tchop Logo

Platform

Solutions

Resources

Company

EN

Login

tchop Logo

EN

Login

tchop Logo

EN

Login

Grid pattern

BYOD (bring your own device)

BYOD means doing work on a personally owned device. What a policy has to settle, how the split between work and private data is enforced, and when it is the wrong call.

What does BYOD mean?

BYOD stands for bring your own device. It means doing work on a personally owned phone, tablet or computer rather than on hardware the employer issued. The US National Institute of Standards and Technology defines it as "the practice of performing work-related activities on personally owned devices". The device belongs to the person, the work data on it belongs to the employer.

Does BYOD mean the same thing everywhere?

Not quite, and search results mix three senses. In IT and HR, BYOD is the workplace policy described above, and that is the sense used on this page. Mobile carriers use "BYOD" to mean bringing a handset you already own to a new plan instead of buying one from the carrier. Socially, "BYOD" occasionally stands for bring your own drinks. Only the first has a security policy attached.

How does BYOD work technically?

The problem is two owners and one device, and it is solved by separation rather than by taking control of the whole phone. Android uses a work profile. Google's documentation for Android Enterprise puts it this way: "A work profile is controlled by an IT admin, and the functionality available to it is set separately from the functionality of the user's primary profile", which lets organisations "control the environment where company-specific apps and data are running on a user's device, while still letting users use their personal apps and profiles" (Work profiles, Android Developers). Apple offers an equivalent enrolment that manages only work accounts and apps.

The practical result is that an employer can wipe the work side without touching personal photos. The UK's National Cyber Security Centre states the ownership position plainly: "With BYOD, an organisation has ownership of the corporate data and resources that may be accessed or stored on a device, but the device itself is the property of the user."

What should a BYOD policy cover?

Six items, and most failed rollouts skipped one of them. Which devices and which operating system versions are allowed. Which applications and which data may reach a personal device at all. How the device is secured, meaning screen lock, encryption and updates. What happens when a device is lost, and who may erase what. Who pays for data, repair and replacement. And how it ends when someone leaves or changes phone.

The most important line usually sits at the top: taking part is voluntary. If there is no alternative for someone who declines, the offer is a requirement wearing a different hat, and it will be read that way.

What are the risks of BYOD?

Four carry real weight. The attack surface widens, because device models and patch levels drift apart. Support costs rise, because every combination behaves differently. The separation of work and personal data has to be enforced technically, which takes setup and testing. And the boundary between work and time off blurs once work notifications land on a personal lock screen.

There is also a quieter risk pointing the other way. A personal device holds personal data, and a remote wipe that cannot tell the two apart is a liability for the employer, not just an inconvenience for the person. That is why selective wipe of a work container is the only version worth deploying.

What does BYOD look like under German law?

Two rules apply together, and any company with staff in Germany should read them before the rollout, not after. Section 87(1) no. 6 of the Works Constitution Act gives the works council a codetermination right over "die Einführung und Anwendung von technischen Einrichtungen, die dazu bestimmt sind, das Verhalten oder die Leistung der Arbeitnehmer zu überwachen", meaning technical systems capable of monitoring conduct or performance. The employer's intention is irrelevant; the capability is enough. Section 26(4) of the Federal Data Protection Act then makes a collective agreement an explicit legal basis for processing employee data. In practice a works agreement is both the political and the legal route, and it should also settle whether work notifications are delivered outside working hours.

Why does BYOD come up at all in production and care?

Because in those settings there is often no company device to issue. In Germany in 2025, 68.4% of people employed in businesses with ten or more staff had internet access for work purposes, according to Eurostat. The figure was 64.1% in manufacturing, 61.3% in transport and storage, 60.6% in construction, 47.6% in accommodation and food service, and 39.2% in food, beverage and tobacco manufacturing. The EU27 average was 64.6%. The survey covers businesses with ten or more employees and excludes agriculture, mining and the financial sector. For a plant manager the consequence is concrete: roughly a third of the workforce has no work account, no work mailbox and no issued handset, so any channel that assumes one reaches the office and stops at the factory door. The personal phone is the only device in the building that everyone already has. That is why the BYOD question turns up at the start of almost every employee-app rollout, and why leaving it unanswered answers it anyway, in favour of unofficial WhatsApp groups that nobody approved and nobody can audit.

When is BYOD the wrong choice?

When the data is sensitive enough that the employer needs full control, such as health or personnel records. When a regulator requires complete logging that would not be lawful on a personal device. And when the savings are the reason: support tickets rise with device variety, and a contribution toward data plans or wear and tear usually belongs in the calculation, which narrows the gap against issuing hardware.

How does tchop work on personal devices?

tchop runs on personal devices without device management and without access to the rest of the phone. People register with an access code from their employer instead of a corporate account, content stays inside the company's own app, and access can be revoked for one person without touching their device. Wernsing Food Group uses tchop for communication with its production workforce. One limit belongs here: tchop is not a device management product and does not replace mobile device management for company-issued hardware.

More on the security page at tchop.

FAQs: BYOD

Is BYOD good or bad?

It depends on what the device is used for. For reading notices, rotas and company news, BYOD is usually the only practical option, because many frontline staff have no company device at all. For handling customer records, health data or anything a regulator audits, issued hardware is the honest answer. Most organisations end up running both.

What is a BYOD phone on a mobile plan?

A different meaning of the same letters. Carriers use BYOD for bringing a handset you already own to a new plan rather than buying a subsidised one. It has nothing to do with workplace policy, device management or company data, and it is worth naming because it dominates consumer search results.

Can an employer wipe a personal phone?

Only the part that belongs to it. A full device wipe would destroy personal data and is generally not defensible. What is defensible is a selective wipe of the work profile or the managed applications. The policy should say in plain words which of the two is in scope, and the person should know before they enrol.

Does BYOD save money?

Less than the first calculation suggests. Hardware cost moves off the balance sheet, then reappears as support for many device models, as a stipend for data or damage, and as the setup work for containerisation. The stronger argument for BYOD is reach, not cost: it is often the only way to reach people who were never issued a device.

Sources

  • NIST Special Publication 1800-22, "Mobile Device Security: Bring Your Own Device (BYOD)", September 2023, authors Kaitlin Boeckl, Nakia Grayson, Gema Howell and Naomi Lefkovitz (NIST) with co-authors at MITRE

  • National Cyber Security Centre (UK), "Bring your own device (BYOD)", Device Security Guidance

  • Android Developers, "Work profiles", Android Enterprise

  • Works Constitution Act (BetrVG), section 87(1) no. 6, and Federal Data Protection Act (BDSG), section 26(4)

Want to test your app for free?

Experience the power of tchop™ with a free, fully-branded app for iOS, Android and the web. Let's turn your audience into a community.

Request your free branded app

Want to test your app for free?

Experience the power of tchop™ with a free, fully-branded app for iOS, Android and the web. Let's turn your audience into a community.

Request your free branded app

Want to test your app for free?

Experience the power of tchop™ with a free, fully-branded app for iOS, Android and the web. Let's turn your audience into a community.

Request your free branded app