Policy contents
1Purpose and Scope
This policy establishes clear standards for the use of social media by employees, workers, contractors and authorised representatives of Albrighton Group Services Ltd.
It applies to social media use:
- during working hours or while on duty;
- using company equipment, systems or accounts;
- using personal devices at work or client premises;
- outside work where content identifies, refers to or could reasonably be connected with the company, its clients or its workforce; and
- when publishing or responding on behalf of Albrighton Group Services Ltd.
2What Social Media Includes
Social media includes any online service that enables users to publish, share, comment, message, network, stream or exchange content.
The list is not exhaustive and this policy applies to new or emerging platforms and technologies.
3Use of Social Media at Work
Personal social media use must not take place while an employee is actively performing duties, supervising others, patrolling, controlling access, responding to incidents, monitoring CCTV, operating a vehicle or carrying out any safety-critical or security-critical task.
Limited personal use may be permitted during authorised rest breaks, provided that it:
- does not interfere with duties, productivity, attendance or site instructions;
- does not use client systems or restricted networks without permission;
- does not compromise safety, security, confidentiality or professionalism;
- does not involve prohibited content; and
- complies with local site rules and management instructions.
The company may restrict or block access to social media websites on company systems or devices where this is necessary for security, productivity, legal compliance or operational reasons.
4Official Company Social Media Accounts
Only authorised personnel may create, manage, publish to or represent the company through an official social media account.
Authorised users must:
- publish content that has a clear business purpose;
- follow brand, approval and campaign instructions;
- ensure factual claims are accurate and supportable;
- obtain approval before launching public campaigns, competitions or announcements;
- protect account credentials and use multi-factor authentication where available;
- avoid political, discriminatory, offensive or inflammatory content;
- respect confidentiality, copyright and data-protection requirements; and
- escalate complaints, incidents or reputational issues promptly.
5Personal Social Media Use
Employees are entitled to use social media in a personal capacity, but they must recognise that content can become public, searchable, copied and associated with their employment even where privacy settings are enabled.
When personal content could reasonably be linked to Albrighton Group Services Ltd, employees must:
- make clear that personal opinions are their own;
- avoid suggesting that they are authorised to speak for the company;
- avoid using company logos, uniforms or branded imagery in a misleading manner;
- not publish confidential, sensitive or commercially valuable information;
- not damage working relationships with colleagues, clients, suppliers or contractors; and
- not bring the company or its stakeholders into disrepute.
6Security and Client-Site Restrictions
Prohibited information includes:
- client names or site locations where confidentiality applies;
- guarding levels, staffing numbers, shift times or deployment gaps;
- patrol routes, checkpoints, access codes, keys or alarm details;
- CCTV positions, blind spots, monitoring arrangements or control-room information;
- incident details, crime reports, emergency responses or police references;
- images of vulnerable access points, plant, equipment or high-value materials;
- details of vacant properties, construction sites or other sensitive premises; and
- any client information subject to contractual or operational restrictions.
7Confidentiality and Personal Data
Employees must not post, disclose or share personal information relating to colleagues, clients, visitors, contractors, suppliers or members of the public unless there is a lawful, authorised and necessary reason to do so.
This includes names, images, contact details, identification documents, vehicle registrations, incident information, health information and any other information from which a person may be identified.
Employees must also protect:
- trade secrets and commercially sensitive information;
- client contracts, pricing, proposals and business plans;
- security procedures, internal reports and operational instructions;
- employee records and confidential correspondence; and
- copyright, trademarks and other intellectual property.
8Conduct, Equality and Reputation
Employees must not use social media to:
- harass, bully, threaten, intimidate or humiliate another person;
- publish discriminatory, hateful or offensive content;
- make knowingly false, malicious or defamatory allegations;
- target colleagues, clients or other stakeholders through online arguments or abuse;
- share content that undermines trust in the employee's suitability for a security role; or
- engage in conduct that creates a serious reputational, safeguarding or operational risk.
These standards apply to content posted publicly, privately, anonymously or through closed groups where the content may still affect the workplace or company relationships.
9Images, Video, CCTV and Body-Worn Footage
Employees must not take, copy, download, retain or publish photographs, audio or video from a client site unless specifically authorised.
CCTV recordings, body-worn camera footage, incident photographs and control-room images must never be uploaded to personal accounts, messaging groups or cloud-storage services.
Permission must be obtained before publishing identifiable images of colleagues, clients or members of the public, and publication must have an appropriate lawful and business basis.
10Cybersecurity and Account Protection
Employees should protect themselves and the company by:
- using strong and unique passwords;
- enabling multi-factor authentication;
- limiting publicly visible personal information;
- avoiding links, attachments and messages from unverified sources;
- not sharing login credentials or verification codes;
- reporting suspected account compromise or impersonation; and
- not using social media credentials as passwords for company systems.
11LinkedIn References, Endorsements and Business Contacts
Employees must not provide online recommendations, references or endorsements that could reasonably be interpreted as an official company reference without prior management approval.
Requests for formal references from employees, former employees, clients, suppliers or business contacts must be referred to the appropriate manager.
Business contacts and confidential relationship information obtained through employment must not be copied, exported or used in breach of contractual, confidentiality or data-protection obligations.
12Monitoring
The company may carry out proportionate and lawful monitoring of activity on company systems, devices, accounts and networks for legitimate purposes such as:
- protecting systems, data and confidential information;
- investigating suspected misuse or security incidents;
- maintaining operational effectiveness and productivity;
- preventing harassment, discrimination or other misconduct;
- meeting legal, contractual and regulatory duties; and
- protecting clients, employees and the company's reputation.
Monitoring will be limited to what is necessary and proportionate, with appropriate transparency and safeguards.
13Reporting and Removal of Content
Employees must promptly report:
- unauthorised disclosure of company or client information;
- impersonation or fraudulent company accounts;
- serious online harassment or threats involving the workplace;
- inaccurate information that may create material risk; and
- lost or compromised official account credentials.
Where the company reasonably determines that content breaches this policy, the employee may be required to remove it, preserve relevant evidence and cooperate with an investigation.
14Breaches and Disciplinary Action
Failure to comply with this policy may result in disciplinary action.
Serious breaches may be treated as gross misconduct, particularly where they involve:
- disclosure of client security information;
- publication of CCTV or body-worn footage;
- harassment, discrimination or serious reputational harm;
- deliberate misuse of confidential or personal information;
- unauthorised access to systems or accounts; or
- refusal to remove or report prohibited content.
15Official Legal and Regulatory Guidance
Data protection: The Data Protection Act 2018 and the ICO's UK GDPR guidance and resources apply when personal information is processed through social media or workplace systems.
Employee monitoring: The ICO's monitoring workers guidance explains that monitoring should be lawful, transparent, necessary and proportionate.
Equality and workplace conduct: The Equality Act 2010 applies to discriminatory harassment and conduct connected with employment. Acas guidance on preventing discrimination specifically recommends clear social media rules.
Cybersecurity and unauthorised access: The Computer Misuse Act 1990 addresses unauthorised access to computer systems and data.
