On this page
A project manager at a Thunder Bay engineering firm uses the company laptop on the hotel Wi-Fi to pull up personal tax documents. A field technician in Timmins loses a company iPhone at a job site — the phone has the client contact database, work email, and a SharePoint link that’s still logged in. An office administrator in the region installs a “PDF converter” browser extension on her work desktop that turns out to be adware.
In every one of those cases, the employee didn’t think they were doing anything wrong. That’s because the business never told them, clearly and in writing, what wrong looks like.
That written, signed document is the IT Acceptable Use Policy (AUP) — and in 2026 it is hard to justify running a Canadian small business without one. For many Ontario employers it’s legally required. For the rest, it’s one of the cheapest pieces of legal, cybersecurity, and HR infrastructure you can put in place.
What an IT Acceptable Use Policy Actually Is
An AUP is a short, plain-language document that tells every person with access to your business technology — employees, contractors, volunteers, interns — what they can do, what they cannot do, and what they must do with that access. It covers company-issued laptops, desktops, mobile phones, email accounts, cloud services, and internet access, and it extends to any personal device permitted to touch company data.
It’s not an HR policy in the traditional sense, and it’s not an IT manual. It sits at the intersection: the technical rules made legible to non-technical staff, in language a new hire can read and understand in ten minutes.
A good AUP does four things at once:
- Sets clear expectations so staff know the rules before they break them
- Creates a legal basis for the business to take action if the rules are broken
- Demonstrates due diligence to regulators, auditors, and cyber insurers
- Protects employees from ambiguity about what they’re allowed to do
If you’ve ever had to fire someone for misusing IT, or explain a breach to the Privacy Commissioner, or justify your security posture to an insurer, you already know why these four matter.
Why Ontario Employers Specifically Need This
Ontario’s Working for Workers Act, 2022 (in force since October 11, 2022) requires employers with 25 or more employees as of January 1 of each year to have a written policy on electronic monitoring of employees. The policy must describe whether, how, and in what circumstances the employer monitors employees electronically, and must be provided to every employee — with new hires receiving it within 30 days.
If you have 25+ Ontario employees, you are legally required to have this written down and distributed. An AUP is the standard vehicle.
Under PIPEDA (federal) and employment-related privacy obligations, Canadian employers are also expected to have a documented basis for any monitoring of employee activity — even if it’s just antivirus logs or audit trails on Microsoft 365. Without a written AUP that the employee has acknowledged, your ability to use those logs in a disciplinary or legal context is weaker than it should be.
Below 25 employees, the Ontario requirement doesn’t strictly apply — but cyber insurance underwriters, sector regulators, and professional bodies increasingly expect the policy regardless.
What a Practical AUP Covers
A good AUP is short — two to four pages — and covers eight core areas. Not a 40-page binder. Not “use good judgment.” Concrete, named behaviours.
1. Authorized Use
- What company systems the employee is permitted to access
- What the systems may be used for (business purposes, with a reasonable personal-use allowance if granted)
- Who owns the data created on company systems (you, the business — stated explicitly)
2. Account Security and Credentials
- Password complexity, no sharing, no reuse across personal accounts
- Mandatory MFA on every account
- Passwords stored only in the approved business password manager — never in browsers on personal devices, email, or chat
- Reporting obligations if a password is suspected of being compromised
3. Company-Issued Devices (Laptops, Desktops, Mobile Phones)
This is the section most AUPs are weakest on. Specifics that matter:
- Devices remain the property of the company at all times
- Devices must not be modified, rooted, jailbroken, or have security software disabled
- Devices must remain enrolled in the company’s Mobile Device Management (MDM) platform (typically Microsoft Intune for M365 environments), including any remote-wipe capability
- Patches and updates must be applied within the window set by IT
- Devices must be locked when unattended and returned immediately on termination of employment
- Lost or stolen devices must be reported within one hour of discovery so remote wipe can be initiated — not end-of-day, not “tomorrow”
4. Personal Use and Personal Devices (BYOD)
- What personal use of company devices is permitted (e.g., occasional web browsing on breaks) — and what is not (e.g., installing personal software, streaming, gaming, cryptocurrency mining)
- Rules for personal devices touching company data: MDM enrollment required, minimum OS version, screen lock, approved apps only
- Clear separation of work and personal data where technically possible (Intune app protection policies, Android Work Profile, iOS Managed Apple ID)
- What happens on termination — remote wipe of company data scope only, not personal photos
5. Email, Internet, and Messaging
- Email is for business communication; no use of company email to sign up for personal services
- Forbidden content categories — illegal material, discriminatory/harassing communication, adult content
- Rules against using personal webmail (Gmail, Yahoo) to send or receive company data
- Social media: no disclosure of client information, internal business details, financials, or security posture
6. Data Handling and Classification
- Reference to the business’s data classification tiers (Public / Internal / Confidential / Restricted) and the approved tool list for each
- Prohibition on copying confidential data to personal devices, personal cloud storage (Dropbox, personal OneDrive, Google Drive), or USB drives not issued by the business
- Explicit mention of AI tools — consumer AI tools (free ChatGPT, browser extensions) are off-limits for Internal, Confidential, or Restricted data
7. Monitoring and Privacy
This is the part the Working for Workers Act most directly requires:
- A clear statement that company systems are monitored (who, when, how)
- What kinds of logs are collected — email metadata, login activity, security events, web filtering, MDM telemetry
- The purpose of monitoring — security, compliance, investigation of incidents, troubleshooting
- What reasonable expectation of privacy the employee does (and does not) have on company systems
8. Reporting and Consequences
- Employee obligations to report: suspected phishing, lost/stolen devices, suspicious account behaviour, policy violations by others
- Clear statement that violations may result in progressive discipline up to and including termination
- Signature and date line at the bottom — a dated acknowledgement the employee has read and agreed to the policy
Why Every Employee Must Sign
Unsigned policies are worth what they’re written on.
A signed AUP accomplishes three things a posted one doesn’t:
- Evidentiary value. If an employee is terminated for misuse, the signed policy is proof they were informed of the rule. Without it, “I didn’t know” becomes a defensible position.
- Legal standing. Many provincial wrongful-dismissal cases turn on whether the employer established and communicated clear expectations. The signed acknowledgement is that communication.
- Compliance defensibility. Cyber insurance questionnaires, PIPEDA investigations, and professional audits all ask whether staff have agreed to acceptable-use terms. “Yes, on file, with a date” is a far stronger answer than “we verbally mentioned it at onboarding.”
Re-sign annually, or on any material change. A three-year-old AUP your staff signed once at hire is drifting toward obsolete.
The Most Common Mistakes SMBs Make
Using a generic template. A US-sourced AUP template will not reference Ontario’s Working for Workers Act, PIPEDA, or Canadian privacy expectations. It will also likely include clauses your lawyer doesn’t want you enforcing. Localize or start fresh.
Making it 20+ pages long. If employees don’t read it, they can’t comply with it. Keep it at two to four pages. Put the detail behind it in supporting procedures — a separate data classification sheet, a separate password guide — referenced from the AUP.
No tie to enforcement. A policy without named consequences is a suggestion. State the range of responses (coaching, written warning, termination) even if you hope never to need them.
Never updating it. AI tools, MDM capabilities, and remote-work norms have changed significantly in the last two years. An AUP that doesn’t mention AI, MDM, or personal-device rules in 2026 is stale.
No new-hire or annual re-sign. Signing once at hire in 2021 is not a current policy acknowledgement in 2026.
Company-Issued Resources Deserve Their Own Emphasis
Because this is where most real-world exposure happens, a few specifics worth making explicit in the AUP:
Laptops and desktops — MDM-managed, disk-encrypted (BitLocker or FileVault), auto-locking, patched within the defined window, no unapproved software, no local admin rights for standard users. Returned in working condition at termination; replacement billed if damaged through negligence.
Mobile phones — MDM-enrolled, passcode required, remote-wipe authorized, location services per business-defined rules, no jailbreaking, no sideloaded apps. Company-paid plans are for business use with a reasonable personal-use allowance.
Peripherals and external storage — USB drives only if issued by the business and encrypted; no use of personal USB devices on company hardware. External monitors and docking stations on company hardware only.
Take-home and remote work — devices are used on trusted networks where possible, VPN or Conditional Access required for sensitive systems, no public Wi-Fi without VPN, no shoulder-surfing risk in public spaces.
These are not theoretical. In the last year we’ve worked on incidents originating from: a laptop stolen from a parked vehicle in Thunder Bay, a phone lost on a flight out of an employee downloading company data onto a personal USB before resigning, and a cracked-screen iPhone traded in at a carrier store without being wiped. A clear, signed, enforced AUP would not have stopped the theft or the lost phone, but in every one of those cases it would have limited the exposure — encrypted disks, a one-hour reporting rule, a remote wipe before the data walked away.
How DVG Systems Helps
We deliver AUP setup as part of our managed IT onboarding, and as a standalone engagement for clients whose policies are overdue for refresh:
- A tailored AUP draft for your business — 2 to 4 pages, Canadian and Ontario-aware, matching your risk profile
- Alignment with Microsoft 365 Intune / MDM configuration so the policy matches what the platform actually enforces
- Signature collection workflow via SharePoint, Adobe Sign, or DocuSign — tracked, dated, and auditable
- Annual re-sign reminders built into your HR/IT calendar
- Integration with the data classification tier list and approved-tool list so the AUP references real, current business rules — not generic placeholders
- Policy updates when material technology or regulatory changes occur
The Bottom Line
An IT Acceptable Use Policy is the lowest-effort, highest-leverage piece of IT governance you can put in place. Two to four pages. A signature. An annual refresh. That’s the entire commitment — and it underpins your cybersecurity posture, your legal defensibility, your compliance with Ontario’s Working for Workers Act, and your ability to act when an employee makes a mistake.
Without a signed AUP, every disciplinary decision, every insurance claim, and every incident report starts from a weaker position than it needs to.
With one, your staff know the rules, your business has a record, and your IT and HR teams are speaking the same language for the first time.
If you don’t have one, or the one you have was written before MDM, before MFA, and before AI tools landed on every desk, this is the project to run next.
Related Reading
- Password Sharing at Work: Why “One Login for the Team” Is a Six-Figure Risk — why the AUP needs an explicit no-sharing clause
- How to Safely Share Passwords With Your IT Provider — the credential-handling rules your AUP should reference
- When Employees Leave: The IT Offboarding Checklist — the other side of the employee lifecycle
- A 4-Tier Data Classification Guide for AI — the tiers your AUP should reference for AI tool use
- Cybersecurity, Cyber Insurance, and MSP Liability for Canadian SMBs — why a signed AUP matters to your insurer
DVG Systems provides managed IT services, IT policy drafting, Microsoft Intune deployment, and HR/IT alignment for small and mid-sized businesses across Northern Ontario, including Thunder Bay, Timmins, and the surrounding region. If you’d like help drafting, rolling out, or refreshing your Acceptable Use Policy, book a free assessment or reach us at (807) 700-0061 or solutions@dvgsystems.com.