1. What a mobile phone policy is actually doing for your business
  2. What the policy should cover
    1. Who and what the policy applies to
    2. Personal use during work hours
    3. Company-issued devices
    4. Confidentiality and data security
    5. Health and safety rules
    6. Recording, photography and calls
    7. Driving for work
    8. Exceptions and accessibility
    9. Consequences
  3. The legal obligations your policy needs to address
    1. Fair Work
    2. Work health and safety
    3. Privacy Act 1988 (Cth)
    4. Workplace surveillance
    5. BYOD and containerisation
  4. Rolling out the policy: what makes the difference
  5. Where Artificer Legal can help
  6. The rule that determines whether your policy works

Most Australian workplaces have no shortage of mobile devices. Employees use them to communicate, access systems, manage schedules and stay connected — but phones also introduce risks that written policies are far better at managing than unspoken expectations. When a safety incident happens, a client complains about a recording, or a disciplinary action ends up before the Fair Work Commission, the question that surfaces first is almost always: did you have a clear, communicated policy, and did you apply it?

What a mobile phone policy is actually doing for your business

A mobile phone policy is not just a list of restrictions. It sets the operating boundaries for personal and company-issued devices during work hours, on work premises and when employees are representing the business — and it does several things that unwritten rules cannot.

A clear policy reduces ambiguity. Employees know what is and is not acceptable without having to guess, which means fewer misunderstandings and fewer situations where a manager has to improvise a response to conduct that should have been addressed in writing. Written rules are also easier to apply consistently, which matters significantly when you need to take disciplinary action. Inconsistent enforcement is one of the most common reasons disciplinary outcomes are challenged.

Policies also help with legal compliance. Depending on your industry and the work your people do, mobile phone use can implicate your obligations under work health and safety law, the Privacy Act 1988 (Cth), state workplace surveillance legislation, and road rules. A policy that addresses these areas in plain language signals that you have thought about the risks and taken reasonable steps — which is precisely the standard Australian law asks of employers.

What the policy should cover

The scope of a mobile phone policy will vary by business type, but most workplaces benefit from addressing the following areas.

Who and what the policy applies to

Be explicit about coverage. The policy should state which people are bound — employees, contractors, labour hire workers, volunteers — and which devices are covered. That typically includes personal smartphones, company-issued mobiles, tablets and wearable devices. If you have a bring-your-own-device (BYOD) arrangement, it should appear in the scope.

Personal use during work hours

Rather than a blanket ban that proves difficult to enforce, most businesses do well with a proportionate approach: personal use is permitted during breaks, away from customer-facing areas, with phones on silent during meetings and client interactions. The key is being specific about the contexts where restrictions apply — a general statement that phones should be used "reasonably" is not a policy.

Company-issued devices

Devices owned by the business come with additional considerations. The policy should address which apps are approved, data limits, security settings (passcodes, auto-lock, encryption), and what happens to the device and any stored data when the employee leaves. If you intend to monitor usage on company devices — call logs, data usage or mobile device management software — this must be communicated clearly and comply with applicable surveillance laws (see below).

Confidentiality and data security

Employees should understand that photographing, screenshotting or forwarding confidential materials — client files, pricing, internal reports — without authorisation can constitute a breach of their employment obligations and potentially privacy law. The policy should set minimum security standards for any device used for work purposes: PIN or biometric access, prompt reporting of lost or stolen devices, and restrictions on storing work data on unsecured personal cloud services.

Health and safety rules

Device restrictions in safety-critical settings are not about productivity — they are about the legal duty to provide a safe workplace. A clear prohibition on phone use while operating machinery, preparing food or performing other safety-critical tasks is a proportionate and reasonable workplace rule. Dedicated break areas where employees can check their phones are a practical complement to these restrictions.

Recording, photography and calls

The rules on recording conversations vary between Australian states and territories — some require all parties to consent; others permit one-party consent in certain circumstances. Your policy should require employees to seek permission before recording calls or meetings and clarify what photography is permissible on client sites or in sensitive areas. This is an area where getting the detail right matters, because breaches can expose both the employee and the business to legal consequences.

Driving for work

Every state and territory in Australia prohibits drivers from holding a mobile phone at any time while driving. The Australian Road Rules, adopted by each jurisdiction, contain these prohibitions, and state-specific traffic legislation also applies. The rules on hands-free use differ between jurisdictions and are typically stricter for learner and provisional licence holders. Your policy should require employees to comply with the road rules of whatever state they are driving in and to pull over safely before using any device.

Exceptions and accessibility

A workable policy acknowledges that emergencies happen and that some employees may have medical or disability-related reasons for needing access to a device. Building a short, sensible exceptions clause into the policy — rather than treating every situation as a disciplinary matter — reduces friction and reflects the good-faith approach that employment law expects.

Consequences

Spell out the range of responses to a breach: from a coaching conversation for a first minor slip-up to formal disciplinary action for repeated or serious conduct. Cross-reference your employment contracts and any applicable enterprise agreement or award so the consequences are consistent with your existing framework.

Fair Work

There is no standalone Fair Work instrument that prescribes the content of a mobile phone policy. What the Fair Work system does require is that workplace policies are reasonable, clearly communicated and applied consistently. When a dismissal or disciplinary outcome is challenged before the Fair Work Commission, decision-makers consider whether the policy was proportionate to the risk, whether the employee was made aware of it, and whether it was applied the same way across the team. A policy that employees have never seen, or one that is enforced selectively, is much harder to defend.

Your policy should also be consistent with any applicable modern award or enterprise agreement. Some instruments include provisions about workplace conduct or consultation that may affect how you implement changes to an existing policy.

Work health and safety

Under s 19 of the Work Health and Safety Act 2011 (Cth) — and the equivalent provisions in most state and territory WHS legislation — a person conducting a business or undertaking (PCBU) must ensure, so far as is reasonably practicable, the health and safety of workers. Mobile phone restrictions in high-risk environments are a direct expression of this duty. Signage, training and a written policy collectively demonstrate that you have taken reasonable steps to address a foreseeable risk. The WHS framework applies to physical and psychological health, so distractions that create a risk of harm — particularly in manual or safety-critical work — fall within its scope.

Privacy Act 1988 (Cth)

The Privacy Act 1988 (Cth) applies to organisations that are "APP entities" — which generally means businesses with an annual turnover above $3 million. Businesses below this threshold are usually exempt, but important exceptions apply: private sector health service providers are covered regardless of turnover, as are businesses that trade in personal information for a benefit or advantage and certain other categories prescribed by the Act.

If your business is covered, or likely to be covered, you need to ensure that any personal information handled on mobile devices is managed in accordance with the Australian Privacy Principles — including that it is protected from misuse or unauthorised access. A mobile phone policy that addresses data security on devices is part of meeting that obligation. Even if you fall within the small business exemption, setting clear data-handling rules is sound practice that protects both your clients and your business.

Workplace surveillance

Monitoring employee devices — whether through call logs, mobile device management (MDM) software or location tracking — is regulated by state and territory legislation. NSW's Workplace Surveillance Act 2005 is the most detailed of these instruments and requires employers to give employees at least 14 days' notice before surveillance commences. The ACT's Workplace Privacy Act 2011 similarly requires that surveillance be conducted overtly, with appropriate notice to workers. Other jurisdictions have general surveillance devices legislation that applies in this context.

The obligation across all jurisdictions is transparency: employees must be told what is being monitored, why and by whom. Covert monitoring of employee devices — without notice or consent — can constitute an offence under state law. If your business uses or is considering MDM software or similar tools, the policy must explain this clearly, and you should confirm the specific requirements in each state or territory where you have employees.

BYOD and containerisation

BYOD arrangements — where employees use personal devices for work — raise a further layer of complexity. If you intend to monitor BYOD devices or wipe them remotely, you need to be clear about the limits of what you can access. Consider whether a containerised work environment (a separate, managed workspace on the personal device) is appropriate; this limits your access to work data only and reduces the risk of overreach into personal information.

Rolling out the policy: what makes the difference

Writing the policy is the easy part. Effective implementation requires a few additional steps that businesses often overlook.

Communicate it explicitly. Issuing a policy document and assuming employees have read it is not enough. Walk through the policy at induction, explain the reasoning — safety, professionalism, protecting client information — and give employees the opportunity to ask questions.

Get written acknowledgement. A signed or electronic acknowledgement creates a record that the policy was communicated and understood. This is particularly important if the policy is ever relied upon in a disciplinary process.

Apply it consistently. A manager who ignores personal phone use in some cases but acts on it in others creates both legal risk and a perception of unfairness. Consistency is a prerequisite for enforcement credibility.

Review it regularly. Workplace technology changes, legal frameworks evolve and your business grows. A policy that was fit for purpose two years ago may not reflect your current WHS risks, surveillance tools or BYOD arrangements. Annual review — or review after a significant incident or a change in applicable law — keeps the policy current and defensible.

Test your incident response. Ensure you have a clear process for responding to a lost or stolen device: who is notified, whether the device can be remotely wiped, and how potential data breaches are reported. If your business is covered by the Privacy Act, you also need to consider your obligations under the Notifiable Data Breaches scheme.

A mobile phone policy touches several areas of law — employment, privacy, WHS and workplace surveillance — and the detail that matters most is often jurisdiction-specific. An Artificer Legal practitioner can:

  • assess which legislative obligations apply to your business based on its size, industry and the states or territories where you operate;
  • draft a mobile phone policy that is proportionate, legally sound and consistent with your employment contracts, enterprise agreement (if applicable) and existing staff handbook;
  • advise on the notice requirements that apply if you intend to monitor devices or implement MDM software in any jurisdiction where you have employees;
  • review your BYOD approach and identify where your current arrangements may create legal exposure; and
  • assist with the broader policy framework — privacy policy, data breach response plan, information security policy — that your mobile phone policy should connect to.

If you have an existing policy and want it reviewed, or if you are starting from scratch, we can help you build something that will hold up if it is ever tested.

The rule that determines whether your policy works

The most common reason a mobile phone policy fails when it matters — in a Fair Work proceeding, a WHS investigation or a privacy incident — is not that it was badly written. It is that it was not consistently communicated and applied. A policy that lives in a shared drive, unsigned, unreferred to since induction, gives you very little protection. The act of writing the policy is table stakes; the discipline of communicating, documenting and enforcing it consistently is what makes it a genuine risk management tool.

A practical mobile phone policy workplace framework for Australian businesses should identify the specific risks your employees face, set proportionate rules for each context, align with the legal obligations that apply to your industry and size, and be embedded into onboarding and regular team communication. A well-constructed and consistently applied policy protects employees, protects clients and protects the business — and it is far less costly to get right before an incident than to reconstruct after one.