The risks
Personal devices may lack updates, disk encryption or screen lock, may be shared with family members and may carry apps the company would never approve. When the employee leaves, company data can stay on the device. A lost or stolen phone with access to email is a common source of incidents.
How to manage it
A clear BYOD policy defines which devices and uses are allowed, the minimum security requirements and what happens when someone leaves. MDM with a separate work profile lets the company manage and wipe work data without seeing personal content. Our article on what an MDM can and cannot see explains the boundaries. Conditional access can block devices that do not meet the requirements, and DLP limits what data can be copied to personal apps.
Privacy and labour law
Monitoring a personal device has limits under the GDPR and, in Spain, the digital rights of workers in the LOPDGDD. Employees should be informed of what is managed and what is not, and controls should be proportionate.
Where it shows up in compliance
ISO 27001 covers user endpoint devices and remote working (Annex A 8.1 and 6.7). Auditors ask how personal devices with access to company data are controlled, so BYOD needs to be in scope, not ignored.




