Most small businesses have a BYOD situation whether they’ve decided to have one or not. Staff check work email on personal phones. Contractors do work on personal laptops. People work from home using devices you’ve never seen. The question isn’t usually “should we allow BYOD?” — it’s “how do we handle what’s already happening?”

A sensible BYOD policy doesn’t require enterprise MDM software or a dedicated IT team. It requires clarity about what employees can and can’t do on personal devices, what data those devices can access, and what happens when a device is lost or an employee leaves.

The Risks You’re Actually Managing

Personal devices present three main security risks to your business:

Data exposure: When company data — emails, files, customer information — sits on a personal device, you lose control over how it’s stored and protected. A phone with no passcode, a laptop without full-disk encryption, or an old device that isn’t receiving security updates all create exposure that your IT infrastructure can’t compensate for.

Account access after departure: Staff who have accessed company accounts on personal devices often remain logged in after they leave. If you don’t have a process for revoking that access, ex-employees can sometimes reach company data for weeks or months.

Malware pathways: Personal devices often have lower security hygiene than company-managed ones. A personal phone used on company Wi-Fi, or syncing files through shared cloud storage, can introduce malware or compromise credentials.

What a BYOD Policy Should Cover

You don’t need a legal document. A one-page policy that employees acknowledge is enough for most small businesses. Cover these elements:

Eligible devices and minimum security requirements: Define what devices can be used for work (smartphones, laptops, tablets), and set minimum standards — a current operating system, auto-updates enabled, a device PIN or passcode, screen lock after inactivity, and full-disk encryption for laptops.

What business data can be accessed on personal devices: Be specific. Email and calendar are usually fine. A database of customer financial records probably shouldn’t be accessible from a personal phone with no MDM control. Define the categories and be explicit.

Separation of personal and business data: At minimum, personal devices used for work should use separate apps or profiles for business apps. On Android, a Work Profile provides genuine separation — business apps can’t see personal data and vice versa. On iOS, business accounts can be managed through configuration profiles. Both are free and don’t require purchasing MDM software.

What happens when a device is lost: Establish that employees must report a lost device immediately. Define whether remote wipe is possible and expected — and get written consent for this before a device is lost, not after. Note that remote wiping a personal device of all data (not just business data) has legal and practical complications; be clear about what your process actually involves.

What happens when an employee leaves: Your offboarding process should include a step to revoke access to all company accounts from personal devices. For email, this means removing accounts. For cloud storage, revoking sharing. For any business applications, deactivating the account.

Acceptable use on business systems: Whether the employee can use company Wi-Fi for personal browsing, stream personal content through company accounts, or install non-approved software on a company-managed app.

Technical Controls You Can Apply Without MDM Software

Full mobile device management (MDM) solutions like Microsoft Intune or Jamf require investment and expertise to run properly. For most small businesses, there are lighter-weight approaches.

Conditional access through Microsoft 365 or Google Workspace: Both platforms allow you to require that devices meet minimum security standards before connecting. In Microsoft 365, basic conditional access policies can require MFA, block access from specific countries, and refuse connections from devices that don’t pass basic compliance checks. This works with personal devices and doesn’t require installing anything beyond the standard apps.

Work Profiles (Android) and Managed Apple IDs (iOS): These give you separation between personal and business data without full device control. Business apps and data live in the managed profile; personal apps can’t access them. The employee keeps their personal data private. You can wipe only the business profile when they leave. Both are available at no extra cost — they’re built into the operating systems.

Requiring specific app versions: Rather than managing devices, you can manage access. Require that staff use the official Microsoft Teams or Outlook app (not a web browser) for business communications, and configure those apps to enforce your security policies (session timeout, no copy-paste to personal apps, no local cache of sensitive files). Most business apps support these configurations in their settings.

This is where small businesses sometimes get caught out. When business data on a personal device gets processed or transmitted — even just email — data protection law applies. Key points:

You’re still the data controller: Even though the data lives on an employee’s personal device, you remain responsible for it as the data controller under UK GDPR. If that device is breached and customer data is exposed, you’re accountable.

Get written agreement before applying any technical controls: Before you configure a device to allow remote wipe, install an MDM agent, or apply any management profile, you need the employee’s clear consent and ideally a signed agreement explaining what you can and cannot do. Doing this after the fact creates legal risk.

You can’t monitor personal usage: If an employee uses personal apps on their personal device, you have no right to monitor that activity. Policies that attempt to log personal communications or access personal data are likely unlawful. Stick to monitoring and controlling the business data and accounts, not the device itself.

Staff privacy applies: Even in a BYOD context, employees have a reasonable expectation of privacy for personal data on personal devices. Don’t overreach your policy.

Practical Starting Point

If you have no BYOD policy at all, the minimum viable version to implement this week:

  1. Write a one-page policy covering the points above and have everyone sign it
  2. Enable MFA on every business account (email, cloud storage, any SaaS tools) — this is the single most effective protection against compromised credentials regardless of what device they’re accessed from
  3. Check that all staff are using the official Microsoft 365 or Google Workspace apps on mobile, not just browser access
  4. Add a BYOD offboarding step to your leaving process — even just a checklist that includes “remove business accounts from personal devices”

Most of the risk in BYOD situations comes from accounts remaining accessible after departure and from lack of MFA. Fix those two things and you’ve addressed the most common ways personal device use leads to actual incidents.