Skip to main content

Glossary

BYOD

BYOD (Bring Your Own Device) is the practice of letting employees use their personal phone or tablet for work. The company doesn't buy the hardware; it only secures the work-related part of it, typically through a separate managed workspace on the device.

How it works

On a personal device, the company can't control everything, and shouldn't try. Modern BYOD relies on separation. Android creates a work profile: a second, isolated user space with its own apps, its own contacts and its own encryption keys. iOS and iPadOS use User Enrollment, introduced in iOS 13 in 2019, which puts managed apps and accounts on a separate APFS volume.

The user installs an enrollment app or profile, accepts the terms, and IT pushes corporate apps, email and security rules into that space: passcode, encryption, no copy-paste from work apps to personal ones. When the person leaves, only the work space is wiped. The holiday photos stay.

Why it matters for a fleet

BYOD cuts hardware spend and keeps employees on a device they already know. But it moves the risk. A lost or compromised phone now holds company data, and without a managed separation nobody can wipe it remotely or prove it was encrypted.

It's also a legal question. Under GDPR, the employer must protect professional data without monitoring the employee's private life. A separated, documented workspace is the simplest answer to both demands, and it's what regulators like France's CNIL recommend.

One caveat: BYOD works poorly for shared or frontline devices. A scanner used by three shifts a day should be company-owned. And support gets harder, because IT can't control which Android version or which manufacturer's skin the employee brought in. Set a minimum OS version in the policy and stick to it.

How Appaloosa handles it

Appaloosa enrolls personal devices in work profile mode on Android and User Enrollment on iOS and iPadOS, without taking over the whole device. The admin deploys business apps, applies security rules and wipes the work space remotely, never touching personal data. The employee sees exactly what the company manages. Enrollment modes are described on the Mobile Device Management page.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

Ready to try Appaloosa? Start free

Frequently asked questions

Can my employer see my personal photos or messages in BYOD?
No. With a separated work space, the employer only sees the apps and data it deployed itself. Personal apps, photos and messages remain invisible and can't be wiped by the company. Both Apple and Google publish what each enrollment mode exposes.
What's the difference between BYOD and COPE?
In BYOD, the employee owns the device and the company manages only a part of it. In COPE, the company owns the device and manages it fully while allowing personal use. The management depth and the wipe scope differ accordingly.
Is BYOD compatible with GDPR?
Yes, provided professional data is clearly separated, encrypted and can be wiped remotely without touching personal data. That's exactly what work profile enrollment on Android and User Enrollment on iOS provide. Document the policy and inform employees in writing.