Sometimes—but it should be a deliberate business decision, not something that happens by default.
Personal devices can be convenient. Employees already know how to use them, they may prefer carrying one phone, and occasional access from a personal device can help people work flexibly.
The difficulty begins when convenience quietly becomes the business’s normal operating model without clear boundaries around support, access, privacy and responsibility.
Not all personal-device use is the same
There is a significant difference between checking a calendar on a personal phone and using a personal laptop every day to access client records, business applications and shared files.
The right approach depends on:
- What information the person can access.
- How regularly the device is used for work.
- Whether the business can apply appropriate controls.
- What support the employee expects.
- What happens if the device is lost, replaced or shared.
- How business information will be removed when employment ends.
A simple yes-or-no policy rarely reflects those differences.
Company devices create a clearer baseline
A company-provided device gives the business more control over how it is configured, protected and supported.
Applications can be installed consistently. Updates and encryption can be managed. Access decisions can take account of whether the device meets the organisation’s requirements. When the device reaches the end of its life—or the employee leaves—it can be recovered, reset and reassigned.
There is also a clearer division between personal and business use.
That does not mean every employee needs every type of device supplied by the company. It means the equipment used for regular, important work should match the level of responsibility placed upon it.
Personal devices need clear boundaries
Where personal devices are allowed, employees should understand what the business can and cannot see, which applications may be used, where information should be stored and what support is available.
The business should also be realistic. It may be reasonable to protect company information inside managed applications on a personal phone. It is much harder to guarantee the condition, availability and supportability of an entirely personal laptop used as someone’s primary workstation.
A policy that cannot be applied consistently is unlikely to provide much protection.
The question is broader than ownership
A company-owned device can still be poorly managed. A personal device can sometimes be used responsibly within carefully controlled limits.
The better question is:
Can the business protect its information, support the employee and remove access cleanly without taking inappropriate control of someone’s personal device?
For some roles, company equipment will provide the clearest and most dependable answer. For limited or occasional access, a managed personal-device arrangement may be entirely reasonable.
The important thing is to decide where the boundary sits before a lost phone, failed laptop or departing employee forces the business to make that decision under pressure.

