ComplyChat Start free

Guide · Work messaging

Staff messaging policy

A staff messaging policy is the document that decides where the organisation’s conversations live. Most organisations have a policy on email and one on social media and nothing in between, which is where the work now happens: the shift group, the class team chat, the trustees’ thread, the direct message to a manager at nine at night. The best published model of the missing document was written by the Cabinet Office for civil servants after the same discovery, and its rules transfer to any organisation with a duty to keep records: use the organisation’s systems for the organisation’s business; treat WhatsApp, private email and SMS as channels that do not give the organisation access to what is in them; and accept that using them for anything significant “engages your recordkeeping responsibilities”. This guide sets out what a staff messaging policy has to say about channels, about the record, about hours and expectations, about personal phones and about what the organisation may look at, with the regulators’ own words where they exist, and the one paragraph that most policies leave out.

11 minute read

A charity’s operations manager pins the last page of a new policy to a corridor noticeboard while two colleagues read the first, the pages blank at this distance
01

The model: the Cabinet Office’s rules for its own staff

The Cabinet Office guidance on non-corporate communication channels (March 2023) is government policy for central government and its arm’s length bodies, and it is quoted here because it is the most carefully written messaging policy in the public domain. Its goals are the ones any organisation would write: “To facilitate efficient day-to-day government discussions in a modern way; To reduce risks to the security of information; To comply with the principles of good government, including record-keeping, accountability and transparency.” Its first principle is ownership: “Government communications belong to the Crown and must be handled lawfully. If you hold such communications in NCCCs you do so on behalf of your department.” Its second is the default: “Departments should, as far as reasonably practicable, enable approaches in their core systems that reduce the need for NCCCs”, and “In general, it is expected that you use government systems for government business.”

Its definitions are the ones a policy needs. “Government systems” are “corporately-overseen systems providing corporate access to the information held in them. In contrast, an NCCC is a communication channel that does not provide corporate access to information.” The examples are the apps every staff group uses: “WhatsApp, Signal; private email; private messaging on social media platforms e.g. Facebook or LinkedIn; and SMS text messaging.” And the test of what may go where is the significance of the information, not the seniority of the sender: “Significant government information is information that materially impacts the direction of a piece of work or that gives evidence of a material change to a situation.”

The rule that follows is a two-by-two: on a corporately managed device, non-corporate channels may carry logistics with “professional judgement” and significant information only with “particular care”; on “a privately owned and managed device” significant information needs “exceptional circumstances” and “any use in these circumstances should be reported”, logistics are “permitted with due regard to your security responsibilities”, and the most sensitive material “must not” use them at all. Then the sentence that makes it a records policy and not a security one: “Any use of NCCCs for significant government business engages your recordkeeping responsibilities.” A school, a charity or a care service can adopt that structure in a page.

02

Channels: which for what

The first section of the policy is a table, and the organisation has to fill it in honestly, listing the channels staff actually use rather than the ones it wishes they used. For each: whether it is the organisation’s (it can access, export and retain what is in it) or not; what it may carry; and what it must never carry. A workable classification for the sectors this guide is written for:

  • The organisation’s own channels (its email, its messaging system, its records system): the default for all work conversations, and the only place for anything about a named pupil, resident, service user, donor, parent or colleague, for decisions, and for anything a regulator could ask about.
  • Non-corporate channels on any device (WhatsApp, Signal, SMS, private email, social media messaging): logistics only, meaning arrangements that identify nobody and decide nothing: “running ten minutes late”, “can anyone cover Thursday”. Groups on these channels are for the same purpose and nothing else, and the policy says who may create one and who closes it when the purpose ends.
  • Never on a non-corporate channel: images of the people the organisation serves, safeguarding detail, health information, bank or payment details, and anything that a member of staff would not want read out at a tribunal, which is the plain-English test staff remember.

A word on platform settings, because half of what is published under this heading is about them. A messaging platform the organisation runs has an admin side: Microsoft Teams, for example, lets a Teams admin set messaging policies (a default policy and custom policies assigned to groups of users) that decide whether users can edit or delete sent messages, use read receipts, priority notifications, GIFs, memes and emojis, or the immersive reader. Those settings implement part of a policy; they are not the policy. Whether staff may discuss a resident in a group chat, what is inappropriate, when notifications may be sent, and where a message about a person has to end up are decisions about conduct and records that no admin centre can make, and the document is where they are made. Set the platform to match the document, not the other way round.

The sector rules sit behind the table. Keeping children safe in education 2026 requires the staff behaviour policy to cover “acceptable use of technologies (including the use of mobile devices), staff/pupil relationships and communications including the use of social media”, so a school’s messaging policy is part of that document. CQC’s Regulation 17 requires “an accurate, complete and contemporaneous record” of care and of “decisions taken”, and Regulation 16 makes “any further correspondence with the complainants” producible to CQC within 28 days, so a care provider’s table has to say where a text from a family member goes.

03

The record: where every message that matters has to end up

The second section is the one that distinguishes a records policy from an etiquette guide. Its rule is the Cabinet Office’s: using a non-corporate channel for anything significant “engages your recordkeeping responsibilities”, and the person who used it is the person responsible for the record. The policy lists the triggers in the organisation’s own terms (a concern about a person; a decision; an instruction; a complaint; an incident; a change to someone’s care, placement or role; anything a regulator, an inspector or a court could ask about), and for each the rule is the same: the message is transferred to the organisation’s record that day, with its time and sender, by the person who received it, and the entry in the record says where it came from.

The policy should say why, because staff follow rules they understand. The ICO’s right of access guidance is the reason for the individual: information staff hold on personal devices “may be within scope if you receive a SAR”, and the organisation “should ask them to search their private emails, devices or instant messaging applications”. The regulator’s record duty is the reason for the organisation: the care record, the safeguarding chronology and the complaints file are only as complete as the day the first message reached them. And the tribunal is the reason for both: relevant messages “which may harm your case as well as those which may help it” must be disclosed, and the ones on personal phones are the ones the organisation cannot find when it needs them.

The policy also sets retention for the organisation’s own channels, in line with its retention schedule, and says plainly that no retention can be promised for a non-corporate channel: whatever is there is there until the app, the phone or the person removes it.

04

Hours, expectations and tone

The third section is the one staff read first. It says when messages may be sent and when a reply is expected, and it separates the two: a manager may write at nine at night and a member of staff is not expected to answer until the working day, unless the policy names an on-call arrangement and pays for it. It says which channel is used for something urgent, and that a message in a group is not an instruction to any individual until it is addressed to one. It sets expectations of tone in a sentence or two, with the reminder that every message in a work channel is a work record: readable by the organisation, producible to a requester, and quotable in a hearing.

It covers groups specifically: purpose, membership, who administers, no adding of people from outside the organisation without agreement, no images of the people the organisation serves, and closure when the purpose ends. It covers leaving: what happens to a departing member of staff’s access to the organisation’s channels on the day they leave, and the expectation that work information on their own devices is returned or deleted. And it covers the two conversations most policies forget: with the people the organisation serves and their families, where the organisation decides which channels it offers them, and with trustees or governors, who are bound by the same policy and are the group most likely to have created their own chat.

A hospice ward manager at a nurses’ station types on a wall-mounted workstation while her personal phone lies face down on the counter
05

What the organisation will and will not look at

The fourth section is where a policy is most often unlawful, and the ICO’s employment guidance on monitoring workers is the reference. The organisation may check its own channels, and the policy says so, with the purposes: “you must tell workers about monitoring in a way that is accessible and easy to understand”, and “Monitoring conducted without transparency is unfair and could negatively impact trust relationships.” The organisation may not read a worker’s own phone, install anything on it, or capture the worker’s private use of a personal device: “You should ensure that when workers are using their own personal devices for work, you are not capturing their private use of their device.” Checking without telling is justified only “in very exceptional circumstances”, which a messaging policy should not attempt to define for itself.

So the policy states the asymmetry plainly. Messages on the organisation’s channels are the organisation’s records, kept, searchable and producible, and everyone in them is told so. Messages on staff’s own phones are the worker’s, and the organisation’s only route to the work-related ones is to ask the worker to search and produce them, which the policy makes a duty when a request or a dispute requires it. Written that way, the policy is lawful, and it gives staff a reason to keep work conversations on the organisation’s channel that has nothing to do with being watched: it is the only place the organisation can protect them from a dispute about what was said.

06

The paragraph most policies leave out

Every messaging policy on the pattern above contains an instruction it cannot enforce: use the organisation’s channel for anything that matters. The instruction fails at the moment it is needed, which is the moment a teaching assistant on a playground, a carer in a corridor or a volunteer at a hall door has something to say about a person and a phone in their hand. If the organisation’s channel is an email system on a desktop in an office, the message goes on WhatsApp, the policy is breached, and the record begins with the entry typed up later. The first message, the one that shows when the organisation knew, is on a phone it cannot read.

The paragraph most policies leave out is therefore the one that says what the organisation’s channel is on a phone: a channel as fast as the app it replaces, on any device including a personal one, where the message is on the record with its time as it is sent, and the worker’s own conversations stay in the worker’s own apps. With that paragraph the rest of the policy becomes possible to follow; without it the policy is a description of a breach the organisation has scheduled. Two limits, stated plainly and including for products like ours: no channel can recover conversations that have already happened elsewhere, and no channel is a policy; the table of channels, the record rule, the hours and the limits on looking still have to be written down and adopted.

A question for the next leadership or trustees’ meeting: read the policy’s instruction for a concern about a person, then ask the newest member of staff where they would actually send it from the corridor. If the two answers differ, the policy is describing the organisation it wishes it were.

07

Official guidance and your next step

The primary sources are the Cabinet Office’s Non-corporate communication channels for government business (March 2023), which applies to central government and is quoted here as the model; the ICO’s right of access guidance on finding and retrieving information and its employment guidance on data protection and monitoring workers; Keeping children safe in education 2026 on the staff behaviour policy; and CQC’s guidance on Regulation 16 and Regulation 17. The ICO’s guidance applies to every controller under UK GDPR; the Cabinet Office’s only to government, which is why it is a model here and not a rule.

This guide is a summary of published guidance for England, not a substitute for it and not legal advice. A messaging policy touches employment contracts, data protection and, in regulated settings, the conditions of registration; take advice on the parts that bind individual staff.

Then do one thing: list every channel the organisation’s staff used for work in the last week, including the ones it does not run, and mark for each whether the organisation could produce last Tuesday’s messages from it. The policy is the answer to the second column.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. A messaging policy that tells staff to use the organisation’s channel needs a channel that works from a corridor, and that is what ComplyChat is: a channel your organisation owns, on any phone including a personal one, on the record from the first message, filing into your own Microsoft 365 once your tenant is connected and kept under your own retention rules, with everyone in it told it is on the record. A member of staff’s own messages stay in their own apps, where nothing lawful can read them. There is no WhatsApp, Signal or Meta anything in the path, and we cannot see a personal phone. It is not a policy and it does not replace one; it is the channel the policy names.

How it works · Why us · Pricing · FAQ