What Belongs in an Acceptable Use Policy
A practical checklist for South African employers writing rules for email, devices, and cloud accounts that staff will actually read.
An acceptable use policy should describe how people may use company systems, not punish every imaginable mistake. Start with accounts, devices, personal use boundaries, and what happens when someone leaves.
Name the systems in use today: email, shared drives, collaboration tools, and any bring-your-own-device arrangements. Vague references to “IT systems” leave managers guessing during disputes.
Include a short section on monitoring and privacy expectations under POPIA. Staff need to know when logs may be reviewed and who authorises that review.
Keep the tone firm and fair. Policy language that only lawyers understand rarely survives the first onboarding week. Pair each rule with a one-line reason tied to confidentiality or operational continuity.
Finish with acknowledgement wording and a revision date. Policies that never update become shelf ornaments after the next system change.