| name | byod-policy |
| title | BYOD Policy |
| description | Drafts a Bring Your Own Device (BYOD) policy for U.S. employers governing personal device access to company systems. Covers MDM enrollment, encryption, remote wipe authority, privacy expectations, data classification, and regulatory overlays (HIPAA, GLBA, SOX, GDPR). Use when creating or updating BYOD policies, mobile device security policies, or personal device programs. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/byod-policy |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | data-protection |
| language | en |
BYOD Policy
Generates an employer-facing BYOD policy balancing operational flexibility with data security, regulatory compliance, and enforceable employee obligations.
Prerequisites
Gather before drafting:
- Organization profile — industry, size, applicable regulations (HIPAA, GLBA, SOX, GDPR, CCPA)
- Device scope — smartphones, tablets, laptops, wearables
- MDM platform — company-approved mobile device management software, if any
- Data classification — which tiers are permitted on personal devices
- IT support boundaries — helpdesk scope for personal vs. company apps
- Stipend terms — any reimbursement for device use
Output Structure
| # | Section | Key Contents |
|---|
| 1 | Purpose & Scope | Why BYOD is permitted; covered employees, devices, systems |
| 2 | Eligibility & Enrollment | Approval process; IT registration; MDM installation |
| 3 | Security Requirements | Minimum device standards (see checklist below) |
| 4 | Company Rights | Remote access, monitoring, wipe authority and triggers |
| 5 | Privacy Expectations | What company may/may not access; commingled data |
| 6 | Employee Responsibilities | Reporting obligations; financial responsibility |
| 7 | Data Handling | Permitted classifications; backup, retention, deletion |
| 8 | Regulatory Compliance | Industry-specific overlays |
| 9 | Support & Liability | IT support scope; negligence liability |
| 10 | Acknowledgment | Signature block; disciplinary consequences |
Key Section Details
Security Requirements (Section 3)
Include minimum standards:
- Screen lock: PIN/password ≥ [X] chars, biometric, or MFA
- Patching: OS/security updates within [X] days of release
- MDM agent installed and active
- Full-device or work-profile encryption enabled
- Auto-lock timeout ≤ [X] minutes
- Remote wipe confirmed before enrollment