BYOD Policy for an Indian SMB: A Template You Can Adapt in an Afternoon
The short version. A BYOD policy for an Indian SMB needs six parts: scope, a device security baseline, data-handling rules, MDM enforcement, an offboarding step, and acceptable use. You can draft all six in one afternoon. The hard part is not the writing. It is enforcing selective wipe and offboarding after the document gets signed.
The founder ran a 40-person services firm in Navi Mumbai. He had 51 devices on his network and no clean list of which nine were personal phones carrying client data. He asked me for “a BYOD policy, one page, nothing fancy.” I am Arjun. I have written this document for fleets from 20 seats to 300. We built his in one afternoon over two cups of thanda chai, and the writing was the easy part.
Bring your own device, or BYOD, is when staff use personal laptops and phones for work. It saves the company hardware money. It also moves your client data onto machines you do not own and cannot see. A policy is how you get the saving without the blind spot. Achha, let us walk through what it has to say.
What should a BYOD policy actually cover?
The founder’s first draft was three lines about not sharing passwords. That is not a policy. That is a wish. A real BYOD policy answers six questions, and every one of them maps to a decision someone will have to make at 6 PM on a bad day.
Scope comes first. Which devices are allowed, which roles may use them, and which data classes may touch a personal device at all. His sales team needed email and the CRM on their phones. His accounts head wanted the ledger nowhere near a personal laptop. Pakka. That split is the policy’s spine, and it is a business call, not an IT one.
Then comes the security baseline, the data rules, the enforcement method, and the exit. We have run device policies across BFSI fleets, including a 2,847-device estate for one insurer, and the pattern never changes. The policy is quick to write. The offboarding clause is where the data actually walks out of the building.
Which BYOD security rules are non-negotiable?
Four controls are not optional, and they cost nothing but a settings change. A screen lock with a real passcode. Full-disk or device encryption, which every modern phone and laptop already ships with. Automatic security updates left switched on. And a way to remotely remove company data if the device is lost. These four map cleanly to access-control practice in ISO 27001 (iso.org), so you are not inventing a standard, you are borrowing a tested one.
The rule that founders resist is data partitioning. Work data lives in a managed container, personal data stays outside it, and the two do not mix. It sounds heavy. It is the single thing that lets you wipe the work half without touching the employee’s family photos. Without partitioning, “wipe the device” means an argument with a resigning employee, and you will lose that argument.
This is also where India’s data law stops being abstract. The DPDP Act 2023 makes you the data fiduciary for the personal data your business holds. A serious protection failure carries penalties up to Rs 250 crore (meity.gov.in). If a salesperson’s personal phone holds 4,000 customer records and it is stolen, “it was his phone, not ours” is not a defence the law recognises (prsindia.org). Your BYOD policy is part of how you show you took reasonable safeguards.
The six-part BYOD policy template
Here is the frame we filled in that afternoon. Copy the six rows, write one honest paragraph under each for your own business, and you have a working draft.
| Section | What it must state |
|---|---|
| 1. Scope and eligibility | Which roles may use personal devices, which device types are allowed, and which data classes are barred from them. |
| 2. Security baseline | Passcode, encryption, auto-updates, screen-lock timeout. The four non-negotiables, stated as minimums. |
| 3. Data handling | Work data stays in a managed container. No company data in personal cloud drives, personal email, or WhatsApp exports. |
| 4. Enforcement (MDM) | Enrolment in your MDM before access is granted. What the company can and cannot see. Selective wipe of work data only. |
| 5. Offboarding | The exact step on the last working day: work container removed and access revoked, with the step logged. |
| 6. Acceptable use and consent | What the employee agrees to, what the company will never touch, and a signature with a date. |
Notice section four does two jobs. It says what you will enforce, and it says what you will not see. Staff accept a policy far faster when it names the boundary in plain words. “We can remove work apps. We cannot read your gallery or your personal chats.” Put that sentence in. It buys you more compliance than any threat.
What we told him to enforce first
A policy nobody enforces is decoration. So we picked one control to make real before he circulated the PDF. Enrol every device in a mobile device manager. Work data then sits in a container the company can wipe on its own. For a firm already paying for Microsoft 365, that meant turning on Intune enforcement he had already bought and never switched on. Bas. One console, work container, selective wipe. Not the whole ISO programme on day one.
The second thing we fixed was the exit. His old process was to ask leavers to “delete the company stuff.” We replaced it with one logged step on the last day, run from the MDM. It removes the work container and revokes access, and the confirmation gets filed. That is the clause that separates a policy from a story you tell auditors. Want the same discipline on company-owned machines? That is what device lifecycle management covers end to end. It is also why we pair BYOD rules with Secure Data Guard, for the data that leaves over email and USB.
If you are writing your BYOD policy yourself
Write the offboarding clause first, before scope, before anything. It is the part every template skips and every breach needs. Give it a named owner and a fixed day.
Keep the document to two pages. A four-page policy is a policy nobody reads, and an unread policy protects no one. State the four security minimums as settings, not as principles, so IT can check them in a report. And get a real signature with a date, because consent you cannot prove is consent you did not get. If you would rather not draft it cold, our team has done this enough times that a DPDP readiness check will map your gaps in a first sitting. It also helps to read how employees actually move company data out before you decide what to lock.
Questions the founder asked that afternoon
Do I legally need a BYOD policy in India? No single law names the document. But under the DPDP Act 2023 you must show reasonable security safeguards for personal data (meity.gov.in), and a signed BYOD policy is direct evidence you took them. Without one, you are defending a gap you chose to leave open.
Can we run BYOD without an MDM? You can, and you will not be able to enforce a single rule you wrote. No MDM means no container and no selective wipe, which leaves you no proof you ever offboarded anyone. For anything past a handful of seats, the enforcement layer is the policy.
What does enforcement cost for a small fleet? If you are on Microsoft 365 Business Premium, Intune is already included, so the cost is setup, not licence. Layered data protection through Secure Data Guard starts from Rs 749 per device per month*. Match the spend to the fleet. A 12-person office does not need what a 300-device estate needs.
How is a BYOD policy different from a company-device policy? Ownership. On a company device you control the whole machine. On a personal one you may only touch the work container, and you must say so in writing. The security floor is the same. The consent and privacy language is what changes.
Key takeaways
- A BYOD policy has six parts: scope, security baseline, data handling, MDM enforcement, offboarding, and acceptable use.
- The four security minimums cost nothing: passcode, encryption, auto-updates, and remote work-data wipe.
- Data partitioning is what makes selective wipe possible without touching personal files.
- Enforcement lives in an MDM. Without one, the policy is only a wish.
- Under the DPDP Act 2023, a signed policy is your evidence of reasonable safeguards, with penalties up to Rs 250 crore for failures.
Future Arjun, if you are reading this before the next rollout: write the offboarding clause first, and make the founder sign the acceptable-use page in the room. The document that survives an audit is the one somebody actually enforced on a Tuesday.
Want us to pressure-test your BYOD policy against the DPDP Act and your real device list? Send us the seat count and the split of personal versus company devices, and we will tell you where the gaps are. 200+ Indian businesses served, 17+ years in the field. Response within 24 working hours. Message us on WhatsApp or care@siriusstar.in.
*Indicative pricing, before seat-band discounts. Confirm current rates at quote time.







