Remote Work and Bring Your Own Device Policy
- Document ID
- PDC-RWB-SAMPLE
- Document version
- 1.0
- Template version
- v1.0.0
- Effective date
- September 27, 2026
- Next review
- September 27, 2027
1. Purpose
This policy sets the rules [Company Name] employees must follow when they work away from a company site and when they use any device, company-issued or personal, to reach company email, apps or data. Remote work and mobile devices make the business more flexible. They also move company information onto home networks, public Wi-Fi and personal phones, where it is easier to lose, steal or expose.
The goal is simple: work from anywhere the company approves, keep company data inside company systems, keep devices updated and locked, and report problems quickly. Following this policy supports the company in meeting its legal, contract and customer obligations and respects the privacy of personal devices.
If you are not sure whether something is allowed, stop and ask the IT Manager before you act.
2. Scope
Who it covers. This policy applies to all employees of [Company Name], and to temporary workers, interns and contractors who use company systems or handle company or customer information, whether they work remotely full time, on a hybrid schedule, while traveling, or only check email on a phone.
What it covers. It covers every device used to reach company email, chat, files or systems, including company-issued computers, phones and tablets, and any personal device the company allows. It covers every location outside a company site, including homes, hotels, vehicles, customer and supplier sites, and public places.
Other policies. This policy works alongside the company's information security, acceptable use, password and incident response policies, and its HR policies. When two rules conflict, follow the stricter rule. Where a law, regulation or customer contract is stricter than this policy, it applies instead.
Your rights. Nothing in this policy limits your right to discuss wages, hours or other working conditions with coworkers, or to report a possible violation of law to a government agency.
3. Key Terms
- Remote work
- Any company work done away from a company site, including full-time remote work, hybrid schedules, occasional work from home and work while traveling.
- Company device
- A computer, phone, tablet or other device the company owns or leases and issues to you.
- Personal device (BYOD)
- A phone, tablet or computer that you own, used for company work as this policy allows. BYOD stands for bring your own device.
- Company data
- Any information the company, its customers, suppliers or employees have not made public, in any form, including email, chat, files, photos and paper.
- Approved storage
- The company email, file storage and business systems the company provides and manages, such as its company cloud storage and shared drives.
- App protection (MAM)
- Protection applied to company apps, such as email and chat, that keeps company data inside those apps without the company managing the rest of the device.
- Device management (MDM)
- Enrolling a device in a company management system so the company can require security settings and install or remove company apps and data.
- Selective wipe
- Removing only company data, accounts and apps from a device, leaving personal apps, photos and messages untouched.
- VPN or secure access app
- Company software that creates a protected connection from your device to company systems, including zero trust network access tools.
- Multi-factor authentication
- Signing in with something beyond a password, such as an authenticator app prompt, a security key or a fingerprint.
- Public Wi-Fi
- Any wireless network the company or you do not control, including hotel, airport, coffee shop, conference and guest networks.
4. Remote Work Eligibility and Workspace
Eligibility. Remote and hybrid work is available only for roles the company has approved for it, and only after the employee and their manager agree the arrangement in writing, including the schedule, the primary work location and the equipment the company will provide.
A business arrangement. Remote work is a business arrangement, not an entitlement. The company may change or end an arrangement with reasonable notice, or immediately when business needs, performance, conduct or security require it. Requests to work remotely as a reasonable accommodation for a disability or other protected reason go through the company accommodation process rather than this section.
Your workspace. Work from the primary location in your arrangement, in a space that is safe, reasonably quiet and private enough that others cannot read your screen or hear confidential calls. Remote work is not a substitute for dependent care, and you must be able to focus on work during working hours.
Injuries. Report any injury that happens while you are working remotely to your manager and HR right away, the same as you would at a company site.
Training. You must complete the company remote work security training before you are given remote access or use a personal device for company work, and repeat it every year.
5. Company-Issued Devices
The company provides the computer each remote role needs, and all computer-based company work must be done on a company computer.
When you use a company device, you must:
- Keep it for your own use only. Family members, friends and roommates must not use it, even briefly or for schoolwork.
- Lock the screen whenever you step away. Devices are also set to lock automatically after 5 minutes or less.
- Leave the security tools, encryption, firewall and updates the company installed turned on, and never try to disable or get around them.
- Install software only from the company-approved list or with IT approval.
- Allow security updates and restarts when prompted, and never postpone them for more than 3 days.
- Connect the device to the internet and sign in at least every 14 days so it receives updates. Devices not seen for 30 days may be locked until IT checks them.
- Do not plug in USB drives, chargers or other accessories from unknown sources, and do not store company data on personal USB drives.
- Report damage, loss or strange behavior right away.
Personal use. Limited personal use of a company device by you is governed by the company's acceptable use rules. Do not store personal files on a company device. The company is not responsible for personal files left on it.
6. Personal Devices (BYOD)
What is allowed. You may use a personal phone or tablet for company email, chat and calendar, and for other mobile apps the company has approved, but only in the company versions of those apps, signed in with your company account, and only after the company protection described below is in place. Personal devices are optional. The company will provide the devices your role needs.
App protection. Company data on personal phones and tablets is protected inside the company apps rather than across the whole device. The protected apps may require their own PIN or fingerprint, encrypt company data, block copying or saving company data into personal apps and personal storage, and refuse to open on a device that is out of date, jailbroken or rooted. The company can remove company data and accounts from those apps (a selective wipe) but cannot erase or see your personal apps, photos or messages.
Personal computers. Personal laptops and desktops must not be used for company work, including through a web browser. Personal computers are a common source of stolen passwords, and the company cannot check or protect them. Use the company computer you were issued.
Minimum standards. A personal phone or tablet used for company work must meet these standards at all times. Company tools check some of them automatically and may block access until the device meets them again.
| Requirement | Standard |
|---|---|
| Operating system | A version the manufacturer still supports with security updates |
| Updates | Security updates installed within 14 days of release |
| Screen lock | A PIN of at least 6 digits, a password or biometric unlock, locking automatically after 5 minutes or less |
| Encryption | Device encryption turned on |
| Integrity | Not jailbroken or rooted, and not running beta or modified software |
| Apps | Installed only from the official app store for the device |
Sharing the device. Family members may use your personal device, but they must never use the company apps. Do not share the device PIN or app PIN with anyone, and do not leave company apps open for someone else to use.
Changing or selling a device. Before you sell, trade in, give away, repair or replace a personal device used for company work, sign out of the company apps and tell the IT Manager so company access can be removed.
Sign-in approvals. Using a personal phone only to approve company sign-ins with the company authenticator app is not considered BYOD under this policy. Anyone who prefers not to use a personal phone for this may ask for a hardware security key or another company-provided method instead.
7. Home Networks, Public Wi-Fi and Remote Access
Your home network. Your home Wi-Fi router carries company traffic, so it must meet these basics. Ask the IT team for help if you are not sure how.
- Change the router administrator password from the factory default to a unique, strong password.
- Use WPA3 encryption, or WPA2 if the router does not support WPA3, with a strong Wi-Fi password. Never use an open network, WEP or WPS.
- Keep router firmware updated, turn on automatic updates if available, and replace routers the manufacturer no longer supports.
- Put smart home devices, game consoles and guests on a separate guest network where your router allows it.
- Do not use a network run by a neighbor, landlord or building unless you connect the company VPN or secure access app first.
Connecting to company systems. Company cloud services, such as email, chat and file storage, may be reached directly over the internet, protected by multi-factor authentication and the company sign-in rules. Internal systems, such as file servers, ERP and business applications hosted at a company site, may be reached only through the company VPN or secure access app.
Public Wi-Fi. Public Wi-Fi, such as hotels, coffee shops, airports and customer or supplier guest networks, may be used for company work only after the company VPN or secure access app is connected. If it will not connect, use the hotspot on your phone instead. Never sign in through a public network that asks for your company password or wants you to install something first.
Signing in. Always sign in to company systems with multi-factor authentication. Never approve a sign-in prompt you did not start, and report unexpected prompts right away.
8. Storing, Sharing and Printing Company Data
Company data must stay in approved storage. Whether you are on a company device or a personal one, you must not:
- Save company files to personal cloud storage, personal email, personal USB drives or the local storage of a personal device
- Forward company email or files to a personal email address or messaging app
- Use personal text messaging, WhatsApp or other personal apps for company business the company has not approved
- Take photos or screenshots of company data with a personal device, except inside protected company apps or where this policy allows it
- Keep company data after you no longer need it for your work
Printing and paper records. Print at home only when the work truly needs paper, and never print confidential or regulated records at home. Use a printer connected directly to your computer or your home network, collect printouts right away, keep them where others in your home cannot read them, and shred them with a cross-cut shredder, or bring them to a company site for secure disposal, when you no longer need them.
Personal information. Personal information about employees, customers or anyone else, such as Social Security, driver's license, bank account and health details, must stay in approved company systems and must not be saved to a personal account, a removable drive or a personal device outside the protected company apps. North Carolina and other state breach notification laws can require the company to notify affected people when a lost device or misdirected file exposes personal information, so prompt reporting matters.
9. Physical Security and Confidential Conversations
At home and in public. Treat every place outside a company site as one where others may see or hear your work.
- Lock your screen every time you step away, even at home.
- Use a privacy screen filter when working in public places or while traveling, and position your screen away from windows and walkways.
- Never leave devices unattended in public, and never leave them in a vehicle overnight or in view.
- Store company devices and any company paper out of sight and out of reach of others in your home when you are not using them.
- Do not let anyone else use your company accounts, and do not share your passwords, PINs or security keys with anyone, including family members.
Video calls and phone calls. Confidential conversations need the same care as confidential documents.
- Use headphones and a private space for confidential calls, and never discuss confidential matters in public places, shared rides or where family members can hear.
- Use a blurred or company background when your surroundings could show personal or confidential information.
- Before sharing your screen, close unrelated windows, email and chat, and share one window rather than your whole screen when you can.
- Check who has joined before discussing confidential matters, and do not admit unknown attendees or note-taking bots.
- Record a call only with the company's approval and after telling everyone on the call. Some states require every participant to agree before a call is recorded.
- Mute or turn off voice assistants and smart speakers in the room during confidential calls.
10. Travel and Working Away From Home
Traveling with devices. Keep company devices with you. Carry laptops and phones on board rather than in checked luggage, and avoid leaving them in a vehicle. If you must, lock them in the trunk or out of sight before you arrive, not in the parking lot, and never overnight. Use a hotel safe or take them with you, and charge devices from your own charger and a wall outlet rather than public USB charging ports.
International travel. Before you take a company device outside the United States, or use company systems from outside the United States, get approval from the IT Manager at least 10 business days in advance. Some countries restrict encryption or the use of VPNs, and border officials in the United States and elsewhere may inspect devices, so take only the devices and data the trip needs. The company may block sign-ins from other countries unless travel has been approved.
Working from another state or country. Working from a different state for more than two weeks, or from any other country for any length of time, requires written approval in advance, even when the trip is personal. Where you work can change tax, payroll, employment law and data protection obligations for the company.
11. Lost or Stolen Devices and Security Incidents
Report right away, and no later than 4 hours after you notice, if:
- A company device, or a personal device with company apps or data on it, is lost, stolen or left behind somewhere you cannot get back to
- You think someone else has seen, copied or used company data on one of your devices
- You clicked a suspicious link, opened a suspicious file or entered your password on a site you now doubt
- You got a sign-in prompt you did not start, or a device is acting strangely
- Company paper records were lost, misplaced or thrown away without shredding
How to report. Contact the IT Manager, by phone if you can. Say what happened, which device or records were involved, what data may have been on them, when and where you last had them, and whether the device was locked. Do not wait days while you search for a missing device. If a device was stolen, file a police report and share the report number.
What the company will do. The company will block access and may remotely lock, locate or erase a company device. For a personal device, the company will remove company data and accounts (a selective wipe) and will erase the whole device only if you ask.
No blame for prompt reports. The company will not charge you for a company device that is lost, stolen or damaged by accident when you report it as this policy requires. You will never be disciplined for reporting a mistake in good faith. Hiding a loss or delaying a report on purpose is a violation of this policy.
12. Privacy and Monitoring
Company devices and accounts. Company devices, accounts and systems belong to the company. As the law allows, the company may monitor, log and review their use, including sign-ins, network traffic, security alerts, email and files, to protect the business, so do not expect privacy in anything on a company device or account. Device location is used only to recover a lost or stolen device or to investigate a security incident, never to track where you are.
Personal devices. The company will set up app protection so that it collects only what it needs to protect company data. It may see your name, the device model and operating system version, the company apps you use, and whether the device meets this policy.
The company will not collect, view or erase:
- Personal email, text messages, call history or voicemail
- Personal photos, videos, files or contacts
- Personal apps, browsing history or social media
- Your location
Legal holds. If company data on a personal device is needed for a lawsuit, investigation or legal hold, you must help the company preserve and collect that company data. The company will limit any review to company data.
Notice. This policy is your notice of the monitoring it describes. Where state law requires a separate written notice or acknowledgment of electronic monitoring, the company will provide it.
13. Expenses and Working Hours
Equipment. The company provides the equipment each remote role needs, such as a computer and headset. The company does not generally pay for home internet, utilities or furniture unless the law requires it or it is approved in writing.
Personal phone costs. Employees approved to use a personal phone for company work receive a fixed monthly stipend, in an amount set by the company, through payroll. If your actual business cost is higher than the stipend, submit it through the normal expense process and the company will review it.
State reimbursement laws. Some states, including California and Illinois, require employers to reimburse necessary business expenses, which can include a reasonable share of personal phone and home internet costs. Where a law in North Carolina or in the state where you work requires more than this section provides, the company will follow the law.
Working hours for non-exempt employees. Non-exempt employees, meaning those who are paid hourly or are otherwise eligible for overtime, must not read or answer work email, chat, texts or calls outside their scheduled hours unless their manager has approved it in advance. If you do any work outside your scheduled hours, even a few minutes, record it.
The company will pay for all time worked, including time spent on a personal phone, even when the work was not approved. Managers must not ask for, encourage or accept unrecorded work. Take meal and rest breaks as company policy and state law require. Having company apps on your phone does not mean you must be available outside your working hours.
14. Leaving the Company
When you leave the company, or when your role no longer needs remote access or a device:
- Your access to company systems will end on your last day, or earlier if the company decides.
- Return all company devices, accessories, security keys, badges and company paper records within 5 business days after your last day. If you work remotely, the company will provide prepaid shipping and packaging.
- Do not reset, wipe or remove data from company devices yourself. The company needs them returned as they are.
- Remove your personal files from company devices before your last day.
- On or before your last day, the company will remove company apps, accounts and data from your personal devices with a selective wipe. Keep the devices connected so this can happen.
- Delete any company data you have anywhere outside approved storage, and do not keep copies. The company may ask you to confirm this in writing.
Unreturned equipment. The company may take steps to recover unreturned equipment, including remotely locking it, as the law allows. Your duty to protect confidential information continues after you leave.
15. Exceptions and Violations
Exceptions. Any exception to this policy must be requested from the IT Manager, approved in writing, limited in time and recorded. Exceptions cannot override a law, regulation or customer contract.
Violations. Breaking this policy may lead to discipline, up to and including termination of employment or of a contract, consistent with company policy and applicable law. The company may also suspend remote access, end a remote work arrangement or remove a personal device from company access.
Keeping this policy current. The IT Manager is responsible for this policy and will review it by September 27, 2027, or sooner when the company changes its devices or remote access tools, or when laws change. The company will tell you when the rules change.
16. Employee Acknowledgment
I have received and read the [Company Name] Remote Work and Bring Your Own Device Policy, effective September 27, 2026. I understand it, I have had the chance to ask questions, and I agree to follow it. I understand that breaking it may lead to discipline, up to and including termination, and that the company may monitor company devices and accounts as the policy describes. I understand that the company may update this policy, and that this acknowledgment is not a contract of employment.
Personal devices. If I use a personal device for company work, I agree to the company protection described in this policy, and I consent to the company removing company data, accounts and apps from that device when it is lost or stolen, when I stop using it for company work, or when I leave the company.
Employee name (printed)
Employee signature
Date
17. Document Control and Revision History
| Field | Value |
|---|---|
| Document | Remote Work and Bring Your Own Device Policy |
| Organization | [Company Name] |
| Document ID | PDC-RWB-SAMPLE |
| Document version | 1.0 |
| Effective date | September 27, 2026 |
| Next scheduled review | September 27, 2027 |
| Policy owner | IT Manager |
| Approved by | Chief Executive Officer |
| Source template | Preferred Data Corporation Remote Work and BYOD Policy template v1.0.0 |
Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.
| Version | Date | Description of change | Approved by |
|---|---|---|---|
| 1.0 | September 27, 2026 | Initial adoption, generated from template v1.0.0. | Chief Executive Officer |
| Blank | Blank | Blank | Blank |
| Blank | Blank | Blank | Blank |
18. Template Notice and Legal Disclaimer
This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.
Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.
Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.