Work Phones vs BYOD: Privacy Act 2020 Risks in NZ and BYOD Policies

Alex Solo
byAlex Solo11 min read

If you’re running a small business, it’s completely normal to want the simplest (and cheapest) setup for your team’s tech.

Sometimes that means company-issued work phones. Other times it means letting staff use their own devices for work - the classic bring-your-own-device (BYOD) approach.

The catch? The moment personal phones start storing or accessing customer details, employee information, or confidential business data, you’re in Privacy Act territory (in New Zealand, that’s the Privacy Act 2020). And if you don’t have a clear BYOD policy in place, even a minor issue (like a lost phone) can turn into a privacy incident that’s stressful, time-consuming, and potentially costly.

Below, we break down the key Privacy Act 2020 risks for NZ employers when comparing work phones vs BYOD, and what you can do to set your business up properly from day one.

Why Work Phones And BYOD Create Different Privacy Risks

From a practical perspective, the difference between work phones and BYOD is simple:

  • Work phone: you own the device, you manage it, and you can usually control what happens to business data on it.
  • BYOD: the employee owns the device, and your business data is sharing space with their personal photos, messages, apps, and accounts.

That overlap is where privacy and employment risks tend to show up.

Work Phones: More Control, But Still Not “Risk-Free”

With company-issued phones, you generally have a stronger ability to:

  • apply security settings (PINs, encryption, remote lock/wipe)
  • control which apps can be installed
  • manage company accounts and passwords
  • retrieve business records if needed (for example, if there’s a complaint or dispute)

However, employers can still get into trouble if they access staff communications or data in a way that’s not fair, not necessary, or not clearly explained upfront. Even on a work device, employees may still have privacy expectations depending on how the device is used in practice.

BYOD: Convenience Comes With More “Grey Areas”

BYOD can be great for small businesses because you may not need to purchase devices for every team member. But you’re taking on harder questions, like:

  • Where does “work data” end and “personal data” begin?
  • What happens if an employee refuses to hand over their phone when you need access to business records?
  • Can you remotely wipe a phone if it’s lost - and what if that deletes personal content?
  • How do you manage staff leaving (or being dismissed) when key client conversations are on their personal phone?

This is exactly why having a clear BYOD policy (and a wider set of workplace privacy rules) matters. It’s not about being heavy-handed - it’s about setting expectations so everyone knows where they stand.

What The Privacy Act 2020 Means For Employers Managing Devices

If your staff use phones (work-issued or personal) to collect, store, or access personal information, your business needs to comply with the Privacy Act 2020.

In plain English, the Privacy Act is about using personal information responsibly - including how you collect it, secure it, use it, disclose it, and dispose of it (through the Information Privacy Principles, or IPPs).

When we’re talking about phones and BYOD, these are some of the most relevant privacy issues for employers.

Personal Information Can Be Everywhere On A Phone

On a typical workday, a phone might contain personal information such as:

  • customer names, phone numbers, email addresses, and delivery addresses
  • client notes (including sensitive details, depending on your industry)
  • employee information (like rosters, sick leave messages, performance notes)
  • photos, audio, or CCTV snippets shared via workplace chat
  • message histories in email, WhatsApp-style tools, or social media DMs used for business

If your business is in an industry that handles health details, finances, or other “high sensitivity” information, the expectations on security and access controls are even higher.

You Need A Clear, Lawful Purpose For Collecting And Accessing Data

A common small business trap is thinking: “If it’s on a phone used for work, we can look at it if we need to.”

In reality, you should be able to justify (and communicate) key basics such as:

  • why you’re collecting that information (IPP1 - purpose of collection)
  • how it will be used (IPP10 - limits on use)
  • who might access it or receive it (IPP11 - limits on disclosure)
  • how long you’ll keep it (IPP9 - retention of personal information)

That’s why it’s worth aligning your device approach with your broader privacy documentation, like a Privacy Policy and internal protocols around employee data.

You Must Take Reasonable Steps To Keep Information Safe

The Privacy Act expects you to protect personal information with reasonable security safeguards (IPP5 - storage and security of personal information).

In a device context, “reasonable steps” often includes things like:

  • passcodes and screen locks
  • multi-factor authentication (especially for email and cloud tools)
  • ability to remotely lock or wipe work data
  • keeping operating systems updated
  • rules against storing business info in personal notes apps or personal email accounts

If you allow BYOD but don’t set any minimum security standards, it’s much harder to argue you took reasonable steps if something goes wrong.

Notifiable Privacy Breaches Are A Real Risk For Small Businesses

Under the Privacy Act 2020, some privacy breaches must be notified to the Privacy Commissioner and to affected individuals. Whether a breach is “notifiable” depends on the risk of serious harm.

Lost phones, stolen phones, or compromised accounts can absolutely lead to notifiable breaches - especially if the device wasn’t protected properly.

Having a practical Data Breach Response Plan makes it much easier to respond quickly and consistently when something happens (because, realistically, something eventually will).

What Should A BYOD Policy Include? (A Small Business Checklist)

If you’re letting staff use personal phones for work, a BYOD policy is one of the cleanest ways to reduce confusion and manage Privacy Act risk.

Think of it as your “rules of the road” for business data on personal devices.

While your exact policy should be tailored to your business, here are the key topics most NZ employers should cover.

1) Scope: Who Can Use BYOD And For What?

  • Which roles are permitted to use BYOD (or whether it’s optional vs required)
  • What tasks can be done on personal devices (email, calls, messaging, CRM access, photos, etc.)
  • What information must not be stored on personal devices (for example, sensitive customer documents)

2) Minimum Security Requirements

  • mandatory PIN/passcode and auto-lock settings
  • no sharing devices with family members while work accounts are logged in
  • rules about jailbroken/rooted devices
  • requirements to keep OS updates installed
  • where possible, use of mobile device management (MDM) or container-based work apps

It’s also common to pair your BYOD policy with an Acceptable Use Policy so you’re not trying to cram every tech rule into one document.

3) Separation Of Work And Personal Data

This is where BYOD policies often succeed or fail.

Your goal should be to reduce the chance that:

  • work files are saved into personal cloud backups
  • customer conversations are happening in personal social media accounts
  • employees can’t hand over business records without handing over their entire private phone

Practical solutions can include requiring staff to:

  • use company-managed email and calendar only
  • use approved messaging channels for customers
  • store documents in company cloud storage (not local device storage)

4) Ownership Of Business Information And Business Records

This is a big one for small businesses.

Your BYOD policy should be clear that:

  • business contacts, customer communications, and work product created in the course of employment are business records
  • employees must cooperate with requests to provide business records when reasonably required (for example, for customer complaints, legal disputes, or audits)
  • your business may require certain business information to be transferred back to the business on exit

This should be consistent with your Employment Contract and any confidentiality clauses you use.

A BYOD policy works best when it’s not just “posted somewhere”. You want employees to actively acknowledge it.

That acknowledgement is helpful because it shows the rules were clearly communicated - particularly if there’s later a dispute about access, monitoring, or wiping of work data.

In practice, this often sits alongside wider HR documentation like a Workplace Policy and an employee privacy/internal monitoring policy, so your expectations are consistent across the business.

Monitoring, Accessing And Wiping Devices: Doing It Lawfully

For many employers, the most uncomfortable BYOD question is: “If it’s their phone, can we access it?”

There’s no one-size-fits-all answer. But there are some consistent principles that will keep you on safer ground.

Start With The Least Intrusive Option

As a general risk-management approach, you want to avoid policies that require broad access to an employee’s entire device unless you genuinely need it.

Instead, structure systems so you can access business information without touching personal content, such as:

  • keeping customer records in your CRM, not in private messages
  • using company email accounts where messages can be accessed through admin tools
  • requiring customer communications to happen through approved channels

This is not just about privacy - it also protects your business continuity if someone is away sick, resigns suddenly, or is dismissed.

Be Clear About When Access Might Be Required

Your BYOD policy should spell out the situations where you may request access to business information on the device. For example:

  • responding to a customer complaint or dispute
  • meeting legal obligations (for example, responding to an access request)
  • investigating suspected misconduct (handled carefully and fairly)
  • recovering business data when an employee leaves

Importantly, even if your policy allows it, how you actually carry out access matters. In employment situations, process and fairness are critical.

Remote Wipe: Set Expectations Early

Remote wipe is one of the biggest BYOD flashpoints.

If you’re using tools that can wipe work data (or the entire phone), your policy should make it very clear:

  • what can be wiped (work container vs whole device)
  • when wiping may happen (lost phone, termination, security incident)
  • whether the employee must back up personal data themselves
  • who authorises a wipe internally (so it’s not done casually)

From a Privacy Act perspective, wiping can be sensible as a security measure - but you want to minimise the risk of deleting personal content unnecessarily, and you want the employee to understand the process upfront.

Avoid “Secret Monitoring” Approaches

It can be tempting to install monitoring tools without much discussion, especially when you’re worried about productivity or leaks.

But from a legal and relationship standpoint, it’s usually better to be transparent about:

  • what you monitor (for example, access logs vs message content)
  • why you monitor it (security, compliance, customer service quality)
  • how monitoring information is used and stored

If your business is relying on monitoring, make sure your approach is consistent with your overall employee privacy practices and your internal policies.

Managing The BYOD Lifecycle: Onboarding, Offboarding, And Privacy Breaches

A BYOD arrangement isn’t a “set and forget” decision. Most problems happen at predictable moments - when someone starts, when something goes wrong, and when someone leaves.

If you plan for those moments, you’ll avoid a lot of headaches.

Onboarding: Make Setup Part Of Day One

When a team member starts and you’re allowing BYOD, your onboarding should cover:

  • getting them to sign/acknowledge the BYOD policy
  • setting up company accounts properly (MFA, password manager if used, device lock)
  • confirming which apps/tools are approved for customer communications
  • explaining what happens if the phone is lost or stolen

This is also where your employment documents should align - for example, your Employment Contract might cover confidentiality and return of company property/information, while your BYOD policy sets the practical “how”.

Offboarding: Don’t Leave Business Data “Floating” On Personal Phones

Imagine this: a staff member resigns and you realise the last six months of client conversations are in their personal SMS and social DMs. That’s not just awkward - it’s a genuine operational and privacy risk.

Your offboarding process should include a checklist for BYOD users, such as:

  • removing company email/accounts from the device
  • transferring business contacts back to the business system
  • ensuring work files/photos are uploaded to company storage and deleted locally if required
  • confirming any work chat channels are deactivated
  • documenting that the steps have been completed

This helps you protect customer information, protect your confidential business info, and reduce the chance of disputes later.

If A Phone Is Lost Or Stolen: Treat It As A Privacy Incident Immediately

If a BYOD phone (or a work phone) goes missing, time matters. Your team should know exactly what to do without needing to improvise.

A solid process usually includes:

  • immediate reporting to a manager
  • remote lock or wipe of work accounts/data (where available)
  • password resets for key systems
  • internal assessment of what information may have been exposed
  • consideration of whether notification is required under the Privacy Act 2020

This is where having a Data Breach Response Plan can make the difference between a controlled response and a scramble.

Work Phones Still Need Clear Rules (Yes, Even If You Own The Device)

If you’re leaning towards company-issued phones to avoid BYOD complexity, that’s often a great move - but you still want clear internal rules on things like:

  • permitted personal use (if any)
  • what monitoring may occur
  • how long you keep messages and call records
  • how you handle privacy complaints

That’s why many employers keep a consistent approach across all devices, supported by broader workplace policies and clear internal privacy practices.

Key Takeaways

  • A strong BYOD policy helps you manage Privacy Act 2020 risk by setting clear expectations about security, access, and separation of work/personal data.
  • Work phones generally give you more control, but you still need to be careful about employee privacy expectations and how you access or monitor information.
  • Under the Privacy Act 2020, you need to take reasonable steps to protect personal information (IPP5) - and phones are a common weak point if security standards aren’t set.
  • BYOD arrangements often break down at predictable moments (onboarding, offboarding, lost devices), so having a documented process is just as important as having the policy itself.
  • Remote wipe, monitoring, and access requests should be addressed upfront in your BYOD policy, and handled in a way that’s fair, necessary, and not overly intrusive.
  • Policies and contracts should work together - your device rules should align with your Employment Contract, Workplace Policy, and privacy documentation such as a Privacy Policy.

If you’d like help putting a BYOD policy in place (or reviewing your current approach to employee privacy and device use), reach out to our team at 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo

Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.