MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Bring Your Own Device (BYOD) is rarely without legal risk: if you allow employees to use their own phones, laptops, or tablets for work, you, as an employer, remain responsible for privacy, the security of company data, and even for illegal software on those private devices. Anyone who introduces BYOD without clear agreements and technical measures runs into the GDPR, the limits of the right of inspection, and potential liability for copyright infringement. Below, you can read exactly where the risks lie, what the consequences can be, and how you, as an SME entrepreneur, can manage them with a good BYOD policy.
What is BYOD (Bring Your Own Device)?
BYOD stands for Bring Your Own Device: employees use their own smartphone, laptop, or tablet for business tasks instead of employer equipment. There is often an allowance for this, as private devices cost money and wear out. BYOD is popular: employees work on familiar devices, the employer saves on hardware, and it reduces electronic waste.
Opposite those advantages stands a legal downside. As soon as work and private life come together on the same device, business data, personal data, and privacy become intertwined. It is precisely there that the risks arise. Briefly summarized, these run along three lines: privacy and the right of inspection, the security of business data, and liability for illegal software.
BYOD brings business and private life together: privacy and the right of control
Even with a company laptop, the dividing line between work and private life regularly causes discussion. For example, you are not allowed to simply access an employee's email. Moreover, if it concerns a private device that family members also use, the situation becomes even more complex: holiday photos, personal messages, and business files are mixed together on that same device.
Three interests clash here:
- The employer's right of inspection – you want to maintain oversight of business data and correct usage.
- The confidentiality of business data – customer data and trade secrets – must not leak.
- Employee privacy – the GDPR imposes strict requirements on the processing and access to personal data.
Under the GDPR, you may only process employees' personal data if it is necessary and proportionate and if there is a valid legal basis for doing so. Monitoring a private device quickly infringes upon personal privacy, so it may not be done without limits. It is therefore important to make clear agreements in advance and put them in writing , and to implement technical measures, such as working with shielded, encrypted containers in which business data is kept separate from the private part.
Rule of thumb: the more strictly you technically separate business and private life, the less likely you are to infringe upon someone's personal privacy during an inspection – and the stronger your position under the GDPR.
BYOD and copyright infringement: are you liable as an employer?
Privacy regulations are not the only thing that can throw a spanner in the works. In Dutch case law, it has been established that an employer may, under certain circumstances, be held liable for infringements committed by an employee, for example through the use of illegal software, even if it is installed on a private device . This concerns a form of strict liability of the employer for errors committed by subordinates; however, a number of conditions must be met for this to apply.
Functional link between the infringement and the work
The employer is not liable for every infringement that occurs incidentally on the device. There must be a functional connection between the tasks assigned to the employee and the infringement. Two elements typically play a role in this:
- The assigned task increases the likelihood of the infringement. Anyone performing their work with specific software increases the chance that precisely that software will be deployed (possibly illegally).
- The employer has control over the behavior. You can prohibit installation or make use technically impossible.
The first requirement is easily met in practice, especially with BYOD. Even if you offer legal software, this does not automatically absolve you of liability. Control is also usually broad, as you can prohibit or block use. Note: case law indicates that a mere prohibition on paper does not automatically eliminate liability – which is precisely why technical measures are so important.
An example makes it concrete. If an employee uses an illegal version of a word processor to draft business letters, employer liability is obvious: this directly relates to the assigned tasks. If that same employee illegally downloads a game in their spare time, that functional connection is usually absent, unless you happen to employ a professional gamer.
Take technical measures
Technically, it is not always easy to maintain control. A commonly used solution is working via a hosted desktop or a secure work environment: as an employer, you determine which (legal) software is provided and only the employee's hardware is used. Bring your own device, but not your own software.
Does an employee handbook or IT policy help?
An employee handbook or IT policy is a useful tool, but it does not completely resolve the liability risk. Employer liability towards the rights holder remains in principle, so the employer may still be held liable for an infringement.
Nevertheless, clear rules do indeed have value. They work preventively (employees know what is and isn't allowed) and repressively (it is easier to take action and impose internal sanctions in case of violations). This reduces the likelihood of problems and strengthens your position should something go wrong.
Establish a BYOD policy
BYOD quickly leads to legal challenges: employee privacy is at stake, you want to maintain control over company data, and the issues surrounding illegal software make matters even more complicated. The solution lies in establishing clear agreements in a separate BYOD policy, supplemented by your IT policy and employee handbook.
A good BYOD policy regulates at least:
- which devices and which use are permitted;
- which (legal) software is mandatory or prohibited;
- how business data is protected and secured (containers, encryption, passwords);
- what happens in the event of loss, theft, or termination of employment (think of remote deletion of business data);
- which control the employer may exercise, within the limits of the GDPR;
- who is responsible for maintenance, updates, and costs.
Existing documents also deserve a check. You can include additional agreements in the employment contract , and if you work with personal data via external parties, a data processing agreement is sometimes required. This completes the legal chain surrounding BYOD.
Implementing BYOD in 6 steps
If you want to implement BYOD responsibly, follow these steps:
- Define your goal and scope. Which functions, which devices, and which data are received via BYOD?
- Map out the risks. Look specifically at personal data, trade secrets, and software usage.
- Choose your technology. Consider encrypted containers, a hosted desktop, mobile device management, and the ability to remotely wipe business data.
- Document the agreements. Draft a BYOD policy and link it to your IT policy, employee handbook, and employment contract.
- Manage the GDPR aspects. Determine the legal basis and proportionality of the audit and, where necessary, a data processing agreement with suppliers.
- Communicate and evaluate. Inform employees, have them sign the policy, and review the agreements periodically.
Frequently asked questions about BYOD
What does BYOD mean?
BYOD stands for Bring Your Own Device. Employees use their own smartphone, laptop, or tablet for business tasks, usually in exchange for a fee covering usage and wear and tear.
Is my employer allowed to check my private phone with BYOD?
Not without further ado. Monitoring a private device infringes upon your personal privacy and, under the GDPR, must be necessary, proportionate, and based on a valid legal ground. Prior agreements, documented arrangements, and a technical separation between business and private use are important in this regard.
Am I, as an employer, liable for illegal software on a private device?
That is possible. If there is a functional link between the assigned tasks and the infringement, and you have control over the usage, then you can be held liable as an employer, even if the software is on a private device. A written prohibition does not automatically exclude this. Have this assessed on a case-by-case basis.
Does a BYOD policy eliminate all risks?
No, but it reduces them significantly. A BYOD policy prevents ambiguity, works preventively and repressively, and strengthens your position. It does not completely eliminate legal liability towards rights holders; therefore, technical measures and sound contracts remain necessary.
Which documents do I need for BYOD?
Usually a combination of a BYOD or IT policy, an employee handbook, and appropriate provisions in the employment contract. If you work with personal data via suppliers, a data processing agreement may also be required.
Is BYOD mandatory, or can an employee refuse?
BYOD is based in principle on agreements between employer and employee. You can offer and encourage it, but the use of a private device for work requires consent and clear conditions. If you want to introduce it more broadly, establish what applies to those who participate and those who do not.
Want to arrange BYOD legally correctly? We can help you
At MKB Juristen, we are fans of BYOD, but we know the legal consequences like no other. We are happy to help you with a watertight BYOD policy, a suitable employee handbook , and the right agreements in your employment contract, so that BYOD primarily delivers benefits.
Would you like to discuss your situation? View our expertise in employment law, privacy and data protection , and copyright, contact us via our legal assistance, or schedule an intake interview directly. We are happy to think things through with you.