A “Bring Your Own Device” (BYOD) policy governs employees’ use of personal devices — like smartphones, computers (desktop or laptop), tablets, smart watches, or other electronic devices — for business use. The employee owns the device, but the organization owns both the platform for accessing information and all the business information.

Benefits of a BYOD Policy
- No need for multiple devices. Personnel may use what they already have and are comfortable with.
- Control over information. Work data stays on business platforms that are segregated from employee personal information.
- Comfort in protected information. The company controls software and data storage, with the ability to restrict or remove employee access at all times.
- Work flexibility, including remote work options. This helps attract and retain quality personnel. Remote work can cut down on the size of rented office space. Temporary, seasonal, or student intern workers can gain access to applications and services with more control and limited risk to the entity.
- Increased productivity. Employees using their preferred device and operating system skip the learning curve associated with unfamiliar technology. They can also log in on days that would otherwise mean lost work time — whether recovering from a minor illness, managing an after-hours emergency, or avoiding a long commute — turning time that was previously unavailable into productive work time.
- Redundancy to workers unable to access their main workplace. This is an important part of disaster recovery plans.
- Lowered costs. Workers purchase their own devices in exchange for the convenience of not carrying/maintaining two devices (one for personal use and one for work).

Challenges to Consider
- Individual interests. Employees have privacy rights over their personal devices and what they do with them; they may have limited budgets for upgrades and appropriate devices/operating systems; they must desire to comply.
- Entity interests. Duty to protect entity data and data of others (plan participants, other employees, etc.); how many devices can they afford to support; what type of support can they afford — is it enough; contractual obligations to entity vendors, employees, participants in plans, and others.
- Security challenges. Individually-owned devices are often more vulnerable to malware than company-issued hardware. IT support is more complex because staff must understand numerous operating systems and hardware configurations, rather than a single, entity-approved type of device.
- Compatibility. Operating systems and different software versions could cause technical issues when sharing files or working on the same documents. A policy should outline the required versions when this type of issue could occur.
Key Considerations of a BYOD Policy
- Eligible Devices - Define which devices and operating systems are permitted, including minimum version allowed, and require that all updates remain current. Specify any devices, software, or applications that are prohibited due to known security risks. Review and update the approved device list at least annually as technology evolves.
- Platform Setup - Typically, the entity’s IT department or a third-party vendor handles installing and removing the entity’s platform from personal devices. Passwords should be controlled by the organization, not the individual.
- Day-to-Day Administration - A designated employee or third party should oversee daily operations. Access should be as limited as possible while still allowing the administrator to assist users with issues such as forgotten passwords or device errors.
- Cost Allocation - The entity should cover any entity-related software, platforms, and IT services. Employees are responsible for their personal device, personal software or applications, and IT support for personal use. If the entity extends IT support for personal issues, it should require the employee’s explicit permission and a waiver of liability. Generally, the employee pays for monthly data and internet fees. If the entity provides a stipend (monthly or yearly) to the employee, it should be proportional to business use relative to personal use, and prorated if the employee leaves the entity mid-billing cycle.
- Security — MDM/MAM Software - Mobile Device Management (MDM) or Mobile Application Management (MAM) software creates a secure, encrypted environment for company data. These tools enable two-factor authentication, strong password and screen lock requirements, and remote data wiping in the event of a lost, stolen, or compromised device. All entity data should be encrypted in motion and at rest, and the entity should provide all additional tools required for compliance, such as antivirus and malware protection.
- Data Storage - All applications, files, and data owned by the entity should be stored in the cloud or on entity platforms; never on employee personal devices.
- Employee Privacy - The policy should clarify that entity IT monitors only entity-owned apps and data, not personal applications, photos, or other content on the employee’s device. The entity should never require access beyond its own software and content. The policy should also state that employees are responsible for any personal actions that compromise company software or data.
- IT Support - Employees are responsible for the repair or replacement of their personal device, and for resolving issues stemming from personal use. The entity is responsible for setting up and funding any VPN or email synchronization required for business use, and for resolving any issues arising out of business use.
- Acceptable Uses - The policy should prohibit high-risk behaviors, such as jailbreaking or rooting devices, using unsecured public WiFi to access entity servers, and allowing unauthorized individuals (such as household members) to access entity platforms. Lost or stolen devices must be reported immediately to prevent data breaches. As new threats are identified, push notifications should be used to alert registered device users.
- Data Removal - When an employee obtains a new device, changes roles, or leaves the entity, all entity data must be wiped from the personal device immediately. The entity should maintain current backups of all data stored on employee devices, and the policy should clearly communicate these expectations.
- Policy Violations - Language should clearly outline employment consequences for violations, consistent with general employment law practices, including verbal or written warnings, writeups, and termination of employment. Violations that may result in immediate termination, should be clearly stated.
- Employee Participation - Employees feel more invested in policies they help shape and implement. Involve the appropriate team members in reviewing policy decisions and establish a clear process for employees to submit ongoing feedback and report issues.
