What an acceptable use policy is, and which rules require one
An acceptable use policy (often shortened to AUP) is the organisation's written rules for the use of its information systems: who may use them, for what, with what safeguards, what is not allowed, what the organisation checks, and what happens if the rules are broken. It is usually signed at induction. For staff it sits beside the code of conduct, the data protection policy, the information security policies and the social media policy, and acceptable use policies only work if these agree with each other.
Schools and colleges. Keeping children safe in education 2026 lists the policies staff must be given, and among them is "a staff behaviour policy (sometimes called the code of conduct) which should, amongst other things, include low-level concerns, allegations against staff and whistleblowing, plus acceptable use of technologies (including the use of mobile devices), staff/pupil relationships and communications including the use of social media" (paragraph 123). The Department for Education's filtering and monitoring standard then assumes the AUP exists: "School and college monitoring procedures need to be reflected in your acceptable use policy (AUP)", and "make sure that everyone using your school's network knows that filtering and monitoring processes are in place."
Every organisation. Under Article 32 of the UK General Data Protection Regulation a controller must take appropriate technical and organisational security measures to keep personal data secure, and rules for staff about how they use systems holding it are one of the most basic organisational measures there are. Unauthorised access to computer material is an offence under section 1 of the Computer Misuse Act 1990, and an AUP is where an organisation says what access each person is authorised to have. For a care provider, Regulation 17 requires records to be maintained securely, which reaches the devices and accounts they are kept on. For a charity, the trustees' duty to manage its resources responsibly includes its data and its systems.
A policy is also what the employer relies on when something goes wrong. A disciplinary for misuse of IT turns on whether the rule was clear and the employee knew it; a breach report to the ICO turns on whether the organisation had measures in place; a cyber insurance claim may turn on whether staff had been told not to do what they did.
What a staff acceptable use policy has to cover
Templates vary, but a policy that works for a school, a charity or a care service covers the same ground. Each item should be a rule someone can follow, not a statement of intent.
- Who and what the policy applies to. Staff, volunteers, governors or trustees, agency and bank staff, contractors, and visitors using the Wi-Fi; and every system: accounts, email, cloud storage, the network and internet access, organisation-owned laptops, tablets and phones, and any personal device used for work.
- Accounts and passwords. One person, one account; no sharing of logins, including on shared care or classroom devices; strong passwords or passphrases and multi-factor authentication where it is offered; lock the screen when leaving a device.
- Personal data and confidential information. What may be stored where; no pupil, resident or service user information in personal email, personal cloud storage or unapproved apps; no downloading to removable media without permission; how to send personal data securely.
- Email use and messaging. Which channels are for work communication, which are not, and what must never be sent by message at all. This is the clause section 06 is about.
- Internet and personal use. Whether limited personal use of the internet and email is allowed, and on what terms; what counts as unacceptable use, including content that must never be accessed and attempts to get round filtering or network security; and in a school, that filtering and monitoring are in place and why.
- Photographs and recordings. Images of pupils, residents or service users only on organisation devices, only for stated purposes, never on personal phones or social media without the authorised process.
- Social media. The organisation's accounts, and the line for personal accounts; usually a cross-reference to the social media policy.
- Software, downloads and AI tools. Only approved software; no installing unapproved apps; respect for copyright and intellectual property in material staff did not create; whether generative AI tools may be used and with what data. KCSIE 2026 points schools to the Department's guidance on generative AI in education, and personal data should not be entered into an AI tool the organisation has not approved.
- Reporting a security incident. What to report and how quickly: a lost or stolen device, a suspicious email, a message sent to the wrong person, content a child should not have seen, a suspected breach. Reporting quickly is what lets the organisation decide whether a personal data breach must be notified to the ICO within 72 hours.
- What the organisation checks, and how staff are told. See section 05.
- Consequences. That a breach of this policy may be dealt with under the disciplinary procedure, and that serious misuse, such as unauthorised access to systems or data, may be a criminal matter under the applicable law.
- Signature and review. Signed at induction, re-confirmed when it changes, reviewed at least annually.
What differs in a school, a care service and a charity
Schools and colleges. The staff AUP is part of the safeguarding framework, not only an IT document. KCSIE 2026 says online safety should be reflected in the child protection policy, "which, amongst other things, should include appropriate filtering and monitoring on school devices and school networks" (paragraph 169). It asks governing bodies and proprietors to ensure "appropriate filtering and monitoring systems" are in place, with a review "at least once every academic year" and a record of the checks, and to make sure that "the leadership team and relevant staff have an awareness and understanding of the provisions in place" and "know how to escalate concerns when identified" (paragraph 173). It also points schools to the cyber security standards for schools and colleges as part of information security (paragraphs 178 and 179). The filtering and monitoring standard lists what staff should report, including if they witness or suspect unsuitable material has been created or accessed, or find that they can access unsuitable material. The staff AUP is where each of those expectations becomes a rule a member of staff has signed, and it must agree with the staff behaviour policy. Pupils have their own AUP, written for their age; it is a different document.
Care services. The AUP has to deal with devices that move between people: the handheld on which carers record care notes, the tablet residents use for video calls, the office PC the night staff share. Shared devices make individual logins and screen locks the most important rules in the policy, because the care record is only trustworthy if it shows who wrote each entry. It should say that photographs of residents are taken only on the provider's devices, for a stated purpose, and never kept on a personal phone, and how agency and bank staff get access for a shift and lose it afterwards.
Charities. The AUP has to reach people the charity does not employ. Volunteers and trustees often use their own laptops, phones and personal email for charity business, and a policy written only for employees will not reach the trustee who keeps the board papers in a personal inbox. The workable version is short: charity business in charity accounts, even for volunteers and trustees; a lost device that holds charity data reported the same day; no beneficiary information in personal messaging. The NCSC's cyber security advice for small organisations is written for exactly this size of organisation.
Personal devices: what the policy can and cannot say
Most staff in schools, charities and care services use their own phone for some part of their work, even where the organisation provides devices. An acceptable use policy has to deal with that honestly, because a clause that bans what everyone does is a clause nobody reads.
The National Cyber Security Centre's guidance on personal devices sets the balance: a scheme "requires careful design in order to ensure that it works well for employees", weighing "your organisation's need to protect and maintain control of its data and systems against the usability, and privacy expectations of the device owner". It warns that where the approved approach is too hard, employees "may even find other ways to do their job using 'shadow IT' that are likely to increase your security risk". In a school or a care home, shadow IT usually means a WhatsApp group.
What an AUP can reasonably require of a personal device used for work:
- a screen lock with a PIN, password or biometric, and up-to-date software;
- work accounts accessed through the organisation's apps, not forwarded to personal accounts;
- no photographs of pupils, residents or service users, and no personal data about them saved to the phone or its personal cloud backup;
- a lost or stolen phone that holds work accounts reported the same day;
- work access removed when the person leaves, by closing the account rather than by asking for the phone.
What it cannot do is give the organisation access to the rest of the phone. The organisation can manage its own apps and accounts on a personal device; it cannot read the owner's private messages, and a policy that implies otherwise promises something the law does not allow. The personal mobile phone policy guide covers the rules for phones on site and in front of pupils or residents; the guide to work messages on personal phones covers the organisation's responsibility for what is sent from them.

Making it work: plain rules, open checks, fair enforcement
Most AUPs fail in the same three ways: they are too long to read, they describe checks staff were never told about, and they are enforced inconsistently. Each has a straightforward fix.
- Write it to be read. Two or three pages of rules, in plain language, with a one-page summary staff actually keep. Legal definitions and technical standards go in an appendix or in the IT team's own procedures.
- Say what is checked. The ICO's guidance on monitoring workers says "Workers have the right to be informed about the collection and use of their information", and that you "must tell workers about monitoring in a way that is accessible and easy to understand". It also says workers should be able to "see and, if necessary, explain or challenge the results of any monitoring" within, or alongside, disciplinary or grievance procedures. So the AUP states what the organisation checks (web filtering logs, access to records, use of accounts), why, who sees the results, and that private use of a personal device is not examined. A high-risk form of checking needs a data protection impact assessment first.
- Sign it, and re-sign it. At induction, and again when it changes. In a school, the staff AUP is part of what staff are given at induction under KCSIE; keep a record of who has signed which version.
- Enforce it proportionately. Most breaches are mistakes and need a conversation and a fix; some are misconduct and go through the disciplinary procedure under the Acas Code; a few, such as deliberate unauthorised access or accessing indecent images, are criminal and, in a school or care service, safeguarding matters first.
- Review it with the systems. Annually, and whenever a new system, device or tool is introduced. In a school, review it alongside the annual filtering and monitoring review, so that the policy describes the systems actually in use.
The acceptable use policy is only as good as the match between its rules and the tools the organisation provides. A rule that says "use only approved systems" is kept when the approved systems do the job, and broken when they do not.
The rule most acceptable use policies cannot keep
Almost every staff AUP in a school, a charity or a care service contains a version of the same clause: communication about pupils, residents or service users must use the organisation's approved systems, not personal email or personal messaging apps. It is the right rule. It is also, in most organisations, the rule broken every day, by the people who signed it, often with the knowledge of the people who wrote it.
The reason is not carelessness. Email is too slow for "can someone cover the gate?" and too formal for "is she all right? she seemed upset at pick-up", so the staff group chat does the work, on personal phones, outside the filtering, outside the records, outside the retention schedule and outside the AUP. When something goes wrong, the organisation's own policy is the first document to show that the conversation should not have happened where it did, and the last to explain where it should have happened instead.
The answer is to give the rule a tool that can be used as quickly as the chat it replaces. ComplyChat is a messaging channel the organisation owns: messages are recorded on the server as they are sent, everyone added is told the channel is on the record and can object or leave, and a mobile number verified by SMS is an identity on it, so bank staff, volunteers and others without a work account can be in the same channel as everyone else. On paid plans, once the organisation's Microsoft 365 tenant is connected, the lasting record files there under the organisation's own retention rules. It does not reach or read WhatsApp or any other app on a phone, it is not a filtering or device management system, and it cannot recover conversations that have already happened elsewhere. ComplyChat Free is personal messaging with one private group, direct messages and three calendar months of recent history, with no Microsoft 365 archive; it is a way to try the approach, not an organisational record.
A question for the next leadership or trustees' meeting: our acceptable use policy names the approved systems for talking about the people we look after; if we asked staff which system they used for the last such conversation, what would they say?
Official guidance and your next step
For schools, the primary sources are Keeping children safe in education 2026, paragraphs 123 and 164 to 181, and the Department for Education's digital and technology standards, including the filtering and monitoring and cyber security standards. For every organisation, the ICO's guidance on monitoring workers and the NCSC's personal device guidance. Your local authority, trust, IT service providers or data protection officer will usually have a model staff AUP; an acceptable use policy template is easier to adapt than to write, provided you check every rule against the systems you actually use and the compliance record you will need. Quotations are from those documents as published on 25 September 2026; check the date on any ICO page, because the Data (Use and Access) Act 2025 has amended data protection law and the ICO is still updating its guidance to match.
This guide is a summary for organisations in England, not legal advice. Before using an AUP as the basis for disciplinary action, or introducing any new form of checking staff use of systems, take advice.
Then do one thing: read your AUP's clause on communication, and check whether the system it names is the one staff actually use to talk about the people you look after. If it is not, the clause is either wrong or unkept, and either needs fixing before the next inspection or incident finds it.
We build ComplyChat for the work conversations organisations need to keep. An acceptable use policy is where most organisations already say that those conversations belong on approved systems, and where the gap between the rule and the staff group chat is plainest. ComplyChat gives those conversations a channel the organisation owns; explore Free personal messaging, or compare the paid plans if you need the lasting record in your own Microsoft 365.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Keeping children safe in education 2026 gov.uk
- Filtering and monitoring standard gov.uk
- Section 1 of the Computer Misuse Act 1990 legislation.gov.uk
- Cyber security standards for schools and colleges gov.uk
- Cyber security advice for small organisations ncsc.gov.uk
- Guidance on personal devices ncsc.gov.uk
- Guidance on monitoring workers ico.org.uk


