[Company Logo][Company Name]
- Policy No.:
- [Reference Number]
- Version:
- [Version Number]
- Effective Date:
- [Date]
- Policy Owner:
- Information Technology
1. Purpose
Email is the main channel for official communication at [Company Name]. This policy ensures it is used professionally, securely and in a way that protects company and customer information.
2. Scope
It applies to all users of company email accounts ([domain]) and shared mailboxes, on any device.
3. Definitions
- Official email: any account on the company domain.
- Confidential information: as defined in the Confidentiality Policy.
- Phishing: a fraudulent email designed to steal credentials, money or data.
4. Policy
- Official email must be used for all business communication with customers, vendors and colleagues; personal email accounts must not be used for company work.
- Emails must be courteous and professional and carry the standard signature: Name, Designation, Department, [Company Name], phone.
- Auto-forwarding of company email to external accounts is prohibited.
- Confidential attachments (salary data, customer lists, contracts) must be sent password-protected or through [Secure Share Tool], only to those who need them.
- Do not send chain mails, offensive content or mass mailings without approval from [Department].
- Do not click links or open attachments from unexpected senders; report suspicious emails to [Phishing Report Email].
- Bank detail changes requested by email must be verified by phone using known contact numbers.
- Mailboxes are retained for [Number] years. Deleting business records to hide information is prohibited.
- On separation, the mailbox is disabled on the Last Working Day; access may be given to the manager for [Number] days with HR approval.
5. Procedure
- IT creates the mailbox on joining after the AUP acknowledgement.
- Shared mailbox access is requested through the manager.
- Accidental sending of confidential data to the wrong person must be reported to IT within [Number] hours.
6. Responsibilities
- Users: follow etiquette and security rules.
- IT: spam filtering, backup and access control.
- HR: inform IT of exits on time.
7. Non-compliance
Misuse of email, including harassment, data leakage or auto-forwarding, may lead to action under the Disciplinary Policy.
8. Review & Approval
IT will review this policy annually.
Approved by
[Authorised Signatory][Designation]Date:
[Date]Acknowledged by
[Employee Name]Date:
[Date]