Image 1 of 1
Acceptable Use Policy Template for Startups & Small Business | People Stack Now
Without a clear Acceptable Use Policy, there is no documented basis for disciplinary action when someone misuses Company systems — and the organization may have compromised its ability to monitor or access its own devices. This policy closes that gap.
Covers: scope (hardware, software, cloud, networks, BYOD), acceptable and unacceptable use, email standards and anti-spam obligations (PECR/CAN-SPAM/CASL/AU Spam Act), device security standards, monitoring obligations with a five-jurisdiction flag (GDPR/UK GDPR, ECPA, PIPEDA, Privacy Act), and breach consequences. Includes specific guidance on AI tools.
FAQS
Q Why does a small business need an Acceptable Use Policy?
Without a documented AUP, the organization has no contractual or policy basis for disciplinary action when someone misuses Company systems. It also creates risk around monitoring — accessing employee communications or logs without a prior communicated policy may be unlawful under GDPR, the Electronic Communications Privacy Act, or equivalent legislation. The AUP establishes the rules, communicates them, and creates the documented framework for both disciplinary action and lawful monitoring.
Q Does the policy cover personal device use (BYOD)?
Yes. The scope section explicitly addresses personally owned devices used for work. It sets out the conditions for permitted BYOD use, the security requirements that apply, the organization's right to require remote wipe of Company data from personal devices, and the employee's responsibility to maintain the device in a state that protects Company data.
Q What does the policy say about monitoring?
The monitoring section balances legitimate business interests with employee privacy rights. It states clearly what may be monitored, the purpose, and that monitoring is not continuous or individually targeted without cause. A five-jurisdiction flag covers GDPR (IE/UK), ECPA and state law (US), PIPEDA (CA), and the Privacy Act / Workplace Surveillance Act (AU) — because the legal requirements differ significantly.
Q Does this policy cover AI tools?
Yes. The unacceptable uses section prohibits entering Confidential Information into public AI tools. This provision works alongside the AI Usage Policy, which provides the full governance framework. For organisations wanting basic AI coverage in a single policy, the AUP provides the foundation; for comprehensive AI governance, the dedicated AI Usage Policy is recommended.
Without a clear Acceptable Use Policy, there is no documented basis for disciplinary action when someone misuses Company systems — and the organization may have compromised its ability to monitor or access its own devices. This policy closes that gap.
Covers: scope (hardware, software, cloud, networks, BYOD), acceptable and unacceptable use, email standards and anti-spam obligations (PECR/CAN-SPAM/CASL/AU Spam Act), device security standards, monitoring obligations with a five-jurisdiction flag (GDPR/UK GDPR, ECPA, PIPEDA, Privacy Act), and breach consequences. Includes specific guidance on AI tools.
FAQS
Q Why does a small business need an Acceptable Use Policy?
Without a documented AUP, the organization has no contractual or policy basis for disciplinary action when someone misuses Company systems. It also creates risk around monitoring — accessing employee communications or logs without a prior communicated policy may be unlawful under GDPR, the Electronic Communications Privacy Act, or equivalent legislation. The AUP establishes the rules, communicates them, and creates the documented framework for both disciplinary action and lawful monitoring.
Q Does the policy cover personal device use (BYOD)?
Yes. The scope section explicitly addresses personally owned devices used for work. It sets out the conditions for permitted BYOD use, the security requirements that apply, the organization's right to require remote wipe of Company data from personal devices, and the employee's responsibility to maintain the device in a state that protects Company data.
Q What does the policy say about monitoring?
The monitoring section balances legitimate business interests with employee privacy rights. It states clearly what may be monitored, the purpose, and that monitoring is not continuous or individually targeted without cause. A five-jurisdiction flag covers GDPR (IE/UK), ECPA and state law (US), PIPEDA (CA), and the Privacy Act / Workplace Surveillance Act (AU) — because the legal requirements differ significantly.
Q Does this policy cover AI tools?
Yes. The unacceptable uses section prohibits entering Confidential Information into public AI tools. This provision works alongside the AI Usage Policy, which provides the full governance framework. For organisations wanting basic AI coverage in a single policy, the AUP provides the foundation; for comprehensive AI governance, the dedicated AI Usage Policy is recommended.