BYOD Policy Free UK Template · v1.0

Bring Your Own Device (BYOD) Policy

A free UK-aligned template covering 4 essential clauses. Edit the highlighted fields, sign, and adopt.

Document owner[Insert role — typically IT Director or Head of Information Security]
Approved by[Insert name and date of board / management approval]
Version1.0
Date of issue[DD Month YYYY]
Review cycleAnnually, or upon material change to the IT estate
ClassificationInternal — All Employees
Applies toAll employees, contractors, agency workers and third parties accessing [Company] data on personal devices
This free template provides four foundational clauses: Purpose & Scope, Definitions, Acceptable Use, and Security Baseline. A complete audit-ready BYOD policy also requires clauses covering MDM/containerisation configuration, incident response and lost-device procedure, the ACAS-compliant leaver wipe workflow, and an employee acceptable-use acknowledgement form. The full 7-clause version with ISO 27001 Annex A mapping is available at the link at the end of this document.

1.Purpose and Scope

This policy sets out the conditions under which [Company] permits employees and authorised third parties to use personal devices to access company information, systems and communications. The objective is to enable flexible working while maintaining proportionate protection over personal data and confidential business information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable contractual obligations.

This policy applies to any personally owned smartphone, tablet, laptop, desktop or wearable device used to:

Participation in the BYOD scheme is voluntary. Where access to company systems is a reasonable requirement of the role, [Company] will offer a company-issued device as an alternative. Use of a personal device for company purposes outside this policy is not authorised.

2.Definitions

Personal device means any computing device the employee or third party owns or controls and which is not asset-tagged or managed by [Company] IT.

BYOD scheme means the framework established by this policy under which a personal device may be enrolled for access to company systems.

Mobile Device Management (MDM) means the technical platform — for example Microsoft Intune, Jamf, or Google Workspace Endpoint Management — used by [Company] to apply configuration profiles, security baselines and selective-wipe controls to enrolled devices.

Work profile / managed app means a logically separated container on the device within which company data is stored and processed. Examples include the Android Enterprise Work Profile, an iOS Managed App, and the encrypted partitions established by enterprise mobility products.

Selective wipe means the removal of the work profile, managed apps, and company data from a device without affecting the user's personal data, applications, photographs or contacts.

Personal data has the meaning assigned in Article 4(1) UK GDPR.

3.Acceptable Use

Users approved to participate in the BYOD scheme shall:

  1. Enrol the device with the [Company] MDM platform prior to first access to company systems;
  2. Access company resources exclusively through the approved work profile, managed application set, or browser-based session, and never store company data in personal cloud storage (iCloud Drive, personal Google Drive, Dropbox personal, etc.);
  3. Use only operating system versions still in receipt of vendor security updates. [Company] will publish the supported version list and update it quarterly;
  4. Promptly install operating system and managed-application security updates pushed via MDM;
  5. Report a lost, stolen or compromised device to [Company] IT within four working hours of discovery, by the means set out in the incident response procedure;
  6. Cooperate with reasonable evidence preservation and lawful disclosure requirements affecting work-profile data, including legal hold and subject access requests under UK GDPR Articles 15 and 17.

Users shall not:

4.Security Baseline

Each enrolled device must satisfy the following minimum technical controls. These controls are applied automatically by the MDM configuration profile and audited at enrolment and on a continuous basis thereafter.

4.1 Identity and access

4.2 Encryption

4.3 Operating-system support

4.4 Network

4.5 Anti-malware and integrity

Get the full BYOD policy — 7 clauses, ISO 27001-aligned

This free version covers the four foundational clauses. The full £39.99 single-policy version adds: MDM/containerisation configuration baseline, incident response and lost-device procedure, the ACAS-compliant leaver wipe workflow, and an employee acceptable-use acknowledgement form. Editable Word + PDF, instant download, lifetime access, no subscription.

Buy the full policy — £39.99