Glossary
Acceptable use policy
An acceptable use policy (AUP) is the document that tells employees what they may and may not do with company devices, company data and, under BYOD, the work side of their personal phone, and what the company itself will and won't do on those devices. For an IT team it's the legal and human counterpart of the MDM policy: the console enforces, the AUP explains and gets signed.
How it works
An AUP is written once, reviewed by legal and HR, signed by the employee at onboarding, and referenced every time a rule is enforced. In France it's usually called a "charte informatique" and is annexed to the internal regulations after consultation of the works council (CSE), which makes it enforceable in disciplinary matters. Germany's works councils have similar rights, and GDPR applies everywhere in the EU.
A good mobile AUP covers a short list of things:
- Which devices are in scope: company-owned, personal under BYOD, shared.
- What the user must do: keep a passcode, install updates, report loss within a set time (24 hours is common), not jailbreak or root.
- What the user must not do: sideload apps, store work files in personal cloud drives, lend the device.
- What the company will do: which data the MDM collects (model, OS version, installed apps on company devices, only the work side on BYOD), when it wipes (full wipe on company devices, work data only on personal ones), and under which conditions it locates a device.
- What happens when the person leaves.
The MDM's own tooling helps. Terms of use can be displayed at enrollment and require acceptance before the device is managed, and the console's inventory tells you exactly what data is collected, which is what the policy has to disclose.
Why it matters for a fleet
Without a signed AUP, a remote wipe on a personal phone is a legal problem, and disabling a camera on a company phone is a grievance. With one, both are the application of a rule the employee accepted.
Under GDPR, the AUP is also where the transparency obligation is met. An employee has the right to know what the company sees on the device, and "the MDM can see everything" is neither accurate nor acceptable. Spell out that on a personal phone the company sees only the work profile, and that geolocation, if used at all, is limited to lost company devices.
The mistake to avoid is the 30-page document nobody reads. Two pages, plain language, a table of what's visible per device type, and a signature block. Then match the MDM configuration to what you wrote, because an audit compares the two.
How Appaloosa handles it
Appaloosa gives the AUP something concrete to point to. On company-managed devices it collects inventory (model, OS version, compliance state, installed apps) and can apply lost mode and full remote wipe; on personal devices it manages only the work profile on Android or the work apps and accounts deployed on iOS, and removes only those. Real-time geolocation is available only on request with supporting evidence, never on BYOD. Those boundaries are the ones an AUP should state, and the policy catalog is on the mobile device management page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo