IT Policy

(A pdf copy of this policy is available for download here.)

Introduction

This IT policy sets out a documented framework which outlines the rules and expectations for using technology within the Town Council. Its primary purpose is to ensure consistent, secure and compliant use of the Council’s IT assets including hardware, software, networks, data, internet use and emails. The policy applies at all times, including when work is carried out away from the Town Council offices. This policy can be read in conjunction with the Council’s cyber security policy and forms part of the Council’s digital and data compliance.

Purpose of the IT Policy

The purpose of this IT policy is to establish clear parameters for how councillors, staff, and other authorised users use council-provided technology or equipment in the course of their duties. This policy will:

  • Set expectations for appropriate use of equipment and systems;
  • Raise awareness of risks associated with IT use;
  • Safeguard the Council’s data and digital assets;
  • Clarify what constitutes acceptable and unacceptable use;
  • Outline the consequences of policy breaches.

Monitoring of IT Use

As an IT provider, the Council has the right to monitor the use of its IT equipment and systems, provided there is a legitimate reason for doing so and councillors, employees and other authorised users are informed that such monitoring may take place. Any monitoring must be proportionate and comply with relevant data protection and privacy laws. Other persons may be included if they access or use Council systems, e.g. if they have a Council e-mail address.

Scope of this policy

This policy applies to all councillors, staff, and other authorised users, regardless of their working location or pattern, including those who are home-based, office-based, or work on a flexible or part-time basis. It sets out the expectations for the appropriate use of IT equipment and systems provided by the Council.

1. Computer use

Hardware

1.1.1 Council computer equipment is provided for council purposes; however, reasonable personal use is permitted (“reasonable” interpreted as in the opinion of the Clerk to the Town Council). Any personal use of Council computers and systems should not interrupt daily council work in any way. Councillors, staff, and other authorised users are asked to restrict personal use to official lunch breaks or before or after working hours.

1.1.2 All computer and other electronic equipment supplied should be treated with good care at all times. Computer equipment is expensive, and any damage sustained will have a financial impact on the Council.

1.1.3 Computer and electronic hardware should be kept clean, and every precaution taken to prevent food and drink being dropped or spilled onto it.

1.1.4 Equipment should not be dismantled or reassembled without seeking advice.

1.1.5 Councillors, staff, and other authorised users are not to purchase any computer or mobile equipment (including software) unless previously authorised.

1.1.6 Personal disks, USB sticks, CDs, DVDs, data storage devices etc. cannot be used on Council computers without the prior approval of the Clerk to the Town Council.

2. Equipment

2.1 Portable equipment

Portable equipment includes laptop computers, netbooks, tablets, mobile and smart phones with email capability and access to the internet etc.

All portable computers must be stored safely and securely when not in use in the office (e.g. when travelling or when working from home).

It is important to ensure all portable devices are protected with encryption in case they are lost or stolen. Laptops that hold Council data, including emails and files, must be protected with a pin code.

Multi-Factor Authentication (MFA) is a security process that requires users to verify their identity using two or more independent methods—for example, entering a password (something you know) and confirming a code sent to your mobile device (something you have). This significantly reduces the risk of unauthorised access to systems and sensitive data. NALC recommends implementing MFA as a best practice to enhance information security and support compliance with data protection obligations under the UK GDPR and the Data Protection Act 2018.

If an item of portable equipment is lost or damaged this should be reported to the Clerk to the Town Council. If the loss or damage is due to an act of negligence, the individual responsible may be liable to meet the first £100 of the loss/damage.

To protect confidential information, unless it is a requirement of the job and this has been authorised, it is forbidden for photographs or videos to be taken on council premises without the prior written permission of the Clerk to the Town Council. This includes mobile telephones with camera function, camcorder, tape or other recording device for sound or pictures – moving or still.

Under no circumstances should any non public meeting or conversation be recorded without the permission of those present. This does not affect statutory rights (under The Openness of Local Government Regulations 2014).

In addition, the Council does not permit webcams (which may be pre-installed on many laptops) to be used in the workplace, other than for conference calls for council purposes. If there is any doubt as to whether a device falls under this clause, advice should be sought from the Clerk to the Town Council.

2.2 Use of own devices

Personal laptops and other computers or other devices should not be brought into work and used to access council IT systems during working hours, unless this has been authorised by the Town Clerk. This is to ensure that no viruses enter the system, to prevent time being wasted during working hours on personal use and to assist in maintaining security, confidentiality, and data protection.

Councillors, staff, and other authorised persons that use council systems are expected to use all devices in an ethical and respectful manner and in accordance with this policy. Accessing inappropriate websites or services on any device via the IT infrastructure that is paid for or provided by the council carries a high degree of risk and, for employees, may result in disciplinary action, including summary dismissal (without notice). For workers or contractors, the Council may terminate the worker agreement. This is irrespective of the ownership of the device used. An example would be downloading copyright music illegally or accessing pornographic material.

In cases of legal proceedings against the Council or staff, the Council may need to temporarily take possession of a device, whether council-owned or personal, to retrieve relevant data.

Wherever possible the user should maintain a clear separation between the personal data processed on the council’s behalf and that processed for their own personal use, for example, by using different apps for council and personal use. If the device supports both work and personal profiles, the work profile must always be used for work-related purposes.

Councillors, staff, and other authorised users who intend to use their own devices via the Council’s infrastructure must ensure that they:

  • Use a 6-digit pin or strong password (e.g. three random words such as PurpleCandleRiver) to protect their device(s) from being accessed.
    For smartphones and tablets this should lock the device after three failed login attempts;
  • Configure their device(s) to automatically prompt for a password after a period of inactivity of more than 10 minutes;
  • Ensure secure Wi-Fi networks are used;
  • Ensure that work-related data cannot be viewed or retrieved by family or friends who may use the device;
  • Inform the Clerk to the Town Council if their device(s) is/are lost, stolen, or inappropriately accessed where there is risk of access to Council data or resources.

Upon leaving the Council, councillors, staff and other authorised users must delete their .gov.uk email address from their personal device and provide log in details so that these can be changed.

Personal data relating to anyone connected to the Council should not be saved to any personal accounts.

Personal information and sensitive data should never be saved on councillors, staff, or other authorised users’ own devices as this may breach confidentiality agreements, especially if the device is used by other people from time to time.

If removable media are used to transfer data (e.g. USB drives or CDs), the user must securely delete the data on the media once the transfer is complete.

Councillors, staff, and other authorised users who open any attachments should ensure that cached copies are deleted immediately after use. The Clerk to the Town Council will provide assistance or training in doing this if needed.

Any work done on a user’s own equipment should be stored securely and password protected.

If transferring data (email or other means), this should be done through an encrypted channel (e.g. VPN or HTTPS). Unsecured wireless networks should not be used.

Prior to disposal of any device that has work data stored on it, and on leaving the Council, councillors, staff, and other authorised users must allow IT West access to the device to ensure passwords, user access shortcuts and identifiable data are removed.

Councillors, staff, and other authorised users must take responsibility for understanding how their device(s) work in respect to the rules above if accessing Council servers/services via their own equipment. The Council will use reasonable endeavours to assist, but users are personally liable for their own device(s) and any costs incurred.

3. Health and safety

The Council has a duty to ensure that regular appropriate eye tests, carried out by a competent person, are offered to employees using display screen equipment. Further details are set out during staff induction.

Any VDU user who feels that their workstation requires changes to make it compliant must speak to the Clerk to the Town Council.

3.1.3 If any hazards are detected at a workstation, including “noises” from the IT equipment, this should be reported immediately to the Clerk to the Town Council.

4. Password and authentication policy

4.1.1 All user accounts must be protected by strong, secure passwords. The Council follows the National Cyber Security Centre (NCSC) recommendations for creating passwords using three random words (e.g. PurpleCandleRiver). This approach is endorsed in NALC guidance.

In addition to strong passwords, Multi-Factor Authentication (MFA) should be enabled wherever possible.

To further strengthen account security:

  • Initial user account passwords must be generated by the IT provider.
  • Default passwords provided by vendors or the IT provider must be changed immediately upon installation or setup.
  • Service or System (e.g. Website) account passwords are generated and managed by the IT provider.

The Council recommends these practices as part of its commitment to robust information security and to support compliance with the UK GDPR and the Data Protection Act 2018.

Upon leaving the Council, councillors, staff and other authorised users must delete their .gov.uk email address and provide log in details so that these can be changed.

For more guidance, see the NCSC’s advice on password security: NCSC Password Guidance

4.1.2 Access to Passwords

  • Passwords are personal and must not be shared under any circumstances.
  • Only the assigned user of an account may access or use the associated password.
  • In exceptional cases (e.g., incident response or employee offboarding), access to system credentials may be granted to authorised personnel from the IT provider with appropriate approvals and logging.
  • Administrative credentials must be stored securely and only accessible to authorised personnel, with a copy provided to the Clerk to the Town Council in a sealed envelope, to be accessed only in an emergency.

4.1.3 Password Storage and Management

Passwords must not be stored in plain text or written down in insecure locations.

4.1.4 Password Change Requirements

Immediately change password if compromise is suspected.

4.1.5 Password Access Control and Logging

  • All access to administrative or shared credentials must be logged and auditable.
  • Attempts to access unauthorised passwords will be treated as a security incident.

4.1.6 Responsibility

Users are responsible for creating and maintaining secure passwords for their accounts.

The IT security provider is responsible for:

  • Managing system/service credentials.
  • Enforcing password policies.
  • Auditing and monitoring password-related security practices.

5. Monitoring

5.1.1 The Council reserves the right to monitor and maintain logs of computer usage and inspect any files stored on its network, servers, computers, or associated technology to ensure compliance with this policy and relevant legislation.

5.1.2 The Council will monitor the use of electronic communications and use of the internet in line with the Investigatory Powers (Interception by Councils etc for Monitoring and Record-keeping Purposes) Regulations 2018.

5.1.3 Monitoring of an employee’s email and/or internet use will be conducted in accordance with an impact assessment to ensure monitoring is necessary and proportionate. Monitoring is in the Council’s legitimate interests and is to ensure this policy is being complied with.

5.1.4 Information obtained through monitoring may be shared internally (including with relevant councillors and IT staff where necessary) and may be shared with external HR or legal advisers for professional advice. External advisers will have appropriate data protection policies and protocols in place.

The information gathered through monitoring will be retained only long enough for any breach of this policy to come to light and for any investigation to be conducted.

Councillors, staff, and other authorised users have rights in relation to their data, including the right to make a subject access request and the right to have data rectified or erased in some circumstances (see the Council’s data protection policy).

Such monitoring and the retrieval of the content of any messages may be for the purposes of checking whether the use of the system is legitimate, to find lost messages or to retrieve messages lost due to computer failure, to assist in the investigation of wrongful acts, or to comply with any legal obligation.

The Council has software and systems in place that can monitor and record all internet usage using ESET. A daily log is kept of all activity, detailing the names of websites accessed, along with the date and time of access, by individual councillors, staff, and other authorised users. Records of internet use and sites visited will normally be retained for a period of 90 days.

5.1.9 The Council reserves the right to inspect all files stored on its computer systems to assure compliance with this policy. The Council also reserves the right to monitor the types of sites being accessed and the extent and frequency of internet use to ensure the system is not being abused and to protect the Council from potential damage or disrepute.

5.1.10 Any use the Council considers “improper”, either in terms of content or time spent, may result in disciplinary proceedings.

6. Remote working

6.1.1 Increased IT security measures apply to those who work away from their normal place of work as follows:

  • If logging into Council systems remotely using computers that do not belong to the Council or are not owned by the user, passwords must not be saved. The user must log out at the end of the session and delete browser logs/history. If the device configuration does not clearly support these actions (e.g. an internet café), Council services should not be accessed from that device.
  • The location and direction of the screen should be checked to ensure confidential information is out of view. Steps should be taken to avoid messages being read by others, including other travellers on public transport.
  • Any data printed should be collected and stored securely.
  • All electronic files should be password protected and the data saved to Council systems/services when accessible.
  • Any data should be kept safely and disposed of securely.
  • Where possible, the ability to remotely wipe any mobile devices that process sensitive information should be retained in case of loss or theft.
  • Councillors, staff, and other authorised users who work away from the office with sensitive data should be equipped with a screen privacy filter for mobile devices and should use this at all times when accessing such data away from the office.

7. Email

Council email facilities are intended to promote effective and speedy communication on work-related matters. Although email is encouraged, it can be risky. Councillors, staff, and other authorised users need to be careful not to introduce viruses onto Council systems and should take proper account of the security advice below.

On occasion, it will be quicker to action an issue by telephone or face to face, rather than via protracted email chains. Emails should not be used as a substitute for face to face or telephone conversations. Councillors, staff, and other authorised users are expected to decide which is the optimum channel of communication to complete tasks quickly and effectively.

These rules are designed to minimise the legal risks when using email at work and to guide councillors, staff, and other authorised users as to what may and may not be done. If something is not covered in the policy, councillors, staff, and other authorised users should ask the Clerk to the Town Council and IT West rather than assuming the right answer.

All councillors, staff, and other authorised users who need to use email as part of their role will be given their own Council email address and account – council.gov.uk.The Council may withdraw email access at any time if it is no longer necessary for the role or if the system is being abused. This is the most protected email address; it ensures security and continuity and is the email address to be used.

8. Use of the internet

Copyright

Much of what appears on the Internet is protected by copyright. Any copying without permission, including electronic copying, is illegal and therefore prohibited.

The Copyright, Designs and Patents Act 1988 sets out the rules. Copyright laws apply to documents and to software. Infringement could lead to legal action against the Council and damages, as well as disciplinary action (including dismissal) against the perpetrator.

It is easy to copy electronically, but this does not make it any less an offence. The Council’s policy is to comply with copyright laws.

Councillors, staff, and other authorised users should not assume that because a document or file is on the Internet, it can be freely copied. There is a difference between information in the public domain (which may still be copyright protected) and information which is not protected by copyright (e.g. where the author has been dead for more than 70 years).

Usually, a website will contain copyright conditions; these warnings should be read before downloading or copying.

Copyright and database right law can be complicated. Users should check with the Clerk to the Town Council if unsure.

Trademarks, links and data protection

The Council does not permit the registration of any new domain names or trademarks relating to the Council’s names or products anywhere in the world, unless authorised to do so. Nor should links be added from Council web pages to external sites without checking first with the Clerk to the Town Council.

Special rules apply to the processing of personal and sensitive personal data. For further guidance, see the Council’s data protection policy (on the Town Council website).

Accuracy of information

One of the main benefits of the internet is access to large amounts of information, which is often more up to date than traditional sources. Be aware that, as the internet is uncontrolled, some information may be less accurate than it appears.

9. Use of social media

Social media includes blogs; Wikipedia and similar sites; multimedia or user generated media sites (YouTube); social networking sites (Facebook, LinkedIn, X (formerly Twitter), Instagram, TikTok, etc.); virtual worlds; text messaging and mobile device communications; and traditional media such as TV and newspapers. Care should be taken when using social media at any time, either using Council systems or at home.

Personal use of social networking/media and chat sites are not permitted during working hours.

The Council recognises the importance of councillors, staff, and other authorised users joining in and helping to shape sector conversation and enhancing its image through blogging and interaction in social media. Where it is relevant to use social networking sites as part of the individual’s position, this is acceptable.

However, inappropriate comments and postings can adversely affect the reputation of the Council, even if it is not directly referenced. If comments or photographs could reasonably be interpreted as being associated with the Council, or if remarks could be abusive, humiliating, sexual harassment, discriminatory or derogatory, or could constitute bullying or harassment, the Council will treat this as a serious disciplinary offence.

To protect both the Council and its interests, everyone is required to comply with the following rules about social media, whether in relation to their Council role or personal social networking sites, and irrespective of whether this is during or after working hours:

  • Contacts from any of the Council’s databases should not be downloaded and connected with on LinkedIn or other social networking sites, unless authorised.
  • Any blog that mentions the Council, its current work, councillors, employees, other users associated with the Council, partner organisations, local groups, suppliers or parishioners should
    identify the author and state the views are their own and do not represent the Council’s views. Writers must not claim or give the impression they are speaking on behalf of the Council.
  • Any employee or Councillor developing a site/blog that will mention the Council must inform the Clerk to the Town Council and gain agreement before going live.
  • The Council expects respectful behaviour; unauthorised copyright use, unfounded/derogatory statements, or misrepresentation may constitute gross misconduct.
  • Photos, videos, or audio recordings must not be taken on Council premises without explicit permission.
  • Inappropriate conversations should not take place on any social networking sites, including forums.
  • Do not post private/confidential/internal Council information. This includes (non-exhaustively) internal manuals, procedures, training documents, non-public financial/operational information,
    personal information about councillors/staff/authorised users, and anything relating to disciplinary/grievance/legal issues. This does not affect statutory publication duties (including FOI).
  • Councillors, staff, and other authorised users are personally liable for what they write/present online. Councillors should be mindful of the Members Code of Conduct and Nolan Principles.
    Employees may face disciplinary action for content that is defamatory, embarrassing, pornographic, proprietary, harassing, libellous, or creates a hostile work environment.
  • Postings must not breach copyright or other law, disclose confidential information, defame or make derogatory comments, or disclose personal data in breach of data protection legislation.
  • Media contacts relating to the Council should be referred to the Clerk to the Town Council.
  • Profiles on LinkedIn/Facebook must be accurate and up to date; users must update their profile on leaving the Council.
  • After leaving the Council, individuals must not post inappropriate comments about the Council or its councillors/staff/authorised users on social media.
  • Professional contacts and confidential information obtained in a Council capacity (including via LinkedIn) may be considered Council property and may be subject to disclosure upon request.

The Council may monitor external postings on social media sites from time to time. Social media is not an appropriate place to air Council concerns or complaints; these should be raised with the Council or through formal procedures.

Misuse

Misuse of IT systems and equipment is not in line with the Council’s standards of conduct and will be taken seriously. Any inappropriate or unauthorised use may lead to formal action,
including disciplinary proceedings or, in serious cases, dismissal.

Adopted: 9 February 2026