Contract TemplateHR Policies

IT Acceptable Use Policy
Template — South Africa

An attorney-drafted IT Acceptable Use Policy template designed specifically for South African workplaces. This comprehensive, legally compliant document governs employee use of company IT systems, networks, and devices — covering email and internet usage, BYOD arrangements, employer monitoring rights under RICA, data classification, cybersecurity responsibilities under the Cybercrimes Act 19 of 2020, POPIA-compliant data handling, and ECTA electronic communications compliance.

Quick answer

What is a IT Acceptable Use Policy in South Africa?

An IT Acceptable Use Policy (IT AUP) governs employee use of company IT systems, networks, and devices in South Africa. It establishes the employer as "system controller" under the Regulation of Interception of Communications Act 70 of 2002 (RICA) to enable lawful monitoring, implements POPIA Conditions 2, 6 and 7, addresses the Cybercrimes Act 19 of 2020 (Sections 2-14), and creates the incident reporting framework aligned with POPIA Section 22 and Cybercrimes Act Section 54.

Drafted and reviewed by

Martin Kotze

Attorney & Founder, My-Contracts.co.za · Legal Practice Council of South Africa (LPC F17333)

Last legal review

In short

IT Acceptable Use Policy TL;DR

The IT Acceptable Use Policy is the cornerstone of workplace cybersecurity governance and the legal shield enabling lawful employer monitoring in South Africa. It establishes the employer as "system controller" under Section 6 of the Regulation of Interception of Communications Act 70 of 2002 (RICA) — without this, any monitoring of employee email or internet activity is potentially a criminal offence under RICA Section 49. It implements POPIA Condition 2 (purpose specification), Condition 6 (openness through transparent disclosure), and Condition 7 (security safeguards) for the personal information processed through monitoring. It deters conduct that would constitute offences under the Cybercrimes Act 19 of 2020 (Sections 2-14: unlawful access, interception, interference, cyber fraud, cyber extortion, malicious communications), and it establishes the reporting workflow aligned with POPIA Section 22 (72-hour breach notification) and Cybercrimes Act Section 54 (72-hour SAPS reporting for electronic communications service providers and financial institutions). It also addresses BYOD, data classification, AI-tool usage, and copyright-compliant software.

Also known as: Acceptable Use Policy, IT AUP, Computer Use Policy, Internet and Email Policy, Information Technology Policy, IT Governance Policy, Technology Use Policy.

Why It Matters

Why Your Business Needs This Agreement

Ransomware Attacks Enabled by Employee IT Misuse

South Africa ranks among the top African countries targeted by ransomware attacks, with employee actions — clicking phishing links, downloading malicious attachments, installing unauthorised software — being the primary entry vector. Without a clear IT Acceptable Use Policy establishing security obligations, training requirements, and incident reporting procedures, the employer has no formal framework for preventing or responding to ransomware attacks. Average ransomware recovery costs for South African businesses exceed R5 million when downtime, data loss, and remediation are factored in.

POPIA Data Breaches from Uncontrolled Data Handling

Employees who store personal information on unsecured USB drives, forward client data to personal email accounts, or upload company files to personal cloud storage create uncontrolled copies of regulated data outside the employer's security perimeter. When these copies are compromised, the employer faces POPIA section 22 breach notification obligations, Information Regulator enforcement action with fines up to R10 million, and civil liability to affected data subjects. Without a data classification and handling policy, employees have no framework for understanding which data requires special protection.

Unlawful Monitoring Without RICA Compliance

Employers who monitor employee email, internet activity, or device usage without establishing themselves as "system controller" under RICA and without informing employees may be committing a criminal offence under RICA section 49. The IT Acceptable Use Policy is the mechanism that establishes the employer's lawful authority to monitor — without it, all monitoring evidence is potentially inadmissible and the employer faces prosecution. This is a critical gap that many South African employers have not addressed.

Software Piracy Liability for the Employer

When employees install pirated or unlicensed software on company systems, the employer faces vicarious liability under the Copyright Act 98 of 1978. The Business Software Alliance (BSA) actively investigates software piracy in South Africa, and settlements can run into millions of rands in licence fees, penalties, and legal costs. Without a policy prohibiting unauthorised software installation and establishing regular licence audits, the employer has no defence against BSA enforcement actions.

Cybercrimes Act Reporting Failure

Financial institutions and electronic communications service providers that fail to report certain cybercrimes to the SAPS within 72 hours under section 54 of the Cybercrimes Act face criminal prosecution. Without an IT Acceptable Use Policy that establishes incident reporting procedures aligned with the Cybercrimes Act, these organisations may miss mandatory reporting deadlines, creating regulatory exposure for the organisation and personal criminal liability for responsible officers.

What is a IT Acceptable Use Policy?

Company IT systems are the operational backbone of modern South African businesses, and their misuse exposes organisations to cybersecurity breaches, data protection violations, criminal liability, and significant financial losses. The legal landscape governing IT use in South Africa is shaped by four primary statutes: the Electronic Communications and Transactions Act 25 of 2002 (ECTA), the Protection of Personal Information Act 4 of 2013 (POPIA), the Cybercrimes Act 19 of 2020, and the Regulation of Interception of Communications and Provision of Communication-Related Information Act 70 of 2002 (RICA). Each imposes distinct obligations on employers and employees, and a failure to address any one of them creates legal exposure.

The Cybercrimes Act 19 of 2020, which became fully operational in phases from December 2021, is particularly significant for IT acceptable use. Section 2 criminalises the unlawful access of a computer system, section 3 criminalises the unlawful interception of data, section 5 addresses unlawful interference with a computer system, and section 7 criminalises cyber extortion. These offences carry penalties of up to 15 years' imprisonment. For employers, the Act creates both a shield (protecting company systems from employee misuse) and a sword (imposing obligations to report certain cybercrime offences under section 54, which requires electronic communications service providers and financial institutions to report certain offences to the South African Police Service within 72 hours).

RICA governs the employer's right to monitor employee communications. Section 6 permits an employer who is the "system controller" of a telecommunications system to monitor communications conducted on that system, provided the monitoring is for purposes related to the system controller's business and one of the parties to the communication has consented. The IT Acceptable Use Policy serves as the mechanism for establishing the employer as system controller and for providing the required consent framework. Without a policy establishing these elements, employer monitoring of email and internet usage may be unlawful under RICA, exposing the employer to criminal prosecution.

Without an IT Acceptable Use Policy establishing the employer as RICA "system controller," every monitoring of employee email is potentially a criminal offence under RICA Section 49.

POPIA requires employers to process employee personal information lawfully, and monitoring of IT usage constitutes processing. Condition 2 (purpose specification) requires a clearly defined purpose for monitoring, Condition 3 (further processing limitation) restricts the use of monitoring data for purposes other than those specified, and Condition 7 (security safeguards) mandates appropriate technical measures to protect the personal information collected through monitoring. The employer's POPIA impact assessment should specifically address IT monitoring.

This attorney-drafted template provides a comprehensive framework covering email etiquette and retention policies, internet browsing restrictions and acceptable use, BYOD security requirements including mobile device management, the employer's monitoring rights under RICA with POPIA-compliant disclosure, data classification (public, internal, confidential, restricted) with handling requirements for each level, password management and multi-factor authentication, software installation and licence compliance, incident reporting procedures aligned with the Cybercrimes Act and POPIA breach notification requirements, removable media and cloud storage restrictions, and a disciplinary framework for IT policy violations aligned with LRA Schedule 8.

Who Needs This

Every South African organisation that provides IT equipment, systems, or network access to employees
Companies permitting employees to use personal devices for work purposes (BYOD arrangements)
Businesses in financial services, healthcare, legal, or other regulated industries with heightened data security obligations
IT departments seeking a formal, legally compliant policy framework for acceptable use of company technology
Employers who need legal authority to monitor employee email, internet, and device activity under RICA
Organisations that have experienced cybersecurity incidents, data breaches, or IT misuse by employees
Companies processing personal information through IT systems that must demonstrate POPIA Condition 7 compliance
Any South African business seeking to reduce cybersecurity risk and establish clear IT use boundaries

Want early access to the IT Acceptable Use Policy template?

We'll email you the moment early access opens

Legal Requirements

What an IT Acceptable Use Policy Must Include Under South African Law

Clauses required by the Cybercrimes Act 19 of 2020, RICA 70 of 2002, ECTA 25 of 2002, POPIA, and the Copyright Act 98 of 1978 for a compliant IT Acceptable Use Policy.

ClauseRequired / Recommended ByKey Reference
Scope and IT systems covered (devices, networks, cloud)Best practiceIT asset inventory
Email usage and retention standardsElectronic Communications and Transactions Act 25 of 2002Section 15 electronic evidence
Internet use and web filtering disclosurePOPIA; RICARICA Section 6
BYOD security with MDM enrolment and remote wipe consentPOPIA Condition 7; consentPOPIA Section 11
Monitoring provisions with RICA system controller designationRegulation of Interception of Communications Act 70 of 2002RICA Section 6
POPIA transparency notice for monitoring purposesPOPIAConditions 2 and 6
Four-tier data classification (Public, Internal, Confidential, Restricted)POPIA Condition 7POPIA Sections 19 and 26
Password management and multi-factor authenticationPOPIA Condition 7NIST SP 800-63 baseline
Prohibition on unauthorised software per Copyright ActCopyright Act 98 of 1978Section 27
Incident reporting with 72-hour POPIA notificationPOPIA; Cybercrimes Act 19 of 2020POPIA Section 22; Cybercrimes Act Section 54
AI and generative AI tool usage guidelinesPOPIA; IP considerationsPOPIA Sections 18–22
Disciplinary framework aligned with LRA Schedule 8Labour Relations Act 66 of 1995Schedule 8 Items 3–7

The Cybercrimes Act 19 of 2020 imposes penalties of up to 15 years imprisonment for unlawful access to computer systems — employees who access restricted systems without authorisation face criminal prosecution

Without an IT Acceptable Use Policy establishing the employer as RICA "system controller," all monitoring of employee email and internet activity may be a criminal offence under RICA section 49

POPIA section 22 requires notification of data breaches to the Information Regulator within 72 hours — IT policies that establish incident reporting procedures are essential for meeting this deadline

The Business Software Alliance actively investigates software piracy in South Africa — employers whose staff install pirated software face settlements running into millions of rands

Ransomware recovery costs for South African businesses average R5 million+ when downtime, data loss, legal costs, and remediation are included — employee IT misuse is the primary attack vector

Template Contents

Key Clauses Included

This IT Acceptable Use Policy template covers 12 essential sections, each drafted by South African attorneys.

01

Scope, Definitions & IT Systems Covered

Defines all IT systems covered by the policy — hardware (desktops, laptops, tablets, smartphones, servers), software (operating systems, applications, cloud services), networks (LAN, WAN, Wi-Fi, VPN), communication systems (email, instant messaging, video conferencing), and data storage (on-premise, cloud, removable media). Establishes the categories of users subject to the policy and defines key terms such as "authorised use," "personal use," "IT resources," and "system controller" as referenced in RICA.

02

Email & Electronic Communications

Comprehensive rules for professional email conduct, the extent of permitted personal email use on company systems, email retention and archiving requirements aligned with ECTA section 15 evidence provisions, prohibition on forwarding confidential information to personal email accounts, auto-signature standards, prohibition on mass unsolicited emails, and the handling of suspicious emails and phishing attempts. Addresses the legal admissibility of email communications as evidence under ECTA.

03

Internet & Web Browsing

Defines permitted and prohibited website categories during work hours, streaming and bandwidth restrictions, download rules and file size limits, the employer's right to filter, block, or restrict access to certain content categories, the prohibition on accessing illegal content (including child exploitation material, which must be reported to the Film and Publication Board), and the logging of internet activity for security and compliance purposes.

04

BYOD — Bring Your Own Device

Comprehensive requirements for personal devices used for work purposes including minimum operating system and security standards, mandatory mobile device management (MDM) enrolment, remote wipe consent for company data, separation of personal and company data through containerisation, liability for device loss or theft, the process for de-provisioning when the employee leaves, and the employer's limitation to managing only company data and applications on personal devices.

05

Monitoring, Interception & Privacy

Establishes the employer as "system controller" under RICA section 6, defines the scope and purpose of monitoring (email, internet, file access, device usage), provides the required transparency notice under POPIA Condition 6, addresses the employee's limited expectation of privacy on company-owned systems, sets out the lawful basis for monitoring under POPIA section 11, and establishes the protocol for accessing monitoring data in disciplinary proceedings. Addresses the prohibition on covert monitoring except where serious misconduct is suspected.

06

Data Classification & Handling

Establishes four data classification levels — Public (freely distributable), Internal (not for external distribution), Confidential (restricted access, business-critical), and Restricted (highest sensitivity, legally protected) — with specific handling requirements for each level including storage locations, encryption requirements, transmission methods, access controls, and disposal procedures. Addresses POPIA classification of personal information and special personal information.

07

Password, Authentication & Access Management

Password complexity requirements (minimum 12 characters, mixed case, numbers, symbols), prohibition on password reuse and sharing, multi-factor authentication mandates for sensitive systems, session timeout settings, the employee's duty to report compromised credentials immediately, privileged access management for IT administrators, and account lockout policies after failed authentication attempts.

08

Software, Licensing & Hardware

Absolute prohibition on installing unauthorised software (including cracked or pirated software, which constitutes a criminal offence under the Copyright Act 98 of 1978), software licence compliance obligations, the process for requesting and approving new software, rules for connecting personal peripherals to company networks, and the prohibition on modifying company hardware without IT authorisation.

09

Removable Media & Cloud Storage

Restrictions on the use of USB drives, external hard drives, and other removable media — including mandatory encryption and approval for any data transfer to removable devices. Rules for approved and prohibited cloud storage services, the prohibition on storing Confidential or Restricted data on personal cloud accounts, and the requirement for approved cloud services to meet POPIA security standards.

10

Cybersecurity Incident Reporting & Response

Mandatory obligation to report suspected security incidents, phishing attempts, malware infections, ransomware attacks, and data breaches immediately to the IT department. Links to the organisation's incident response plan, POPIA section 22 breach notification obligations (72-hour notification to the Information Regulator), and Cybercrimes Act section 54 reporting obligations for electronic communications service providers and financial institutions.

11

Artificial Intelligence & Generative AI Tools

Guidelines for the use of AI tools including ChatGPT, Claude, Copilot, and other generative AI platforms. Prohibition on inputting Confidential or Restricted company data into public AI tools, requirements for approved AI tools, intellectual property considerations for AI-generated content, and the obligation to verify AI outputs before relying on them for business decisions.

12

Disciplinary Consequences & Enforcement

Progressive disciplinary framework aligned with LRA Schedule 8 for IT policy violations, ranging from verbal warnings for minor infractions (excessive personal browsing) to summary dismissal for serious offences (unauthorised access to systems, data theft, installation of malicious software). Addresses the employer's obligation to report criminal IT conduct to the South African Police Service under the Cybercrimes Act.

Legal Compliance

South African Law Compliance

Cybercrimes Act

Cybercrimes Act 19 of 2020

Creates criminal offences directly relevant to IT acceptable use: section 2 (unlawful access to a computer system — up to 15 years imprisonment), section 3 (unlawful interception of data), section 5 (unlawful interference with computer systems), section 7 (cyber extortion), and section 8 (unlawful acquisition of data, including personal information). Section 54 imposes reporting obligations on electronic communications service providers and financial institutions. The policy deters employees from engaging in conduct that constitutes a cybercrime and establishes the employer's reporting obligations.

RICA

Regulation of Interception of Communications and Provision of Communication-Related Information Act 70 of 2002

Section 6 permits employers to monitor employee communications on company systems where the employer is the "system controller" and the monitoring is for business purposes with employee awareness. Section 5 prohibits unlawful interception of communications. The IT Acceptable Use Policy establishes the employer as system controller under RICA and provides the transparency required for lawful monitoring — without this policy, any employer monitoring of email or internet activity may constitute a criminal offence under RICA.

ECTA

Electronic Communications and Transactions Act 25 of 2002

Governs electronic communications, provides for the legal recognition and admissibility of electronic evidence under section 15, and establishes offences for unauthorised access to computer systems (which complement the Cybercrimes Act provisions). Section 86 criminalises unauthorised access to, interception of, or interference with data. The policy relies on ECTA to define the boundaries of authorised and unauthorised use and to establish that electronic records (including email and system logs) are admissible evidence.

POPIA

Protection of Personal Information Act 4 of 2013

Monitoring of IT usage constitutes processing of employee personal information, engaging POPIA's eight conditions for lawful processing. Condition 2 (purpose specification) requires a defined purpose for monitoring, Condition 6 (openness) requires transparent disclosure, and Condition 7 (security safeguards) mandates appropriate security measures for the personal information collected through monitoring. Data breaches caused by IT misuse trigger section 22 mandatory notification to the Information Regulator within 72 hours. Penalties include fines up to R10 million and imprisonment up to 10 years.

Copyright Act

Copyright Act 98 of 1978

Section 27 criminalises the use of infringing copies of computer software — installing pirated or unlicensed software on company systems exposes both the employee and the employer to criminal prosecution and civil damages. The policy's prohibition on unauthorised software installation directly addresses copyright compliance and protects the employer from vicarious liability for software piracy.

South African businesses are lining up for My-Contracts — be first in when we launch

POPIA CompliantLegally ReviewedDigital Signing Available
Simple Process

Create Your IT Acceptable Use Policy in Minutes

Our guided wizard walks you through every clause — no legal knowledge required. Attorney-drafted, South African law compliant.

01

Audit your current IT systems and identify risks

Begin with a comprehensive inventory of IT assets and risks. Catalogue every IT system, device, and network used by employees — endpoints (desktops, laptops, tablets, smartphones), servers, cloud services (IaaS, PaaS, SaaS), messaging platforms (email, Teams, Slack), and communication systems (VPN, video conferencing). Assess the current level of BYOD usage and the extent of Mobile Device Management (MDM) enrolment. Review existing security controls (firewalls, endpoint protection, email filtering, multi-factor authentication, privileged access management) and identify gaps. Review past IT security incidents — phishing attempts, malware infections, data loss events — for patterns and systemic vulnerabilities. Identify the data classification levels applicable to your business by category (personal information under POPIA, financial records, IP, trade secrets) and the lawful basis for processing each.

02

Customise the template for your technology environment

Complete the template with your organisation's specific IT infrastructure detail — the approved operating systems and software list, the approved cloud services (with specific storage platforms such as Microsoft 365, Google Workspace, or company-hosted SharePoint), the BYOD enrolment procedure and MDM requirements, the monitoring scope (email, internet, file access, device usage), the data classification definitions with examples from your business, password complexity policies (minimum 12 characters, multi-factor authentication mandatory for sensitive systems), and the incident response contacts. Ensure the policy reflects actual technology reality — policies that mandate controls the organisation has not implemented are indefensible. Address emerging technologies: AI and generative AI tool usage, remote work, and personal cloud storage alternatives.

03

Establish RICA system controller status and POPIA compliance

Formally designate the employer as "system controller" under Section 6 of the Regulation of Interception of Communications Act 70 of 2002 (RICA) for all company communication systems. This is the single most important legal step — without it, any employer monitoring of employee email, internet, or messaging activity is potentially a criminal offence under RICA Section 49 and any evidence obtained may be inadmissible in disciplinary proceedings. Ensure the monitoring provisions comply with POPIA's conditions for lawful processing: Condition 2 (purpose specification must be explicit, not vague), Condition 6 (openness requires transparent disclosure to employees), Condition 7 (security safeguards for monitoring data), and the proportionality test. Document the lawful basis for each type of monitoring — typically legitimate interest under Section 11(1)(f) combined with consent. Engage your Information Officer (appointed under POPIA Section 56) to approve the monitoring provisions.

04

Communicate the policy, train employees, and obtain acknowledgements

Distribute the policy to every employee via email, the intranet, and onboarding materials, and obtain a signed acknowledgement from each. The acknowledgement is both a POPIA openness requirement and critical evidence for any disciplinary or monitoring dispute. Conduct mandatory cybersecurity awareness training covering phishing recognition (most ransomware enters through phishing), password hygiene and multi-factor authentication, data handling by classification level, approved and prohibited cloud services, BYOD obligations, and incident reporting. For high-risk roles (finance, HR, IT administrators, executives), deliver enhanced training on social engineering, privileged access, and targeted phishing. Repeat training annually and whenever major threats emerge (for example, after a significant ransomware campaign in South Africa). Maintain training records and certifications for evidence of the POPIA Condition 7 "appropriate measures" defence.

05

Implement technical controls matching the policy requirements

Implement the technical controls referenced in the policy. Deploy web filtering to block prohibited content categories and known malicious sites. Enable email monitoring, spam filtering, and DLP (data loss prevention) tools. Enrol all BYOD devices in MDM (Microsoft Intune, Jamf, MobileIron, or equivalent) with containerisation separating company data from personal data and remote wipe capability. Implement encryption for removable media and an approval workflow for USB drive use. Configure role-based access controls for classified data — Restricted data should have access limited to a named group with multi-factor authentication. Deploy endpoint detection and response (EDR) tools. For financial institutions and ECS providers, configure the Cybercrimes Act Section 54 reporting workflow to trigger the 72-hour SAPS notification.

06

Build the incident response and POPIA breach notification workflow

Design an incident response plan that satisfies POPIA Section 22 and, where applicable, Cybercrimes Act Section 54. When an incident is reported — phishing success, malware infection, ransomware, lost device, suspected data exfiltration — the workflow must contain, investigate, remediate, and notify. Containment includes isolating affected systems (but do not shut them down without forensic guidance), blocking compromised accounts, and preserving evidence. Investigation determines scope, impact, and whether personal information was compromised. If personal information was compromised, notify the Information Regulator and affected data subjects as soon as reasonably possible (the Regulator's guidance is 72 hours). For ECS providers and financial institutions, the Cybercrimes Act Section 54 requires reporting specified offences to the SAPS within 72 hours. Document every decision for regulatory audit.

07

Review the policy annually against threat evolution and legal developments

Conduct an annual policy review covering four dimensions. First, legal developments — new POPIA Regulator guidance, Cybercrimes Act Regulations (the Act is implemented in phases and regulations are still being issued), Copyright Act amendments, and Labour Court judgments on IT-related dismissals. Second, threat evolution — new ransomware campaigns, new phishing techniques, new social engineering patterns, new AI-generated attacks. Third, technology evolution — the approved software and cloud services list must reflect current enterprise offerings, new AI tools (particularly large language models) require specific use policies addressing data leakage into training sets, and emerging technologies (Web3, Metaverse) may require new categories. Fourth, organisational experience — capture lessons from incidents and near-misses. Re-circulate and re-acknowledge the updated policy.

Your IT Acceptable Use Policy is ready
Common Questions

Frequently Asked Questions

Yes. Under RICA section 6, an employer who is the "system controller" of the company email system may monitor employee emails, provided employees have been informed that monitoring takes place and the monitoring is for business purposes. The IT Acceptable Use Policy serves as this notice and establishes the employer as system controller. South African courts have held that employees have a limited expectation of privacy on company-owned systems when a clear monitoring policy is in place. Personal emails sent via company systems are also subject to monitoring, which is why the policy recommends that employees use personal devices and personal email accounts for private correspondence.

This it acceptable use policy page answers

  • RICA employer monitoring system controller
  • POPIA IT monitoring conditions
  • Cybercrimes Act 2020 workplace offences
  • BYOD policy South Africa mobile device management
  • data classification public internal confidential restricted
  • ChatGPT AI tool company data policy
  • pirated software Copyright Act employer liability
  • POPIA data breach 72-hour notification
  • Cybercrimes Act section 54 reporting obligations
  • employer right to read employee email
Why This Template

What You Get With This Template

Drafted specifically for South African law — addresses Cybercrimes Act 19 of 2020, RICA, ECTA, POPIA, and Copyright Act requirements in a single policy

Establishes the employer as RICA "system controller" with lawful authority to monitor employee email, internet, and device activity

POPIA-compliant monitoring provisions with transparent disclosure, purpose specification, and proportionality requirements

Comprehensive data classification framework (Public, Internal, Confidential, Restricted) with practical handling requirements for each level

BYOD security requirements including MDM enrolment, containerisation, and remote wipe provisions

Incident reporting procedures aligned with both POPIA section 22 (72-hour breach notification) and Cybercrimes Act section 54 obligations

Addresses emerging technologies including AI tools, generative AI, and cloud computing with practical security guidelines

Progressive disciplinary framework aligned with LRA Schedule 8 for consistent enforcement of IT policy violations

Be First to Draft Your IT Acceptable Use Policy

Early access opens soon. Join the waiting list and we'll email you the moment it does.

One launch email — no spamFounding-member pricing