A free UK-aligned template covering 4 essential clauses. Edit the highlighted fields, sign, and adopt.
| Document owner | [Insert role — typically Head of IT or Information Security Manager] |
|---|---|
| Approved by | [Insert name and date of board / management approval] |
| Version | 1.0 |
| Date of issue | [DD Month YYYY] |
| Review cycle | Annually, or upon material change to the IT estate |
| Classification | Internal — All Employees, Contractors, and Authorised Third Parties |
| Applies to | All users of [Company] IT systems, networks, devices, applications and data |
This policy sets out the conditions under which [Company] permits employees, contractors, agency workers and authorised third parties (collectively, "Users") to access and use [Company] information systems, networks, devices, applications and data (collectively, "Systems"). The objective is to maintain the confidentiality, integrity and availability of [Company] information assets, comply with applicable legal and regulatory obligations including the UK GDPR and the Data Protection Act 2018, and protect Users from unintentional harm caused by misuse.
This policy applies to:
Systems means the totality of [Company] IT assets defined above.
Personal Use means use of Systems for purposes unrelated to [Company] business.
Sensitive Data means personal data as defined in UK GDPR Article 4(1), commercial-in-confidence information, intellectual property, and data classified as Confidential or Restricted under [Company]'s Information Classification Policy.
Monitoring means automated or manual review of System activity for security, compliance or operational purposes.
Users shall use [Company] Systems primarily for [Company] business purposes. Limited Personal Use is permitted provided it does not interfere with work duties, expose [Company] to legal or reputational risk, or consume disproportionate System resources. Specifically, Users shall:
Limited Personal Use of [Company] email, internet access and devices is permitted at the discretion of [Company], subject to the prohibitions in Clause 3. Personal Use must be reasonable in frequency and duration, must not occur during agreed working hours unless during authorised breaks, and must not generate financial or reputational liability for [Company]. Users have no expectation of privacy in respect of Personal Use on [Company] Systems beyond what is required by law.
The following activities are expressly prohibited when using [Company] Systems:
Compliance with this policy is a condition of access to [Company] Systems and a contractual obligation for employees, contractors and third parties. [Company] reserves the right to suspend or terminate System access where there is evidence of breach. Breach by employees may be addressed through the [Company] Disciplinary and Grievance Procedure; serious breaches may amount to gross misconduct.
[Company] monitors System activity for the legitimate interests of information security, regulatory compliance, intellectual property protection and operational continuity. Monitoring is conducted lawfully under UK GDPR Article 6(1)(f) (legitimate interests) and, where personal data is involved, after a documented legitimate-interests assessment. Categories of monitoring include: authentication and access logs, email and messaging metadata, internet-browsing logs, cloud-application usage telemetry, endpoint security events, and DLP triggers. Content of messages and files is not routinely reviewed; targeted content review may be conducted on reasonable cause.
[Company] meets its UK GDPR Article 13/14 transparency obligation through the [Company] Privacy Notice, the at-login banner on managed devices, and the new-joiner induction. Users are informed at recruitment, at induction and via this policy that their use of [Company] Systems is subject to monitoring.
Where monitoring indicates a possible breach, the [Company] Head of IT or Information Security Manager will assess proportionality, document the basis for further investigation, and, where targeted review is justified, conduct the review with HR in attendance. Findings are escalated to the disciplinary process where appropriate. The full audit-ready policy contains the detailed investigation procedure with RIPA 2000 + IPA 2016 considerations, evidence handling, and chain-of-custody requirements — see the upsell block at the end of this document.
Users who become aware of a possible breach of this policy by themselves or others are required to report it to [Company] IT or HR. Where the report concerns a qualifying disclosure under the Public Interest Disclosure Act 1998 (PIDA), the [Company] Whistleblowing Policy applies and protects the reporting User from detriment.
This free version covers four foundational clauses. The full £29.99 single-policy version adds the employee acknowledgement form (audit-evidence under ISO 27001 A.6.3), the joiner/mover/leaver checklist with timed access revocation, cloud SaaS-specific controls for Microsoft 365 + Google Workspace + Slack + Zoom, BYOD/MDM integration clauses, role-based exception procedures, and the detailed investigation procedure with RIPA 2000 + IPA 2016 considerations. Editable Word + PDF, instant download, lifetime access, no subscription.
Buy the full policy — £29.99 →