All sample legal documents

Sample IT Acceptable Use Policy

A worked England and Wales IT acceptable-use policy covering company systems, devices, security, personal use, monitoring, AI tools, information handling, reporting, investigations and sanctions.

Jurisdiction: Illustrative England and Wales employment and information-security policy — UK GDPR, Computer Misuse Act 1990, intellectual property, confidentiality, monitoring and equality obligations must be checked

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

IT ACCEPTABLE USE POLICY

Important legal-advice, jurisdiction and formality warning

This fictional policy is a worked example for an organisation in England and Wales. It is not legal advice, is not a complete cyber-security standard and does not itself create a contractual right to use any system. Before issue, the organisation must check the employment contract, disciplinary procedure, UK GDPR and Data Protection Act 2018, Computer Misuse Act 1990, Investigatory Powers Act 2016 where applicable, workplace-monitoring requirements, copyright and database rights, confidentiality obligations, equality duties, licensing terms, regulatory requirements and sector-specific guidance. Monitoring must be necessary, proportionate, transparent and lawfully notified; it must not become covert surveillance without a separate lawful basis and required authorisation. This policy does not authorise unlawful access, processing of sensitive data or the use of live AI tools with confidential information. All people, dates, addresses, systems and examples below are fictional.

Owner, scope and status

This policy is issued by Northmere Medical Supplies Limited, company number 13620574, 4 Hartwell Industrial Park, Worcester WR4 9PL. It applies from 12 September 2026 to employees, workers, agency staff, contractors, secondees and visitors who use Northmere's systems or information. The owner is Sana Mirza, Information Governance Manager, at security@northmere.example.test. It was approved on 2 September 2026 by Helen Louise Armitage, Operations Director, and will be reviewed on 12 September 2027 or after a significant incident or technology change. It is a non-contractual policy, subject to the employment contract and other policies. A breach may be addressed under a fair disciplinary or contract process, but no outcome is predetermined.

“Company system” includes Northmere accounts, laptops, telephones, servers, cloud services, network, email, messaging, warehouse scanners, business applications and any device or service used to access company information. “Company information” includes customer, patient, supplier, employee, stock, financial, technical and confidential business information. “Personal use” means limited use that is lawful, reasonable, does not interfere with work or security, and complies with this policy.

1. Access and account security

Each user receives only the access needed for their role. Accounts are personal and must not be shared, lent, transferred or used to conceal another person's activity. Passwords must be unique, at least fourteen characters where the system permits, stored in the approved password manager and protected from disclosure. Multi-factor authentication must be enabled whenever provided. A user must lock the screen when leaving a device, keep recovery codes secure and never approve a sign-in request that they did not initiate.

Northmere will remove access when a role changes or employment ends. Managers must notify IT promptly of a transfer, extended leave or change of duties. Users must not try to bypass a control, disable endpoint protection, obtain administrator rights, scan a network, intercept traffic, test a vulnerability or access another account unless IT has approved a documented security test. Security testing by a supplier requires written scope and dates; good intentions do not make unauthorised access lawful.

Company laptops must use the managed build, encryption, automatic updates and endpoint protection. Users must not install cracked software, unlicensed fonts, browser extensions of unknown origin, cryptocurrency miners, games that create a security risk or applications that have not been approved by IT. Removable media is prohibited unless encrypted and approved for a defined business purpose. Personal devices may not access patient, customer or employee records unless the BYOD team has approved and enrolled them in writing.

2. Information classification and handling

Northmere classifies information as Public, Internal, Confidential or Restricted. Public information has been approved for external release. Internal information is for ordinary work use. Confidential information includes commercial terms, contracts, supplier pricing, non-public operations and personnel matters. Restricted information includes health, patient, identity, payroll, authentication, investigation and legally privileged information. The owner of information is responsible for its classification and access review.

Restricted and Confidential information must be sent only through approved encrypted systems to a verified recipient. A user must check an address before sending, use secure links with expiry where available, avoid putting sensitive information in an email subject, and use a minimum necessary extract. Paper records must be locked when unattended and disposed of through the confidential-waste service. A user must not photograph a screen, copy a record to personal notes or discuss a customer or employee in a public place.

Northmere shares information with processors only under approved contracts and instructions. Uploading company information to an unapproved translation site, file-sharing service, public forum or browser plug-in is prohibited. Data exports must be approved by the information owner and, where personal data is involved, by the Data Protection Lead. International access or transfer must be checked under the applicable data-transfer mechanism. Users must follow the retention schedule and must not destroy information subject to a legal hold or investigation.

3. Email, internet and communications

Email and collaboration systems are for work, with limited personal use that is lawful and does not create cost, distraction, harassment, security risk or reputational harm. Users must not send threatening, discriminatory, sexually explicit, defamatory or deliberately offensive material. A joke is not a defence if it creates a hostile environment. Work communications may be evidence in a dispute or subject to a lawful information request, so users must write accurately and professionally.

Phishing, unexpected payment requests, urgent password messages, unusual attachments and altered bank details must be reported using the “Report suspicious” function or to IT on 01905 555 410. Do not click further, forward a malicious attachment to colleagues or delete evidence after reporting. Finance staff must verify a bank-account change through a known telephone number and a second approval. A user who clicked a suspicious link will receive support and must report it promptly; concealment of an incident is a separate concern.

Internet access must not be used for unlawful activity, unauthorised commercial activity, gambling that creates a work or security risk, harassment, copyright infringement, extremist material or access to material that may put another person at risk. Northmere recognises that legitimate work can involve difficult or distressing content; such access must be approved, recorded where required and supported by a risk assessment. The policy is not intended to restrict lawful trade-union activity, whistleblowing, reporting wrongdoing or protected expression.

4. Personal use and devices away from work

Personal use is allowed during breaks on a company device only when it follows this policy. A user must not use company systems to run a private business, store family photographs, mine digital currency, make political fundraising transactions on behalf of Northmere, or register a third party for a service. Personal use must not disclose the employer's name or imply endorsement. A user must not use a company account as the recovery address for a personal service that they need after employment.

When working remotely, users must keep devices away from household members, use a private network where possible, avoid public Wi-Fi unless protected by the approved VPN, and use a privacy screen where required. A device must not be left in an unlocked car or checked luggage. Travel abroad with a device containing Restricted information requires approval from Gareth Owen, IT Security Lead, at least five working days in advance, and may be refused because of legal, security or export restrictions.

Northmere provides a managed laptop to Leah Bennett, Quality Coordinator, asset NM-LT-331, and a managed phone asset NM-PH-214. Leah may use the phone for a personal call during a break but may not store customer information in its personal messaging application. She must report loss to IT within one hour and must remotely lock the device if instructed. These examples illustrate the rules and are not a general permission for personal storage.

5. Generative AI and automated services

Users must not paste Restricted, Confidential or personal data into a public or unapproved generative-AI, transcription, summarisation, code or image service. They must not upload a customer complaint, employee investigation, medical information, contract, source code, password, security configuration or unpublished stock forecast to such a tool. An approved service may be used only for the defined purpose, with the data minimised, contractual safeguards confirmed and a human review completed.

AI output is not an authority and can be inaccurate, discriminatory, confidential, infringing or fabricated. A user must verify every material fact, citation, calculation, translation and recommendation against a reliable source and must not allow an automated tool to make a solely automated employment, customer or safety decision. A manager remains responsible for a decision. Where a person may be affected by automated assistance, the relevant privacy information, equality assessment, human review and challenge route must be provided.

Northmere's approved tool, ClearDraft Enterprise, may be used by Leah Bennett only for non-confidential formatting and a first draft of a public product description. She must remove personal information, check the output against the approved product sheet, record that human review occurred and obtain Marketing approval before publication. It must not be used for a medical product claim, a disciplinary decision or an answer to a patient. The approval may be withdrawn after a security or quality review.

6. Monitoring, privacy and legitimate work

Northmere may log authentication, device health, malware alerts, network traffic metadata, file access, email security events, warehouse transactions and support tickets for security, continuity, service management, legal compliance and investigation. The organisation may review content where necessary and proportionate for a defined purpose, such as a suspected breach, safeguarding concern, legal hold or service failure. The Employee Privacy Notice and Monitoring Information explain the purposes, retention, access controls and rights.

Monitoring is not continuous observation of a person's private life. Northmere will not use webcam activation, keystroke scoring or private-device content as routine performance measures under this policy. Any new intrusive monitoring requires a documented necessity and proportionality assessment, consultation where required, data-protection review and appropriate notice. Personal use may still be visible in security logs, and users should not expect company systems to be private in the same way as a personal device.

Northmere will retain security logs for twelve months, access records for eighteen months and investigation material for six years after closure, subject to legal hold, the privacy notice and a shorter period where appropriate. Access is restricted to IT, Information Governance, People, Legal or an authorised investigator. A user may raise a privacy concern with Thomas Edwin Bell, Data Protection Lead, at privacy@northmere.example.test, without losing the right to make a grievance or contact the Information Commissioner's Office.

7. Reporting incidents and preserving evidence

Report a suspected breach, lost device, malware, accidental disclosure, unauthorised access, impersonation, suspicious payment instruction or loss of paper information immediately to security@northmere.example.test and 01905 555 410. Outside office hours, call the duty manager on 01905 555 411. Include what happened, when, what information or device was involved, who may have received it and what action has already been taken. Do not delay reporting while trying to establish every detail.

IT may isolate a device, reset credentials, suspend an account or preserve logs. Users must follow instructions, not wipe or reformat a device, not contact an external recipient about a suspected breach unless instructed, and not post about an incident online. Northmere will assess whether a personal-data breach must be notified to the Information Commissioner's Office within the applicable period and whether affected people or customers must be informed. Prompt reporting is treated as responsible conduct; deliberate misuse or concealment may be handled separately.

If a user believes information is being processed unlawfully, they should report it to Information Governance or use the speak-up procedure. No one will be penalised for raising a genuine concern in good faith, although knowingly false allegations may be addressed under the relevant process. Evidence must be preserved respectfully and in accordance with legal privilege and data-protection requirements.

8. Prohibited conduct, investigations and outcomes

The following are examples of prohibited conduct: sharing credentials; accessing records without a work need; bypassing security; introducing malicious code; copying Restricted information to a personal service; infringing copyright deliberately; using systems to harass or discriminate; falsifying an electronic record; interfering with an investigation; or making a prohibited automated decision. An accidental act is not automatically misconduct, and its circumstances, training, workload, impact, prompt report and any disability or adjustment must be considered.

An investigation will be proportionate and, where a formal employment outcome is possible, will identify the concern, gather relevant evidence, invite the person's response and follow the Disciplinary Policy and ACAS Code as applicable. The investigator and decision-maker should be separate where practicable. A worker may have a companion at a formal disciplinary hearing where the law or policy provides. Outcomes may include guidance, additional training, access changes, a warning or dismissal, but the policy does not predetermine the sanction.

Users may request an access correction, report an accessibility barrier or ask for a reasonable adjustment through Sana Mirza. An accessibility need does not justify withholding essential security controls; IT must seek an equivalent secure control. Trade-union communications, whistleblowing and lawful employee representation are not prohibited personal use.

9. Training, acknowledgement and review

Before receiving access, each user must complete induction training, phishing awareness and data-protection training. Refresher training is due each September and after a material incident or system change. Managers must ensure agency staff and contractors receive appropriate instructions and that access ends promptly. IT will review privileged accounts monthly; information owners will review Restricted access quarterly.

The policy will be discussed at the Northmere Information Governance Forum on 26 August each year, and anonymised incident themes will be reported to the Operations Board. Suggestions and concerns may be sent to security@northmere.example.test. This policy does not remove any statutory right, contractual duty or separate reporting route.

Approval and acknowledgement

For Northmere Medical Supplies Limited:

Helen Louise Armitage, Operations Director Signature: ____________________ Date: 2 September 2026

Policy owner: Sana Mirza, Information Governance Manager Signature: ____________________ Date: 2 September 2026

User acknowledgement: Leah Bennett, Quality Coordinator Signature: ____________________ Date: 12 September 2026

The signature records receipt, training and an opportunity to ask questions. It does not authorise conduct prohibited by law or waive privacy, equality, employment or whistleblowing rights.

Create a version for your situation

Create a tailored IT Acceptable Use Policy