TL;DR
- BYOD stands for bring your own device. It means employees using phones, tablets or computers that they own to do their work, instead of, or alongside, equipment that the employer provides.
- The device belongs to the employee, but the work data on it still belongs to the organisation, and so does the responsibility for protecting it. That split is the source of most BYOD problems.
- A good BYOD policy says what people may do on their own devices, what the employer can see and control, who pays, and what happens when someone loses a device or leaves.
A new starter asks whether they can read work email on their own phone. A manager says yes, because it seems harmless and saves buying a handset. Nobody writes anything down. That is how most organisations adopt BYOD: by accident.
This article explains what BYOD stands for and what it means at work, why employers allow it, the risks, five ways of setting it up, what a BYOD policy should cover and what employees should ask before they agree. It draws on guidance from the UK's National Cyber Security Centre (NCSC) and the Information Commissioner's Office (ICO).
Device rules are usually agreed in a new starter's first days. See how New Dynamics onboarding brings tasks, early goals and manager conversations into a clear path for a new starter.
What does BYOD stand for?
BYOD stands for bring your own device.
The Cambridge Dictionary defines BYOD as “the practice of companies or schools saying that employees or students can bring their own computers, phones, etc. to work or school in order to do their work on them”.
The NCSC, in its guidance on bring your own device, puts it in one sentence: “BYOD is the concept of employees using their personally owned device(s) for work purposes.”
The phrase is usually explained as a play on “bring your own bottle”, the note on a party invitation. It covers smartphones, tablets, laptops and home desktop computers. It covers the office, the home and anywhere between. In schools and colleges, BYOD means students bringing their own laptops or tablets to lessons. This article is about the workplace.
What BYOD means in practice: who owns what
The NCSC's definition goes on to make the point that matters most: “With BYOD, an organisation has ownership of the corporate data and resources that may be accessed or stored on a device, but the device itself is the property of the user.”
So there are three things to keep apart.
- The device belongs to the employee. So do the photos, messages and apps on it.
- The work data belongs to the organisation, wherever it is stored.
- The responsibility for protecting that data stays with the organisation. The NCSC says that, from a legal perspective, it “rests with the data controller, not the device owner”.
An employer cannot treat a personal phone as if it were company property. An employee cannot treat customer records as if they were holiday photos. A BYOD policy exists to manage that overlap.

Why organisations allow BYOD
The NCSC lists five aims.
- To give people the ability to use IT that they feel comfortable with.
- To reduce the overheads of buying and providing corporate devices.
- To enable flexible working, including remote working.
- To increase productivity.
- To provide a fallback when workers cannot reach their main place of work.
The NCSC notes that BYOD surged in popularity during the COVID-19 pandemic, when organisations did whatever was needed to keep working. It adds that arrangements made in haste are likely to need revising if they are to last. If your BYOD approach dates from 2020 and has not been looked at since, that sentence is about you.
The risks of BYOD
The NCSC lists six security challenges:
- ensuring that personal devices and their owners comply with company policies and procedures;
- supporting a wide range of device types and operating systems;
- protecting corporate data;
- protecting corporate infrastructure;
- protecting the personal privacy of the device owner;
- ensuring legal compliance and meeting contractual obligations.
The ICO, in its guidance on what to consider with BYOD, is more concrete about home devices. Software may be out of date. Data is unlikely to be encrypted. Passwords may be weak. Work files are easily copied to a personal USB stick. The ICO adds a point that is easy to forget: “Devices are likely to be shared between family members.” Relatives may then see personal data that they should not.
The ICO compares three approaches to home working. Company-issued devices are “generally the most secure option, but it is also the most expensive”. Using your own device to access company software is more cost-effective, with some security risks. Simply using your own device “has the most security risks and should be avoided for all but the smallest organisations” with an immediate need.
There is a people risk too. The NCSC warns that organisations should be mindful of the effect that BYOD may have on work-life balance. When work email sits on a personal phone, the working day has no edge. Our article on work-life integration discusses how to set boundaries.
BYOD, CYOD, COPE and COBO
You may meet three related abbreviations. They describe who owns the device and how far personal use is allowed.
| Term | Stands for | Who owns the device | Personal use |
|---|---|---|---|
| BYOD | Bring your own device | Employee | Yes, it is their device |
| CYOD | Choose your own device | Employer | Depends on the policy |
| COPE | Corporately owned, personally enabled | Employer | Allowed, within limits |
| COBO | Corporately owned, business only | Employer | Not allowed |
The NCSC also suggests a mixed model. Some employees do not own, and cannot afford, a device that is suitable for work. If flexible working is required, it advises organisations to consider offering corporately owned devices alongside BYOD. Nobody should have to buy a phone to do their job.
Five ways to set up BYOD
The NCSC's page on deployment approaches describes five. They differ mainly in how much control the employee hands over.
| Approach | How it works | What it means for the employee |
|---|---|---|
| Web browser | People sign in to work services in a browser | Nothing is installed. The NCSC calls it the simplest type of BYOD, and lists a wide range of risks |
| Virtual or remote desktop | The device shows a view of a work desktop that runs elsewhere | Very little work data is kept on the device |
| Bootable operating system | A home computer starts up from a managed work environment | Harder to set up. The NCSC calls it the lowest risk way of enabling home PCs |
| Mobile device management (MDM) | The device is enrolled in a corporate system that has a degree of control over it and its settings | The employer has the most control. The NCSC notes that this can concern owners |
| Mobile application management (MAM) | Work apps sit in a managed container. The user manages the rest of the device | Remote wiping is limited to work data and the managed apps |
The choice is a technical one, for IT or a security adviser. But HR should understand it, because it decides what the policy can honestly promise employees about privacy.
What a BYOD policy should cover
The NCSC's second action is to develop the policy, which “should clarify and communicate both organisational and employee responsibilities”. Drawing on its questions, a policy should answer the following.
- Who is eligible. The NCSC notes that BYOD will not suit some groups, such as senior managers who regularly handle more sensitive data.
- Which tasks are allowed, and which are not. The NCSC's example is permitting expense claims from a personal device, but not email. It says that it is just as important to write down what you do not want people to do.
- Which devices and versions are accepted. Older, unsupported software is more likely to contain weaknesses that cannot be fixed.
- Security requirements. A passcode, up-to-date software and multi-factor authentication, which the NCSC calls “a minimum requirement”.
- How work and personal data are kept apart. The ICO says that the device owner's data and the organisation's data should be separate.
- What the employer can see and do. Say it plainly, including whether anything can be wiped remotely, and what.
- Sharing. Whether family members may use the device. The NCSC says that if an employee cannot keep to the policy, for example on a shared family device, BYOD access should not be permitted.
- Loss, theft and security incidents. Whom to tell, how quickly, and what happens next.
- Repairs. A repair shop may be able to reach work data. Decide what must happen before a device is handed over.
- Costs. Whether the organisation contributes to the device, the data plan or repairs.
- Working hours. BYOD does not mean being available at all times.
- Changing device, changing role and leaving. The NCSC says that when staff leave or replace a device, you should ensure that all business data is removed and that access to business systems is revoked.
- Use abroad. Whether devices may be used for work in other countries.
Keep it short, and write it for the people who must follow it. The NCSC makes a point that every policy writer should remember: security controls that make a device harder to use will drive down adoption, and overly restrictive controls may encourage staff to find workarounds. It calls the result shadow IT, and it increases your risk.
Your BYOD policy should sit beside your other rules on technology. Our AI acceptable use policy framework covers a related question, and our code of conduct examples show how to write rules that people read.
How to introduce BYOD: the NCSC's five actions
- Determine your objectives, user needs and risks. Is this an interim or a long-term solution? What must people be able to do? Involve the users throughout.
- Develop the policy. Set the goals first, then choose the controls that will achieve them.
- Understand the additional costs and implications. These include more support work, more reliance on people following procedures, and legal issues.
- Choose a deployment approach. One of the five above, or a hybrid.
- Put technical controls in place. Match them to the approach that you chose.
The NCSC's advice on scope is modest. BYOD should be used “for a limited set of defined tasks that are acceptable to your risk appetite”. Start with the most common devices and the tasks with the most benefit. Take on only what your IT support can handle.

The law, briefly
In the UK, personal data on an employee's own device is still the organisation's responsibility under data protection law. The NCSC points employers to the Data Protection Act, the GDPR and the ICO's guidance, and reminds them that employees are entitled to a degree of privacy at work.
If your BYOD set-up reports information about the device or its use, the ICO's guidance on monitoring workers is relevant. Both ICO pages cited here are marked as under review because of the Data (Use and Access) Act, so check them for changes.
Regulated industries may face extra obstacles, and the NCSC notes that some commercial agreements restrict the use of business software or data on personal devices. Check your contracts.
This section describes UK guidance. It is general information, not legal advice, and the rules differ in other countries. Our employee data protection guide helps you to plan the wider policy.
For employees: five things to ask before you agree
Using your own phone for work is convenient. Before you enrol it, ask five questions.
- Tasks. What am I allowed to do on my device, and what must I never do on it?
- Privacy. What can the organisation see on my device, and can it wipe anything?
- Security. What must I do: a passcode, updates, an authentication app?
- Costs. Does the organisation contribute to the device, the data or repairs?
- Leaving. What happens to the work apps and data when I change my phone or leave?
A good policy answers all five in writing. If nobody can answer the second question, wait until they can. And if you would rather keep work off your own phone altogether, ask what the alternative is.
For managers, the difference is between an offhand yes and an informed agreement.

Common mistakes
BYOD by accident. No decision, no policy, and nobody knows which devices hold work data.
A temporary fix that became permanent. The NCSC advises that if BYOD is a short-term solution, you should set an end date before you start.
A policy that people cannot follow. Rules that rely wholly on perfect behaviour fail. The NCSC asks what you will do when users do not follow the procedures.
Silence about privacy. People assume the worst about what IT can see. Tell them.
Forgetting leavers. Work email on a former employee's phone is a data breach waiting to be found. Put device access on your leaver checklist, beside the items in our exit interview questions article.
Assuming that everyone has a suitable device. Offer an alternative.
Letting BYOD stretch the working day. Agree when people are expected to respond, and when they are not.
Frequently asked questions
What does BYOD stand for?
BYOD stands for bring your own device. It describes employees using phones, tablets or computers that they own for work. In education it describes students bringing their own devices to lessons.
What is BYOD in the workplace?
In the workplace, BYOD is an arrangement in which employees use their personal devices to reach work email, files or systems. The employee owns the device. The organisation still owns the work data, and remains responsible for protecting it.
What is a BYOD policy?
A BYOD policy is a written statement of who may use personal devices for work, which tasks are allowed, the security requirements, what the employer can see and control, who pays, and what happens when a device is lost or an employee leaves.
Is BYOD safe?
It carries more risk than using equipment that the employer manages, because the organisation has less control over the device. The NCSC says that the challenges should not be played down, but that the right technical controls and policies can minimise the risks.
Can my employer see my personal data on a BYOD phone?
It depends on how BYOD is set up. With browser access, nothing is installed. With mobile application management, control is limited to the work apps. With mobile device management, the organisation has a degree of control over the device, and the NCSC notes that such tools can often report details such as the list of installed apps. Ask what your employer's set-up can see.
What is the difference between BYOD and CYOD?
With BYOD, the employee owns the device and uses it for work. With CYOD, or choose your own device, the employer owns the device, and the employee picks it from an approved list. CYOD gives the organisation more control over the device. BYOD avoids the cost of buying devices, although the NCSC warns that it adds support costs.
Your next step: find out where you stand
- List the ways in which people reach work data from personal devices today. Email on phones counts.
- Decide, with IT, which tasks you are content to allow.
- Write a BYOD policy of two pages or fewer, using the list above.
- Add the policy to your onboarding checklist, and device access to your leaver checklist.
To plan how your organisation handles personal data about and held by employees, read and download our employee data protection guide. The guide is free to read, and the PDF uses our short download form.
Want every new starter to get clear expectations from their first day? Book a New Dynamics demo and bring your current approach. You can also email contact@new-dynamics.com.


