Policy, explained

{{POLICY_NAME}}

👥 For: {{AUDIENCE}} 📄 Source: {{SOURCE_REF}} ⏱ ~{{READING_MINUTES}} min read 🗓 Version {{POLICY_VERSION}}

The short version

If you only read one box, read this. Each point links to the full explanation below.

  • You must report a suspected data breach within 24 hours of discovering it (§1).
  • You must not use a personal device for customer data — the only exception is a device IT has enrolled in MDM (§2).
  • Late breach reports have no stated exception. If you've missed the window, report it anyway and flag the delay.

1. Reporting a suspected breach

you email a spreadsheet of customer details to the wrong supplier. You spot it that afternoon and you're not sure whether anyone has opened it.
What this means

You must not wait to see whether it becomes a bigger problem. Customer data may have been exposed, so the Information Security team needs to know quickly.

The actual policy — word for word
Employees must report any suspected data breach to the Information Security team within 24 hours of discovery. Source: §4.1, Information Security Policy
What you should do

Report it as soon as you realise. Include what was sent, who received it, when it happened, and whether you've tried to recall or delete the message.

T+0 — you discover the mistake. The 24-hour clock starts now, not when it's confirmed.
Within 24h — report to Information Security with the details above.
After report — IT assesses risk and meets any legal reporting duties.
The clock starts at discovery, not at confirmation.
Why it exists Fast reporting gives the organisation time to contain the issue, assess the risk, and meet legal or regulatory reporting deadlines that it could otherwise miss.

2. Using personal devices for customer data

you're working from home and it's quicker to pull up a customer record on your own phone than to open the laptop. Is that allowed?
What this means

As a rule, no. Personal devices are off-limits for customer data. There is one narrow exception, and it is decided by IT — not by you.

The actual policy — word for word
Personal devices must not be used to access customer data, except where IT has enrolled the device in mobile device management (MDM). Source: §6.3, Acceptable Use Policy
Has IT enrolled this device in MDM?
Yes You may access customer data on it.
No You must not — use a managed device instead.
"Reasonably secure in my own opinion" is not a branch on this tree. Only IT enrolment counts.

Do

  • Use a company laptop or an IT-enrolled (MDM) device.
  • Ask IT to enrol a device before using it for customer data.

Don't

  • Use a personal phone or tablet that IT hasn't enrolled.
  • Decide for yourself that a device is "secure enough".
Why it exists MDM lets the organisation wipe a lost device and enforce encryption. A personal device IT can't manage is a route for customer data to leak if it's lost or sold.

Exceptions & approvals

Personal device exception

A personal device may be used for customer data only once IT has enrolled it in MDM (§6.3). This is the single stated exception — it is not a general permission to use personal devices.

Needs human review

What counts as a "suspected" breach

The policy is not explicit on how strong a suspicion must be before the 24-hour clock starts. If you're unsure, treat it as in-scope and check with Information Security — don't wait for certainty.

Check your understanding

Tick each one only if it's actually true for you. These are about understanding the rules above — not just confirming you opened the page.

0 of 4 understood

Not sure about something? This page explains the policy, but it can't answer every situation. Ask {{POLICY_OWNER}} before acting if your case isn't covered here — that's expected, not a failure.