The IT usage policy is the document that sets the rules for using a business’s digital tools: what everyone may do with their computer, email and access rights, and what the employer monitors. Many businesses have one. Few use it: written once from a generic template and filed in a shared folder, it describes a business that does not exist and that nobody recognises.
A useful policy does the opposite. It starts from actual practice — the tools really in use, the situations really encountered — and it is made enforceable against those it binds. Without the first condition nobody reads it; without the second it protects nobody.
Is an IT usage policy mandatory?
No: no text requires a business to write an IT usage policy. But several obligations make one necessary in practice. The employer must inform employees, before putting them in place, of any means used to monitor their activity, and consult staff representatives about them: the CNIL, the French data protection authority, points out that this information can be given through a policy, annexed or not to the internal rules, through an individual note or through a staff notice. The employer must also ensure the security of the personal data it processes, which requires rules known to those who handle that data.
A policy is the clearest way to hold these obligations together. Without one, monitoring email or a sanction for misusing a tool rests on rules the employee can claim never to have known.
The sections of a useful IT usage policy
ANSSI, the French national cybersecurity agency, has published a drafting guide in eight key points for small and mid-sized businesses. It remains the best framework, provided it is filled in with the real business rather than with generalities.
- The objective. Protecting the security of the information system by making every user a participant in that security, not merely a subject of monitoring.
- Precise definitions. User, administrator, authentication means, information system: defined terms limit interpretation.
- Purpose and scope. Whom the policy applies to — employees, interns, contractors, temporary staff — and to which tools.
- Use. What is permitted, in particular personal use of work tools and work use of personal devices, and the limits of each.
- User duties. Confidentiality, protecting authentication means, vigilance against fraudulent messages, precautions before importing any outside data.
- Monitoring measures. Which ones, for what purpose, how long data is kept, and on what conditions they are proportionate.
- Sanctions. A scale proportionate to the seriousness of the breach.
- Enforceability. How the policy is brought to everyone’s attention and becomes applicable.
Two sections are often missing from older policies, because the practices they cover are recent. The first concerns online tools an employee can sign up for alone — a file-sharing service, a note-taking tool, a generative AI: who is allowed to adopt one, and with what data? Every tool of this kind is a processor under the GDPR, requiring a contract compliant with Article 28. The second concerns the right to disconnect, which the businesses concerned must organise.
Finally, a policy is only worth anything if it matches what the business really knows about its equipment. Banning unauthorised software presupposes knowing which software is installed; limiting administrator rights presupposes knowing who holds them. That is the role of IT asset management: the policy sets the rule, the inventory makes it possible to keep it.
Form matters as much as substance. A policy is read by people who are not IT specialists: short sentences, concrete examples, one rule per paragraph. The ANSSI guide insists on this — the document must be understandable by everyone, whatever their familiarity with IT. A thirty-page policy in legal language will be signed and never applied.
Making it enforceable: annex to the internal rules, informing the works council
A policy only binds an employee if it is enforceable against them. There are two routes.
An annex to the internal rules. Internal rules (règlement intérieur) are mandatory in businesses with at least fifty employees. A policy annexed to them, or any notice setting general and permanent rules in the areas they cover, follows the same procedure: an opinion from the works council (CSE), transmission to the labour inspectorate, communication to employees by any means, and entry into force on a date set at least one month after these formalities are completed. Filing with the employment tribunal registry, long required, was abolished by the economic simplification act of 26 May 2026.
Individual acceptance. A business without internal rules can have each employee accept the policy, by signature or as an annex to the employment contract. The ANSSI guide points out that external users — contractors, subcontractors, partners — must also be covered, through a clause in the contracts with their employer.
The procedure also applies to amendments. A policy annexed to the internal rules whose content changes — a new monitoring tool, a new rule on online tools — goes back through the works council’s opinion, transmission to the labour inspectorate and communication to employees. That is one more reason to write it from actual practice from the start: a policy that is right from the outset needs revising less often.
In both cases the decisive condition is the same: everyone must have been able to read it. A sanction based on a policy the employee never received is fragile.
Case: a small business whose teams worked on devices supplied by its clients
The situation arises in consulting professions, and we meet it regularly: some of the teams work on devices supplied by clients, inside their systems, with their credentials.
A generic policy does not answer it, because it assumes the business supplies the tools it regulates. Here three sets of rules overlap: the client’s policy, which applies to its devices and networks; the business’s policy, which applies to its employees; and the confidentiality commitments in the service contract. The business’s policy must say how they fit together — which prevail on client devices, which of the business’s data may pass through them, which of the business’s tools remain permitted, and whom to alert about an incident observed at a client.
The case illustrates the general rule: a useful policy is written from the business’s real situations. One that ignores half of its teams’ working time only applies to the other half.
Download the template
The template follows the eight points of the ANSSI guide, published under an open licence, and adds the two recent sections mentioned above: online tools signed up for by employees, and working on third-party equipment. Each section carries the questions the business must answer before writing, and a sample wording to adapt. It is sent by email.
A template is no substitute for adapting it, or for having it reviewed by an employment law professional before annexing it to the internal rules. It is the kind of work Maeliom Consulting carries out with management: start from actual practice, then write the rule.
Common questions
Is an IT usage policy mandatory for a small business?
No. But it is the simplest way to inform employees of the usage rules and monitoring, which an employer must do before being able to rely on them.
Must the works council be consulted to introduce an IT usage policy?
Yes when it is annexed to the internal rules, whose procedure includes the works council’s opinion. Means of monitoring employee activity also require staff representatives to be informed and consulted.
How does an IT usage policy relate to the GDPR?
The policy contributes to the security of the personal data the business processes, and informs employees of the processing linked to monitoring. It replaces neither the record of processing activities nor contracts with processors.
Can a policy apply to contractors?
Yes, through a clause in the contract with their employer, which undertakes to make it known to them. This is the route recommended by the ANSSI guide.
Sources: ANSSI, IT and digital tools usage policy guide (2017); French Ministry of Labour, internal rules; Service public, abolition of registry filing (27 May 2026); CNIL, IT tools at work.