IT glossary
BYOD (Bring Your Own Device)
BYOD, or bring your own device, is letting staff use their own phones and laptops for work, under rules about what company data may go on them.
For most organizations this is not a decision that was made. It happened, one work email account on one personal phone at a time, and the policy arrived afterwards if it arrived at all. That is worth saying plainly, because the useful question is rarely “should we allow this”, it is “what are the rules for the thing we are already doing”.
Why it matters to you
The problem is not the device. It is what happens at the end.
When someone leaves, their personal phone leaves with them, and on it are cached emails, a contacts list, files in a sync folder, and often a saved login. If the only offboarding step is disabling the account, the copies already on that device stay where they are. Nobody is being dishonest. It just was never removed.
That is the whole BYOD problem in one sentence, and it is solvable, but only if it was set up beforehand.
What a workable arrangement looks like
- Company data lives in a container, so work email and files sit in a managed area of the phone, separate from personal apps and photos
- A selective wipe removes the work container and nothing else, no family photos, no personal messages
- A screen lock and encryption are required before the device is enrolled
- MFA on every account, since the device is now a place a login lives
- The rules are written down, and staff read them before enrolling, not after
The trade you are asking people to make
Be straight about this, because staff notice. You are asking to place employer controls on a device they paid for. They will reasonably want to know whether you can see their browsing, their location, their personal apps, or their photos. In a properly configured container setup the answer is no, and the honest thing is to say exactly what is and is not visible, in writing, before enrolment.
Where that conversation is skipped, people quietly opt out, forwarding work mail to a personal account, or keeping a second unmanaged copy. Which lands you back where you started, with less visibility than before.
The alternative worth pricing
Sometimes the simplest answer is a company-provided phone for the roles that genuinely need mobile access. It removes the privacy question entirely, and for a small number of people it is often cheaper than the policy work.