Mobile Phone Policies, Scope and Coverage
Who Does the Mobile Phone Policy Cover?
Define which staff the Mobile Phone Policy applies to: all staff, specific departments, specific roles, or specific levels. Most businesses apply the same policy to all staff, but some distinguish between roles (field staff have different allowances than office staff, for example).
Be explicit. “This policy applies to all employees and contractors using company-provided mobile phones.”
Personal Devices and BYOD policy
Are staff allowed to use personal phones for business? Do you have a separate BYOD policy for personal devices used for business? If BYOD is allowed, how is it different from a company-owned mobile phone policy?
Make clear whether personal device use is permitted, required, discouraged, or prohibited. Most businesses prefer company-owned phones for security and cost control.
Permitted Use and Personal Use
Primary Purpose
State clearly: a mobile phone is provided for business use. Staff should prioritise business calls, emails, and messages.
Personal Use Allowance
Few businesses prohibit personal use entirely. Reasonable personal use (calling family, checking personal email during break) is normal. But unlimited personal use is problematic.
Define what personal use is permitted: “Limited personal use is permitted during non-working hours. Personal use during working hours should be minimal and not interfere with job duties.”
Alternative approach: “Personal use is prohibited during working hours. Limited personal use is permitted before and after work and during breaks.”
Prohibited Use
Explicitly prohibit certain uses: accessing adult content, gambling, illegal activities, harassing or offensive communications, using phone while driving (unless hands-free), etc.
Examples: “Staff are prohibited from: using phone while driving except via hands-free, sending harassing or offensive messages, accessing adult or illegal content, using phone for business competing with company business, discussing confidential company information with unauthorized parties.”
Be specific about what’s prohibited. Vague prohibitions are hard to enforce.
Ownership, Responsibility, and Damage
Device Ownership
Make clear: the company owns the device. Staff are responsible for the device while in their custody. Upon leaving employment, the device must be returned to the company.
Damage and Loss Responsibility
Define who pays if the device is damaged or lost. Common approaches:
- Company pays for normal wear and tear, accidental damage. Staff pay for damage from negligence or misuse. Staff pay for loss unless immediately reported.
- Company pays all damage and loss (high cost but removes incentive to hide problems).
- Staff pay percentage of replacement cost (e.g., staff pay 20%, company pays 80%, creating shared responsibility).
Define “immediately reported”: loss must be reported within 24 hours. Delayed reporting suggests staff negligence.
Replacement Device Process
If device is damaged or lost, what’s the replacement process? Is there a replacement device available immediately, or does the staff wait for repair/replacement? Does replacement incur any cost to staff? When does an old device get replaced vs when does staff continue on an older device?
Clear process prevents disputes about responsibility and replacement timelines.
Cost Management and Overage Charges
Allowances
State what allowances each staff member receives: minutes for calls, data allowance, SMS allowance. Different roles may have different allowances (field staff get higher allowances than office staff, for example).
Example: “Sales staff receive 2,000 minutes, unlimited SMS, 5 GB data. Office staff receive 500 minutes, 200 SMS, 1 GB data.”
Overage Charges
What happens if staff exceed allowances? Options:
- Company pays all overage charges (staff have no cost incentive to control usage).
- Staff pay all overage charges (strong incentive to control usage but can be harsh for accidental usage).
- Company and staff share overage charges 50/50 (balanced incentive).
- Company pays overages up to certain limit, staff pays beyond that (caps liability while maintaining incentive).
Make clear which approach applies. Document specifically who pays for international charges, roaming charges, premium SMS.
Cost Controls
Implement spending caps to prevent surprise bills. If staff member reaches spending cap, service is blocked or staff is notified to prevent further charges.
State in policy: “Spending caps are set at [amount]. If usage approaches cap, staff will be notified. Service may be blocked if cap is exceeded unless staff requests exception.”
International and Roaming
International calling and roaming are expensive. Are these services enabled by default? Do staff need to request them? Are they allowed only for business travel? Are they blocked entirely?
Example policy: “International calling and roaming are blocked by default. Staff planning business travel outside UK can request temporary roaming activation. Requests must be submitted 1 week in advance and include business justification. International calls during travel are staff responsibility at standard international rates.”
Security Requirements
Password Protection
All devices must have strong password or biometric authentication. “Strong password” means minimum 8 characters, mix of letters and numbers, not dictionary words or personal information.
Alternative: “All devices must be protected with strong password (minimum 8 characters including numbers and special characters) or biometric authentication (fingerprint, face recognition).”
Encryption
All devices must have encryption enabled. “Device encryption must be enabled. IT can verify encryption status.”
Software Updates
Devices must be updated with latest security patches. “Operating system and apps must be kept updated with latest security patches. Enable automatic updates or manually update at least monthly.”
Mobile Device Management
For businesses using MDM, state clearly: “Company will enroll your device in Mobile Device Management (MDM) system. MDM allows company to enforce security policies, monitor compliance, and remotely wipe lost devices. By accepting device, you consent to MDM enrollment and monitoring.”
Prohibited Apps and Services
Are certain apps prohibited? Are certain services (Wi-Fi calling, hotspot sharing) allowed or prohibited?
Example: “Staff may not install apps without IT approval. Unauthorized apps may contain malware or access business data without permission.”
Wi-Fi and VPN
When accessing business systems over public Wi-Fi, VPN is required. “When accessing business email or systems using public Wi-Fi, VPN must be enabled. VPN access information is available from IT department.”
Data and Privacy
Business Data on Device
What business data can staff store on phone? Email, contacts, documents? Are certain data types prohibited on personal devices?
Example: “Staff may access and store business email, documents, and client contact information on company device. Highly sensitive information (financial data, executive-only information) should not be stored on devices – access only when necessary.”
Privacy and Monitoring
Inform staff clearly about monitoring. “Company may monitor device usage, location (if MDM enabled), and app installations. Personal information is not monitored. Device is monitored to enforce security and protect company data.”
Be honest about what’s monitored and why. Privacy regulations may require explicit consent for monitoring.
Confidentiality
Staff must not discuss confidential company information over phone or in text messages where conversation could be overheard or intercepted. “Confidential company information must not be discussed in public locations or in unsecured messaging. Use secure messaging apps for sensitive conversations.”
Device Inspection and Audits
Company reserves right to inspect devices for compliance with policy: security settings, prohibited apps, business data management. “Company may periodically inspect devices to verify compliance with security policy. Inspections are conducted by IT with advance notice when possible.”
Balance company need for security with staff privacy expectations.
Termination and Device Return
When staff leave company, device must be returned. “Upon termination of employment or contractor agreement, device must be returned to company within [24 hours]. Failure to return device may result in charges for device replacement.”
Remote wipe should occur immediately. “Upon termination, company will remotely wipe device to protect confidential information. Staff will lose access to business email and company data after remote wipe.”
Violations and Enforcement
What happens if staff violates policy? Progressive discipline is common: first violation is warning, second is written warning, third is termination for repeated violation. Serious violations (security breaches, illegal use) may result in immediate termination.
Example: “Policy violations will result in progressive discipline: first violation – verbal warning; second violation – written warning; third violation – suspension or termination. Serious violations (security breaches, illegal use, harassment) may result in immediate termination. Company reserves right to pursue legal action for damages resulting from policy violations.”
Policy Maintenance and Updates
Technology changes. Threats evolve. Policy should be reviewed annually and updated as needed. “This policy will be reviewed annually and updated as needed based on technology changes and business requirements. Updated policies will be distributed to all staff.”
Implementation and Communication
Document the Policy
Write policy in clear, simple language. Avoid legal jargon. Make it easy for staff to understand what’s expected.
Distribute to All Staff
Provide written copy to every staff member who receives mobile device. Electronic copy in employee handbook is standard.
Require Acknowledgment
Have staff sign acknowledgment that they’ve read and understand policy. Keep signed acknowledgments on file. This documents that staff knew the rules and agreed to them.
Train Staff
Explain policy verbally when new staff is onboarded and device is provided. Answer questions. Clarify ambiguities. Training ensures understanding and reduces conflicts later.
Enforce Consistently
Apply policy consistently to all staff. Inconsistent enforcement creates perception of unfairness and undermines policy credibility. If some staff violate policy without consequences, others will too.
Policy Template Considerations
Elements to include in written policy: purpose, scope, permitted use, prohibited use, security requirements, cost responsibility, device ownership and damage, international use, BYOD (if applicable), data and privacy, termination procedures, violations and enforcement, policy review schedule.
Keep policy concise (1-2 pages). Long policies are less likely to be read and understood.
Working with HR and Legal
Contact Multidata for guidance on mobile phone policies and implementation. We help businesses develop clear, fair policies that balance business needs with staff expectations. We help implement policies, set up monitoring and controls, and train staff on expectations. We also ensure mobile policies coordinate with VoIP phone system policies and broadband connectivity for a complete communications strategy.
Consult with HR and the legal team when developing policy. Requirements may vary based on employment law in your jurisdiction and industry-specific regulations. For guidance on employment law and mobile policies, ACAS provides resources on workplace policies and employment best practices in the UK.
Frequently Asked Questions
-
Should we allow personal use at all?
Completely prohibiting personal use is unrealistic and creates staff morale issues. Reasonable personal use (brief calls to family, checking personal email) is normal. Setting clear boundaries (during breaks, not during customer meetings, etc.) is more practical than prohibition. -
How strictly should we enforce the policy?
-
Can we monitor personal use?
-
What if staff refuses to sign policy acknowledgment?
-
How do we handle VoIP calls on mobile policy?