GlossarySecurity awareness

BYOD

Short answer

BYOD (Bring Your Own Device) is a policy that lets employees use their personal laptops, phones or tablets for work. It improves flexibility, but the company must protect its data on devices it does not own, while respecting the employee's privacy.

The risks

Personal devices may lack updates, disk encryption or screen lock, may be shared with family members and may carry apps the company would never approve. When the employee leaves, company data can stay on the device. A lost or stolen phone with access to email is a common source of incidents.

How to manage it

A clear BYOD policy defines which devices and uses are allowed, the minimum security requirements and what happens when someone leaves. MDM with a separate work profile lets the company manage and wipe work data without seeing personal content. Our article on what an MDM can and cannot see explains the boundaries. Conditional access can block devices that do not meet the requirements, and DLP limits what data can be copied to personal apps.

Privacy and labour law

Monitoring a personal device has limits under the GDPR and, in Spain, the digital rights of workers in the LOPDGDD. Employees should be informed of what is managed and what is not, and controls should be proportionate.

Where it shows up in compliance

ISO 27001 covers user endpoint devices and remote working (Annex A 8.1 and 6.7). Auditors ask how personal devices with access to company data are controlled, so BYOD needs to be in scope, not ignored.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub