Skip to content
What the employee puts in
What the employer puts in

Capital, wear, storage, control, availabilityAccess, sometimes a payment, some support

Bring your own device

Nobody decided to let staff buy the equipment

Someone asked to read email on their phone, the answer was yes, and four years later a third of the workforce is doing company work on hardware the company has never seen. That is a procurement decision. Fifty notes on what it costs, what the agreement should say, and why it all goes wrong at the exit.

  • EmployeeBuys the device, replaces it, carries the loss if it breaks
    EmployerSaves the hardware line, immediately and visibly
  • EmployeeAccepts a configuration on property that is legally theirs
    EmployerGives up the specification, the replacement cycle and the clean return
  • EmployeeHolds somebody else's data at home, and the obligations that follow it
    EmployerKeeps every duty regarding that data, on hardware it cannot inspect
  • EmployeeCarries work in their pocket wherever they go
    EmployerGets availability it never asked for and never costed

Core notes remain focused on the BYOD bargain; separate guides compare named tools. No unverified average-savings claims. Nothing here is legal or tax advice.

The drift that produced it

The sequence is consistent enough to be predictable. Someone senior wants email on their phone. Then field staff want it, because carrying two devices is absurd. Then a contractor needs access for six weeks. Then the finance system gets a mobile application.

The practical lesson in “Nobody decided to let staff buy the equipment” is to connect every record to a named decision. Organisations exploring this workforce platform for how to monitor employees without being intrusive can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.

At no point does anybody ask what the organisation has agreed to. Each individual decision is sensible; the aggregate is an arrangement nobody specified, with no agreement behind it, no stated minimum and no idea what happens when somebody leaves.

For an independent reference relevant to “Nobody decided to let staff buy the equipment”, consult the European Data Protection Board guidelines; compare its principles with the proposed ownership model, access rules and real support process.

The telling symptom is that most organisations cannot say how many personal devices hold their data — not approximately, at all. If that is true where you are, the arrangement exists and is unmanaged, which is worse than either having it deliberately or not having it.

What was actually traded

An organisation that buys laptops controls four things beyond the hardware: the specification, the replacement cycle, the configuration, and the moment of return. Under a drifted BYOD arrangement all four are gone. The specification is whatever people happen to own, the replacement cycle is their household budget, the configuration is partial, and the return is a conversation on somebody's last day about a device you have no right to.

On the other side the employee provides capital, wear on property they paid for, storage of somebody else's information, acceptance of a configuration they did not choose, and — the largest and least acknowledged — availability, because a work application on a personal phone means work wherever the phone is.

Most agreements enumerate the technical requirements in detail and the employee's contributions nowhere. Writing both columns is what turns a policy being issued into terms being agreed.

Three classifications, three different obligations

Every arrangement is voluntary, expected or required, and most policies do not say which.

Genuinely voluntary means declining carries no disadvantage, because a company device is available. Expected means nobody says it is mandatory and everybody does it — the commonest arrangement and the least honest. Required means the job needs a device and the employer does not supply one, which in several jurisdictions triggers duties around necessary expenses.

The test is simple: has anybody actually declined in the last two years, and what happened to them? If nobody has, or nobody comfortably, the arrangement is not voluntary whatever the document says — and the payment question, the consent question and the exit question all have different answers depending on which of the three applies.

The saving, counted honestly

The hardware line falls, visibly and immediately. Four other lines rise and are rarely put in the same calculation.

Support cost per incident, because a standard fleet means a known configuration and a practised fix while a hundred different devices means every problem is novel. Administration: agreements, enrolment, stipend processing, exit checks. Incident cost, because a lost personal device is a longer and more uncertain event. And the allowance itself, grossed up if it is taxable.

Organisations that run the arithmetic find the net saving positive but considerably smaller than the hardware line suggested, and for support-intensive or hardware-demanding roles sometimes negative. That does not settle the decision — flexibility and staff preference are legitimate reasons — but a decision made on an overstated saving is made on the wrong basis.

Deriving the allowance rather than choosing it

Most allowances are a round number somebody picked. Deriving one takes ten minutes: what the organisation would otherwise spend on a device, divided by the replacement period, multiplied by an honest work share, plus the attributable running costs.

The derivation matters more than the amount. A figure with arithmetic behind it can be argued with component by component, which is a far better conversation than one about a feeling. It also protects the employer where a jurisdiction requires reasonable reimbursement of necessary expenses: a documented derivation is evidence that the figure was reasonable, and a round number is not.

Then review it annually. An allowance set five years ago is describing a different market, and the people it has stopped covering will not tell you — asking for an equipment allowance sounds like quibbling in a way that asking for a pay rise does not.

One device, two owners of the data

The employee owns the device, the operating system, their files and the right to decide what happens to the object. The employer owns the work data and the obligations attached to it. Neither claim is disputed; the difficulty is that they occupy the same storage.

The instinct is to solve this with permissions. Technical separation solves it better: where work data lives in a container the operating system maintains, the boundary is enforced rather than agreed. The employer acts on the container; the personal side is not reachable, by construction rather than by restraint.

Which makes the container decision the most consequential technical choice in the arrangement — and a people decision as much as a security one. It determines whether the employer can honestly answer the question everybody asks, which is whether their photographs can be erased.

Why the exit is where it fails

Revoking access takes seconds in a system the organisation controls. Removing data from a device it does not own requires that device to connect, which requires a departing person to switch it on, which they have no particular reason to do.

So the data sits there — weeks, months, indefinitely. Most organisations have former employees' phones holding company mail and no idea which ones.

The fix is fifteen minutes on the last day: do the removal during the exit conversation, before access is revoked, with both parties watching. It produces the confirmation, resolves the cooperation question and lets the person see exactly what was taken.

And design for the contested exit rather than the cooperative one. The cooperative one takes care of itself; the dismissal removes notice, goodwill and cooperation simultaneously, and everything available at that moment is mitigation of decisions made years earlier.

The alternatives worth costing

Choose-your-own, company-owned. The organisation buys, the employee picks from a list, reasonable personal use is permitted, and the device returns at the end. It keeps what people actually wanted — choice and a single device — and recovers ownership, which resolves the exit entirely.

Access-only. Nothing stored locally, so there is nothing to remove at exit, nothing to retain or disclose, and nothing lost when a phone is stolen. The hardware requirements collapse to almost nothing, which also solves the too-old-device problem. It depends on one control that is frequently not switched on: preventing downloads on unmanaged devices.

And the hybrid, which is what most organisations are already running through accumulated exceptions. Three categories — equipped, choice, access-only — decided deliberately and published, work considerably better than the same outcome arrived at by individual negotiation, which looks like favouritism and frequently is.

05 of 08 6 notes

When it breaks

Somebody cannot work because their own equipment stopped. That is an operational problem in the costume of a personal one.

08 of 08 1 notes

Reference

Definitions, and where to start for the common situations.

If you do two things

A container, and the paragraph about leaving

Choose a work profile space rather than full enrolment, so that removal takes the work space and nothing else. Then write down what happens when somebody goes. Neither costs money, both are decided once, and between them they prevent most of what goes wrong here.

Whose Device, Whose Data