Home » IT Policy

IT Policy

Millom Without Parish Council

Millom Without Parish Council Information Technology Policy

Introduction

Purpose of the IT Policy

The purpose of an IT policy is to establish clear parameters for how councillors, staff, and other authorised users use council-provided technology or equipment in the course of their duties. A well-defined policy helps to:

  • Set expectations for appropriate use of equipment and systems
  • Raise awareness of risks associated with IT use
  • Safeguard the council’s data and digital assets
  • Clarify what constitutes acceptable and unacceptable use
  • Outline the consequences of policy breaches

The council will determine whether limited personal use of IT equipment is permitted.

Monitoring of IT Use

The council may monitor the use of its IT equipment and systems where legitimate, proportionate, and compliant with data protection laws. Monitoring may include other persons who access council systems, such as those with council email addresses.

Scope of this Policy

This policy applies to all councillors, staff, and authorised users regardless of working location or pattern.

Computer Use

1.1 Hardware

1.1.1 Council computer equipment is provided for council purposes only.

1.1.2 Users must lock computers when leaving desks to prevent unauthorised access.

1.1.3 Equipment must be treated with care at all times.

1.1.4 Equipment must be kept clean and protected from spills.

1.1.5 Equipment must not be dismantled without advice.

1.1.6 Equipment and software must not be purchased without authorisation.

1.1.7 Personal storage devices may not be used without approval.

Equipment

2.1 Portable Equipment

2.1.1 Portable equipment includes laptops, tablets, smartphones, and similar devices.

2.1.2 Backup procedures must be followed.

2.1.3 Equipment must be kept secure at all times, including when working from home or travelling.

2.1.4 Devices must be encrypted and protected with security codes and wipe functions.

2.1.5 Loss or damage must be reported, with potential liability up to £100 for negligence.

2.1.6 Photography or video recording on council premises requires written permission.

2.1.7 Non-public meetings must not be recorded without consent.

2.1.8 Webcams may only be used for council business.

2.2 Use of Own Devices

2.2.2 Personal devices may be used at the council’s discretion.

2.2.3 Council email accounts must be used for work communications.

2.2.4 Devices may be taken temporarily during legal proceedings.

2.2.5 Personal and council data should be kept separate.

2.2.6 Users must secure their devices with strong passwords and inactivity locks.

2.2.7 Confidential attachments must be password protected and wipe functions enabled.

2.2.8 Council data must not be stored on personal cloud services.

2.2.9 Sensitive information must not be stored on personal devices.

2.2.10 Removable media must be wiped after use.

2.2.11 Work data must be securely backed up.

2.2.12 Council data must be removed from devices upon disposal or leaving employment.

2.2.13 Users are responsible for risks associated with personal device use.

Health and Safety

Appropriate workstations and eye tests will be provided for display screen equipment users.

Password and Authentication Policy

Strong passwords using three random words must be used, alongside Multi-Factor Authentication where possible.

Account security measures include IT-managed credentials, immediate default password changes, and compliance with data protection law.

Access to Passwords

  • Passwords must not be shared
  • Only assigned users may access accounts
  • Emergency administrative access controlled and logged

Password Storage and Management

  • No plain text storage
  • Use encrypted password managers

Password Change Requirements

  • Change immediately if compromised

Password Access Control and Logging

  • All administrative access logged
  • Unauthorised attempts treated as incidents

Monitoring

System usage may be monitored, logged, and inspected for compliance and security.

Monitoring is proportionate and legally compliant.

Data may be shared internally or with advisers.

Computers will be regularly scanned for viruses and unauthorised software.

Remote Working

Additional security measures apply when working remotely, including secure logouts, privacy of screens, secure storage of printed and electronic data, and safe transport of documents and devices.

Email

Email systems are for council business only and must be used responsibly.

Use of the Internet

Copyright

Copyright laws apply to all online material and must be respected.

Trademarks, Links and Data Protection

Unauthorised domain registration and linking is prohibited. Personal data must be processed lawfully.

Accuracy of Information

Internet information may not always be reliable.

Use of Social Media

Social media must be used responsibly and professionally.

Inappropriate content damaging the council’s reputation may result in disciplinary action.

All users must:

  • Not claim to represent the council without permission
  • Gain approval before publishing council-related content
  • Remain respectful and lawful
  • Protect confidential information
  • Refer media enquiries to the clerk
  • Maintain accurate professional profiles
  • Provide login access for council-managed accounts
  • Remove council data on leaving

Misuse

Misuse of IT systems may result in disciplinary action or dismissal.

Millom Without Parish Council
Connecting Our Communities

Email The Clerk

01229 775492

100% Green Hosting. 100% green Hosting from Technophobia ltd
0
visits to this site
© 2026 Millom Without Parish Council. All rights reserved Privacy Policy | Terms and Conditions
Website Designed by Whamos Ltd