Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

Bring Your Own Device (BYOD) for Research Data Collection

In research data collection, BYOD (bring your own device) is a practice in which participants or researchers use their own personally-owned smartphone, tablet, or wearable -- rather than a device supplied, configured, and owned by the study -- to run a data-collection app or sensor. What makes an instance BYOD is device ownership and control: the hardware belongs to the participant or researcher, not the study team, so the study cannot fully standardize, lock down, or reclaim it, and must build its data-integrity and security controls around that constraint.

ByCASRAI Editorial Board
· Last updated 18 Jul 2026

Examples

Worked examples

  • Is an instance

    An ecological momentary assessment (EMA) study asks participants to download a survey app onto their own smartphone and answer brief prompts several times a day for two weeks, rather than issuing a study-owned device.

  • Is an instance

    A remote monitoring study asks participants to sync data from a consumer smartwatch or fitness tracker they already own (step count, heart rate, sleep) to a study server via a research SDK or export tool, instead of distributing a study-specific wearable to every participant.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A trial that ships each enrolled participant a locked-down, study-configured tablet preloaded with the electronic patient-reported outcome (ePRO) app, to be returned at study close-out, is a provisioned-device model, not BYOD -- even though data collection is equally remote and app-based, the device itself remains the sponsor's or study's property and is centrally managed.

Editorial commentary

Bring your own device (BYOD) data collection means a study relies on hardware the participant or researcher already owns and controls — a personal smartphone, tablet, or consumer wearable — rather than a device the study purchases, configures, and later reclaims. It is now common in ecological momentary assessment (EMA/ESM), passive sensor and activity monitoring, and electronic patient-reported outcome (ePRO) collection, because it avoids the cost and logistics of provisioning a fleet of study devices and lets data collection happen inside the participant’s normal routine.

Why studies choose BYOD

  • Recruitment and retention: participants install an app rather than learn an unfamiliar study-issued device, lowering the burden of enrolling and staying enrolled.
  • Ecological validity: data captured on a device the participant carries habitually (their own phone, their own watch) can better reflect real-world behavior than data captured on a device used only because the study requires it.
  • Cost and logistics: no device purchasing, shipping, provisioning, or end-of-study retrieval.

Governance and data-integrity challenges

These advantages come with distinct risks that a study-provisioned device largely avoids or centrally controls:

  • Device and sensor heterogeneity: participants’ phones and wearables span different manufacturers, operating-system versions, and sensor hardware, so a step count, heart-rate reading, or GPS trace is not necessarily comparable across participants the way it would be from identical, centrally calibrated study hardware. Studies using BYOD sensor data typically need to document device make/model/OS as a covariate and validate sensor accuracy rather than assume it.
  • Data security: a personal device is not under the study’s mobile-device-management control — it may be shared with family members, run outdated software, lack encryption, or already host other apps with broad permissions. Because the study cannot lock the device down the way it could a provisioned one, security controls have to live in the study app itself (encryption in transit and at rest, authentication, minimal local data retention) rather than in device configuration.
  • Data provenance and chain of custody: without a controlled device, a study needs its own audit trail showing which participant, which device, and which app version produced a given data point, since it cannot rely on device-level attestation the way a fully managed device allows. See data provenance.
  • Informed consent scope: participants need to understand what is being collected from their own device — which sensors or data streams the app accesses, whether collection is continuous/passive or only active during prompted tasks, how study data is kept separate from the participant’s personal data and other apps, and how to fully remove the app and any collected data if they withdraw. This is an extension of ordinary informed-consent practice (see informed consent and the fuller informed consent in research guide), not a separate consent framework.
  • Equity and selection bias: requiring participants to already own a suitable smartphone or wearable can systematically exclude people who don’t — older adults, lower-income participants, and other groups with lower device ownership or older/incompatible hardware. FDA’s guidance on remote data acquisition explicitly cautions against excluding otherwise-eligible participants solely because they lack a compatible personal device, which is why many BYOD designs pair it with a fallback of study-provisioned “loaner” devices for participants without one.

Regulatory and standards context

FDA’s final guidance, Digital Health Technologies for Remote Data Acquisition in Clinical Investigations (issued December 2023), addresses BYOD directly for FDA-regulated clinical investigations: it lays out the tradeoffs of a BYOD approach relative to sponsor-provisioned devices and reiterates that participants without access to a qualifying personal device should not be excluded from the trial. For clinical investigations under FDA oversight, a BYOD data-collection design should be documented and justified as part of the protocol’s digital health technology selection and validation plan, alongside the usual data-management-plan considerations that apply to any remote or electronic data capture (see electronic data capture (EDC) and data management plan (DMP)).

Outside the clinical-trial context, NIST’s practice guide SP 1800-22, Mobile Device Security: Bring Your Own Device (BYOD) is the standard general-purpose reference for securing personally-owned mobile devices used to access an organization’s systems and data, and its architecture (containerization, mobile application management, minimal-permission app design) is a reasonable model for research IT teams building a study-specific BYOD app rather than relying on full device management.

Where the personal device is used to transmit protected health information, ordinary HIPAA obligations for the covered entity/business associate still apply regardless of who owns the hardware — see HIPAA in clinical research.

References

  • FDA, Digital Health Technologies for Remote Data Acquisition in Clinical Investigations: Guidance for Industry, Investigators, and Other Stakeholders (final guidance, December 2023).
  • NIST Special Publication 1800-22, Mobile Device Security: Bring Your Own Device (BYOD), National Cybersecurity Center of Excellence (final, 2023).

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Bring Your Own Device (BYOD) for Research Data Collection"
      vocab-term-identifier="https://casrai.org/dictionary/term/byod-research-data-collection" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/byod-research-data-collection",
  "name": "Bring Your Own Device (BYOD) for Research Data Collection",
  "identifier": "https://casrai.org/dictionary/term/byod-research-data-collection",
  "description": "In research data collection, BYOD (bring your own device) is a practice in which participants or researchers use their own personally-owned smartphone, tablet, or wearable -- rather than a device supplied, configured, and owned by the study -- to run a data-collection app or sensor. What makes an instance BYOD is device ownership and control: the hardware belongs to the participant or researcher, not the study team, so the study cannot fully standardize, lock down, or reclaim it, and must build its data-integrity and security controls around that constraint.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/byod-research-data-collection",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-18T06:30:49",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →