A digital nomad policy is the written rule set that says which employees may work from another country, from where, for how long, and who signs it off. Without one, every trip becomes a private deal between a worker and a manager, and your company carries the tax and immigration risk without knowing it.
The demand is not going away. MBO Partners counted 18.5 million American digital nomads in 2025, about 12% of the workforce, and 11.2 million of them were employees rather than freelancers. Most are on a payroll, not on a contractor invoice.
This guide covers what belongs in the policy, the four compliance risks that decide whether a request is approved, and the country rules that changed in 2026.
Key Takeaways
- A written policy turns informal permission into an auditable process that HR, tax and IT can all follow.
- Employee nomads grew 10% in 2025 while independent nomads fell 7%, so the exposure is landing on employers.
- Screen four risks before approval: immigration, tax residency and permanent establishment, payroll and social security, and duty of care including data protection.
- OECD guidance from November 2025 gives a reference point for when a home office abroad can create a taxable presence.
- Europe now records every entry and exit biometrically, so day counts can no longer be estimated loosely.
Why your company needs a policy now
In its 2025 Digital Nomads report, MBO Partners put the US total at 18.5 million people who work remotely while travelling, up 2.2% on 2024 and 153% on 2019. The mix matters for employers: nomads with traditional jobs rose 10% to 11.2 million, while independent workers fell 7% to 7.3 million. The growth is happening inside companies, among people who have a manager, a payslip and a laptop issued by IT.
The hidden nomad problem
The same survey found that 13% of employee nomads work for an employer that does not know they are travelling, and another 18% have manager approval but no company policy behind it. Close to a third are operating in a gap your records cannot see.
That gap is where the cost sits. If a tax authority asks where an employee was working in March, “we are not sure” is an expensive answer. A policy does not stop people travelling. It makes the travel visible early enough to check.
Who should write one first
Small companies use a policy to compete for talent without inventing an answer every time someone asks. Mid-sized firms need it once approvals outgrow one HR manager’s memory. Large employers fold it into an existing mobility framework so short trips and full employee relocations follow one process.
“Write the rules before the requests pile up. Reconstructing a year of untracked travel at audit time costs far more than approving it properly in advance.”
What a digital nomad policy covers
A good policy answers four questions: who may apply, where they may go, for how long, and what they must do before booking anything. Everything else is detail.
Eligibility, locations and day limits
Start by naming the roles that qualify. Fully remote, asynchronous work travels well. Client-facing sales, signing contracts, handling regulated data or being physically present does not.
Then publish a list of approved countries rather than approving the world. A short list keeps your advisers’ workload small and your answers consistent. Set a maximum number of days per country and per year, and say plainly that the limit protects the employee from becoming tax resident somewhere unexpected.
The request and approval workflow
Use one form that captures the destination, exact dates, the role, and the employee’s confirmation that they hold the right visa and insurance. Route it to HR, tax and IT, and give each a deadline. Approvals that sit for three weeks push people into travelling first and asking later. Say in writing that the company gives no personal immigration or tax advice, and that approval can be withdrawn if local rules change.
Equipment, security and working hours
Specify which devices may leave the country, which security settings are mandatory, and what happens if a laptop is lost abroad. Add the working norms that keep the team functional: core overlap hours, response expectations and a minimum connection standard. Teams that already run on asynchronous work or follow the sun scheduling absorb a scattered map far more easily than teams built around live meetings.
The four compliance risks that decide approvals
Every request comes down to the same four checks. Run them in this order, because the first can end the conversation on its own.
Immigration and right to work
A tourist stamp is permission to visit, not permission to work. Some countries tolerate remote work for a foreign employer on a visitor entry, others treat it as unauthorised work, and the penalty falls on the traveller at the border. More than 70 countries now run a formal remote work permit, which is the cleaner route for stays beyond a few weeks. Our guide to digital nomad visas covers the income thresholds and application steps country by country.
Tax residency and permanent establishment
Two risks hide behind this heading. The first is personal: stay long enough and the employee becomes taxable in the host country, often around 183 days, though some countries count faster.
The second is corporate. A permanent establishment, meaning a taxable presence for the company itself, can arise when someone works from a fixed place abroad or habitually concludes contracts there. The OECD updated its Model Tax Convention commentary on 19 November 2025 with a useful reference point: a home office used for less than half of an employee’s total working time over twelve months is generally not treated as a place of business, and even above that share there normally has to be a commercial reason for the arrangement. Convenience, retention and saving office costs are explicitly not commercial reasons.
Treat that as guidance, not a safe harbour. The commentary is not law, several countries filed reservations, and the applicable tax treaty decides the outcome. Where revenue-generating work is involved, take advice country by country.
Payroll, withholding and social security
Host country rules may require local payroll registration, local income tax withholding, or contributions to a different social security system. Inside the EU and in countries with a totalisation agreement, an A1 certificate or certificate of coverage keeps the employee in their home scheme, but it must be applied for before travel rather than explained afterwards. Longer stays sometimes need a local entity or an employer of record. Our overview of global payroll solutions explains where each model fits and what it costs.
Duty of care, data protection and cybersecurity
Duty of care means knowing where your people are and being able to reach them: medical cover, an emergency contact route and a location risk briefing, not a paragraph of good intentions.
Data protection deserves its own line in the form. An employee opening a customer database from outside the home region can amount to a cross-border data transfer, and some sectors sit under strict data localization laws. Pair the policy with device encryption, multi-factor authentication and least-privilege access, the controls covered in our guide to cybersecurity for remote work and in a zero trust setup. Unapproved tools picked up on the road are also how shadow IT spreads.
“Screen immigration first, tax second, payroll third and duty of care throughout. Most rejected requests fail on the first check, so run it before anyone books a flight.”
Country rules: visas, borders and day counts in 2026
Country rules move every year, which is why your approved list should be short enough to keep current.
What the popular destinations require
Spain’s digital nomad visa is pegged at 200% of the national minimum wage, so the threshold rose with the February 2026 wage increase to about 2,849 euros a month for a single applicant. Portugal’s D8 is pegged at four times its minimum wage and now sits at 3,680 euros a month, applied at the rate in force on the appointment date rather than the filing date.
Thailand’s Destination Thailand Visa still runs for five years with stays of up to 180 days per entry, but from 31 August 2026 applicants must apply in their country of nationality or residence and supply a criminal record certificate. The UAE issues a one-year virtual work permit through Dubai and Abu Dhabi, and Barbados still offers its Welcome Stamp for up to twelve months.
Europe now counts the days for you
The EU Entry/Exit System began its rollout in October 2025 and became fully operational across the Schengen area on 10 April 2026. Entries and exits of non-EU travellers are now recorded biometrically instead of by passport stamp, so the 90 days in any 180 rule is checked by a database rather than by an officer reading ink. An overstay that once passed unnoticed is flagged automatically, which makes internal day tracking part of the policy rather than a nice extra.
Slowmading lowers the admin load
Nomads themselves are slowing down. MBO Partners recorded an average of 6.2 locations per year in 2025, down from 7.2 in 2023, with the average stay stretching to 6.4 weeks. Fewer, longer stays in vetted countries mean fewer visa applications and a day count that is easier to keep clean. A policy that rewards three-month stays in five approved countries is simpler to run than one that quietly permits twelve short hops.
How to roll the policy out
Publish the rules where people already look, usually the handbook and the onboarding checklist rather than a shared drive nobody opens. Brief managers separately, because they receive the first question.
Track approvals, destinations and days in one system so you can answer an auditor without emailing forty people. Review the policy once a year, and immediately when a key country changes its rules.
Then measure two things: how many requests you approve, and how many people travelled without asking. The second number tells you whether the policy works. If it stays high, the process is too slow or the list too narrow. Companies that also publish a hybrid work policy and a global holiday calendar tend to get fewer edge-case questions, because the ordinary cases are already answered.
Conclusion
A digital nomad policy is not a perk document. It is a risk control that happens to be popular with employees.
Name the eligible roles, approve a short list of countries, set day limits, and route every request through one form that HR, tax and IT can see. Check immigration first, then tax residency and permanent establishment, then payroll and social security, then duty of care and data protection.
Keep the country list current, encourage longer stays in fewer places, and track the days now that borders do it for you. Done that way, flexible work stops being a quiet liability and becomes something you can offer on purpose, for the same reason companies invest in talent retention and a working remote company culture in the first place.
For the wider picture, see our overview of digital nomads and the technology behind them and the work from anywhere economy, plus managing cross-border teams and employee data privacy rules. For a practical framework and workforce data, see the nomads workforce guide.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







