Acceptable Use of Technology

ACCEPTABLE USE OF TECHNOLOGY POLICY

[Name of Charity]

Approved by the Board of Directors: [Date]
Next scheduled review: [Date, no later than 12 months from approval]
Policy owner: [Executive Director / IT lead]

1. Purpose

This Policy sets out how [Name of Charity] (the "Charity") expects its directors, officers, employees, volunteers, contractors, and other representatives ("Personnel") to use the Charity's information systems, devices, accounts, networks, and technology resources.

Technology is central to how the Charity delivers its mission. Used well, it enables the Charity's work. Used poorly, it exposes the Charity to legal, financial, reputational, and operational risk. This Policy sets the ground rules.

2. Scope

This Policy applies to all use of:

(a) Charity-owned or Charity-provided devices (laptops, desktops, phones, tablets, servers, storage media);

(b) Charity-owned or Charity-provided accounts (email, cloud storage, CRM, accounting, communications, collaboration, AI tools);

(c) the Charity's networks, including on-premises and cloud environments;

(d) Personnel's own devices and accounts when used to perform Charity work (see Section 8);

(e) third-party systems and services accessed on the Charity's behalf; and

(f) information held on any of the above.

This Policy operates alongside the Charity's Privacy Policy, AI Policy, Data Breach Response Policy, Confidentiality Policy, Records Retention Policy, Code of Conduct, and other governance documents. Where these overlap, the more restrictive provision applies.

3. General expectations

Personnel are expected to use the Charity's technology resources:

(a) for the Charity's legitimate purposes;

(b) in a manner that protects the Charity's confidential information, the personal information of others, and the security of the Charity's systems;

(c) in compliance with applicable law, including privacy, human rights, intellectual property, employment, and criminal law;

(d) in compliance with the Charity's policies; and

(e) with reasonable care.

Occasional personal use of Charity technology (for example, sending a personal email during a break) is tolerated, provided it does not interfere with work, expose the Charity to risk, or breach other provisions of this Policy.

4. Accounts and credentials

4.1 Individual accounts. Personnel are assigned individual accounts for the systems they need. Shared accounts are avoided except where necessary (for example, a shared inquiries inbox) and are governed by a documented protocol.

4.2 Passwords. Personnel must use strong, unique passwords for Charity accounts. Passwords must not be reused across services, written down in accessible locations, or shared with others (including other Personnel, family members, or vendors).

4.3 Multi-factor authentication. Multi-factor authentication (MFA) must be enabled on all Charity accounts where technically supported. Personnel must not disable MFA or seek workarounds.

4.4 Credential-sharing. Personnel must not share account credentials, including with other Personnel. Where another Personnel member requires access to a system, formal access is provisioned rather than credentials shared.

4.5 Departure. When Personnel leave the Charity, their access is revoked promptly. Personnel are expected to cooperate with account transitions and to return Charity information and devices.

5. Devices

5.1 Charity-provided devices. Charity-provided devices remain the property of the Charity. Personnel are expected to:

(a) keep the device physically secure (not left in vehicles, unattended in public, or accessible to unauthorized persons);

(b) apply security updates promptly;

(c) not install software that has not been approved by the [IT lead / Executive Director];

(d) not disable security software (antivirus, encryption, MFA, remote-wipe capability); and

(e) return the device on request or on departure.

5.2 Lost or stolen devices. Lost or stolen devices must be reported immediately to the [IT lead / Executive Director / Privacy Officer]. Reporting triggers assessment under the Data Breach Response Policy.

5.3 Encryption. Charity-provided devices must be encrypted. Portable storage media (USB drives, external hard drives) used for Charity information must also be encrypted, or must not be used.

6. Email and communications

6.1 Charity email accounts. Personnel use Charity email accounts for Charity business. Charity business is not conducted from personal email accounts except in emergencies, and any Charity information sent from personal accounts is transferred to Charity systems and deleted from personal accounts promptly.

6.2 Phishing and social engineering. Personnel are expected to exercise caution with unexpected emails, links, and attachments. When in doubt, verify through a separate channel. Reporting suspected phishing to the [IT lead / Executive Director] is expected, not optional.

6.3 Misdirected communications. Personnel who accidentally send information to the wrong recipient must report the incident promptly under the Data Breach Response Policy. This includes misdirected emails, incorrect email attachments, and BCC/CC errors.

6.4 Professional standards. Charity communications reflect on the Charity. Personnel are expected to communicate professionally, respectfully, and consistently with the Charity's values.

7. Confidential information

7.1 Handling. Confidential information (including personal information, donor information, beneficiary information, employee information, financial information, and other information covered by a duty of confidence) is handled on Charity-approved systems. Personnel must not:

(a) transfer confidential information to personal accounts or personal devices without approval;

(b) store confidential information in unapproved cloud services;

(c) share confidential information with third parties (including AI tools) except in accordance with the Charity's policies; or

(d) discuss confidential information in public or insecure settings.

7.2 Cross-reference to AI Policy. Use of AI tools involving confidential information is governed by the AI Policy. In particular, confidential information must not be input into free consumer AI tools.

7.3 Retention and disposal. Confidential information is retained and disposed of in accordance with the Records Retention Policy. Personnel must not retain confidential information beyond its useful life for Charity purposes.

8. Personal devices and accounts

8.1 General approach. The Charity's default expectation is that Charity work is performed on Charity-provided systems. Personal devices are used only where necessary and only in accordance with this Section.

8.2 Conditions for use of personal devices. Personnel using personal devices for Charity work must:

(a) obtain approval from the [Executive Director / IT lead];

(b) ensure the device is up to date, encrypted, and password-protected;

(c) not store Charity confidential information on the personal device outside of approved Charity applications;

(d) allow remote-wipe of Charity applications on the device if the device is lost or the Personnel member departs; and

(e) comply with all other provisions of this Policy.

8.3 Personal social media. Personnel using personal social media accounts must not:

(a) speak on behalf of the Charity without authorization;

(b) share confidential information;

(c) misrepresent their role at the Charity; or

(d) engage in conduct that could reasonably damage the Charity's reputation.

9. Software, tools, and services

9.1 Approved tools only. Personnel use software, tools, and services approved by the [IT lead / Executive Director] for Charity work. This includes cloud services, browser extensions, mobile applications, collaboration tools, and AI tools.

9.2 Unauthorized software. Personnel must not install unauthorized software on Charity systems, sign the Charity up for services without approval, or use their Charity email address to register for third-party services outside their scope of duties.

9.3 Approval process. Requests for new tools are directed to the [IT lead / Executive Director]. Approval considers security, privacy, cost, functionality, contractual protections, and consistency with other Charity policies (including the AI Policy).

9.4 Free tools. Free tools often have weaker privacy and security protections than paid or enterprise tools. Personnel should treat free tools with heightened caution and must not use them for confidential information without approval.

10. Internet and network use

10.1 General. Personnel may use the Charity's internet connection for Charity work and reasonable personal use. Prohibited uses include:

(a) accessing, downloading, or transmitting illegal, discriminatory, harassing, obscene, or defamatory material;

(b) engaging in activity that could compromise the security of Charity systems;

(c) unauthorized access to systems, whether the Charity's or others';

(d) high-bandwidth personal activity that interferes with Charity operations; and

(e) activity that violates law or Charity policy.

10.2 Public and unsecured networks. Personnel accessing Charity systems from public or unsecured networks (coffee shops, airports, hotels) must use a virtual private network (VPN) or other approved secure connection method.

11. Monitoring

The Charity may, in accordance with applicable law and its Privacy Policy, monitor use of Charity systems, devices, and accounts for purposes including security, compliance, investigation of suspected breaches, and system administration. Personnel should not have an expectation of privacy in the use of Charity systems for personal purposes. Monitoring is conducted proportionately and only for legitimate purposes.

12. Reporting

Personnel must report the following to the [IT lead / Executive Director / Privacy Officer] promptly:

(a) suspected security incidents or breaches;

(b) lost or stolen devices or credentials;

(c) suspected phishing or social engineering;

(d) misdirected communications;

(e) accidental exposure of confidential information (including to AI tools);

(f) suspected violations of this Policy; and

(g) any other event that could compromise the Charity's systems or information.

Reporting in good faith does not attract discipline. Failure to report may.

13. Departure

On departure from the Charity, Personnel:

(a) return all Charity-owned devices, storage media, credentials, and materials;

(b) cooperate with the transfer of Charity information from personal devices and accounts;

(c) confirm that Charity information has been removed from personal devices and accounts; and

(d) do not retain, use, or disclose Charity confidential information.

Access to Charity systems is revoked on departure. Personnel who continue in a volunteer or advisory role after ending employment are provisioned appropriate access for the new role.

14. Compliance

Failure to comply with this Policy may result in disciplinary action, up to and including termination of employment or engagement, and may result in personal liability where the conduct also breaches applicable law. Contractors and vendors who breach this Policy may have their engagement terminated.

15. Related policies

This Policy should be read alongside the Charity's:

(a) Privacy Policy;
(b) AI Policy;
(c) Data Breach Response Policy;
(d) Confidentiality Policy;
(e) Records Retention Policy;
(f) Code of Conduct;
(g) Social Media Policy; and
(h) Human Resources Policies.

16. Review

This Policy is reviewed at least annually, and sooner if:

(a) applicable law or technology changes materially;

(b) an incident indicates a gap in the Policy;

(c) the Charity's operations or systems change materially; or

(d) the Board directs a review.

17. Contact

Questions about this Policy should be directed to [name / role / email].

Version: 1.0
Approved: [Date]
Next review: [Date]

Why this Policy matters.

This is the foundation of the charity's technology governance. Every other tech-related policy (AI, privacy, data breach, social media, records retention) sits on top of it. Without it, there is no baseline expectation for how staff and volunteers should be using the systems that hold the charity's information. With it, the more specialized policies have something to anchor to.

What the charity needs to do before adopting.

  1. Identify the policy owner. The Policy assumes a designated IT lead or the Executive Director. For most small and mid-sized charities, there is no dedicated IT person. The Executive Director typically holds the role, sometimes supported by an outsourced IT vendor. Make the assignment explicit.
  2. Inventory the systems. Before the Policy can be operationalized, the charity should know what systems and accounts are actually in use. Email, CRM, accounting, cloud storage, communications tools, AI tools, payment processing, HR systems, and so on. If the inventory does not exist, build it during Policy rollout.
  3. Assess current practice against the Policy. The Policy will identify gaps. Multi-factor authentication not universally enabled, personal devices used without approval, shared credentials, free tools in use for confidential information. Do not adopt the Policy without a plan to close the main gaps. Adopting a Policy that describes practices the charity does not follow creates its own risk.
  4. Approve the list of authorized tools. Section 9 refers to an approved-tools list. The list is separate from the Policy so it can be updated without amending the Policy each time. Have a first version ready when the Policy is adopted.
  5. Confirm the Bring Your Own Device (BYOD) position. Section 8 permits personal device use with conditions. If the charity's actual position is different (either stricter or more permissive), adjust the Section before adopting.
  6. Confirm monitoring practices. Section 11 permits monitoring within legal limits. If the charity actually monitors use of systems, this needs to be disclosed clearly and consistently with the Privacy Policy. If it does not, that is also worth documenting. Employee privacy expectations under Ontario law (and increasingly other provinces) are not to be underestimated.

Volunteers are the group most likely to fall outside the Policy in practice. Charities often onboard volunteers without the same rigour applied to employees, but volunteers frequently handle confidential information. Make sure volunteer onboarding includes this Policy.

Executive directors and board members are the other group most likely to be exempted informally. They should not be. Some of the most damaging breaches involve senior people using personal devices, personal email, or unapproved tools for convenience.

BYOD is the section that gets the most pushback in adoption. Many staff already use personal devices for work, and tightening the rules feels intrusive. Two responses. First, if the charity does not want to be responsible for what happens on personal devices, the answer is to provide Charity devices. Second, if personal devices will be used, then the conditions in Section 8 are how the charity protects itself. Choose one path deliberately, rather than drifting.

Free AI tools deserve specific attention. Even after the AI Policy is adopted, staff will experiment. The Acceptable Use Policy's Section 9.4 is the general rule. The AI Policy is the specific one. Both should be introduced together.

When to update. Any time the charity adopts a major new system, changes its device or BYOD approach, has an incident, or updates the AI Policy. Also at any material change in Canadian employment or privacy law affecting workplace monitoring or personal information handling. The Policy is written to be stable, but this area moves.

How this fits with the other policies you've built. The AI Policy, Data Breach Response Policy, and Acceptable Use of Technology Policy form a coherent set. The Acceptable Use Policy is the foundation. The AI Policy is the specialist overlay for AI tools. The Data Breach Response Policy is what activates when something goes wrong under either of the others. Adopting all three together is significantly more valuable than adopting any one alone, and the charity should plan the rollout that way.

The Canadian legal landscape for charity data and technology governance has changed significantly in the past three years, and continues to change. The key drivers:

Privacy law. PIPEDA has required mandatory breach reporting since 2018. Quebec's Law 25, phased in through 2022 and 2023, introduced a lower notification threshold, stricter timelines, and enhanced individual rights. Any charity that holds personal information about Quebec residents is caught, and that is most national charities. Provincial private-sector privacy legislation in Alberta and British Columbia adds further requirements. Sector-specific regimes (PHIPA in Ontario, for health information) add another layer.

AI adoption. Generative AI tools have moved from novelty to routine use in charity workflows in less than three years. Agentic AI, which takes autonomous action across systems, is now landing in charity operations. Neither is a phenomenon boards can safely leave to the executive director alone.

Regulator attention. The federal Office of the Privacy Commissioner, the Quebec Commission d'accès à l'information, and provincial commissioners are actively investigating breaches and privacy failures at organizations of all sizes. Charities are not exempt from scrutiny by virtue of their mission.

Insurer expectations. Directors and officers, cyber, and general liability insurers are increasingly asking about technology governance at renewal. Coverage terms and premiums are shaped by the answers.

Board fiduciary duty. Canadian charity directors owe a duty of care that extends to operational risk. Technology risk is now unambiguously part of that duty. A board that has not turned its mind to these questions is a board that will have difficulty demonstrating it exercised reasonable care if something goes wrong.