DPDP NavigatorAct 2023 · Rules 2025
All templates
PoliciesSection 8

Acceptable Use Policy (Personal Data Handling) Template

An internal employee-facing policy defining permitted and prohibited handling of personal data across systems and devices.

Template
ACCEPTABLE USE POLICY — PERSONAL DATA HANDLING

[Organization Name]
Effective Date: [Effective Date] | Applies to: All employees, contractors, and interns

1. PURPOSE
This Policy defines acceptable and prohibited practices for employees who access, process, or store personal data of customers, employees, or other Data Principals in the course of their work, supporting [Organization Name]'s obligation under Section 8 of the DPDP Act, 2023 to implement reasonable security safeguards and prevent personal data breaches.

2. WHO THIS APPLIES TO
Every individual with system access to any database, application, or file containing personal data, including full-time staff, contractors, interns, and third-party support personnel operating under our credentials.

3. PERMITTED USE
   a. Access personal data only to the extent necessary to perform your assigned role ("need-to-know" principle).
   b. Use only approved, company-issued systems and applications to process personal data; approved tools are listed at [internal link/Annexure].
   c. Store personal data only in designated, access-controlled systems — not in personal cloud storage, personal email, or unencrypted local drives.
   d. Share personal data internally only through approved channels (e.g., role-based access in [System Name]), and externally only through a Data Processing Agreement or Data Sharing Agreement approved by Legal.

4. PROHIBITED PRACTICES
   a. Downloading personal data to personal devices, USB drives, or personal cloud accounts.
   b. Forwarding personal data to personal email addresses or unauthorised messaging apps.
   c. Screenshotting or exporting bulk personal data for purposes outside your assigned task.
   d. Sharing login credentials or bypassing access controls.
   e. Using personal data for any purpose other than the one for which it was collected (purpose limitation), including "curiosity" lookups of customer or colleague records.
   f. Retaining personal data beyond the periods specified in the Data Retention Policy.

5. DEVICE AND SYSTEM SECURITY
   a. All company devices must have disk encryption, endpoint protection, and screen-lock enabled.
   b. Multi-factor authentication is mandatory for systems holding Tier 3/Tier 4 data (see Data Classification Policy).
   c. Report a lost or stolen device holding personal data within [X hours] to IT Security.

6. REMOTE AND HYBRID WORK
When accessing personal data remotely, employees must use the company VPN, avoid public Wi-Fi for Tier 3/4 data access, and ensure physical documents containing personal data are not left unattended.

7. THIRD-PARTY AND AI TOOL USE
Personal data must not be entered into unapproved third-party tools, including generative AI tools, translation services, or productivity plugins, unless the tool has been vetted and approved by IT Security and covered by an appropriate data processing agreement.

8. MONITORING
[Organization Name] may monitor system access logs to personal data repositories to detect unauthorised access, consistent with our security safeguard obligations; such monitoring is conducted proportionately and in line with our Employee Data Processing Notice.

9. INCIDENT REPORTING
Any suspected misuse, unauthorised access, or accidental exposure of personal data must be reported immediately per the Data Breach Response Policy — do not attempt to independently investigate or conceal the incident.

10. CONSEQUENCES OF NON-COMPLIANCE
Violation of this Policy may result in disciplinary action up to and including termination of employment or contract, and may expose the individual to personal liability under applicable law.

11. ACKNOWLEDGEMENT
I confirm I have read, understood, and agree to comply with this Acceptable Use Policy.

Employee Name: ______________________ Signature: ______________________ Date: ______________

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.