BYOD policy: personal devices, company data, one page of rules

Friday, 5:40. A designer photographs a whiteboard full of client material with her personal phone, edits the render on her own laptop over the café wi-fi, and emails the draft from her personal Gmail because the company one is signed out on her phone. Nobody did anything malicious. But the client files now live on two machines nobody can wipe, inside a cloud drive the company has never seen, behind an inbox that will still work after she resigns. That is what happens without a BYOD policy — and the fix is not buying everyone a second phone. It is one page that says which personal devices may touch company data, what the company sees and wipes in exchange, and the five things any such device must have before the first sync. The remote work baseline covers working from home; BYOD is the narrower and leakier problem: your hardware, their data.

1. Decide the device list before anyone asks

2. The trade: enrollment for privacy — made explicit

3. The five non-negotiables, checked before first sync

4. Where company data may and may not live

5. Accounts: separation is the whole trick

6. The exit: offboarding a device the company never owned

7. Lost or stolen personal device: the same runbook, one twist

8. One page, signed at onboarding, alive in the reviews