Home › HRMS › HR policies › IT acceptable use policy
HR policy template

IT acceptable use policy template

An IT acceptable use policy sets the rules for company laptops, desktops, email, internet, Wi-Fi, software and cloud accounts. It tells employees what is allowed, what is not and how the company monitors its systems, so that security incidents, licence violations and misuse are prevented and handled fairly. It applies from the first login and matters more as work moves to laptops, cloud tools and phones.

When to use it: Give it to every employee before IT issues a laptop or login, and record their acceptance. The IT head writes it with HR, and the managing director approves it. Update it when you adopt new tools such as cloud storage, remote access or AI chat tools, and remind staff after any security incident.

IT acceptable use policy template

Copy the text below and replace everything in square brackets with your company details.

1. Purpose

This policy protects the Company's systems and data, and the people who use them, by setting clear rules for acceptable use of the IT resources of [Company Name].

2. Scope

It applies to employees, trainees, interns, consultants and contractors who use Company devices, networks, email, software or cloud accounts, at the office, at home or while travelling. Personal devices used for work are covered in detail by the BYOD Policy.

3. Definitions

  • IT resources: computers, phones, printers, networks, Wi-Fi, email, software, cloud storage and accounts provided by the Company.
  • Security incident: any event that may expose Company systems or data, such as a lost laptop, a clicked phishing link or a virus alert.

4. Policy: acceptable use

  • IT resources are provided for work. Brief personal use, such as a personal email or a train booking, is allowed if it does not affect work, security or network capacity.
  • Use only software approved and licensed by the Company. Do not install anything yourself.
  • Save work files on [Approved Storage], never on personal email or personal cloud drives.
  • Use strong passphrases, turn on two-step login wherever it is offered, and never share passwords or OTPs, not even with IT staff.
  • Lock your screen when you step away, and keep laptops with you when travelling, never in a parked car.

5. Policy: not allowed

  • Accessing, downloading or sharing pornographic, violent, hateful or illegal material.
  • Downloading pirated software, films or music, or using torrent sites.
  • Plugging in unknown pen drives, or disabling antivirus, firewall or updates.
  • Using Company email for chain messages, political campaigns or bulk personal mail.
  • Pasting confidential, customer or employee information into public AI chat tools, translation sites or file converters that IT has not approved.
  • Trying to access systems or data you are not authorised to use.

6. Monitoring

Company systems, email and internet traffic may be monitored and logged for security, compliance and investigations, in line with applicable law. Monitoring is done by authorised IT staff. The content of an individual's email or files is reviewed only for a specific reason and with written approval from [Designation].

7. Procedure for incidents and exits

  • Report a lost or stolen device, a suspicious link you clicked or a virus alert to [IT Helpdesk Email or Phone] immediately. Early reports are never penalised.
  • Do not try to investigate an incident yourself, and disconnect from the network if IT asks you to.
  • Misuse is handled under the Disciplinary Action Policy, and access may be suspended during an investigation.
  • On the last working day, IT disables all accounts and collects every Company device.

8. Responsibilities

  • Users: follow this policy and report incidents at once.
  • Managers: request access for their team members only for what their role needs.
  • IT: maintain security controls, approve software, handle incidents and remove access on exit.
  • HR: tell IT about joiners, role changes and last working days in good time.

9. Exceptions

IT may approve a documented exception, such as a specialised tool for a project, for a fixed period. Exceptions are recorded and reviewed when they expire.

10. Review

The IT head reviews this policy every [12] months and whenever the Company adopts a new category of tool or suffers a significant security incident.

What to include

Personal use in moderation

Allow brief personal use rather than banning it. A total ban is unrealistic and makes the rest of the policy look unserious.

Approved software only

Require IT approval for software. Pirated or unvetted software brings licence risk and is a common way for malware to get in.

Passwords and OTPs

Say that passwords and OTPs are never shared, not even with IT. Fraudsters often pose as IT support or bank staff to ask for them.

Honest monitoring notice

Tell employees what is monitored and why, and who approves content review. Monitoring that employees never knew about damages trust when it surfaces.

Public AI and online tools

Address AI chat tools, translators and file converters directly. Confidential data pasted into them may be stored outside your control.

Fast incident reporting

Promise that early reports will not be penalised. The minutes after a phishing click matter, and fear of blame delays the report.

Common mistakes to avoid

Run it in ZeniaHR

Within ZeniaHR, capture controls limit web punches to allowed office networks by IP address or range. Access Control gives each role only the actions it needs in each module, such as view, edit, approve, export or configure, so export rights stay with the few roles that need them. Recording a resignation sets the last working day, which gives IT a firm date to disable accounts and collect devices.

See it on your own data

A 30-minute demo on a video call. We set up your departments, shifts and leave rules and show attendance, leave and payroll running for your team. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What is an IT acceptable use policy?

An IT acceptable use policy is a set of rules for using company computers, email, internet, software and cloud accounts. It says what is allowed and what is not, how passwords and data must be handled, how the company monitors its systems, how to report incidents, and what happens if the rules are broken.

Can a company monitor employees' work email?

Company email and systems are generally treated as company resources, and many employers monitor them for security and compliance. Do it openly: state what is monitored and why, allow content review only for specific reasons with senior approval, and restrict who sees the results. Take legal advice before monitoring anything beyond standard security logs.

Can employees use company laptops for personal work?

Brief personal use, such as checking personal email or booking a ticket, is usually allowed if it does not affect work or security. Installing personal software, storing personal files in bulk, streaming or downloading pirated content, and running a side business on a company laptop are not. The policy should draw that line clearly.

Should employees use AI chat tools at work?

Only as the policy allows. Public AI chat tools, translators and file converters may store what is typed or uploaded, so employees should never paste confidential, customer or employee information into them. A practical approach is to approve specific tools for specific tasks, name them in the policy and explain how to request others.