Purpose and Scope
This policy sets out the rules for using [Organisation Name]’s IT systems, including computers, mobile devices, email, internet access, software, and cloud services. It applies to all employees, contractors, and third parties accessing our systems on-site or remotely.
It protects our technical infrastructure, company data, and personal information, ensuring we comply with data protection laws including the UK GDPR and Data Protection Act 2018.
Working through related paperwork at the same time? See also our US IT Acceptable Use Policy Template, Privacy Notice for Employees Template and UK Data Breach Response Procedure Template.
Policy Statement
[Organisation Name] provides IT systems to support daily business operations. You must use these systems lawfully, securely, and professionally. We allow reasonable personal use within defined limits, but all systems and data remain company property, and business needs always come first.
We handle policy breaches through our disciplinary procedure and, if personal data is involved, our data breach response procedure. Unauthorized access to systems or records may also lead to criminal prosecution.
Responsibilities
- Policy Owner ([Role]): Maintains this policy, approves written exceptions, and conducts incident reviews.
- IT Lead ([Role]): Manages user accounts and access rights, applies security updates, and leads technical incident responses.
- Managers: Ensure team members read and understand this policy, and submit access change requests promptly during onboarding, transfers, or offboarding.
- All Users: Follow all policy rules, complete assigned security training, and report suspected security incidents or vulnerabilities immediately.
Acceptable Use
- Access systems only through your assigned account. Never share or borrow login details.
- Use software and cloud services approved by [Role]. Get written authorization before installing any new application.
- Store all work files in designated company locations (such as shared drives) rather than local desktops, USB drives, or personal cloud storage.
- Lock your device screen whenever you step away from your workstation, whether in the office or working remotely.
- Use approved company email and messaging platforms for all business communications to keep clear records and maintain compliance.
Unacceptable Use
- Sharing passwords or login credentials with anyone, including colleagues or managers.
- Accessing, downloading, storing, or sending material that is illegal, discriminatory, offensive, or harassing.
- Sending company or customer data to personal email accounts, unapproved messaging channels, or personal storage devices.
- Attempting to access systems, records, or accounts without authorization.
- Disabling, changing, or bypassing security controls, such as antivirus software, screen timeout locks, or device encryption.
- Using company systems to run private businesses or conduct unapproved external work.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
Security Controls and Passwords
- Use strong, unique passwords for every account. Change them immediately if you suspect a breach.
- Use multi-factor authentication on all platforms where [Role] enables it.
- Treat unexpected requests for passwords, money transfers, or urgent action as suspicious. Always verify them using a second communication method before acting.
- Install software and security updates within [Number] days of receiving a prompt.
- Report lost, stolen, or damaged devices to [Role] immediately.
Personal Use and System Monitoring
You may use company email and the internet for reasonable personal use during breaks, provided this does not disrupt operations, consume excessive network resources, or break any unacceptable use rules. Management reserves the right to suspend or withdraw personal use privileges at any time.
[Organisation Name] monitors system use only as necessary for network security, legal compliance, and operational management (such as automated spam filters, web filtering logs, and access logs). We do not routinely monitor private communications. Targeted monitoring requires formal approval from [Role] and must follow our worker monitoring guidelines and employee privacy notice.
Incident Response Procedure
- Report any suspected incident, such as clicking a suspicious link, losing a device, sending personal data to the wrong email, or noticing unusual account activity, to [Role] immediately.
- Contain the threat under [Role]’s guidance by isolating affected devices, revoking compromised logins, and preserving activity logs or evidence.
- Check if personal data was exposed. If a data breach occurred, follow the data breach response procedure. We must report notifiable breaches to the supervisory authority within 72 hours of becoming aware of them.
- Log the incident details, root cause, and corrective actions in [System/Location]. Use these findings to update our policies and future training.
Records and Policy Review
- We store signed acknowledgments, training completion records, and incident logs in [System/Location].
- We review this policy annually, or following a major security incident or significant change to our IT infrastructure.
- Policy Owner: [Role]
- Next Review Date: [Date]
FAQs on an IT and acceptable use policy
What is an IT and acceptable use policy?
An IT and acceptable use policy sets out the rules for using your organisation’s IT systems, including computers, mobile devices, email, internet access, software, and cloud services. It applies to all employees, contractors, and third parties accessing our systems on-site or remotely.
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does an IT and acceptable use policy include?
This template covers acceptable use, unacceptable use, security controls and passwords and personal use and system monitoring.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement an IT and acceptable use policy with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.