Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- Step 1: Map your real-world IT risks
- Step 2: Choose a sensible set of core policies
- Step 3: Make responsibilities obvious
- Step 4: Align policies with contracts and privacy documents
- Step 5: Cover monitoring carefully
- Step 6: Train people and keep the documents alive
- Common mistakes businesses make
- A practical example for a small UK business
- Key Takeaways
Many UK businesses know they need IT rules, but they often leave them half-finished, copied from an old template, or buried in a staff handbook nobody reads.
The result is predictable: passwords shared over chat, personal devices used without any ground rules, software bought without approval, and confusion when a data breach or phishing attack hits. Another common mistake is treating IT policies as an internal admin issue only, when they also connect directly to privacy, employment, contracts and day-to-day risk.
This guide answers the practical question founders and managers usually have: what do IT policies and procedures actually look like in a real UK business, and what should they cover? We’ll walk through useful examples, when these documents matter most, the legal points that tend to sit behind them, and the mistakes that catch businesses before they sign contracts, onboard staff or spend money on setup.
Overview
IT policies set the rules. IT procedures explain how those rules are followed in practice. For UK startups and SMEs, the right set of documents can reduce security risks, make staff expectations clearer, and support compliance with privacy and employment obligations.
- Decide which IT policies your business actually needs, rather than copying a long corporate pack
- Separate policies from procedures so staff know both the rule and the step-by-step process
- Match your documents to real business risks such as remote working, cloud systems, customer data and supplier access
- Make sure your IT rules line up with privacy notices, employment contracts and internal disciplinary processes
- Review ownership, access, monitoring and security before you sign supplier contracts or hand out devices
- Train staff and keep records, because a policy nobody understands is rarely much help when something goes wrong
What It Policies and Procedures Examples Means For UK Businesses
For a UK business, IT policies and procedures examples are working models of the internal rules and processes that govern technology use, data handling, access, security and incident response.
A policy usually states the standard your business expects. A procedure usually sets out who does what, when, and how. Both matter. A short rule saying employees must use strong passwords is useful, but a procedure explaining password manager use, reset steps, multi-factor authentication and account lockout handling is what makes that rule work in real life.
What counts as an IT policy?
An IT policy is generally a statement of business rules for systems, devices, data and digital behaviour. It tells staff, contractors and sometimes suppliers what is allowed, what is required and what is prohibited.
Common examples include:
- Acceptable use policy
- Password and access control policy
- Bring your own device policy
- Remote working and homeworking IT policy
- Data retention and deletion policy
- Cybersecurity or information security policy
- Email, messaging and internet use policy
- Software procurement and licensing policy
- Backup and disaster recovery policy
- Incident response and data breach escalation policy
What counts as an IT procedure?
An IT procedure is the operating instruction behind the policy. It is more practical and often more detailed. Procedures are especially useful where the business needs consistency across managers, teams or external providers.
Examples include:
- How to onboard a new starter into email, file storage and business systems
- How to remove access when an employee leaves
- How to report a suspected phishing email
- How to approve new software purchases
- How to classify, store and delete customer records
- How to respond if a laptop is lost or stolen
- How to restore business data from backups after an outage
Why these documents matter legally
These documents are not just operational paperwork. They often support legal compliance and help show that your business has thought about risk in a sensible way.
In the UK, IT policies frequently overlap with:
- UK GDPR and data protection expectations, especially around access, retention, security and breach response
- Employment law issues such as monitoring, disciplinary action, hybrid working and employee obligations
- Commercial contracts, particularly where a customer or supplier expects minimum security standards
- Intellectual property ownership, especially where staff use personal devices or unapproved software
- Confidentiality and trade secrets, where loose IT practices can weaken internal protections
This does not mean every SME needs a large enterprise policy suite. It means your business should have documents that fit the way you actually operate.
Simple examples of clauses businesses often include
A good acceptable use policy might state that company systems are for authorised business use, limited personal use is permitted if it does not affect work or security, and staff must not install unauthorised software. A password policy might require unique passwords, multi-factor authentication for key systems, and an immediate report if credentials are exposed.
A remote working policy might say that confidential information must not be viewed in public places where it can be overlooked, business devices must be locked when unattended, and home routers should use secure settings. A software procedure might require manager approval, a legal or procurement check on licence terms, and a technical review before any app is connected to customer data.
When This Issue Comes Up
Most businesses do not look for it policies and procedures examples out of curiosity. They look when a practical trigger forces the issue.
You are hiring your first employees or contractors
The moment new people get access to devices, logins and customer information, informal rules stop being enough. Founders often assume a quick verbal explanation will do, but that leaves too much open to interpretation.
This is where businesses usually need at least:
- An acceptable use policy
- A password and access policy
- An onboarding and offboarding procedure
- Clear confidentiality wording in employment contracts or contractor agreements
You are moving to remote or hybrid work
Homeworking creates obvious convenience, but it also raises questions about device security, document access, screen privacy, use of personal equipment and reporting lost devices. If nothing is written down, managers handle issues inconsistently and staff make up their own rules.
You are collecting more customer data
As the business grows, data tends to spread across platforms, inboxes, spreadsheets and chat tools. That is often when founders realise they have a privacy notice or privacy policy on their website but no internal rules for storage, deletion, permissions or breach escalation.
External-facing privacy information and internal data procedures should line up. If your privacy messaging says you keep data only as long as necessary, your internal process should explain what that means in practice.
You are buying software or signing with a client
Customers, especially larger ones, may ask what security controls you have before they sign. Suppliers may also impose licence restrictions, security responsibilities or data handling terms. If your internal position is unclear, contract negotiations become harder and promises may be made that your team cannot realistically meet.
Before you sign a contract, check whether your IT policies support commitments around:
- Access controls
- Encryption or device security
- Sub-processor or supplier use
- Incident reporting timeframes
- Staff training
- Data deletion on termination
You have had a near miss or a real incident
A phishing email opened by a team member, a misplaced phone, a shared login, or a former contractor still having system access are all common triggers. Businesses often write their first serious procedure after something has already gone wrong.
That is understandable, but the better time is before you spend money on setup, onboard a new team or promise clients specific standards.
Practical Steps And Common Mistakes
The best IT policy set is the one your business can actually follow, train on and enforce.
Step 1: Map your real-world IT risks
Start with the way your business actually works. A design agency using cloud storage, freelancers and client assets has different needs from a retailer with EPOS systems and customer accounts, or a health tech startup handling sensitive information.
Think about:
- What devices are used, and who owns them
- Where business data is stored
- Who has access to what
- Whether staff work remotely
- What happens when someone joins or leaves
- What customer or supplier promises you already make
- Whether personal devices or apps are used for work
The point is not to create a perfect security framework. The point is to identify where your business is exposed and where written rules will actually help.
Step 2: Choose a sensible set of core policies
Most startups and SMEs do not need twenty separate IT documents. They do need a clear core set that covers their biggest risks.
A practical starting bundle often includes:
- Acceptable use policy
- Password and authentication policy
- Access control and account management procedure
- Remote working or bring your own device policy
- Incident reporting and response procedure
- Data retention and deletion policy
- Software approval and licensing procedure
If you operate in a regulated space or handle large volumes of personal data, you may need more detail. If your setup is simpler, fewer documents may be enough.
Step 3: Make responsibilities obvious
A common drafting error is writing policies with no owner. If a document says devices must be encrypted, who checks? If an account should be removed on departure, who tells IT or your managed service provider? If a breach is suspected, who decides whether it needs escalation?
Each procedure should identify:
- The person or role responsible
- The steps to take
- The timeframe
- Any approvals needed
- The record that should be kept
This is especially important for SMEs that rely on external IT support. A supplier can help, but your business still needs internal decision-makers.
Step 4: Align policies with contracts and privacy documents
Your IT rules should not contradict your public or contractual promises. This is where founders often get caught. A customer contract may promise prompt incident notification, but your internal procedure may not say who reports incidents or within what timeframe. A privacy notice may refer to secure processing and limited retention, while staff keep old customer files indefinitely.
Check alignment with:
- Employment contracts and staff handbooks
- Contractor agreements
- Customer terms
- Supplier and SaaS contracts
- Privacy notices
- Data processing terms where relevant
Step 5: Cover monitoring carefully
Many businesses want the right to monitor company systems, emails or internet use. That can be legitimate, but the rules should be clear, proportionate and consistent with your data protection approach and employment documentation.
The main risk is not only legal. It is also cultural. If monitoring is vague or hidden, disputes are more likely when performance issues or misconduct allegations appear later.
A sensible policy usually explains:
- What may be monitored
- Why monitoring may occur
- Who may carry it out
- How information will be used
- What personal use, if any, is allowed
Step 6: Train people and keep the documents alive
Even a well-written policy fails if nobody knows it exists. Staff need a practical explanation at onboarding and refreshers when systems, roles or risks change.
You do not need dramatic annual programmes. For many SMEs, short targeted training and clear acknowledgements are enough, as long as they are real and repeated when needed.
Common mistakes businesses make
The same problems appear again and again.
- Using a US or generic overseas template that does not fit UK legal context or actual operations
- Writing policies only for employees, while contractors and consultants use the same systems
- Ignoring personal devices even though staff use their own phones and laptops for work
- Promising technical measures in contracts that the business does not currently have
- Failing to remove access promptly when someone leaves
- Leaving software buying to individual teams without licence or security checks
- Separating privacy compliance from day-to-day IT procedures
- Drafting disciplinary consequences vaguely, making enforcement harder later
A practical example for a small UK business
Imagine a growing ecommerce company with eight staff, a few freelancers, cloud accounting software, a customer database and a remote team. It does not need a huge policy manual. It probably does need a short acceptable use policy, a password and MFA policy, a remote working and device policy, a basic data retention rule, and a clear procedure for onboarding, offboarding and reporting suspicious emails.
It should also review its website privacy notice, supplier terms for software tools, employment contracts and confidentiality wording. If freelancers access the customer database or shared folders, contractor agreements and access rules need to reflect that reality.
FAQs
Do small businesses in the UK need written IT policies?
Often yes, especially if staff or contractors use business systems, customer data is handled, or remote working is common. The documents do not need to be long, but they should be clear and usable.
What is the difference between an IT policy and an IT procedure?
A policy states the rule or standard. A procedure explains the steps to follow. Most businesses need both, particularly for access, security and incident response.
Can I just use a free template?
You can use a template as a starting point, but templates often fail because they do not match your systems, contracts or real working practices. A policy that does not reflect reality can create as much risk as having none.
Should IT policies be part of employment contracts?
Usually not in full. Employment contracts often refer to policies and require employees to comply with them. That gives the business room to update internal rules without rewriting every contract, though the wording should be handled carefully.
How often should IT policies be reviewed?
Review them when your systems, team structure, supplier setup or data use changes, and after any security incident or near miss. For many SMEs, an annual review plus event-based updates is sensible.
Key Takeaways
- IT policies tell people the rules, and IT procedures tell them how those rules work in practice
- UK startups and SMEs usually need a focused set of documents covering acceptable use, passwords, access, remote working, software approval, retention and incident response
- Your IT documents should match the way your business actually operates, including contractors, personal devices and cloud tools
- These policies often connect directly to UK privacy requirements, employment arrangements, confidentiality protections and commercial contracts
- The biggest mistakes are copying generic templates, ignoring real workflows, and failing to train staff or assign responsibility
- It is worth reviewing IT rules before you sign a contract, hire staff, launch new systems or expand customer data collection
If your business is dealing with it policies and procedures examples and wants help with staff IT policies, privacy documents, supplier contracts, contract review, and contractor or employment terms, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.






