Allowing personal devices for work reduces cost and creates legal exposure in several directions.

Policy essentials. Which devices and applications are permitted; the security requirements — passcode, encryption, current operating system, remote wipe capability; a prohibition on unauthorised applications; and the employer’s right to access, monitor and wipe business data.

Consent. Written acknowledgement, because remote wiping a personal device or accessing personal content without consent creates claims under computer access and privacy statutes.

Containerisation. Technical separation of business data from personal data, which permits selective wipe and limits the employer’s access to personal content. This is the single most effective control and resolves most of the legal difficulty.

Discovery. Business communications on a personal device are within the employer’s control where the policy asserts rights, and are discoverable. Without a policy, collection depends on the employee’s cooperation.

Preservation. Litigation holds must extend to personal devices, and the employer must be able to require preservation — which again depends on the policy.

Offboarding. Removal of business data, verified, and confirmation from the employee.

Wage and hour. Devices enable after-hours work by non-exempt employees, and the policy should address it.