Skip to main content
Data Protection / GDPR

Bring your own device

BYOD refers to the use of privately owned devices such as smartphones, tablets or laptops for work purposes, where the organisation remains accountable for protecting personal data despite having no ownership of the device.

Bring your own device (BYOD) covers every arrangement in which employees use their own privately purchased equipment for business purposes — from checking work email on a personal phone to processing customer records on a private laptop. Under data protection law the allocation of roles does not change: the employer remains the controller within the meaning of Art. 4(7) GDPR because it determines the purposes and means of the processing. It must therefore ensure an appropriate level of protection under Art. 24 and Art. 32 GDPR even though it has neither technical nor legal control over the hardware. This mismatch — accountability without control — is what makes BYOD one of the hardest topics in workplace data protection.

The typical risks are well understood: private and business data end up mixed in the same storage, device backups sync silently into personal cloud accounts, operating systems fall behind on security patches, family members share the device, third-party apps request far-reaching permissions, and devices get lost or stolen. Deletion is an equally serious problem. When someone leaves the company, or when an access or erasure request under Art. 15 or Art. 17 GDPR has to be answered, an organisation without technical separation has no reliable way to locate business data or remove it completely. At the same time, inspecting a private device for control purposes is itself an interference with employees' rights and is not lawful simply because the employer wishes to check.

BYOD only becomes defensible through a combination of rules and technology. What is needed is a written BYOD policy or works agreement, a sound legal basis for processing employee data, a container or mobile device management solution that cryptographically separates business data from the private area and allows a selective remote wipe, minimum requirements for screen lock, encryption and patch level, and defined obligations to report loss and to hand back data on departure. These measures qualify as technical and organisational measures under Art. 32 GDPR, must be documented, and belong in the record of processing activities; where sensitive data sets are involved a data protection impact assessment under Art. 35 GDPR may also be required. Where these building blocks cannot realistically be implemented, issuing corporate devices (COPE or COBO) is the safer route — BYOD is not a cost-saving default but a risk decision that has to be managed deliberately.

Legal Basis

Art. 24, Art. 25, Art. 32 GDPR; Art. 5(1)(f) GDPR; Art. 88 GDPR in conjunction with Sec. 26 BDSG (German Federal Data Protection Act)

Practical Example

A mid-sized service provider lets its sales team use work email and the CRM on personal smartphones. During a review the data protection officer discovers that customer contact data is being synchronised into private cloud accounts through the devices' automatic backups. She stops the existing practice and has a container solution rolled out: business applications run in an encrypted workspace with no backup to private storage, an enforced PIN, a minimum OS version and a selective remote wipe limited to the container. In parallel, a works agreement is concluded that rules out location and usage tracking and sets out the procedure for lost devices. The measures are recorded in the record of processing activities and in the documentation of technical and organisational measures, and employees confirm the policy before the container is activated.

FAQ

The organisation remains the controller because it determines the purposes and means of the processing (Art. 4(7) GDPR). Employees are not processors; they act under the authority of the controller within the meaning of Art. 29 GDPR. Owning the hardware therefore does not shift accountability — it only makes fulfilling it harder.
Only to the extent agreed and genuinely necessary. A selective wipe of the business container is normally acceptable, whereas erasing the entire private device including personal photos or messages would be disproportionate. The permitted scope, the triggers and the procedure should be set out explicitly in the BYOD policy or works agreement and communicated to employees in advance.
Consent in an employment relationship is fragile because of the imbalance of power and can be withdrawn at any time, so it is unsuitable as the sole basis. In practice BYOD arrangements are underpinned by a works agreement under Art. 88 GDPR or by necessity for the employment relationship. Note that the compatibility of Sec. 26(1) BDSG with Art. 88 GDPR has been contested since the Court of Justice's case law, and works agreements must in any event comply with the GDPR's requirements in their own right.

How preeco supports you

Learn how our software supports you with this topic.

Learn more