A cross-sector template governing the acceptable use of email, internet, devices and IT systems, with monitoring, personal-use limits and links to confidentiality and information security
This policy is fully drafted and structured, ready to brand and complete for your service. It covers:
1. Purpose
2. Scope
3. Policy statement and principles
4. Definitions
5. Acceptable use of organisation email
6. Acceptable use of the internet
7. Use of devices, systems and access controls
8. Prohibited use
9. Personal use limits
10. Social media, messaging and video consultation
11. Monitoring of communications and systems
12. Links to confidentiality and information security
13. Reporting incidents, breaches and concerns
14. Roles and responsibilities
15. Training
16. Monitoring, audit and review
17. Related documents
18. Glossary
19. References
Legislation & standards it maps to
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Computer Misuse Act 1990
Regulation of Investigatory Powers Act 2000
Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000
Privacy and Electronic Communications (EC Directive) Regulations 2003
Copyright, Designs and Patents Act 1988
Equality Act 2010
Who it applies to
All employed, bank, agency, locum, contracted, voluntary and self-employed staff, and any third party granted access to the email, internet, devices or information systems of [Organisation Name]
How it works
Buy securely with Stripe - instant, no VAT, no account needed.
Download your editable Word file from the link we email you straight away.
Complete the placeholders for your service, then have it approved before use.
Add the optional updates subscription and we keep it current as guidance changes.