Work Mobile Phone Policy In New Zealand: What To Include

Alex Solo
byAlex Solo10 min read

If you run a small business, it’s pretty normal for work to happen on a phone now. Staff call customers, reply to emails, access job apps, take photos of sites, and message colleagues - all from a device that can be lost, hacked, or used in a way that creates legal risk.

That’s why having a clear work mobile phone policy is one of those “protect your business from day one” steps that can save you a lot of stress later. It sets expectations, protects your confidential information, and helps you respond consistently when something goes wrong.

Below, we break down what a work mobile phone policy is, when you need one, and what to include if you want it to actually work in real life (and not just sit in a folder unread).

What Is A Work Mobile Phone Policy (And Why Does It Matter)?

A work mobile phone policy is a written set of rules that explains how phones can be used for work, what staff can and can’t do on those devices, and how your business will manage privacy, security, and costs.

It’s not just about stopping people from scrolling social media. A well-written policy should also help you manage risks like:

  • Privacy breaches (for example, customer contact lists or medical information being stored on an unprotected phone)
  • Cyber security issues (like malware, phishing, or weak passwords)
  • Unclear boundaries (staff using personal apps for work, or work apps for personal use)
  • Disputes about payment (who pays for data, roaming, accessories, repairs, or replacement)
  • Reputational harm (for example, staff posting workplace content that undermines your brand or breaches confidentiality)
  • Employment issues (inconsistent discipline because expectations weren’t clearly set)

For most small businesses, the real value is clarity: when everyone understands the rules, you reduce misunderstandings and you’re in a much stronger position if you need to investigate a complaint or manage performance.

Do You Need A Work Mobile Phone Policy In Your Business?

You don’t need to be a “tech company” to need a phone policy. If any of the following apply, it’s worth putting one in place:

  • you issue company phones to staff (even to just one manager)
  • your staff use their own phones for work (BYOD - “bring your own device”)
  • staff take photos/videos for work (job sites, products, events, customers, vehicles)
  • staff access customer records, addresses, or booking systems on a phone
  • staff use messaging apps to communicate with customers or staff groups
  • staff travel for work (especially if roaming charges can arise)

In practice, your policy often sits alongside your wider Workplace Policy and should line up with what you say in employment agreements and onboarding documents.

One common mistake we see is businesses relying on “common sense”. The problem is that common sense isn’t consistent - and it’s hard to enforce a rule that was never written down.

What Devices And Situations Should Your Policy Cover?

Before you draft the “rules”, it helps to be clear about scope. Your work mobile phone policy should clearly state what it applies to, because the rules can be very different depending on whether the device is owned by the business or the employee.

Company-Owned Phones

If you provide a phone, you generally have more control over what’s installed, how it’s used, and what happens when someone leaves. But you still need to manage privacy carefully - especially if staff can reasonably expect some personal use.

Your policy should spell out things like:

  • who the phone is issued to and whether it can be shared
  • who owns the phone number (and what happens to it when the employee leaves)
  • what “reasonable personal use” means (if any is allowed)
  • what happens if the device is lost, damaged, or stolen

BYOD (Bring Your Own Device)

BYOD is common in small businesses because it’s cheaper and easier - but it creates extra risk if business data sits on a personal phone you don’t control.

If you allow BYOD, your policy should be very explicit about:

  • what work apps must be installed (and which ones are not allowed)
  • how business data must be stored (for example, in approved apps rather than in personal notes)
  • whether you can require security settings (PIN, biometrics, auto-lock)
  • your right to require remote wipe of work data in certain circumstances
  • how you’ll handle privacy and access (because it’s still the employee’s personal device)

To avoid confusion, it’s also smart to align your phone policy with the employee’s overall obligations in their Employment Contract, especially around confidentiality and return of company property/information.

What To Include In A Work Mobile Phone Policy (A Practical Checklist)

This is the core of your policy. A good approach is to keep the document readable, but still detailed enough that you can rely on it when you need to.

1. Acceptable Use (Work vs Personal)

Start with the basics: what is the phone for, and what use is allowed?

Your policy might cover:

  • work use requirements (for example, being contactable during rostered hours, checking job updates, using the phone for client calls)
  • reasonable personal use (if permitted) and what crosses the line
  • prohibited use (for example, illegal content, harassment, excessive streaming, or anything that could damage your business reputation)
  • use while working (for example, no personal use while serving customers, operating machinery, or driving)

Many businesses include phone rules within a broader Acceptable Use Policy, particularly if you also want to cover laptops, tablets, email, and internet use in one place.

2. Costs, Allowances, And Reimbursements

Phone disputes often come down to money. Your policy should clearly state:

  • who pays for the monthly plan (and what level of plan you provide)
  • who pays for add-ons (hotspot data, international calls, roaming)
  • whether staff can claim reimbursements (and the process for doing so)
  • whether the business pays for accessories (cases, chargers, power banks)
  • what happens if a phone is lost or damaged (including whether the employee may be asked to contribute in limited circumstances, and noting that any deductions from wages generally require the employee’s written consent and must comply with employment law)

If you don’t want surprises, state upfront that employees must get approval before incurring certain charges (like roaming or premium services).

3. Apps, Accounts, And Communication Channels

This section is key because work often happens across apps, not just calls. You should set clear rules on:

  • which apps are approved for work communication (and which are not)
  • when staff can use personal messaging apps for customers (many businesses ban this to avoid data and ownership issues)
  • how staff should set up accounts (for example, using a work email address rather than a personal one)
  • who “owns” contact lists, chat histories, and customer relationships (particularly relevant for sales and service businesses)

If you use AI tools for drafting messages, writing posts, or summarising calls, it’s also worth setting boundaries via a Generative AI Use Policy, especially if confidential information could be entered into third-party tools.

4. Photos, Videos, And Recording

Phones make it easy to take photos of jobs, customers, or workplace incidents - which is useful, but risky if it’s not controlled.

Your policy should cover:

  • when staff are allowed to take photos/videos for work
  • where images must be stored (for example, in a secure work system rather than personal camera roll)
  • rules about photographing customers, children, or private property
  • rules about recording calls or meetings (including that recording can raise privacy and employment issues, and staff must follow the law and any workplace direction - for example, you may require notification/consent in some situations, especially before sharing or using a recording)
  • prohibitions on sharing workplace images on personal social media without permission

This isn’t just about professionalism - it can overlap with privacy and confidentiality obligations, and you want staff to be very clear on what’s allowed.

5. Confidentiality And Protecting Business Information

Phones can carry a lot of sensitive information: customer lists, supplier pricing, staff contact details, internal messages, and documents.

Your policy should explain that staff must protect business information and include practical rules like:

  • no forwarding work emails/documents to personal accounts unless approved
  • no storing customer information in personal notes, screenshots, or unapproved apps
  • no sharing passwords or unlocking devices for other people
  • no downloading unauthorised software

This should match your business’s confidentiality expectations generally (and any confidentiality terms you include in employment documentation).

6. Offboarding: What Happens When Someone Leaves?

When an employee resigns or is terminated, phone-related issues can get messy quickly - especially with BYOD.

Spell out:

  • when a company phone must be returned (and in what condition)
  • how you’ll remove business accounts, SIMs, and data
  • whether numbers or accounts will be transferred back to the business
  • how you’ll handle remote wipe where necessary (and how you’ll protect the employee’s personal content if BYOD applies)

If you want to avoid disputes later, this is one of the most important parts to get right upfront.

How Do You Handle Privacy, Monitoring, And Employee Expectations?

This is where a lot of businesses feel unsure - because you want to protect your business, but you also don’t want to overstep.

In New Zealand, how you handle phone monitoring and access should be consistent with the Privacy Act 2020 and general good practice. The big idea is: if you collect, use, or access personal information, you should have a clear reason, and you should be transparent about it.

Some practical steps you can take in your work mobile phone policy include:

  • be upfront about monitoring (for example, whether you may be able to access call logs, location services, device activity, or work app usage on company-managed systems)
  • limit monitoring to what’s necessary for your business (avoid “just in case” monitoring)
  • explain when access may happen (for example, investigating misconduct, responding to a data breach, or recovering business information, and usually only where you have a lawful basis and have informed staff)
  • set expectations around privacy (for example, personal use may be permitted on a company phone, but staff should not assume it is private if the device or apps are managed by the business)

If you also use tools like GPS tracking, device management software (MDM), or other monitoring, it’s often helpful to document this clearly in your workplace policies and onboarding materials so employees understand what information is collected and why.

You should also think about your external privacy obligations. If staff use phones to collect customer details (names, phone numbers, addresses, photos), your business may need a Privacy Policy that explains what you collect and how you handle it.

One helpful way to frame it in your policy is: “We respect privacy - but we also need to protect our customers, our staff, and our business.” Then you spell out what that means in practice.

Cyber Security And Data Protection: The Non-Negotiables

Even a tiny business can be hit hard by a phone-based security incident. A stolen phone with saved passwords, or a staff member clicking a phishing link, can lead to financial loss and a privacy breach.

Your work mobile phone policy should set minimum security standards, such as:

  • passcode requirements (PIN, biometrics, auto-lock timing)
  • device encryption where available
  • software updates (staff must install updates promptly)
  • approved apps only and restrictions on app downloads
  • safe Wi-Fi rules (avoid public Wi-Fi unless using a secure connection)
  • what to do if the phone is lost or stolen (immediate reporting, remote wipe, password resets)

To keep your approach consistent across the business, it’s common to align your phone policy with an Information Security Policy, especially if you deal with sensitive customer data or run an online system.

It’s also worth planning ahead for “what if something goes wrong?”. A Data Breach Response Plan can help you act quickly if a device is compromised and personal information is affected.

Finally, don’t forget health and safety. Under the Health and Safety at Work Act 2015, you must take reasonably practicable steps to keep people safe at work. Your phone policy can support this by making rules around phone use while driving, operating equipment, or working in hazardous areas.

Key Takeaways

  • A clear work mobile phone policy helps you set expectations, protect business information, and manage employment issues consistently.
  • Your policy should clearly state whether it covers company-owned phones, BYOD, or both - because the privacy and control settings are different.
  • Include practical rules on acceptable use, costs and reimbursements, approved apps, photos/recording, confidentiality, and offboarding when someone leaves.
  • Privacy and monitoring should be handled carefully and transparently, in a way that aligns with the Privacy Act 2020 and your internal employment documents.
  • Minimum security standards (passwords, updates, safe Wi-Fi, reporting lost devices) reduce your risk of cyber incidents and privacy breaches.
  • If you want the policy to actually work day-to-day, roll it out properly: give it to staff, explain it, and apply it consistently.

Note: This article is general information only and doesn’t take into account your specific circumstances. It isn’t legal advice.

If you’d like help putting a work mobile phone policy in place (or reviewing what you already have so it matches your business and your legal obligations), you can reach us at 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get employment right

When should you get employment help?

Employment topics can become risky quickly when documentation, consultation, termination or contractor status is involved.

Alex Solo

Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get employment right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.