Skip to content

Acceptable Use of IT Policy

Updated April 2026

Version: 6

Date: 1 April 2026

Review date: 1 April 2028

Author: James Underwood, Chief Executive, West Sussex Music Trust

Responsible Officer: Chairman of West Sussex Music Trust

West Sussex Music Trust
Acceptable Use of IT Policy

Introduction

The Acceptable Use of IT Policy (AUP) enables West Sussex Music Trust (the organisation/company) to meet its legal obligations to protect information and data and to ensure it makes best use of its investment in IT by setting out what is acceptable use. It applies to all staff and partner organisations working on our behalf (permanent/temporary staff, agency workers, volunteers, visitors, partners, suppliers and contractors), whether on company premises, remotely, at home or in transit. Use of company systems and data is conditional on compliance with this AUP. The company monitors IT use and access to data; serious breaches may be treated as gross misconduct and, where criminal activity is suspected, reported to the police.

Relevant legislation and guidance 

This AUP should be read alongside the following, which inform our standards and controls:

  • Data Protection Act 2018; UK GDPR
  • Computer Misuse Act 1990; Human Rights Act 1998
  • The Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000
  • Applicable guidance from the National Cyber Security Centre (NCSC)
  • Keeping Children Safe in Education 2023
  • Education and Training (Welfare of Children) Act 2021

These references clarify the legal context for acceptable use and monitoring.

Related Policies

This policy should be read alongside the organisation’s policies on: 

  • Online learning 
  • Social media 
  • Safeguarding and child protection 
  • Staff handbook 
  • Data protection 
  • Privacy Notice

 

1. Use of data and information (corporate & personal) and Information Sharing

Users may only access company information when properly authorised and for a business need. Personal data must be shared internally on a need-to-know basis, handled securely, and not disclosed to unauthorised parties. External sharing requires an Information Sharing Agreement and secure transmission, with authorisation recorded. Working data is stored on company network locations (backed up by the IT provider) and information is retained per the company retention schedule.

2. Passwords, access to corporate systems & Multi-Factor Authentication (MFA)

Passwords are unique to each user and must not be shared. Users must use strong passwords and never disclose these credentials; passwords should be reset immediately if a compromise is suspected. The IT provider may ask you to log in for support but will not request your password. 

Multi Factor Authentication

All employees must set up multi-factor authentication (MFA) on their West Sussex Music Microsoft 365 account. 

Multi-factor authentication (MFA) is an additional layer of security for online accounts. 

MFA helps protect an employee’s personal and financial information. Using MFA reduces the risk of someone gaining access to an employee’s account even if they find out the username and password, for example through a cyber attack or scam. Microsoft research suggests MFA can reduce such attacks by as much as 99.9%.  

MFA is a condition of the policies to which employees agree when signing the contract of employment.

3. Use of the Internet

The organisation’s internet connection is for business use; fair personal use is a privilege and not a right.   The organisation reserves the right to monitor all websites visited, including those accessed as part of fair personal use. Users must consider the company’s reputation at all times and report suspected misuse immediately to their line manager or the IT provider.

Unacceptable use includes (non-exhaustive):

  • Accessing pornographic, exploitative, offensive, discriminatory or criminal content
  • Breaching copyright or other intellectual property rights
  • Repeated/intentional access to malicious sites
  • Posting inappropriate or offensive comments (including cyber-bullying)
  • Overloading the connection (e.g., downloading video for private use)
  • Operating a private business using corporate IT facilities
  • Using tools or mechanisms to obscure traffic or bypass filtering/monitoring controls
  • Attempting to gain unauthorised access to restricted areas or accounts
  • Phishing/financial scams; content promoting unlawful discrimination, extremism or hate
  • Excessive non-work use during working hours

Users should be aware that any access to the internet from the company network can be traced back to the company and so associated with the company. This includes the West Sussex Music email addresses and private email (if accessed via the corporate network), comments made on any web log, discussion groups or WIKIs (web pages open for edit by anyone) and any other form of access to resources made available through the internet.   Users should consider the reputation of the company during any use of the company’s internet connection and avoid any activity that might bring the company into disrepute.

If, as part of fair personal use an email address is required (e.g. when making personal posting to websites, ordering goods and services) a private email address must be used and not a company email address.

Any member of  staff who  feels that  use is  being made  of the  internet to  access inappropriate content should report the matter to their line manager immediately.

Excessive use of the internet for non-work-related reasons will be investigated, and line managers should contact HR for advice.  

4. Use of Social Media (see also: Social Media Policy)

Corporate social media channels meet company brand standards and are resourced professionally. 

Members of staff should make sure their use of social media, either for work or personal purposes, is appropriate at all times.  

For private use, do not imply you speak for the company, do not use the corporate email on personal profiles, and do not post defamatory, illegal or offensive content or unauthorised company information. Cyber-bullying of colleagues or customers will lead to disciplinary action. 

The organisation has comprehensive guidelines for staff on appropriate security settings for social media accounts (see appendix 1). 

5. Work-related use of social networking

The same principles should be followed as above; communicate professionally and moderate any content you create (e.g., blogs) to remove inappropriate comments. Personal views are permitted if they do not bring the company into disrepute.

6. Use of Email and instant messaging

Company email addresses

All employees are provided with a West Sussex Music email address and Microsoft 365 accounts. These addresses are formatted as forename.surname@westsussexmusic.co.uk.  Without exception, ALL business communications must be conducted using this email and under no circumstances should personal email addresses ever be used to communicate company business to parents, schools, colleagues, or any other third party.

Remote working employees access company secure emails via Microsoft 365.

Staff must take care with the content of all email messages, as incorrect or improper statements can give rise to claims for discrimination, harassment, defamation, breach of confidentiality or breach of contract.  

Email messages are required to be disclosed in legal proceedings or in response to requests from individuals under the Data Protection Act 2018 in the same way as paper documents. Deletion from a user’s inbox does not mean that an email cannot be recovered for the purposes of disclosure. All email messages should be treated as potentially retrievable. 

Company information to be included in emails

Employees should ensure that official company information is given on any emails that they send. An example of the email layout is provided below:

John Smith

Visiting Music Teacher

West Sussex Music

This message is intended for the use of only the person(s) (“intended recipient”) to whom it is addressed. It may contain information that is privileged and confidential. Accordingly any dissemination, distribution, copying or other use of this message or any of its content by any person other than the intended recipient may constitute a breach of civil or criminal law and is strictly prohibited. If you are not the intended recipient, please contact the sender as soon as possible.”

CCing

Employees should exercise care not to copy emails automatically to all those copied in to the original message to which they are replying. Doing so may result in disclosure of confidential information to the wrong person.

BCCing

When sending group emails to parents, BCC must be used.  BCC can be used to send group emails to parents of children in the same school only.  

Attachments

Employees should not attach any files that may contain a virus to emails, as the organisation could be liable to the recipient for loss suffered. The organisation has virus-checking in place but, if in doubt, employees should check with our IT provider.

Employees should exercise extreme care when receiving emails with attachments from third parties, particularly unidentified third parties, as these may contain viruses.

Personal use of email

Although the email system is primarily for business use, the company understands that employees may on occasion need to send or receive personal emails using their work address. When sending personal emails, employees should show the same care as when sending work-related emails.  Employees should understand that there is no right to privacy for personal emails sent using the work email address within company networks.

Mailbox Ownership: Unless by specific agreement with a senior manager, users may not use any email address other than one specifically allocated and must not send email from another user’s mailbox unless they have delegated access.

Users must not share email passwords (see Section Two for further details). If users are planning to be absent, they should make appropriate arrangements for mail to be diverted if necessary and set an out-of-office message

Inappropriate or offensive content: An email is a formal document and should be treated accordingly. It is good practice to write an email as though it were a formal letter and might be disclosed, and be aware of etiquette such as upper-case text being considered as shouting at the recipient. Sending inappropriate or offensive mail is expressly prohibited. This includes sending email or messages with pornographic, exploitative, offensive, discriminatory or other inappropriate content or links to such sites. Sending or receiving copyright protected or other licensed material without the appropriate permissions is also prohibited.

Any users receiving mail which they feel falls into any of these categories must report it to their line manager or the IT provider immediately.

Misuse of corporate email addresses: Company email addresses must not be used when ordering goods and services for personal use. A private email address must be used for private orders placed via the corporate Internet connection.

Malicious emails (chain emails / spam / viruses): The circulation of chain email may be regarded as misuse and may result in disciplinary action. If users receive a virus warning it must be sent to the IT provider.

Auto-forwarding from a corporate email account is not permitted. 

Misdirected emails

If staff receive an email in error, the sender should be informed and the email deleted. If the email contains sensitive or confidential information, the user must not make use of that information or disclose that information.  

If staff send an email in error that contains the personal information of another person, they must inform the SLT immediately and follow our data breach procedure. 

Communication: If using instant messaging (where available) to communicate with other company users, users must not use any other instant messaging service in place of the company’s service. Users may make use of their corporate email address for limited social correspondence with other company users noting that it is best practice to remove social content when forwarding on or replying to an email.

7. Use of software on company computers

Only software purchased or approved by the company may be used on company computer systems, as it can be appropriately updated, supported, licenses managed and tested when IT upgrades occur. Users must not install software acquired through other means on to any company owned IT assets, including desktop computers, laptops, tablets or mobile phones as this is likely to introduce an additional security risk to corporate systems.

The use or copying of software without the licensor’s permission is illegal and the terms and conditions of software licenses must always be adhered to. Any person carrying out illegal software copying is legally liable and may be prosecuted.

Changes (other than personalising the appearance) may not be made to the configuration of software except by the IT provider or someone authorised by them to make the changes.

Under no circumstances may peer-to-peer software be loaded to company controlled machines. The use of peer-to-peer software provides others with access to data held on a personal computing device. Frequently this software is used illegally to share copyright protected music or films such as via Napster or Bit Torrent. Peer-to-peer software is not required for any of the company corporately approved software.

There are various groups that provide free software which seeks to disguise the origin of network traffic on the Internet. This type of software is promoted as a privacy protection mechanism. Examples of this software are TOR or Freenet. Use of this kind of software on any company IT asset is strictly forbidden.

Whilst it is user responsibility not to deliberately change the configuration of assigned computer software, it is possible for software to be installed on a machine without the full knowledge of the user (through malicious software embedded in emails or in sites visited). If you discover software that has been installed in an unsolicited manner, contact the IT provider who will assist.

If user needs cannot be met by the software solutions already provided users should discuss the matter first with their line manager and then the IT provider.

If you go onto a website and you are told to download a piece of software such as Adobe or Flash player you should click on ignore.

8. Corporate computers and mobile phones

All IT and communications equipment provided by the company to users is corporately owned and users are expected to take all reasonable measures to prevent damage, loss and theft in accordance with the asset distribution form signed when users take over the equipment.

How to protect your computer and/ or phone:

  • Handle your equipment gently; don’t expose it to liquids, extremes of hot or cold or impact
  • Support physical access controls to company buildings by carrying your identity badges at all times and challenging strangers in controlled areas
  • Prevent other people, whether company users or not, to use your computer or phone unless they are authorised by the company to do so
  • Do not pass your equipment on to other company users for their use unless this re-provisioning is coordinated and authorised by the IT provider
  • Inform the IT provider of any equipment that requires disposal so that the disposal can be carried out by means that conform to the UK Regulations for the disposal of waste electrical and electronic equipment (WEEE) and the restriction of hazardous substances (RoHS)
  • For mobile equipment, not to expose it to unreasonable risk of theft. Think about where you leave it, even if you are in a company building and think the office is secure. Lock it away at the end of your working day.
  • For further policy on remote working see Section Nine.

USB sticks – Users must not save any information from company computers or corporate systems to personal USB sticks. 

No equipment must be left unattended and switched on without the user logging off or locking the device. Equipment must never be left unattended in a public place. If users are away from a computer for any period of time they must prevent unauthorised access by using the Ctrl-Alt-Del keys and select ‘lock computer’ – or pressing the Windows Key and ‘L’. 

Telephony

The telephony system is corporately owned and there is no right to private use. The company reserves the right to monitor telephone calls, including those made as incidental personal use.

Corporate voice services must never be used to make offensive or appropriate calls. Fair personal use of the service is permissible. It is the line manager’s responsibility to determine whether the personal use made by users is impacting adversely on their work. Incidental use of the phone service is that which occurs for short periods, and does not interfere with the individual’s work.

Unacceptable use is that which interferes with an individual’s work, the work of others, results in unreasonable costs for the company or brings increased risks to security or of damage to the company’s reputation.

Excessive use of the voice services for non-work-related reasons will be investigated by line managers. 

Telephones, including smart phones

Internet or email access via mobile telephone is subject to the relevant acceptable use detailed in Sections One and Three of this AUP.

If users need to communicate with customers, citizens or third party organisations via SMS text, they must not send any sensitive personal data via SMS text.

If a corporate mobile phone goes missing, it must be reported immediately to SLT to enable the line to be blocked from further use.

Corporate phones should not be used by friends, family or associates of company employees.

Users may withhold their corporate telephone numbers from members of the public where there is a genuine fear of misuse. In such cases users must give them the main switchboard number.

Mobile phones and accessories remain the property of West Sussex Music and must be returned when users leave employment. All computing devices and telephones must be returned to the company when they are no longer required, or if the individual is leaving the employment of the company.

No more than one personal computing device (desktop PC or laptop) shall be assigned to any individual member of company staff, unless a business case for the use of more than one such device by that individual is approved by the Chief Executive.

9. Mobile & home working

We allow staff to access the organisation’s IT facilities and materials remotely on an organisation provided laptop, and on personal devices only via the company providedMicrosoft 365 account, and SpeedAdmin. 

Staff accessing the organisation’s IT facilities and materials remotely must abide by the same rules as those accessing the facilities and materials on site. Staff must be particularly vigilant if they use the organisation’s IT facilities outside the organisation and must take such precautions as our IT provider may require against importing viruses or compromising system security.  

Our IT facilities contain information which is confidential and/or subject to data protection legislation. Such information must be treated with extreme care and in accordance with our data protection policy. 

The organisation’s Privacy Policy can be found on Staff Zone.  

Users can work out of mobile locations or their home according to their role using a variety of mobile technology, typically laptops, smartphones and/or tablet devices and paper documentation. This section applies to any work that takes place outside of company offices and buildings where there is a risk of theft or loss of company data or information.

All users must be mindful of their environment when mobile working and take all reasonable measures to reduce security risk whilst company data or information is in their possession. This applies when using corporate or personal devices. Users should select an appropriate working environment and seek to prevent inadvertent disclosure of sensitive information by avoiding being overlooked, by using printers in trusted locations or collecting them immediately they are printed and checking print sheets.

Users should be aware of the increased vulnerability of company data and information once it is taken out of the company controlled environment and take additional steps as detailed below to prevent data loss or theft and must choose an appropriate location to hold meetings / have conversations about sensitive topics. Be aware that in public other people will have an interest in the topic of discussion.

Working at home

  • Don’t leave laptops, tablets or phones in a place where it is vulnerable to the opportunist thief
  • Keep them away / out of sight of windows and ideally use a separate room or area to work from and store work related documentation / equipment when at home.

Working with paper documentation

  • Do not leave any paper documents unattended at any time whilst out in public. They must be stored in a folder/wallet or bag but separate to any company device
  • If paper documents are no longer required they must be destroyed by shredding (preferably at company offices) and not placed in domestic rubbish or in public bins/skips
  • Paper documentation containing sensitive personal data must not be shared with a non-company employee without specific authorisation or an Information Sharing Agreement.

Working with company portable devices (laptops / tablets / phones with email)

  • Should be locked away at the end of the working day
  • Encryption for laptops must be fully enabled – if it is not enabled users must contact the IT Service desk immediately
  • Encryption password and network passwords must not be shared with any other users
  • Screen lockouts (Ctrl-Alt-Del) must be used when leaving your desk
  • Must not be left overnight in vehicles
  • Must not be left unattended at any time whilst out in public and must be kept out of sight of the opportunist thief
  • Must be connected to the corporate network every 30 days to update security settings and software
  • Can only be used by authorised individuals and not shared with family members/ friends or other persons.

Any loss or theft of a company device must be notified to the Senior Leadership Team immediately. 

Business critical data should be stored on the company’s server wherever possible and not held on the device

Users must not remove or deface any asset registration number.

Using personal devices (including smartphones/tablets and laptops) for work purposes

  • Prevent any sensitive data being left on screen and from being overlooked
  • Ensure that personal computing devices have current anti-virus software
  • Must only be used by authorised individuals and not family members/friends or other persons when logged onto the company network.
  • Devices must be secured with passwords and other security protection (e.g. biometric access)

10. Internetbased (“cloud”) file storage

Users can access file storage online, this is typically referred to as online or cloud based storage.   Typically, this type of facility is linked to an internet based email account, or to subscription services – provided through an internet provider such as BT or Virgin (examples being Microsoft’s Skydrive linked to Hotmail; Apple’s iCloud; Google’s google drive; DropBox; BT’s Digital Vault). The company provides all employees with One Drive and SharePoint access via their Microsoft 365 account.

Online storage enables users to access their files wherever they have internet access; however this type of storage is outside of the management of the company’s security controls that protect users and information. 

Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

Using online storage to store personal data relating to employees, customers or residents; commercially sensitive information, company intellectual property or any other sensitive information or work related data is not permitted.

11. Data security controls 

11.1 Passwords

Whilst computing devices and systems may have security policy enforced through technology and users maintain good security behaviours, it is still paramount that passwords are unique to each user and not shared (including with managers or the IT provider) as they are the gateway between the individual user and the device / system.

If your password is compromised, the system and all data / information held on it can also be assumed to have been compromised. This could typically include customer data but also your employee data such as personal banking details. Therefore protecting your password will protect you from identity theft.

If the IT provider needs to access user accounts to provide support they will ask users to log in for them and will not request their password. Users will be accountable for all actions carried out with their username and password.

11.2 Updates, firewalls & antimalware

Company devices are configured for regular/automatic security and firmware updates and to run approved antimalware. Users must not attempt to disable or bypass these controls.

11.3 Access to facilities and materials

Access rights are rolebased and centrally managed by/with the IT provider. Do not access systems/files/devices to which you have not been granted access. Lock/log out when not in use and at the end of each working day.

11.4 Encryption

Company systems apply appropriate encryption. Personal devices may only access company data where expressly authorised and where the device meets company encryption/security standards.

12. Protection from cyber attacks 

The company will:

  • Maintain layered, proportionate controls; keep them up to date; and regularly review/test effectiveness.
  • Maintain a documented incident response plan, covering roles, communications if systems are down, lawenforcement/Action Fraud reporting, and postincident review; test it at least annually.
  • Require MFA on company and personal devices which use company IT accounts and systems; conduct periodic access reviews (leastprivilege/admin rights); and use a password manager for workforce credentials.
  • Operate an alwayson firewall on company IT equipment and keep endpoint protections current.
  • Apply secure backup practices for Microsoft 365 and other critical systems with defined retention and periodic restore testing (tool/vendor names are not specified in policy).
  • Assess supplier security, including checking for certifications such as Cyber Essentials (or equivalent) where appropriate to the service.
  • Not engage with ransom demands; recovery will follow the incident plan and backups.

13. Monitoring & review (updated)

To protect company systems and uphold this policy, authorised senior personnel may filter and monitor use of company IT (including websites visited, bandwidth usage, email accounts, telephony, user activity/access logs and other electronic communications) to the extent permitted by law. 

  • The organisation monitors IT use in order to: 
  • Obtain information related to organisation business 
  • Investigate compliance with organisation policies, procedures and standards 
  • Ensure effective organisation and IT operation 
  • Conduct training or quality control exercises 
  • Prevent or detect crime 
  • Comply with a subject access request, Freedom of Information Act request, or any other legal obligation 

Findings may be used to obtain information related to company business, investigate compliance, ensure effective operation, conduct training/quality assurance, prevent/detect crime, and meet legal obligations (e.g., subject access/Freedom of Information requests where applicable). The Senior Leadership Team oversees effectiveness reviews with the IT provider. 

14. Summary of Unacceptable Use

The following is considered unacceptable use of the organisation’s IT facilities. Any breach of this policy may result in disciplinary proceedings. 

  • Unacceptable use of the organisation’s IT facilities includes: 
  • Using the organisation’s IT facilities to breach intellectual property rights or copyright  
  • Using the organisation’s IT facilities to bully or harass someone else, or to promote unlawful discrimination 
  • Breaching the organisation’s policies or procedures 
  • Any illegal conduct, or statements which are deemed to be advocating illegal activity 
  • Online gambling, inappropriate advertising, phishing and/or financial scams 
  • Accessing, creating, storing, linking to or sending material that is pornographic, offensive, obscene or otherwise inappropriate or harmful  
  • Consensual and non-consensual sharing of nude and semi-nude images and/or videos and/or livestreams  
  • Activity which defames or disparages the organisation, or risks bringing the organisation into disrepute  
  • Sharing confidential information about the organisation, its pupils, or other members of the organisation’s community 
  • Connecting any device to the organisation’s IT network without approval from authorised personnel  
  • Setting up any software, applications or web services on the organisation’s network without approval by authorised personnel, or creating or using any programme, tool or item of software designed to interfere with the functioning of the organisation’s IT facilities, accounts or data 
  • Gaining, or attempting to gain, access to restricted areas of the network, or to any password protected information, without approval from authorised personnel 
  • Allowing, encouraging or enabling others to gain (or attempt to gain) unauthorised access to the organisation’s IT facilities 
  • Causing intentional damage to the organisation’s IT facilities 
  • Removing, deleting or disposing of the organisation’s IT equipment, systems, programmes or information without permission from authorised personnel 
  • Causing a data breach by accessing, modifying, or sharing data (including personal data) to which a user is not permitted by authorised personnel to have access, or without authorisation 
  • Using inappropriate or offensive language  
  • Promoting a private business, unless that business is directly related to the organisation 
  • Using websites or mechanisms to bypass the organisation’s filtering or monitoring mechanisms.  Engaging in content or conduct that is radicalised, extremist, racist, antisemitic or discriminatory in any other way   
  • This is not an exhaustive list. The organisation reserves the right to amend this list at any time. The CEO will use their professional judgement to determine whether any act or behaviour not on the list above is considered unacceptable use of the organisation’s IT facilities. 

15. Agreement

On an annual basis, all users are required to read, confirm their understanding and agree to comply with this policy by physical signing or digital form submission, the agreement in Appendix 2.

Appendix 1- Social Media – Guidance for staff 

10 rules for staff on social media 
  1. Change your display name – e.g. use your first and middle name, use a maiden name, or put your surname backwards instead 
  2. Change your profile picture to something unidentifiable, or if you don’t, make sure that the image is professional 
  3. Check your privacy settings regularly 
  4. Be careful about tagging other staff members in images or posts 
  5. Don’t share anything publicly that you wouldn’t be happy showing your pupils 
  6. Don’t use social media sites during organisation hours 
  7. Don’t make comments about your job, your colleagues, our organisation or your pupils online – once it’s out there, it’s out there 
  8. Don’t associate yourself with the organisation on your profile (e.g. by setting it as your workplace, or by ‘checking in’ at an event) 
  9. Don’t link your work email address to your social media accounts. Anyone who has this address (or your personal email address/mobile number) is able to find you using this information 
  10. Consider uninstalling unnecessary social media apps from your phone. The app recognises WiFi connections and makes friend suggestions based on who else uses the same WiFi connection (such as parents or pupils) 

  Check your privacy settings 

  • Change the visibility of your posts and photos, e.g.  to ‘Friends only’, rather than ‘Friends of friends’. Otherwise, pupils and their families may still be able to read your posts, see things you’ve shared and look at your pictures if they’re friends with anybody on your contacts list 
  • Don’t forget to check your old posts and photos – limit the visibility of previous posts 
  • The public may still be able to see posts you’ve ‘liked’, even if your profile settings are private, because this depends on the privacy settings of the original poster 
  • Google your name to see what information about you is visible to the public 
  • Prevent search engines from indexing your profile so that people can’t search for you by name – go to bit.ly/2zMdVht to find out how to do this on Facebook 
  • Remember that some information is always public: your display name, profile picture, cover photo, user ID (in the URL for your profile), country, age range and gender  

 What to do if … 

 A pupil adds you on social media 

  • In the first instance, ignore and delete the request. Block the pupil from viewing your profile 
  • Check your privacy settings again, and consider changing your display name or profile picture 
  • If the pupil asks you about the friend request in person, tell them that you’re not allowed to accept friend requests from pupils and that if they persist, you’ll have to notify senior leadership and/or their parents/carers. If the pupil persists, take a screenshot of their request and any accompanying messages 
  • Notify the senior leadership team/Chief Executive about what’s happening 

 A parent/carer adds you on social media 

It is at your discretion whether to respond. Bear in mind that: 

  • Responding to 1 parent/carer’s friend request or message might set an unwelcome precedent for both you and other teachers 
  • Pupils may then have indirect access through their parent/carer’s account to anything you post, share, comment on or are tagged in 
  • If you wish to decline the offer or ignore the message, consider drafting a stock response to let the parent/carer know that you’re doing so 

 You’re being harassed on social   media, or somebody is spreading something offensive about you 

  • Do not retaliate or respond in any way 
  • Save evidence of any abuse by taking screenshots and recording the time and date it occurred 
  • Report the material to social media or the relevant social  network and ask them to remove it. If the perpetrator is a current pupil or staff member, speak to a senior leader in the first instance. 
  • If the perpetrator is a parent/carer or other external adult, a senior member of staff should invite them to a meeting to address any reasonable concerns or complaints and/or request they remove the offending comments or material 
  • If the comments are racist, sexist, of a sexual nature or constitute a hate crime, you or a senior leader should consider contacting the police 

Appendix 2- Acceptable use agreement for staff and trustees  

Acceptable use of the organisation’s IT facilities and the internet:  agreement for staff and trustees 
When using the organisation’s IT facilities/systems and accessing the internet in organisation, or outside organisation on a work device, I will not:  

  • Access, or attempt to access inappropriate material, including but not limited to material of a violent, criminal or pornographic nature (or create, share, link to or send such material) 
  • Use them in any way which could harm the organisation’s reputation 
  • Access social networking sites or chat rooms 
  • Use any improper language when communicating online, including in emails or other messaging services 
  • Install any unauthorised software, or connect unauthorised hardware or devices to the organisation’s network 
  • Share my password with others or log in to the organisation’s network using someone else’s details 
  • Share confidential information about the organisation, its pupils or staff, or other members of the community 
  • Access, modify or share data I’m not authorised to access, modify or share 
  • Promote any private business, unless that business is directly related to the organisation 
I understand that the organisation will monitor the websites I visit and my use of the organisation’s IT facilities and systems. 

I will take all reasonable steps to ensure that work devices and work data are secure and password-protected when using them outside organisation, and keep all data securely stored in accordance with this policy and the organisation’s data protection policy. 

I will let the designated safeguarding lead (DSL) and SLT know if a pupil informs me they have found any material which might upset, distress or harm them or others, and will also do so if I encounter any such material. 

I will always use the organisation’s IT systems and internet responsibly, and ensure that pupils in my care do so too. 

Signed (staff member/trustee/volunteer): 

 

  

Date: 
Back To Top