An acceptable use policy (AUP) sets out how employees may use company equipment, networks, and data, and what kinds of use are prohibited.
An acceptable use policy (AUP) is a document that sets out how employees may use company equipment, networks, and data - and which uses are prohibited. It is the agreement behind every handed-over laptop and phone: the organisation provides the kit, and the user accepts the rules that come with it. The term comes from computing, where an AUP governed who could do what on a shared network; today it covers the whole working setup - devices, internet access, email, cloud accounts, and the data that flows through all of them. Because most of that kit is a data-bearing device, the AUP is as much about protecting data as protecting hardware.
In plain terms, the AUP meaning is simple: it is the rulebook for using company technology safely and lawfully, written so an ordinary employee can read it and know where the lines are. It sits alongside the asset management policy, which governs the kit from the organisation’s side, and it is the document people actually sign when equipment changes hands.
What you will learn
- What an AUP covers
- Acceptable use policy examples (clauses you can adapt)
- Common rules for laptops and phones
- How to write an acceptable use policy
- Who needs to sign an AUP
- Why staff sign at equipment handover
- BYOD and remote work: extending the AUP to personal devices
- What happens when the AUP is violated
- AUP vs BYOD, IT security, and data-retention policies
- The AUP at end of employment and end of device
- Common mistakes
- FAQ
What an AUP covers
The typical policy addresses, in plain language:
- Equipment care and custody - the device stays with the named holder, gets reported promptly if lost, damaged, or stolen, and comes back at the end of employment.
- Permitted and prohibited use - whether reasonable personal use is allowed, and the hard bans: illegal content, harassment, unlicensed software, side businesses on company kit.
- Internet and network use - what the company connection is for, what categories of site or service are off-limits, and the expectation that work traffic comes first.
- Security behaviour - locking screens, not sharing credentials, not disabling protections, not plugging in unknown drives.
- Data handling - what may be stored locally, what must stay in approved systems, and what may never leave the organisation.
- Monitoring and consequences - what the employer may inspect or log, and what happens when the rules are broken.
The list above is the skeleton; the sections below turn each part into the kind of concrete clause searchers actually want to lift into their own document.
Acceptable use policy examples (clauses you can adapt)
People searching for acceptable use policy examples are usually after sample clauses they can paraphrase, not legal boilerplate. Here are the kinds of clauses a workplace AUP contains, grouped by theme. Treat them as patterns to adapt to your own systems and local law - not a finished template.
- Internet and web browsing - “Company internet access is provided primarily for work. Reasonable personal browsing is permitted during breaks, provided it is lawful, does not consume excessive bandwidth, and does not expose the network to risk.” Sites involving illegal content, gambling, or malware are typically named as off-limits.
- Email and messaging - “Company email and messaging accounts are for business use. Do not send confidential data to personal addresses, forward chain mail, or use the account in a way that misrepresents the company.” Many policies add that email is a company record and may be retained.
- Social media - “Do not post on the company’s behalf without authorisation, and do not disclose confidential or client information. Personal opinions posted from personal accounts should not be presented as the company’s position.”
- Passwords and credentials - “Do not share passwords, reuse a personal password for a work account, or write credentials down where others can find them. Enable multi-factor authentication (MFA) where it is offered.” Credential hygiene is one of the most common clauses in modern policies.
- Software installation - “Only install software approved by IT. Do not install unlicensed, pirated, or unvetted applications, and do not disable security tools or updates.”
- Removable media - “Do not connect unknown USB drives or external storage to company devices. Use only approved media for transferring company data.”
- Reasonable personal use - “Limited personal use of company equipment is permitted where it does not interfere with work, breach any other clause of this policy, or store personal files that displace work data.”
A practical AUP rarely needs more than a page or two of clauses like these. The art is keeping them specific enough to enforce and short enough that people read them.
Common rules for laptops and phones
The clauses that earn their keep are the boring ones. No personal cloud accounts for work files - because that is where data goes missing when someone leaves. No family members using the work laptop - because “my kid installed it” is a real incident category. Report damage immediately rather than at return - because a cracked screen discovered eleven months later is unattributable. And return the device itself, not a factory-reset shell: wiping is the organisation’s job, done through proper data sanitization, so that evidence and data are handled deliberately rather than destroyed by a well-meaning leaver.
The same logic applies to phones. A work phone holds email, messaging, and saved logins, so the AUP usually requires a screen lock or biometric unlock, prompt reporting if it is lost, and no jailbreaking or sideloading. None of these rules are exotic - they are simply the everyday habits that keep a data-bearing device from becoming a breach.
How to write an acceptable use policy
A lot of acceptable use policy template searches are really “how do I create one”. You do not need a download - you need a method. A workable AUP comes together in eight steps:
- Define scope and who it applies to. Name the people covered - employees, contractors, temporary staff, and any external clients or partners who get access or equipment.
- List the covered assets and systems. Laptops, phones, tools, the network, email, cloud accounts, and any line-of-business systems. An information asset register or general asset register makes this list easy to keep current.
- Set permitted versus prohibited use. State the reasonable-personal-use allowance and the hard bans clearly, so there is no guessing.
- State security and data-handling rules. Passwords and MFA, screen locks, approved software, removable media, and where company data may and may not live.
- Disclose monitoring. Tell people what may be logged or inspected, up front, so monitoring is transparent rather than a surprise.
- State the consequences. Spell out what happens when the rules are broken (see below) - an unstated consequence is hard to enforce.
- Capture a signed acknowledgement at handover. The signature is what turns a document into an agreement; collect it when equipment and access are issued.
- Review and re-acknowledge on material change. Revisit the policy on a schedule and whenever something material changes - new tools, new working patterns - and have people sign again.
Follow those steps and the policy gets a spine: scope, assets, rules, security, monitoring, consequences, signature, review.
Who needs to sign an AUP
An AUP only protects you if the people it governs have actually agreed to it, so be explicit about who signs:
- Employees sign at onboarding, at the moment they receive equipment and accounts.
- Contractors and temporary staff sign per their engagement terms - often a shorter form covering the same security and data rules for the duration of the work.
- External clients and partners who are issued assets or given access sign too. In a system with a dedicated Client role, those external assignees see only their own assets, but the use rules still apply to them.
Whoever signs, the principle is the same one behind a hand receipt or an equipment loan agreement: the acknowledgement is tied to the person and the kit they hold, and it is recorded where you can find it later.
Why staff sign at equipment handover
An AUP works through acknowledgement. The standard pattern: the policy is signed during onboarding, at the same moment the laptop, phone, or toolkit changes hands, so the rules and the responsibility start together. The signature does two jobs - it makes the rules enforceable, and it removes the “nobody told me” defence. The handover record matters as much as the signature; in AMPthilly, checkouts capture who received which asset and when, with returns logging condition and notes, which pairs naturally with a signed AUP kept on file.
BYOD and remote work: extending the AUP to personal devices
Hybrid and remote work pushed the AUP beyond the company laptop. When people use personal phones and home networks for work - bring your own device, or BYOD - the policy has to say what good behaviour looks like off the office network:
- Secure connections - using a VPN or an approved secure network for work, not open public Wi-Fi, when handling company data.
- MFA on company accounts - so a stolen password on a personal device does not become an open door.
- No company data on personal cloud accounts - work files stay in approved systems, not a personal drive or photo library.
- Confidential data on home networks - sensible handling of sensitive information when working from home, including who else can see the screen.
- The exit clause - company data on a personal device is removed when the person leaves, the same way a company device is wiped.
This is where the AUP and BYOD rules meet. Many organisations simply fold the personal-device rules into the AUP rather than maintaining a separate BYOD document, which keeps one signed agreement rather than two.
What happens when the AUP is violated
A policy with no teeth is decoration. Most organisations apply tiered, progressive enforcement so the response fits the breach:
- Minor lapse (an accidental click, a one-off personal-use overstep) - a verbal or written warning and a quick refresher on the rules.
- Moderate breach (ignoring security rules, installing unapproved software) - a formal warning and, where warranted, suspended or restricted access.
- Serious or repeated breach (deliberate data exposure, persistent disregard) - disciplinary action up to dismissal.
- Criminal conduct (fraud, theft, illegal content) - referral to the relevant authorities.
Two principles make enforcement defensible. First, a consequence has to be stated in the policy the person signed - you cannot dismiss someone for breaking a rule that was never written down. Second, the policy must be applied consistently; an AUP enforced against some people and not others is hard to stand behind. It also helps to disclose monitoring up front, so staff know what may be logged - covered alongside data-retention practices in your data retention policy - rather than discovering it after the fact. Where the breach involves a returned or seized device, the chain of custody and the asset’s audit trail are what turn “we think they did it” into something you can act on.
AUP vs BYOD, IT security, and data-retention policies
The AUP is one of a cluster of overlapping documents that people routinely confuse. Here is how they divide up:
- Acceptable use policy - user-facing rules for using company kit, networks, and data. This is the document employees read and sign.
- BYOD policy - the specific case of personal devices used for work. Often a section of the AUP rather than a standalone policy.
- IT or information security policy - the higher-level, strategic parent document that sets the organisation’s overall security posture, of which the AUP is the day-to-day, human-readable expression. Frameworks like ISO 27001 asset management sit at this level.
- Asset management policy - the organisation-facing rules for how equipment is bought, registered, maintained, and retired. See the asset management policy entry for the full contrast.
- Data-retention policy - what data is kept, where, and for how long before it is deleted.
The short version: the AUP tells a person what they may do; the security policy sets the strategy behind those rules; the asset policy governs the kit itself; and the retention policy governs the data’s lifespan. They overlap by design, and a tidy set of policies cross-references rather than duplicates.
The AUP at end of employment and end of device
The policy’s last clauses bite at exit. Equipment is returned and inspected against the handover record; anything unreturned is chased while the leaver is still reachable. Returned devices then leave AUP territory and enter disposal territory: data is sanitized or the device is routed through ITAD, with destruction evidenced rather than assumed. A good AUP states plainly that company data on personal devices is deleted at exit too - the clause everyone forgets until it matters.
Common mistakes
- One policy for every audience. Office staff, field engineers, and contractors use equipment differently; a single generic AUP fits nobody.
- Unfindable signatures. A signed AUP that cannot be located three years later might as well not exist.
- Rules with no handover trail. “You are responsible for your equipment” is unenforceable if nobody recorded what equipment they actually have.
- No example clauses or detail. A policy that says “use equipment responsibly” without naming passwords, software, removable media, or personal use leaves every grey area to argument.
- Set-and-forget. An AUP that predates remote work, or the tools people actually use, gets ignored - and selectively ignored policies are the hardest to enforce.
FAQ
When should employees sign the acceptable use policy? Before or at the moment they receive equipment or system access - typically during onboarding, alongside the handover of their laptop and accounts. Signing after the fact weakens it: the point is that the person agreed to the rules before they could break them. Re-acknowledge it when the policy changes materially, and record the signed copy somewhere you can find it years later.
Is an acceptable use policy legally binding? It can carry real weight when it is done properly - communicated clearly, acknowledged in writing, and applied consistently. Employers rely on a signed AUP to justify disciplinary action, recover damaged or unreturned equipment, and demonstrate due diligence after a security incident. An AUP nobody was shown, or one enforced only against some people, is worth little. Exact enforceability depends on local employment law.
What is the difference between an AUP and an asset management policy? The AUP faces the user: it tells an employee what they may and may not do with the laptop, phone, network, and data in front of them. The asset management policy faces the organisation: how equipment is purchased, registered, maintained, and retired. They meet at handover - the asset process issues the device, and the AUP governs its use from that moment on.
What should an acceptable use policy include? A workable AUP covers scope (who and what it applies to), the assets and systems it governs, permitted versus prohibited use, security and data-handling rules, password and credential hygiene, a monitoring disclosure, the consequences of breaking the rules, and a signed acknowledgement. The strongest policies also name a reasonable personal-use allowance and an exit clause that removes company data from personal devices, so nothing is left ambiguous.
What is the difference between an acceptable use policy and a BYOD policy? An AUP is the broad user-facing rulebook for company equipment, networks, and data. A BYOD (bring your own device) policy is the narrower set of rules for personal phones and laptops used for work - what must be secured, what data may be stored, and what is removed when someone leaves. In many organisations the BYOD rules are folded into the AUP rather than written as a separate document.
What are the consequences of violating an acceptable use policy? Most organisations apply tiered consequences: a verbal or written warning and retraining for a minor lapse, suspended access for a more serious breach, dismissal for a deliberate or repeated one, and referral to the authorities where the conduct was criminal. Two things make those consequences hold up - the penalty must be stated in the policy the person signed, and it must be applied consistently to everyone.
Is personal use of company equipment allowed under an AUP? Usually some, within limits. Many AUPs permit reasonable, incidental personal use - light web browsing or a quick message on a break - while drawing hard lines around illegal content, harassment, running a side business on company kit, and storing personal files that crowd out work data. The point of the clause is to set an explicit expectation rather than leave staff guessing what counts as fair use.
The takeaway
An acceptable use policy is the human-readable rulebook for company technology: it defines who is covered, what they may and may not do with devices, networks, and data, how security and personal use are handled, what is monitored, and what happens when the rules are broken. The strongest policies are specific (real clauses, not “use responsibly”), signed at handover, extended to cover BYOD and remote work, and applied consistently. Tie each acknowledgement to the person and the kit they actually hold, and the AUP stops being a filing-cabinet document and starts being something you can enforce.
Tools that make this easier
AMPthilly keeps the asset side of an AUP honest. Every laptop, phone, or tool gets a printable QR label that opens its record in any phone browser - no app to install. Check an item out to an employee, contractor, or client and the system records who holds it and when; returns capture condition and notes; and onboarding and offboarding templates make sure the right kit goes out and comes back. Every checkout, return, transfer, and status change lands in the asset’s audit history, so a signed AUP always has the handover trail behind it. Start free - 3 users and 25 assets, no credit card required - or talk to us about a larger rollout.
Related terms
- Asset Management Policy - the organisation-facing companion to a user-facing AUP
- Data-Bearing Device - the equipment class an AUP mostly exists to protect
- Data Retention Policy - how long monitored data and records are kept
- Hand Receipt - the signed acknowledgement that an asset changed hands
- Data Sanitization - what happens to a device’s data after the AUP’s custody ends
- ITAD - the disposal route for returned IT equipment
- Certificate of Destruction - proof that a returned device’s data was destroyed
- E-Waste - where retired equipment must not casually end up