Free template. This policy is provided as a starting point for IT and security teams. Adapt it to your organisation’s needs, jurisdiction, and tooling. Attribution appreciated but not required.


Document Information

ReferencePOL-SEC-001
Version1.0
Issue DateJune 2026
ScopeAll employees and contractors
ClassificationInternal Use
OwnerIT Department / Cybersecurity
Next ReviewJune 2027

1. Purpose

This policy establishes the rules for the acceptable use of external online tools and third-party services when handling corporate documents and files within the work environment.

Its purpose is to protect the confidentiality, integrity, and availability of the organisation’s information, its clients’ data, and any data subject to regulation, in compliance with the General Data Protection Regulation (GDPR) and information security best practices.


2. Scope

This policy applies to:

  • All employees in the organisation.
  • Contractors, consultants, and external workers who access company systems or information.
  • Any corporate or personal device used for work-related activities (BYOD).

3. Definitions

TermDefinition
External online toolAny browser-based or application service that processes, stores, or transforms files on servers outside the organisation’s infrastructure.
Corporate informationAny data, document, file, or communication related to the company’s operations, its clients, or its projects.
Personal dataInformation relating to identified or identifiable natural persons, as defined by the GDPR.
Approved corporate toolAn application or service validated and provided by the IT department for professional use.

4. Usage Rules

4.1 Prohibited Use

The use of unauthorised external online tools for the following activities is strictly prohibited:

  • Uploading, converting, compressing, merging, splitting, or editing documents containing corporate information, client data, or personal data.
  • Processing emails, contracts, reports, credentials, health records, or any sensitive information.
  • Temporarily storing corporate files on unauthorised third-party cloud platforms.

Examples of unauthorised services (non-exhaustive list):

  • ilovepdf.com, smallpdf.com, pdf24.org, pdfcandy.com
  • sodapdf.com, sejda.com, camscanner.com
  • Any similar service requiring files to be uploaded to external servers.

4.2 Permitted Use

The use of external online tools is permitted only when:

  • The file does not contain corporate information, client data, or personal data.
  • The tool has been expressly approved by the IT department.
  • Explicit authorisation has been obtained from the area manager for that specific use.

4.3 Available Corporate Tools

For handling PDF files and office documents, employees should use approved tools such as:

  • Microsoft Word — document conversion and editing, available via Microsoft 365.
  • Microsoft Edge — built-in PDF viewing and annotation.
  • Adobe Acrobat — where a licence has been assigned.
  • Any other tool formally approved and communicated by the IT department.

To request a specific tool not currently available, open a ticket with the Service Desk.


5. Associated Risks

The use of unauthorised external online tools may result in:

  • Leakage of confidential information to third-party servers outside the organisation’s control.
  • GDPR non-compliance, potentially exposing the company to administrative sanctions.
  • Compromise of client or patient data.
  • Civil or contractual liability towards affected third parties.
  • Reputational damage to the organisation.

6. Consequences of Non-Compliance

Violations of this policy will be handled in accordance with the organisation’s disciplinary framework and applicable labour legislation. Consequences may range from a formal warning to more severe disciplinary measures, depending on the severity of the incident.

Any security incident arising from non-compliance must be reported to the IT department and the Cybersecurity team as soon as possible.


7. Responsibilities

RoleResponsibility
Employees / UsersBe aware of and comply with this policy. Notify the Service Desk of any tool needs not currently covered.
Area ManagersSupervise compliance within their teams and authorise exceptions where appropriate.
IT Department / Service DeskProvide adequate corporate tools, manage requests, and report security incidents.
Cybersecurity / SOCMonitor use of unauthorised services, manage incidents, and maintain the blocked domains list up to date.
ManagementApprove this policy, ensure the necessary resources are in place, and lead by example.

8. Validity and Review

This policy comes into force on the date of its approval and remains valid for one year, at which point it will be reviewed and updated as necessary.

Any significant amendments will be communicated to all affected employees with sufficient notice.


Adaptation Guide

When adapting this template to your organisation:

  • Replace scope references with your organisation name and geographic scope.
  • Review section 4.3 and replace with your organisation’s actual approved tooling.
  • Add or remove services from the prohibited list in section 4.1 based on your risk assessment.
  • Align section 6 with your HR disciplinary framework and local labour law.
  • Add an approval and signature block if required by your governance process.

Template authored by Tony Merisan — Enterprise IT Engineer. Licensed for free use and adaptation. Attribution appreciated.