Home › HRMS › HR policies › BYOD policy
HR policy template

BYOD policy template

A bring your own device policy sets the rules for employees who use their personal phones, tablets or laptops for work email, messaging, files or company apps, including the attendance app. It balances the company's need to protect its data with the employee's privacy on a device they own, and covers eligibility, security settings, what the company can and cannot see, cost support and what happens on loss or exit.

When to use it: Adopt it before employees install company email or apps on personal devices, which in practice means before you launch a mobile attendance app or work messaging groups. IT and HR prepare it together for the managing director's approval. Each employee signs it before their device is set up for work.

BYOD policy template

Copy the text below and replace everything in square brackets with your company details.

1. Purpose

This policy allows employees of [Company Name] to use personal devices for work while protecting Company data and respecting the employee's privacy and ownership of the device.

2. Scope

It applies to any employee who uses a personally owned smartphone, tablet or laptop to access Company email, files, messaging groups, the attendance app or any other Company system. Company-issued devices are covered by the IT Acceptable Use Policy.

3. Definitions

  • Personal device: a phone, tablet or laptop bought and owned by the employee.
  • Work data: Company email, files, messages, customer information and app data accessed on the device.
  • Selective wipe: removal of work apps and work data only, leaving personal data untouched.

4. Policy

  • BYOD is allowed for the roles listed in [Annexure or Role List], and for all employees for the attendance and HR self-service app.
  • Minimum security: a screen lock with PIN, password or fingerprint, an up-to-date operating system and apps, device encryption switched on, and no rooted or jailbroken devices.
  • Work data stays in approved apps: [Approved Email App, Approved Storage App]. Do not forward work files to personal email or save them to the phone gallery.
  • The Company will not access personal photos, messages, contacts, browsing history or personal apps.
  • Where device management software is used, it manages only work apps or the work profile, and the employee is told in writing what it can see.
  • Work apps and data may be removed remotely if the device is lost or stolen, or when employment ends. Personal data is never wiped without the employee's written consent.
  • Eligible employees receive [Rupee Amount] a month towards phone and data costs, paid through payroll.
  • Using a personal device for work does not mean being available at all hours. Managers respect off-duty time except in genuine emergencies.

5. Procedure

  • Register the device with IT on the BYOD form. IT checks the security settings and installs the approved apps.
  • Report loss or theft to IT within [Number] hours so that work access can be revoked.
  • When changing phones, remove work apps from the old device and register the new one. The attendance app on a new phone needs HR approval before punches are accepted from it.
  • At exit, IT removes work apps and data in the employee's presence or revokes access remotely on the last working day, and the employee is removed from all work messaging groups.

6. Responsibilities

  • Employees: keep devices secure, keep work data in approved apps and report loss at once.
  • IT: set up devices, publish the approved app list and act on loss reports.
  • Managers: add and remove team members from work groups promptly and respect off-duty time.
  • HR: explain the policy at joining and pay the agreed allowance.

7. Exceptions

An employee who does not wish to use a personal device for work, or whose device does not meet the security requirements, will be offered [a company device, biometric punching or another alternative] where the role requires it.

8. Review

[IT Head Designation] and [HR Head Designation] review this policy every [12] months, as phone features, security threats and the apps employees use for work keep changing.

What to include

The privacy line in plain words

State what the company will never access on a personal device, such as photos, messages and personal apps. Employees accept security rules more readily when their privacy is clearly protected.

Minimum security settings

Keep the list short and checkable: screen lock, updates, encryption, no rooted devices. Long technical lists are not followed.

Work data in work apps

Require approved apps for email and files, and forbid forwarding to personal accounts. This makes selective removal of work data possible later.

Cost support

If a personal phone is needed for work, contribute to its cost through a monthly allowance or reimbursement, and state the amount by role.

Loss and exit

Set a short deadline for reporting loss and say what happens to work data and messaging groups on the last working day.

An alternative for those who opt out

Offer another way to work or mark attendance for employees without a suitable phone. Forcing personal devices on everyone creates resentment and exceptions anyway.

Common mistakes to avoid

Run it in ZeniaHR

The ZeniaHR mobile app ties punches to an approved phone: the first phone is approved automatically and any later phone needs HR approval, so a change of handset follows a clear step. Employees without a suitable phone can punch on a biometric device, which feeds the same punch stream, or on the web from an allowed office network. Capture controls also let you set the mobile location rule, and the monthly allowance can be paid through Direct Payroll.

See it on your own data

A 30-minute demo on a video call. We set up your departments, shifts and leave rules and show attendance, leave and payroll running for your team. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What is a BYOD policy?

A BYOD, or bring your own device, policy sets the rules for using personal phones, tablets and laptops for work. It covers who may do so, minimum security settings, which apps hold work data, what the company can and cannot access, cost support, and what happens when a device is lost or the employee leaves.

Can a company wipe an employee's personal phone?

A fair BYOD policy lets the company remove only work apps and work data, not personal photos, messages or apps, and says so in writing. A full wipe should happen only with the employee's written consent, for example when a phone holding sensitive customer data is stolen and cannot be secured any other way.

Should companies pay employees for using personal phones for work?

It is fair to contribute when the phone is needed regularly for work, through a monthly allowance or reimbursement of a data plan. Set the amount by role, pay it through payroll and state it in the policy, so employees who rely on their phones for calls, email or field punching are not out of pocket.

Can employees be asked to install an attendance app on personal phones?

Many employers do this, but the policy should explain what the app records, such as punch time and location at the moment of punching, and offer an alternative for employees who lack a suitable phone or prefer not to use their own, such as a biometric device or a web punch from the office network.