Free internet acceptable-use policy

Internet Usage & Acceptable Use Policy Template for UK Businesses

An internet usage policy gives employees practical rules for using company internet access, browsers, cloud services and online tools. It helps reduce malware, data leakage and inappropriate use while setting proportionate expectations about personal use and monitoring.

Quick answer

What is this policy and why does it matter?

An employee internet usage policy defines acceptable and prohibited online activity, software and file-download rules, use of cloud and AI services, public Wi-Fi and BYOD expectations, web filtering and how security monitoring is carried out. It creates a consistent standard that can be explained to staff and enforced fairly.

Business case

Why does a company need this policy?

A policy is not a substitute for technical controls, but it gives employees, managers and IT teams one written standard to work from.

✓

Reduce malware and phishing exposure

Rules on suspicious sites, downloads, browser extensions and credential prompts reinforce technical web and endpoint controls.

✓

Control unsanctioned cloud services

Employees can upload business information to personal file sharing, AI tools and online converters. The policy explains which services are approved and what data may leave managed systems.

✓

Make personal use expectations clear

A proportionate policy can allow reasonable personal browsing while setting boundaries around unlawful, unsafe, offensive or excessive use.

✓

Explain filtering and monitoring transparently

Where the organisation filters websites or monitors security events, the policy should explain the purpose and scope so staff understand the control rather than discovering it after an incident.

Inside the template

What should the policy cover?

The downloadable template is designed to be edited around your organisation, technology and employment practices rather than published unchanged.

Business and reasonable personal internet use
Prohibited, unlawful and unsafe activity
Phishing, suspicious websites and credential prompts
Downloads, software and browser extensions
Cloud storage, file sharing and transfer services
AI tools and online document converters
Personal email and unmanaged accounts
Public Wi-Fi, remote working and VPN use
BYOD and personal-device access
Web filtering, DNS security and category blocking
Security logging and proportionate monitoring
Incident reporting and policy enforcement
Who should use it?

Designed for practical UK business use.

  • SMEs providing internet access on company laptops, desktops and phones
  • Businesses with hybrid or remote workers
  • Organisations that use web filtering, secure DNS or managed firewalls
  • Employers that need a clear acceptable-use standard for staff and contractors

Important: This is a practical template and should be adapted to your organisation. It is not legal or employment-law advice.

Implementation

How to put the policy into practice.

  1. 1

    Document the online services employees genuinely need to do their jobs.

  2. 2

    Decide what reasonable personal use is permitted and which activities are prohibited.

  3. 3

    List approved cloud-storage, file-transfer, AI and browser-extension services.

  4. 4

    Align the policy with firewall, secure DNS, endpoint and web-filtering controls so the written rule matches the technical configuration.

  5. 5

    Explain any monitoring or logging clearly and keep it proportionate to the security and business purpose.

  6. 6

    Train staff on phishing, unsafe downloads and how to report a suspicious website or browser event.

Free 39Security download

Get the Internet usage policy.

Editable Internet Usage Policy Template and branded PDF copy.

  • Branded 39Security template
  • Editable Word document
  • Secure email link - no attachment
  • © 2026 Matthew Southgate. All rights reserved.

Email me the download link

By requesting the resource you agree that the transactional delivery email can use a unique open pixel and secure link so 39Security can record delivery-email opens, link clicks and downloads. These measurements can be affected by mail-security scanners and privacy proxies. You will not be added to marketing by this form.

See the privacy notice.

Policy implementation support

Need help making the policy real?

39Security works with businesses across Essex, Kent, Hertfordshire and London to combine acceptable-use policies with managed firewalls, secure endpoints, Microsoft 365 controls and employee cyber-security training.

Talk to 39Security
Frequently asked questions

12 practical answers.

Use these answers alongside your own risk assessment, technical controls and employment or legal advice where needed.

What is an internet usage policy?

An internet usage or acceptable-use policy explains how staff may use company internet access, browsers, web services and online tools, including security, downloads, personal use, cloud services and monitoring.

Should personal internet use be banned at work?

Not necessarily. Many organisations permit reasonable personal use provided it is lawful, does not interfere with work or security and does not create excessive cost or bandwidth use. The rule should be clear and applied consistently.

Can a company monitor employee internet usage?

Monitoring needs a defined purpose, must be necessary and proportionate, and workers should receive clear privacy information about its nature and extent. High-risk monitoring may require a DPIA.

Can staff use personal email for work?

Normally business information should stay in approved organisational systems. Personal email can create uncontrolled storage, retention, access and data-loss risks.

Can staff upload files to online converters and AI tools?

Only if the service is approved for the information involved. Online converters, AI tools, transcription sites and browser extensions can receive a copy of the data and may have their own retention or reuse terms.

Should browser extensions require approval?

Yes. Extensions can receive extensive permissions to read pages, change content or access data. Treat them as software and subject them to the normal approval process.

Can staff bypass web filters if a site is blocked?

No unless an authorised technical process approves the exception. A legitimate business site that is incorrectly blocked should be submitted for review rather than bypassing security controls.

Can staff download software from the internet?

Only in line with the company’s software-approval process. Uncontrolled software and installers are a common route for malware, unwanted applications and licence problems.

Can staff use public Wi-Fi for work?

Yes if the organisation’s remote-working controls are followed. Use approved secure access or VPN where required and avoid exposing confidential information in public places.

What should staff do after clicking a suspicious website?

Stop interacting with the site, report it promptly and follow the incident process. If credentials were entered or a file was downloaded, say so immediately so containment can begin.

Does the policy apply to BYOD?

Yes where personal devices access business systems, but the organisation should also maintain a separate BYOD policy defining device eligibility, security controls and data separation.

Can I download an internet usage policy template?

Yes. Enter your email address on this page and 39Security will email you a secure link to the editable Internet Usage Policy Template.

Related guidance

Keep improving the control set.