IT, email and social media policy

An IT, email and social media policy that sets the rules for the employer's systems and the employee's own accounts, drafted for the employer as part of the staff handbook and core policies, £995 in five working days.

Share

IT, email and social media policy

Buy now, £995

The IT policy is the one that governs most of what employees do all day: what they may use the employer's systems for, how they must keep them secure, what the employer monitors and on what basis, and what they may say about the business on their own social media. It has to be lawful on monitoring, which the data protection regulator has detailed views about, clear on personal social media, which is where dismissals are challenged, and specific on the accounts and content that belong to the business. I draft the policy for the employer as part of the handbook and core policies for a fixed fee of £995, delivered in five working days.

Who this is for

Employers in England and Wales of any size whose staff use email, systems, devices and social media, and employers whose policy predates the regulator's guidance on monitoring workers.

What matters in an IT, email and social media policy

Acceptable use of the employer's systems and personal use

The policy should state what the employer's email, internet, systems and devices may be used for, whether and within what limits personal use is permitted (reasonable personal use outside working time is the usual position, with the employer's right to see it explained), what is prohibited (offensive, discriminatory or illegal content, unauthorised software, circumventing security, accessing colleagues' accounts, which may be an offence under the Computer Misuse Act 1990), and the rules on storing personal files on work systems; a policy that bans all personal use is ignored, and one that is silent leaves the employer unable to act.

Security obligations every employee carries

The policy should set the security rules (passwords and multi-factor authentication, locking devices, phishing awareness and reporting, no sharing of credentials, approved software and storage only, secure handling of attachments and links, reporting of lost devices and suspected breaches immediately), the data classification and handling rules where the employer has them, and the statement that a security breach caused by disregard of the rules is a disciplinary matter; the employer's own obligations under Article 32 of the UK GDPR to keep personal data secure are discharged through staff, and the policy is the instruction.

Monitoring, the privacy notice and the lawful basis

An employer may monitor its systems (email, internet, device activity, location on company devices) only in a way that is lawful, fair and transparent under the UK GDPR and the Data Protection Act 2018, which the Information Commissioner's guidance on monitoring workers interprets as requiring a clear purpose, a lawful basis, a data protection impact assessment for intrusive monitoring, the minimum intrusion that achieves the purpose, and workers told what is monitored and why; interception of communications is governed by the Investigatory Powers Act 2016 and the Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018, and the policy should state what is monitored, refer to the staff privacy notice, and avoid covert monitoring except in the narrow circumstances the guidance allows.

Social media in the employee's own name

The policy should set the rules for personal social media: no disclosure of confidential information or client details, no posts that bring the employer into disrepute, no harassment of colleagues or customers (which the Equality Act 2010 and the anti-harassment policy cover wherever it happens), no statements on the employer's behalf without authority, a disclaimer where the employee identifies the employer, and the recognition that posts in personal time about personal matters are the employee's own; dismissals for social media posts are upheld where the policy was clear and the post damaged the employer, and overturned where the policy was vague, and the policy should be the former.

Confidentiality, intellectual property and the accounts the business owns

The policy should state that the employer's social media, advertising, domain and online accounts belong to the employer and are operated under its control with credentials it holds, that content created for the employer in the course of employment belongs to it under section 11 of the Copyright, Designs and Patents Act 1988, that professional networking connections made for the business are addressed in the contract, and that on leaving the employee hands over accounts and content and does not change passwords or delete material; a brand whose accounts are in a departing employee's name has learnt why the policy matters.

The policy should state that breaches are dealt with under the disciplinary procedure, with examples of what is gross misconduct (deliberate security breaches, accessing colleagues' data, harassment online, disclosure of confidential information), that the employer may suspend access during an investigation, that investigations use the monitoring data the privacy notice describes, and that the employee may be asked to account for activity on their accounts; the policy should be non-contractual, acknowledged on issue, and reviewed as the technology and the guidance change, with the bring your own device policy and the data protection policy for staff alongside it.

What it costs

Staff handbook and core policies, £995. Five working days.

Employment contract, £595. One template you can reuse for a grade of staff. Five working days.

Buying online forms the engagement on payment. The scope is what the employment contracts and handbooks page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how you employ people
  • Restrictive covenants drafted at a scope a court will uphold
  • Confidentiality and intellectual property provisions that put ownership where it belongs
  • The statutory particulars, so the document does the job section 1 of the Employment Rights Act 1996 requires it to do
  • Flexibility clauses where you genuinely need them, drafted to survive challenge
  • Core policies: disciplinary, grievance, sickness absence, equal opportunities, data protection and, increasingly, AI use
  • One round of amendments

What is not included

  • Acting for employees
  • Employment tribunal representation
  • Payroll, pensions auto-enrolment and tax
  • Immigration and sponsor licence work
  • Day to day HR handling, disciplinaries, grievances and redundancy processes

Questions I am often asked

Can we read our employees' work emails?

Within a policy that tells staff what is monitored and why, with a lawful basis and no more intrusion than the purpose needs, under the regulator's guidance. Routine reading of personal emails on a work account is harder to justify than targeted access for a stated purpose.

Can we discipline an employee for a post on their personal account?

If the policy was clear, the post was connected to the employer (confidential information, disrepute, harassment of colleagues) and the sanction was proportionate. A vague policy and a post about the employee's private life do not support dismissal.

Who owns the business's Instagram account if the employee set it up?

The employer, under the policy and the contract, with credentials held by the employer. The policy says so; transferring the account before the employee leaves is the practical step.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.