Free template. This policy is provided as a starting point for IT and security teams. Adapt it to your organisation’s needs, jurisdiction, and tooling. Attribution appreciated but not required.
Document Information
| Reference | POL-SEC-001 |
| Version | 1.0 |
| Issue Date | June 2026 |
| Scope | All employees and contractors |
| Classification | Internal Use |
| Owner | IT Department / Cybersecurity |
| Next Review | June 2027 |
1. Purpose
This policy establishes the rules for the acceptable use of external online tools and third-party services when handling corporate documents and files within the work environment.
Its purpose is to protect the confidentiality, integrity, and availability of the organisation’s information, its clients’ data, and any data subject to regulation, in compliance with the General Data Protection Regulation (GDPR) and information security best practices.
2. Scope
This policy applies to:
- All employees in the organisation.
- Contractors, consultants, and external workers who access company systems or information.
- Any corporate or personal device used for work-related activities (BYOD).
3. Definitions
| Term | Definition |
|---|---|
| External online tool | Any browser-based or application service that processes, stores, or transforms files on servers outside the organisation’s infrastructure. |
| Corporate information | Any data, document, file, or communication related to the company’s operations, its clients, or its projects. |
| Personal data | Information relating to identified or identifiable natural persons, as defined by the GDPR. |
| Approved corporate tool | An application or service validated and provided by the IT department for professional use. |
4. Usage Rules
4.1 Prohibited Use
The use of unauthorised external online tools for the following activities is strictly prohibited:
- Uploading, converting, compressing, merging, splitting, or editing documents containing corporate information, client data, or personal data.
- Processing emails, contracts, reports, credentials, health records, or any sensitive information.
- Temporarily storing corporate files on unauthorised third-party cloud platforms.
Examples of unauthorised services (non-exhaustive list):
- ilovepdf.com, smallpdf.com, pdf24.org, pdfcandy.com
- sodapdf.com, sejda.com, camscanner.com
- Any similar service requiring files to be uploaded to external servers.
4.2 Permitted Use
The use of external online tools is permitted only when:
- The file does not contain corporate information, client data, or personal data.
- The tool has been expressly approved by the IT department.
- Explicit authorisation has been obtained from the area manager for that specific use.
4.3 Available Corporate Tools
For handling PDF files and office documents, employees should use approved tools such as:
- Microsoft Word — document conversion and editing, available via Microsoft 365.
- Microsoft Edge — built-in PDF viewing and annotation.
- Adobe Acrobat — where a licence has been assigned.
- Any other tool formally approved and communicated by the IT department.
To request a specific tool not currently available, open a ticket with the Service Desk.
5. Associated Risks
The use of unauthorised external online tools may result in:
- Leakage of confidential information to third-party servers outside the organisation’s control.
- GDPR non-compliance, potentially exposing the company to administrative sanctions.
- Compromise of client or patient data.
- Civil or contractual liability towards affected third parties.
- Reputational damage to the organisation.
6. Consequences of Non-Compliance
Violations of this policy will be handled in accordance with the organisation’s disciplinary framework and applicable labour legislation. Consequences may range from a formal warning to more severe disciplinary measures, depending on the severity of the incident.
Any security incident arising from non-compliance must be reported to the IT department and the Cybersecurity team as soon as possible.
7. Responsibilities
| Role | Responsibility |
|---|---|
| Employees / Users | Be aware of and comply with this policy. Notify the Service Desk of any tool needs not currently covered. |
| Area Managers | Supervise compliance within their teams and authorise exceptions where appropriate. |
| IT Department / Service Desk | Provide adequate corporate tools, manage requests, and report security incidents. |
| Cybersecurity / SOC | Monitor use of unauthorised services, manage incidents, and maintain the blocked domains list up to date. |
| Management | Approve this policy, ensure the necessary resources are in place, and lead by example. |
8. Validity and Review
This policy comes into force on the date of its approval and remains valid for one year, at which point it will be reviewed and updated as necessary.
Any significant amendments will be communicated to all affected employees with sufficient notice.
Adaptation Guide
When adapting this template to your organisation:
- Replace scope references with your organisation name and geographic scope.
- Review section 4.3 and replace with your organisation’s actual approved tooling.
- Add or remove services from the prohibited list in section 4.1 based on your risk assessment.
- Align section 6 with your HR disciplinary framework and local labour law.
- Add an approval and signature block if required by your governance process.
Template authored by Tony Merisan — Enterprise IT Engineer. Licensed for free use and adaptation. Attribution appreciated.