Add Think Technology as a trusted source Why Every Australian Business Needs a BYOD Policy | TTA

Why every Australian business needs a BYOD policy

Screenshot of a Bring Your Own Device policy template, page 2

A Brisbane professional services firm we work with discovered something uncomfortable during a routine IT audit last year. Three staff members had been accessing client files from personal phones, devices with no PIN lock, no encryption, and no management software in sight. Nothing had gone wrong yet. But the exposure was real, and there was no policy in place to address it.

Bring Your Own Device, or BYOD, is the practice of employees using personal phones, tablets, and laptops to access work systems and data. It has become the quiet default for many Australian businesses, often without anyone making an active decision about it. Our IT consulting team sees this pattern regularly: BYOD happens first, the policy comes second, if at all.

The security risks personal devices introduce

Personal devices generally have fewer controls than company-issued hardware. Staff may not apply updates promptly, may share devices with family members, or may disable screen locks for convenience. When those devices hold work email, client data, or access to cloud systems, the business carries the risk.

A solid BYOD policy sets a minimum security bar. That means requiring devices to run a supported operating system, current guidance from Microsoft points to iOS 17 or later and Android 13 or later as minimum supported versions, along with full-disk encryption, screen lock, and automatic OS updates within a defined timeframe. For businesses using Microsoft 365, tools like Microsoft Intune and App Protection Policies let IT keep corporate data in a protected container without touching employees’ personal photos or messages.

The policy should also address what happens when a device is lost or stolen. Without the right technical controls in place, a lost phone can mean a lost data set. With them, IT can wipe corporate data from the device remotely, leaving personal content untouched.

Compliance obligations under Australian law

Australia’s Notifiable Data Breaches (NDB) scheme requires businesses covered by the Privacy Act 1988 to notify affected individuals and the OAIC when a breach is likely to result in serious harm. A lost, unencrypted personal device holding client records is exactly the kind of event that triggers that obligation.

The numbers show this is not a theoretical risk. The OAIC received 1,205 data breach notifications in 2025, the highest annual total since the NDB scheme began in 2018, and an 8% increase on 2024. Malicious or criminal attacks drove 716 of those notifications. Human error accounted for a growing share. A personal device without controls sits at the intersection of both.

From 30 May 2025, the Cyber Security Act 2024 also introduced mandatory ransomware payment reporting for businesses with annual turnover above $3 million. BYOD environments, where IT visibility is limited, are harder to defend and harder to report on when something goes wrong. A documented BYOD policy with technical enforcement is part of the evidence trail regulators and insurers expect to see.

Queensland businesses should also note that the Information Privacy and Other Legislation Amendment Act 2023 (Qld) introduced mandatory data breach notification requirements for Queensland public sector agencies, with obligations for the private sector continuing to develop. If your business handles Queensland government data, check whether those requirements apply to you.

Access control and offboarding

Controlling which devices can reach which data is more complex when staff use their own hardware. A BYOD policy defines the access rules. It should specify which systems personal devices can access, whether full device enrolment in a mobile device management (MDM) platform is required, and what happens when employment ends.

For organisations on Microsoft 365, Microsoft Intune’s App Protection Policies offer a practical middle ground. Corporate data stays protected inside managed apps like Outlook and Teams. IT can wipe that data selectively when a staff member leaves, without touching personal content. This approach addresses the most common employee privacy objection to BYOD management, that IT will be reading their personal messages.

Offboarding should be in the policy explicitly. When someone leaves, access must be revoked promptly. Without a documented process, it is easy for former staff to retain access to email or shared files longer than intended.

IT support complexity

Supporting a mix of personal devices, varying operating systems, manufacturers, and software versions, takes more time than supporting a standard fleet. A BYOD policy sets expectations on both sides. It should document which devices and operating systems IT will support, what self-service is expected from employees, and the process for reporting a lost or compromised device.

Being clear about these boundaries saves time for IT and reduces frustration for staff. It also helps when things go wrong: everyone knows the process before the incident, not during it.

Legal clarity for employers and staff

Without a written policy, legal disputes over data ownership, monitoring rights, and breach liability are harder to resolve. A BYOD policy documents what the business can and cannot do with a personal device enrolled in its systems, including any right to remotely wipe corporate data. It also records that employees consented to those conditions before enrolment.

That written consent matters. Staff should sign off on the policy as part of onboarding or when the policy is introduced, so expectations are clear from the start.

Five things your BYOD policy should cover

  • Minimum device requirements: supported operating systems, encryption, screen lock, and update timelines.
  • Enrolment: whether MDM enrolment or app-level management (MAM) is required, and which platform is used.
  • Data access rules: which systems and data personal devices can reach, and any restrictions on downloading or storing data locally.
  • Lost or stolen device process: who to contact, what IT will do, and the timeline for remote wipe of corporate data.
  • Offboarding: how and when corporate access and data will be removed when employment ends.

Frequently asked questions about BYOD policies

Do small businesses need a BYOD policy?

Yes. If any staff member uses a personal device to access work email, files, or systems, you have a BYOD environment. A policy does not need to be long or complex, but it should document the minimum security requirements and what happens when a device is lost or an employee leaves. Without it, the business has no clear basis to enforce controls or respond to an incident.

Can our IT team wipe an employee’s personal phone?

With the right tools and a documented policy, IT can selectively wipe corporate data from a personal device without touching personal content. Tools like Microsoft Intune’s App Protection Policies do exactly this. The key is that employees must consent to this in writing before the device is enrolled. A BYOD policy captures that consent and sets out the conditions clearly.

Does BYOD create obligations under the Notifiable Data Breaches scheme?

It can. If a personal device holding personal information is lost or stolen and that breach is likely to result in serious harm, it may be notifiable under the NDB scheme. Businesses covered by the Privacy Act 1988 must notify affected individuals and the OAIC in those circumstances. A BYOD policy with technical controls, such as encryption and remote wipe, can help prevent or contain a breach before it reaches that threshold.

What is the difference between MDM and MAM for BYOD?

Mobile Device Management (MDM) gives IT control over the whole device, enforcing settings, deploying apps, and wiping the device remotely. Mobile Application Management (MAM) protects corporate data only within specific apps like Outlook and Teams, without enrolling or controlling the personal device itself. For staff using personal devices, MAM is generally the less invasive approach and avoids the privacy concerns that come with full device enrolment.

How often should we update our BYOD policy?

Review it at least once a year, or sooner if your IT environment, supported devices, or regulatory obligations change. Minimum OS versions, for example, change as vendors drop support for older versions. A policy written two years ago may allow devices that are no longer receiving security patches. Annual review keeps it current and defensible.

Where to from here?

If your business does not have a BYOD policy yet, the template below is a practical starting point. If you already have one but it hasn’t been reviewed recently, it is worth a fresh look, especially in light of the updated NDB obligations and the Cyber Security Act 2024 requirements. Our team offers IT security assessments that include a review of your device management controls. Get in touch if you would like to talk through where your business stands.

Download the free BYOD Policy Template

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.