An Acceptable Use Policy (AUP) sets out how people may use an organisation’s IT systems and data. It defines the rules for using devices, accounts, networks, internet access, email and messaging, file shares, cloud services and software. It explains what is allowed and what is not, such as limits on personal use, installing software, connecting personal devices, downloading content, handling company or customer data, using social media and working remotely. An AUP also says who it applies to, the expected standards of behaviour, any privacy and monitoring notices, and the consequences of breaking the rules. Staff and contractors are usually asked to read and acknowledge the AUP when they join and again when it is updated. It sits alongside documents like the information security policy and code of conduct, and its aim is to set clear expectations so everyday decisions about technology are consistent and lawful.