For the best experience, openVeritaskon desktop.
Legal Updates

Bring Your Own Device (BYOD) Policy for Employees: What Is the Legal Perspective Under Indonesian Law?

8 July 2026
Yumna Nafisah, S.H.
Legal Updates
Kebijakan Bring Your Own Device (BYOD) bagi Karyawan: Bagaimana Perspektif Hukum Indonesia?

Introduction

The implementation of a Bring Your Own Device (BYOD) policy, which allows or requires employees to use their personal devices to perform their work, has become increasingly common in modern workplaces. While such a policy offers benefits in the form of greater operational flexibility and cost efficiency, it also gives rise to various legal implications that companies need to anticipate.

The use of personal devices for work purposes may increase the risk of unauthorized disclosure of confidential company information, trade secrets, and business data due to lost devices, cyberattacks, or unauthorized access. In addition, using the same device for both personal and business purposes may create issues relating to personal data protection, particularly with respect to the separation of corporate data from employees’ personal data, the company’s authority to conduct monitoring activities, and the deletion of company data stored on employees’ devices. From an employment law perspective, the implementation of a BYOD policy also requires clear regulation of the rights and obligations of the parties, including ownership of work product data, information security standards, responsibility for cybersecurity incidents, and reimbursement mechanisms for device usage and communication network costs.

Accordingly, an understanding of the legal aspects of implementing a BYOD policy is essential for companies to safeguard information security, protect corporate assets, mitigate potential disputes, and ensure compliance with the applicable laws and regulations.

Relevant Provisions Under Indonesian Law

Law Number 27 of 2022 on Personal Data Protection (“PDP Law”)

Article 1 point 4:

“A Personal Data Controller is any person, public body, or international organization that individually or jointly determines the purposes of and exercises control over the processing of Personal Data.”

Article 1 point 6:

“A Personal Data Subject is an individual to whom Personal Data is attached.”

In implementing a Bring Your Own Device (BYOD) policy, the company acts as the Personal Data Controller, namely the party that determines the purposes of and exercises control over the processing of personal data, while employees act as Personal Data Subjects, namely individuals whose personal data is processed in the course of the employment relationship.

Although employees are Personal Data Subjects with respect to their own personal data processed by the company, in performing their duties and functions they also act on behalf of the company when processing data. In that capacity, employees access, use, store, modify, or manage company data, which may include personal data belonging to customers, business partners, and other employees.

Legally, the primary responsibility as the Personal Data Controller remains with the company, as it determines the purposes of and controls the processing of personal data. Nevertheless, employees who process personal data on behalf of the company remain obligated to comply with personal data protection requirements, maintain the confidentiality of information, and implement appropriate security measures in accordance with their authority and responsibilities.

Accordingly, companies should establish adequate internal control mechanisms to ensure compliance with personal data protection requirements across all levels of the organization, including by developing a data governance framework, implementing appropriate policies and procedures, clearly allocating roles and responsibilities, establishing data access controls, and conducting ongoing training and supervision.

Article 20 paragraph (1):

“A Personal Data Controller shall have a lawful basis for processing Personal Data.”

Accordingly, for a company to lawfully install security applications, monitor work activities, or access certain areas of employees’ BYOD devices, it must have a valid legal basis for processing personal data, including:

·      Explicit Consent: Valid consent obtained from employees for specific purposes that have been disclosed by the company.

·      Performance of a Contract: Processing necessary to implement the provisions of the employment agreement or a mutually agreed BYOD policy.

·      Legitimate Interest: Processing that appropriately balances the company’s security needs with employees’ privacy rights.

Article 46 paragraph (1):

“In the event of a personal data protection failure, the Personal Data Controller shall provide written notification to the Personal Data Subject and the competent institution no later than 3 x 24 (three times twenty-four) hours.”

If an employee’s BYOD device is lost or compromised, resulting in a personal data protection failure (data exposure), the company must provide written notification within 3 × 24 hours to the employee (as the Personal Data Subject) and the relevant government institution.

Such notification must at least include:

·      the personal data that has been disclosed;

·      when and how the personal data was disclosed; and

·      the measures taken by the Personal Data Controller to address and recover from the personal data disclosure.

Law Number 1 of 2024 on the Second Amendment to Law Number 11 of 2008 on Electronic Information and Transactions (“EIT Law”)

Article 40 paragraph (5):

“Agencies or institutions other than those referred to in paragraph (3) shall create Electronic Documents and electronic backup records in accordance with their data protection requirements.”

One of the legal issues arising from the implementation of a BYOD policy is the coexistence of employees’ personal data and the company’s confidential information on a single device, which may increase the risk of data leakage and hinder effective data protection.

In this regard, Article 40 paragraph (5) requires every institution to maintain Electronic Documents together with electronic backup records appropriate to its data protection needs. Accordingly, a BYOD policy should establish secure corporate data backup mechanisms that are separate from employees’ personal data to ensure data availability, integrity, and security in the event of device loss, system failure, or cybersecurity incidents.

Need deeper analysis?Try Veritask AI Legal Assistant

Law Number 13 of 2003 on Manpower, as amended by Law Number 6 of 2023 on the Stipulation of Government Regulation in Lieu of Law Number 2 of 2022 on Job Creation as Law (“Manpower Law”)

Article 77 paragraph (2) regulates statutory working hour limits (7 hours per day/40 hours per week for a six-day workweek, or 8 hours per day/40 hours per week for a five-day workweek). If the implementation of a BYOD policy causes employees to work beyond these limits, the additional hours must be treated as overtime.

The implementation of a BYOD policy allows employees to access the Company’s systems and applications through personal devices at any time, including outside normal working hours. However, the existence of such access does not automatically entitle employees to overtime pay.

As a matter of principle, entitlement to overtime compensation remains contingent upon work performed outside normal working hours based on the Company’s assignment or approval in accordance with the applicable laws and regulations. Nevertheless, without adequate regulation, a BYOD policy may increase the risk of claims that the Company implicitly expected or was aware of work being performed outside normal working hours, particularly where communications and work completion through personal devices become common practice.

Accordingly, the Company should ensure that the employment agreement and/or internal policies clearly regulate the working arrangements applicable to BYOD implementation, including expressly providing that BYOD merely serves as a means of accessing the Company’s systems and does not constitute a modification of working hours or create an obligation for employees to remain continuously available outside working hours.

Furthermore, the Company should stipulate that work performed outside normal working hours must be based on prior assignment or approval in accordance with the applicable overtime procedures and should clearly define expectations regarding responses to communications outside working hours to avoid ambiguity and potential employment disputes.

Article 88 governs employees’ right to a decent income and the establishment of wage and allowance structures.

In the context of BYOD, companies must ensure that the policy does not impose unreasonable financial burdens on employees or diminish their fundamental employment rights.

Where employees are required to use their personal devices, companies should ideally provide reimbursement or allowances to cover operational costs, such as device depreciation or internet data expenses.

Furthermore, Article 88 paragraph (3) letter h of the Manpower Law is relevant to regulating expenses arising from the use of personal devices for work purposes, including costs relating to devices, internet access, communications, and software.

Companies should clearly regulate reimbursement mechanisms, allowances, or other forms of compensation through employment agreements, company regulations, or collective bargaining agreements. Such arrangements must continue to protect employees’ rights and must not reduce their entitlement to a decent income as guaranteed under Article 88 paragraphs (1) and (2).

Practical Implications

An inadequately structured BYOD policy may expose businesses to significant risks, including:

·      Data Leakage and Asset Control Risks: The use of personal devices increases the risk of unauthorized disclosure of company data and confidential information due to unauthorized access, lost devices, or cyberattacks. Companies also have more limited control over the security and management of personal devices than company-owned devices.

·      Employee Privacy Risks: Using a single device for both personal and business purposes may create issues regarding data segregation and the limits of the company’s monitoring authority, potentially resulting in violations of employees’ privacy rights if monitoring is excessive.

·      Regulatory Compliance Risks: A company’s failure to implement adequate safeguards for personal data processed through employees’ devices may constitute a violation of personal data protection laws and expose the company to legal consequences under the applicable laws and regulations.

·      Employment Dispute Risks: The absence of clear rules governing the use of personal devices may give rise to disputes concerning responsibility for device usage costs, maintenance, repairs, or replacement where devices are damaged while being used for work purposes.

Recommendations

To minimize legal risks and protect data security, companies are advised to implement the following measures:

·      Establish a BYOD Policy or Agreement: Adopt an internal policy or employment agreement addendum clearly regulating the rights and obligations of the parties, including the use of personal devices, restrictions on access to company data, information security standards, allocation of responsibility for damaged or lost devices, and working arrangements, including overtime.

·      Implement a Mobile Device Management (MDM) System: Deploy technological solutions enabling the segregation of company data from employees’ personal data, secure access controls, and remote wiping of company data where devices are lost, stolen, or upon termination of employment.

·      Establish Information Security Standards: Require minimum security measures for devices used for work, including data encryption, strong passwords or multi-factor authentication, and regular updates to operating systems and applications.

·      Establish a Cost Reimbursement Mechanism: Clearly regulate reimbursement procedures, allowances, or other forms of compensation for expenses relating to personal devices, internet access, communications, and other operational costs incurred in performing work.

·      Conduct Policy Awareness and Ensure Transparency: Provide employees with a clear understanding of the BYOD policy, including the scope of monitoring, personal data protection measures, and the limits of the company’s authority to access personal devices for information security and regulatory compliance purposes.

Closing

The implementation of a Bring Your Own Device (BYOD) policy may provide companies with significant benefits, including increased workplace flexibility, greater operational efficiency, and more effective utilization of technology. However, such implementation also gives rise to various legal implications that must be properly managed, particularly those relating to personal data protection, information security, and the fulfillment of employees’ rights.

Accordingly, it is not sufficient for companies merely to permit the use of personal devices. They should also establish a comprehensive BYOD governance framework through the adoption of internal policies, the implementation of robust technical safeguards, and the clear and proportionate allocation of the rights and obligations of all parties involved.

Share to:

Log in to comment

Log in

What isVeritask

Veritask is an integrated AI-powered legal platform that helps with regulatory research, document preparation, and compliance management in one dashboard.

Free Subscription

Free Subscription

Subscribe to receive a free weekly email with the latest legal analysis.

14-Day Free Trial

Full access to all premium features for 14 days.
Faster legal research and analysis with AI.
No commitment, start right away.