Skip to main content

Glossary

Acceptable use policy

An acceptable use policy (AUP) is the document that tells employees what they may and may not do with company devices, company data and, under BYOD, the work side of their personal phone, and what the company itself will and won't do on those devices. For an IT team it's the legal and human counterpart of the MDM policy: the console enforces, the AUP explains and gets signed.

How it works

An AUP is written once, reviewed by legal and HR, signed by the employee at onboarding, and referenced every time a rule is enforced. In France it's usually called a "charte informatique" and is annexed to the internal regulations after consultation of the works council (CSE), which makes it enforceable in disciplinary matters. Germany's works councils have similar rights, and GDPR applies everywhere in the EU.

A good mobile AUP covers a short list of things:

  • Which devices are in scope: company-owned, personal under BYOD, shared.
  • What the user must do: keep a passcode, install updates, report loss within a set time (24 hours is common), not jailbreak or root.
  • What the user must not do: sideload apps, store work files in personal cloud drives, lend the device.
  • What the company will do: which data the MDM collects (model, OS version, installed apps on company devices, only the work side on BYOD), when it wipes (full wipe on company devices, work data only on personal ones), and under which conditions it locates a device.
  • What happens when the person leaves.

The MDM's own tooling helps. Terms of use can be displayed at enrollment and require acceptance before the device is managed, and the console's inventory tells you exactly what data is collected, which is what the policy has to disclose.

Why it matters for a fleet

Without a signed AUP, a remote wipe on a personal phone is a legal problem, and disabling a camera on a company phone is a grievance. With one, both are the application of a rule the employee accepted.

Under GDPR, the AUP is also where the transparency obligation is met. An employee has the right to know what the company sees on the device, and "the MDM can see everything" is neither accurate nor acceptable. Spell out that on a personal phone the company sees only the work profile, and that geolocation, if used at all, is limited to lost company devices.

The mistake to avoid is the 30-page document nobody reads. Two pages, plain language, a table of what's visible per device type, and a signature block. Then match the MDM configuration to what you wrote, because an audit compares the two.

How Appaloosa handles it

Appaloosa gives the AUP something concrete to point to. On company-managed devices it collects inventory (model, OS version, compliance state, installed apps) and can apply lost mode and full remote wipe; on personal devices it manages only the work profile on Android or the work apps and accounts deployed on iOS, and removes only those. Real-time geolocation is available only on request with supporting evidence, never on BYOD. Those boundaries are the ones an AUP should state, and the policy catalog is on the mobile device management page.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

See Appaloosa run on your fleet Book a demo

Frequently asked questions

Is an acceptable use policy legally required?
Not as such, but it's what makes device rules enforceable. In France, a charte informatique annexed to the internal regulations after works council consultation can support disciplinary action; without it, sanctions are hard to defend. GDPR separately requires you to inform employees of what data the MDM collects, and the AUP is the natural place.
What should a BYOD acceptable use policy say about wiping?
That the company can remove work apps and work data at any time, and that personal data, photos and messages are out of scope. State it explicitly and configure the MDM to match: work profile removal on Android, removal of managed apps and accounts on iOS. A full device wipe on a personal phone should never be possible from your console.
How often should the AUP be updated?
Review it once a year and whenever the MDM configuration changes in a way users would notice, such as adding a new platform, enabling lost mode or changing what's collected. Each material change needs to be communicated, and in France re-submitted to the works council if it's part of the internal regulations.