using their own personal devices for work, you are not capturing their private use of their device”.
- Where the record goes. The trigger list (a concern, a decision, an instruction, a complaint, anything a regulator could ask about) and the rule that it is transferred to the organisation’s record the same day by the person who received it.
The first heading is the one the published templates cover, and it deserves a full paragraph rather than a ban. Reasonable use of mobile phones in the workplace during work hours is stated positively: phones on silent or vibrate and out of sight while working with pupils, residents or service users; personal calls and messages in breaks and away from the floor; an emergency route for staff who need to be reachable (a school office or a care home’s landline number given to a child’s nursery, for example) so that nobody has to keep a phone in a pocket in case. Health and safety is part of it: no handheld use while driving on the organisation’s business, hands-free only where the law and the insurer allow it, and no phones while operating machinery or equipment, in kitchens, on ladders or while supervising water or a road crossing. The productivity and disruption arguments in the templates are real but secondary in these sectors; the reason for the rule is the people in the room. The policy names where it lives (the staff handbook or the staff behaviour policy), how a breach is dealt with (the ordinary disciplinary procedure, with the low-level concerns route for anything touching safeguarding, and the grievance procedure available to a worker who thinks the policy is being applied unfairly), and what counts as the serious end: confidential information or sensitive data about a person leaving the organisation on a personal device is a data breach, and is reported and recorded as one.
The policy also needs a line each on lost or stolen phones (report, and the organisation’s information on it is assumed exposed), on security basics for any phone that carries work email or apps, and on what the policy does not govern: a worker’s own use of their own phone in their own time.
What the policy cannot do
The limits are as important as the rules, because a policy that claims powers the organisation does not have is the one a tribunal or the ICO reads first. From the ICO’s specific considerations on monitoring workers: the employer is “unlikely to be able to justify covert monitoring in usual circumstances”, checking of workers’ communications “can be particularly intrusive if workers are using their own devices”, and the employer must not capture “their private use of their device”. From the same guidance: “Workers have the right to be informed about the collection and use of their information”, and “Monitoring conducted without transparency is unfair”.
In practice the policy cannot require software on a personal phone, cannot require the phone to be handed over on demand, cannot read it, and cannot treat a refusal to hand it over as misconduct. What it can require is conduct: that certain work is not done on the phone, that certain information is not held on it, that staff search and produce work messages when a subject access request or a dispute requires it, and that they preserve rather than delete once they know a request or a dispute exists. The ICO’s wording for the search is the one to copy: the organisation “should ask them to search their private emails, devices or instant messaging applications, as appropriate”.
A policy written the other way round, as a set of powers over the device, fails twice: it is unlawful in the parts that matter, and it tells staff that the organisation regards their phone as its business, which is the fastest way to move the work conversations somewhere the organisation will never see.
What differs by sector
- Schools. The staff behaviour policy is the home, KCSIE names the contents, and the safeguarding case is the sharpest: a message from a member of staff to a pupil on a personal phone is a safeguarding matter before it is a data protection one, and the policy says so. The low-level concerns process KCSIE requires is where breaches of the phone policy are recorded, which means the policy and the low-level concerns procedure have to name each other.
- Care services. The record of care is the point. Handovers, observations, photographs and family contact on personal phones are Regulation 17 records held outside the provider’s system, and the policy is the provider’s answer to an inspector who asks how a decision taken by text reached the care plan. Lone and domiciliary workers use their own phones for the job by necessity, so the policy has to be written for the car between visits, not the office.
- Charities. Volunteers as well as staff, which most templates forget: the volunteer coordinator’s group chat and the trustee who messages the chief executive at night are the two conversations most likely to be asked for. The Cabinet Office model, adapted, covers both, and the trustees adopt it as a decision minuted in the usual way.

The record the policy has to create
A phone policy generates records of its own, and they are the ones an inspector, a tribunal or the ICO asks for. The policy itself, dated and version-controlled, with the date each member of staff was given it and any training on it. The register of exceptions, where the policy allows work on a personal device by permission. The low-level concerns or conduct record of breaches. The subject access and disclosure searches staff were asked to make, with what was returned. And, above all, the organisation’s own record of the work conversations the policy says must not live on personal phones: the care record, the safeguarding file, the complaints log, the minutes.
That last record is where the policy is tested. The rule that “anything about a named child goes on the school’s channel” is only as good as the school having a channel that a teaching assistant on a playground can use as quickly as a text. A policy that forbids the personal phone without providing the alternative has written down a breach and scheduled it.
The conversations the policy is really about
Every phone policy is written after the same discovery: that the conversations which matter most already happen on staff’s own phones. The message about the child who arrived upset; the carer telling the senior that a resident refused medication; the volunteer coordinator being told, in the group, that someone was rude to a service user; the donor’s reply to a fundraiser’s text. These are the informal first stages of every procedure the organisation runs, and they are the records those procedures are supposed to begin with.
A policy can stop the organisation’s information being stored on personal phones as a matter of habit. It cannot stop a concern being raised by the quickest available means, and it should not try. What it can do is say where that conversation should happen instead, and that only works if the instead exists: a channel the organisation owns, on the same phone, as fast as the app it replaces, where the message is on the record with its time as it is sent and the worker’s own messages stay in the worker’s own apps. Two limits, stated plainly and including for products like ours: nothing lawful can read a member of staff’s personal phone or recover conversations that have already happened, and no channel is a policy; the rules about images, numbers, groups and conduct still have to be written and kept.
A question for the next leadership meeting: if the policy says “not on your personal phone”, what does it tell the teaching assistant on the playground, the carer in the car, or the volunteer at the hall door to use instead, and is it on their phone now?
Official guidance and your next step
The primary sources are Keeping children safe in education 2026 (the staff behaviour policy, and the mobile phone policy paragraphs on pupils) and the Department for Education’s Mobile phones in schools guidance; the ICO’s right of access guidance on finding and retrieving information and its employment guidance on monitoring workers with the specific considerations for different methods; the Cabinet Office’s Non-corporate communication channels for government business; and CQC’s guidance on Regulation 17. Employment law on what a contract or a policy may require of a worker is not covered here.
This guide is a summary of published guidance for England, not a substitute for it and not legal advice. What an employer may require of a particular worker depends on the contract, the role and the facts; take advice before disciplining anyone under a phone policy.
Then do one thing: read the organisation’s current phone policy, if there is one, against the eight headings above and mark which it covers. Most cover two.
We build ComplyChat for the work conversations organisations need to keep. A personal phone policy that says “not on your phone” needs to say what to use instead, and that is what ComplyChat is: a channel your organisation owns, on any phone including a personal one, on the record from the first message, filing into your own Microsoft 365 once your tenant is connected and kept under your own retention rules, with everyone in it told it is on the record. A member of staff’s own messages stay in their own apps, where nothing lawful can read them. There is no WhatsApp, Signal or Meta anything in the path, and we cannot see a personal phone. It is not a policy and it does not replace one; it is the line in the policy that says where work conversations go.
How it works · Why us · Pricing · FAQ


