MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Having a bring-your-own-device policy drafted by a specialized lawyer typically costs between 750 and 2,000 euros, depending on the data employees process on their own devices and whether a Works Council is involved. Expect a turnaround time of one to three weeks, the majority of which is spent coordinating with the IT administrator and, where applicable, the consent procedure. Below is an outline of what you receive, how the process works, and what drives up the price.
The short answer
- Basic regulations: 750 to 1,100 euros for an organization without special personal data and without a works council.
- Comprehensive regulations: 1,200 to 2,000 euros for device management, monitoring, or processing of sensitive data.
- Review of existing regulations: 350 to 650 euros, with concrete text proposals.
- Lead time: one to three weeks, longer if the Works Council is required to agree.
- What it determines: whether you may delete, check, and impose a sanction in the event of an incident.
Have a bring-your-own-device policy drawn up: what is included in the price
When requesting a quote, ask for the delivery package instead of the hourly rate. A complete project typically includes:
- An intake with the management and the IT administrator regarding where data ends up and which management tools are available.
- The regulations themselves: scope of application, security requirements, prohibited use, control framework, incident procedure, exit procedure, and sanctions.
- A statement of acknowledgment or an addendum to the employment contract by which the regulations become binding.
- In the case of monitoring, an assessment of whether a Data Protection Impact Assessment pursuant to Art. 35 GDPR is required.
- In the case of a Works Council, an explanation suitable as a request for consent pursuant to Art. 27 of the Works Councils Act.
What is usually excluded: the technical setup of device management, the processing register as a whole, and communication with staff. These are quoted separately or handled by the IT provider.
The process step by step
- Inventory. Which employees use which personal devices, and what data ends up on them? This is the decisive step: regulations that are stricter than practice can handle will not be complied with, and regulations that are detached from the available management tools are unenforceable.
- Risk classification. Linking categories to measures, ranging from only calendar and email to access to financial systems or special categories of personal data. Art. 32 GDPR requires measures that match the risk, not a single regime for everyone.
- Draft. The regulations with all chapters, plus the acknowledgment statement. The audit framework is aligned with the requirements of Art. 8 ECHR and the basis of Art. 6 paragraph 1 sub f GDPR.
- Alignment with IT. Every standard is tested for measurability and enforceability using existing tools. A requirement that no one can verify has no place in it.
- Implementation. In the case of a works council, the request for consent pursuant to Art. 27, paragraph 1, parts k and l of the Works Councils Act (WOR). Without a works council: demonstrable communication and a statement of acknowledgment per employee.
What causes the price to go up
Four factors explain virtually the entire difference between 750 and 2,000 euros:
- Nature of the data. Special personal data, such as in healthcare, or financially and disciplinary sensitive files require a stricter regime, stronger substantiation, and often a data protection impact assessment.
- Monitoring. As soon as you wish to record more than device status and login attempts, the control framework must be assessed for necessity and proportionality per measure, with a description of safeguards and reporting.
- Works Council. The consent process requires an explanation demonstrating the considerations made. This is a separate document and often involves one or two rounds of consultation.
- Concurrence with other policies. If an internet and email protocol, a teleworking policy, or an information security policy already exists, the documents must be consistent. In a dispute, conflicting provisions are the first thing the opposing party points out.
Practical example: an installation company with 28 employees had a set of regulations with two risk categories drawn up for 950 euros. Technicians were only allowed the work order app and calendar on their own phones; office staff were given access to email and documents via a managed work environment. When a technician lost his phone, the work environment could be wiped within an hour, and no notification to the Dutch Data Protection Authority was required because no personal data was stored outside the container.
Do it yourself, buy a model, or have one drawn up
A free template is useful as a starting point, but almost always runs into three problems. First, most templates contain a general provision stating that the employer may wipe the device, without distinction between work environment and private data. That is precisely the provision that fails in a dispute. Second, the control framework regarding grounds, scope, and safeguards is missing, meaning you have no usable basis in the event of a concrete suspicion. Third, it contains standards that you cannot verify with your own tools.
A paid template from a document shop costs 75 to 250 euros and suffices if you only allow calendar and email via a managed app. As soon as device management, monitoring, or sensitive data come into play, customization is cheaper than the first incident. If you have existing regulations reviewed, ask for text proposals per article instead of a general assessment.
Honest recommendation
You don't always need a lawyer for this. If you provide laptops and phones yourself, or if you only allow calendar and email on private devices via a managed app with a personal PIN, then a page in the employee handbook with five rules will suffice: permitted devices, mandatory locking and updates, no storage outside the app, report in case of loss, delete upon departure. Have the IT administrator check whether those rules are enforceable with existing tools, and you are done.
Ensure that regulations are drawn up as soon as customer files, financial systems, or special personal data are stored on your own devices, as soon as you implement monitoring or device management, or as soon as there is a Works Council that requires consent. In those situations, the text determines whether you are permitted to delete and monitor in the event of an incident, and whether a sanction will stand. Request a fixed price including the acknowledgment statement and, where necessary, the request for consent.
Read more: what is a bring your own device policy and drafting a bring your own device policy. You can arrange this directly via the bring your own device policy.
Frequently Asked Questions
Basic regulations typically cost between 750 and 1,100 euros. If you work with device management, monitoring, or special personal data, the price ranges between 1,200 and 2,000 euros. Having only existing regulations reviewed usually costs between 350 and 650 euros, including text proposals per article.
One to three weeks: inventory, risk assessment, draft, coordination with the IT administrator, and implementation. If the Works Council requires approval, count on an additional four to eight weeks, depending on the consultation cycle.
Because a standard that cannot be verified is not a standard. Every requirement in the regulations must be measurable and enforceable using the available management tools. Otherwise, you will end up with a rule on paper that actually works against you in the event of an incident, because you failed to enforce it yourself.
As a starting point, yes. Then pay attention to three points that are almost always missing or go wrong: the distinction between wiping the work environment and the entire device, a control framework with justification, scope, and safeguards, and standards that can be verified with your own tools.
An overview of who uses which personal devices and what data is stored on them, the available management tools, the existing internet and email protocol or information security policy, and whether there is a works council. With this, the risk classification can be completed in a single round.
Only if there is a Works Council, but then almost always. The regulations contain provisions regarding the monitoring of conduct or performance (Article 27, paragraph 1, part k of the Works Councils Act) and regarding the processing of personal data of employees (part l). Without consent, the regulation may be declared void.
With every change to the systems or management tools used, and furthermore once every two years. At that time, at the very least, check whether the security standards still align with current technical practice and whether the control framework still fits with what you are actually documenting.