IT Policy

Sticklepath Parish Council

Sticklepath Parish Council  I.T. Policy

PDF Version of Sticklepath Parish Council IT Policy for Download

1. Introduction

Sticklepath Parish Council ( SPC) recognises the importance of effective and secure information technology (IT) and email usage in supporting its business, operations, and communications.

This policy outlines the guidelines and responsibilities for the appropriate use of IT resources and email by council members, employees, volunteers, and contractors.

2. Scope

This policy applies to all individuals who use SPC’s IT resources, including computers, networks, software, devices, data, WhatsApp and email accounts.  There can be no excuses for anyone not protecting their data or working safely.

3. Acceptable use of IT resources and email

SPC IT resources and email accounts are to be used for official council-related activities and tasks.  All users must adhere to ethical standards, respect copyright and intellectual property rights, and avoid accessing inappropriate or offensive content.

4. Device and software usage

As SPC does not issue computers or phones, emails and documents should be accessed online and not stored on personal computers or phones unless unavoidable. When operating from a personally owned computer, care must be taken to ensure software and applications do not interfere or provide risks to Parish work-related tasks.

5. Data management and security

All sensitive and confidential SPC data will be stored and transmitted securely using approved methods. This includes shared Cloud/One Drive storage, and secure WhatsApp communication. Secure data destruction methods should be used by all as per the Data Retention and Destruction Policy.

6. Network and internet usage

SPC’s network and internet connections should be used responsibly and efficiently for official purposes. Downloading and sharing copyrighted material without proper authorisation is prohibited.

7. Email communication

Email accounts provided by SPC are for official communication only. Emails should be professional and respectful in tone. Confidential or sensitive information must not be sent via email unless it is encrypted.

Be cautious with emails holding attachments and links to avoid phishing and malware. Verify the source before opening any attachments or clicking on links.

From the adoption of the new .gov domain/email addresses, the additional security will be supported by the Cabinet Digital and Data Office ( CDDO) and GOV.UK through their authorised registrars and the Protecting Public Sector Domains Team to monitor for vulnerabilities, and helping to prevent cyberattacks.

8. Password and account security

SPC users are responsible for maintaining the security of their accounts and passwords. Passwords should be strong and not shared with others. Regular password changes are encouraged to enhance security.

9. WhatsApp

The security of encryption through WhatsApp can ensure that communication is secure. However, this mode of communication should only be used to provide prompts to gain attention, share immediate alerts or for informal discussion.

WhatsApp messages should still adhere to best practice in terms of handling confidential or sensitive information, as it still might be required as part of any investigation

Mobile devices should be secured as effectively as computers with passcodes and/or biometric authentication.

10. Email monitoring

SPC reserves the right to monitor Council email communications to ensure compliance with this policy and relevant laws. Monitoring will be conducted in accordance with the Data Protection Act and GDPR.

11. Retention and archiving

Emails should be retained and archived in accordance with legal and regulatory requirements. All users should regularly review and delete unnecessary Council emails to maintain an organised inbox and to comply with the Data Retention and Destruction Policy.

12. Reporting security incidents

All suspected security breaches or incidents will be reported immediately to the Clerk as the designated IT point of contact for investigation and resolution. Report any email-related security incidents or breaches to the Clerk immediately and who will assess the incident and determine if it needs reporting to the Information Commissioner’s Office (ICO) for personal data breaches, or to DNPA as the Planning Authority that would deal with planning breaches

13 Training and awareness

SPC will provide advice, training and resources to educate users ( Councillors and Clerk) about IT security best practices, privacy concerns, and technology updates. All employees and councillors will receive appropriate advice on email security and best practices as guidance is provided by Government or DALC.

14. Compliance and consequences

Breach of this IT and Email Policy may result in the suspension of IT privileges and further consequences as deemed appropriate.

15. Policy review

This policy will be reviewed every 2 years to ensure its relevance and effectiveness. Updates may be made to address emerging technology trends and security measures.

16. Contacts

For IT-related enquiries or assistance, users can contact the Parish Clerk or in extremis, the Internal Auditor

All staff and councillors are responsible for the safety and security of the SPC IT and email systems. By adhering to this IT and Email Policy, SPC aims to create a secure and efficient IT environment that supports its mission and goals.

Date: 6th October 2025
Date for Review: October 2027
Signature: Kevin Sales, Chair.