Allowing personal devices for work reduces cost and creates legal exposure in
several directions.
Policy essentials. Which devices and applications are permitted; the
security requirements — passcode, encryption, current operating system, remote
wipe capability; a prohibition on unauthorized applications; and the employer’s
right to access, monitor and wipe business data.
Consent. Written acknowledgment, because remote wiping a personal device or
accessing personal content without consent creates claims under computer access
and privacy statutes.
Containerization. Technical separation of business data from personal data,
which permits selective wipe and limits the employer’s access to personal
content. This is the single most effective control and resolves most of the
legal difficulty.
Discovery. Business communications on a personal device are within the
employer’s control where the policy asserts rights, and are discoverable. Without
a policy, collection depends on the employee’s cooperation.
Preservation. Litigation holds must extend to personal devices, and the
employer must be able to require preservation — which again depends on the
policy.
Offboarding. Removal of business data, verified, and confirmation from the
employee.
Wage and hour. Devices enable after-hours work by non-exempt employees, and
the policy should address it.