Corporate cell phone policy: what to include
Ten clauses, one page. What a company cell phone policy has to settle before the first argument about a broken handset — and the two clauses most policies forget.

Short answer. A workable policy settles ten things: who gets a phone, who owns it, what counts as acceptable use, what happens when it breaks or is lost, when upgrades happen, what happens at offboarding, how expenses work, the security baseline, what is monitored, and who to contact. One page is enough.
The ten clauses
- Eligibility. Which roles get a company device, which get a stipend, which get neither. Write the rule, not the list of names.
- Ownership. Company-owned, personally-owned or a mix. This determines everything below it.
- Acceptable use. Personal use, tethering, app installs, and driving. Keep it short and enforceable.
- Damage and loss. What the employee reports, to whom, within how long. See the lost-phone procedure.
- Upgrades. On a cycle, on a condition, or on request. Undefined upgrade rules are the single most common source of argument.
- Offboarding. Device return, number handling, and access removal — with a deadline. The onboarding and offboarding checklist covers the mechanics.
- Expenses and reimbursement. If you reimburse personal phones, say how much and how it is substantiated. The IRS treats employer-provided phones with a genuine business purpose as a non-taxable fringe benefit; Notice 2011-72 is the reference, and your accountant is the authority.
- Security baseline. Screen lock, OS updates, remote wipe consent, and what happens on a jailbroken device. NIST SP 800-124 is a sound basis.
- Monitoring and privacy. State plainly what is visible to the company and what is not. Vagueness here damages trust more than any rule.
- Who to contact. One name or one channel. Not "IT", if IT is three people who all say ask someone else.

Which two clauses do most policies forget?
Offboarding deadlines and upgrade rules. Both are silent until they cost you: the first as a line billing for a person who left in March, the second as a running negotiation with whoever asks loudest.
Should the policy cover BYOD?
Only if you genuinely allow it. A policy that describes a BYOD programme you do not run is worse than none, because it implies a control that does not exist. If personal devices touch company email, say so and set the security baseline for them. The FTC's plain-language guidance on protecting a phone and its data is a reasonable floor to point staff at.

Who should own the policy?
Whoever will actually enforce it. A policy owned by nobody is a document; a policy owned by a named person is a process. If that person's real job is something else entirely, that is worth noticing — it is the pattern in phone administrator was never the job.
FAQs
How long should a cell phone policy be?
One page. Anything longer gets skimmed, and a skimmed policy is an unenforceable one.
Should employees sign it?
Yes, at issue of the device, and again when it materially changes. Signature at handover is also the cleanest moment to record the serial number.
Stipend or company-owned device?
Company-owned gives you control, inventory and clean offboarding. Stipends are simpler to administer and harder to secure. Mixed estates need both sections written.
Does MobileDesk write the policy for us?
Your Mobile Success Manager works to the policy you set and keeps the mechanics behind it running — orders, upgrades, offboarding and the inventory that proves it. Get started.


