
IT, communications and social media policy
- Quick and easy to complete
- Improve your cyber security
- UK GDPR compliant
An IT, communications and social media policy sets out guidelines for an organisation’s staff about their use of IT equipment, communications software and social media. Its objectives are to ensure the security of a business’s systems, to protect them from misuse and to maintain professional communication standards. It might be produced as separate policies; for example an IT security policy, a communications policy and a social media policy.
This template will help you to establish clear guidelines for your staff about how they should securely operate your IT equipment, such as requirements as to passwords. It also covers to what extent systems may be used for personal use, including how your business will monitor such use. This will help to ensure that your systems are operated securely and professionally. It will also ensure that you comply with your data protection obligations under the UK GDPR.
This policy could form part of your staff handbook or it could be provided as a standalone policy. If you’re looking to produce an entire staff handbook, use our template staff handbook instead.
Alternatively, you can also purchase this policy as part of the Remote working and cybersecurity toolkit.
Q&A
When should I use this document?
You should use this document if you employ staff who use your business’s IT devices and/or communication systems, including social media. It will help you to set a clear framework for using that hardware and software, helping you to ensure that they are used both securely and professionally.
If you plan on monitoring your staff member’s online activity or use of their communication systems, you should use this policy to make sure they are aware of this before you begin any monitoring. This will help you to comply with your data protection obligations.
Make sure you review this policy regularly and ensure it is updated if you start using any new IT or communications systems.
What does this document cover?
This policy sets out your business’s general rules regarding the use of IT equipment, communications systems and social media. This includes:
-
measures that must be taken to ensure both the cyber security and physical security of equipment, including who suspicious incidents should be reported to;
-
acceptable use of equipment, including to what extent systems may be accessed for personal use;
-
applicable standards when communicating on behalf of the business, including via social media;
-
the extent to which your business may monitor use of its equipment and communication systems; and
-
consequences of breaching the policy.
-
Why do I need this document?
Although you’re not legally obliged to have an IT, communications and social media policy it is best practice to put one in place to help to ensure that the security of your systems is not compromised. Equally, if you will be monitoring your staff members’ use of your IT and communication systems, in nearly all cases you must make them aware of this before you carry out any monitoring. This is a requirement under data protection law, breach of which could lead to significant fines for your business and/or your staff member suing you for invasion of their privacy. This policy will help you to comply with your legal obligations by alerting your staff to the possibility of them being monitored.
This policy will also help to ensure that professional standards are maintained when your staff are communicating on your behalf, including through social media channels.
Where can I find out more?
For guidance about other HR policies that your business should put in place when you take on staff, see our Q&A on HR policies.
For information about your data protection obligations when you are monitoring your staff, see data protection issues when monitoring staff.
If you need a general staff privacy notice to let your staff know how you are processing their personal data during their employment by you, use our template staff privacy notice.
If you want to produce an entire staff handbook, which contains a copy of this policy, see our template staff handbook.
Related Toolkits
Redundancy toolkit
- How-to guide: Redundancy toolkit
Redundancy - Letter warning of proposed redundancies
Redundancy - Selection criteria form
Redundancy - Provisional selection for redundancy letter
Redundancy - First individual consultation meeting agenda
Redundancy - Outcome of individual consultation meeting
Redundancy - Invitation to final individual consultation meeting
Redundancy - Final individual consultation meeting agenda
Redundancy - Notice of termination of employment
Redundancy - Offer of alternative employment
Disciplinary toolkit
- How-to guide: Disciplinary toolkit
Suspension letter pending investigation
Disciplinary investigation template
Invitation to attend a disciplinary hearing
Invitation to attend meeting to discuss sickness absence
List of common disabilities
Note taking template for disciplinary proceedings
Basic script for conducting a disciplinary hearing
First written warning for capability
First written warning for misconduct
Final written warning for capability
Final written warning for misconduct
Sickness absence meeting - outcome letter
Dismissal letter
Invitation to attend a disciplinary appeal hearing
Basic script for conducting a disciplinary appeal hearing
Letter to confirm outcome of a disciplinary appeal
Pregnancy and maternity toolkit
Maternity arrangements letter
Maternity - Amended return date letter
Maternity - Letter confirming sickness absence during last four weeks before childbirth
Maternity - KIT Day Letter
Employee notice of return from maternity leave
Letter to employee confirming dates of return from maternity leave
Pregnancy - health and safety letter
- How-to guide: Pregnancy and maternity toolkit
Pregnancy and maternity risk assessment
Maternity - Employee notice of pregnancy and intention to take maternity leave
Pregnancy - suspension on health and safety grounds letter
Paternity toolkit
- How-to guide: Paternity toolkit
Declaration of eligibility for time off to attend antenatal appointments
Employee declaration of eligibility for time off to attend pre-adoption appointments
Employee declaration of eligibility for time off to attend antenatal appointments with surrogate
Paternity arrangements letter
Employee notice of date of childbirth
Notice of updated return date from paternity leave
Adoption - Employee notice of date of arrival