Subscribe Self-service

Your computing account

University Computing Account Terms and Conditions

  1. Policy Intent

    1. The Acceptable Use Policy is designed to:
      1. Provide clarity on the University’s expectations for staff in using digital systems, networks, and data securely and responsibly.
      2. Ensure that all staff are equipped with the knowledge and awareness to identify and respond to cyber threats, reducing the likelihood of human error.
      3. Ensure consistency in meeting legal, regulatory, and information security standards across the University.
    2. This policy defines the University’s expectations regarding the acceptable use of its digital facilities, including computing devices, systems, networks, and information assets. It applies broadly to accommodate new and emerging technologies, usage patterns, and digital behaviours that may not be explicitly listed.
    3. This policy incorporates and requires compliance with the following external frameworks and statutory obligations:<
      1. The JANET Acceptable Use Policy and JANET Security Policy (as published by Jisc).
      2. The CHEST (Combined Higher Education Software Team) User Obligations and associated Copyright Acknowledgement.
      3. The Jisc General Terms of Service.
      4. The University’s statutory duty under Section 26 of the Counter Terrorism and Security Act 2015, known as the “PREVENT” duty, which aims to prevent individuals from being drawn into terrorism.
    4. This policy ensures that the University’s digital services are accessed and used lawfully, safely, and equitably.
  2. Legislation

    1. The University of Southampton has a responsibility to abide by and adhere to all current UK and EU legislation as well as a variety of other regulatory and contractual requirements.
    2. Information in regards to the University’s data protection strategy can be found within the University’s Information Governance and Data Protection site.
    3. A non-exhaustive summary of the legislation and regulatory obligations that contribute to the form and content of this policy is provided in Relevant Legislation (ISMS).
  3. Definitions and Abbreviations

    1. It is intended that this policy be used in conjunction with other policies published as part of the University’s Information Security Management System, in particular the Information Security Policy, which sets out the formal scope for all policies and other documents within the Information Security Management System (ISMS).
    2. A non-exhaustive list of definitions that contribute to the contents of this policy is provided in the Glossary of Abbreviations and Definitions (ISMS).
  4. Scope

    1. After consideration of the organisation and its context and the needs and expectations of interested parties, the scope of the Information Security Management System is:
      The provision of teaching, research, professional and enterprise services using internal systems, support services and external resources.
    2. The scope applies to:
      All individuals working for or with the University. This includes casual workers including those appointed through UniWorkforce, agency workers, volunteers, individuals with visitor status, all external members of the University’s Council and its committees, external examiners, researchers, clients, contractors and project partners. For the purposes of this policy, it also includes honorary staff and Emeritus Professors/Fellows (this list is non-exhaustive).
    3. Certain parts of this policy apply specifically to students. Sections 5.8 (Halls and Residents – Network Access) and 5.9 (Public Workstation Areas) are relevant to students living in University accommodation and those using public workstations on campus. These sections set out rules and responsibilities that apply directly to students in these environments. This policy does not form part of any employee's contract of employment, and the University may amend it at any time.
    4. For the purposes of this policy, the individuals listed in Section 4.2 under the defined scope shall hereafter be referred to collectively as ‘users’.
  5. University Policy Principles

    1. Appropriate Use

      1. University IT resources are provided primarily for academic, administrative, research, and enterprise purposes.
      2. Limited personal use shall be permitted provided it:
        a. Does not interfere with University operations or job performance.
        b. Does not conflict with a user’s employment obligations.
        c. Does not violate any other University policies.
        d. Does not incur additional costs to the University.
        e. Does not consume significant network bandwidth or storage
        f. Does not involve allowing unauthorised individuals access to University equipment or data.
    2. Information Security and Data Management

      1. Users shall use the University's information technology and communications facilities sensibly, professionally, lawfully, and consistently with their duties, with Controlled Document 5 of 10 Version 2.0 | October 2025 respect for colleagues and students, and in accordance with this policy and the University's other rules and procedures.
      2. Information about students, staff, or any other sensitive matters shall only be stored on systems and services approved by the University. This information shall not be shared with anyone who is not authorised to access it.
      3. Cloud services registered using personal credentials should not be used for University-related activities, unless explicitly approved by the Cyber Security team.
    3. Intellectual Property and Communications

      1. Many aspects of communication are protected by intellectual property rights which are infringed by copying. Downloading, uploading, posting, copying, possessing, processing and distributing material from the internet may be an infringement of copyright or of other intellectual property rights.
      2. Particular care should be taken when using University digital communications systems (such as email, text messaging, blogging and social media) because expressions of fact, intention and opinion may bind you and/or the University and can be produced in court in the same way as other kinds of written statements
      3. Internet-based messaging systems are extremely easy and informal ways of accessing and disseminating information, but this means that it is also easy to send out ill-considered statements. All messages sent via these systems should demonstrate the same professionalism as that which would be taken when writing a letter.
      4. All digital communications may be subject to disclosure to either the public, via Freedom of Information Act legislation, or to individuals, via a Subject Access Request. This includes messaging through tools such as email, SMS messaging, WhatsApp, Signal, Facebook Messenger, Slack and similar.
    4. Account Use and Ethical Standards

      1. Users shall not use University systems to do, say or share anything which would be subject to disciplinary or legal action in any other context such as sending any discriminatory, defamatory, or other unlawful material.
      2. University accounts are for individual use only and shall not be shared. Generic accounts shall only be used for their approved purpose. Users must keep their passwords and authentication credentials confidential and should not use University accounts or email addresses to register for personal or non-University services. For full requirements, refer to the SECPOL-UOS-1013 Identity and Access Control Policy (Password Policy).
      3. If you are in doubt about a course of action, take advice from your supervising line manager.
    5. Monitoring and Oversight

      1. The University reserves the right to undertake monitoring of all activity on University computing equipment for the purposes of:
        a. Ensuring compliance with this policy and related University policies.
        b. Preventing unauthorised access to electronic communications networks.
        c. Preventing malicious code distribution.
        d. Preventing 'denial of service' attacks and damage to computer and electronic communication systems.
        e. Investigating specific complaints of misuse.
        f. Preventin g or detecting crime.
      2. Monitoring of individual usage may only be undertaken where it is reasonable, situation-specific, minimal, and controlled (i.e., in line with formal investigation procedures outlined in University disciplinary processes).
      3. All communications and information held on University facilities remain the responsibility of the University and are subject to University oversight, even when marked as 'personal'.
    6. Prohibited Activities

      1. You shall not perform any of the activities listed in sections 5.7- 5.9 on University equipment without written authorisation from the University IT Team.
    7. Technical Security Violations

      1. Introduce packet-sniffing, password-detecting, key-logging software, or any form of spyware, computer virus or other potentially malicious software.
      2. Seek to gain access to restricted areas of the University's network for which you have not been granted explicit permissions.
      3. Access or attempt to access unauthorised information, resources, or data which you know or ought to know is confidential.
      4. Intentionally or recklessly introduce any form of malware, spyware, computer virus or other potentially malicious software.
      5. Intentionally introduce any software related to crypto-currency mining.
      6. Engage in any activity that may disrupt or interfere with the normal operation and correct functioning of University systems, deny access to other users, or involve deliberate unauthorised access.
      7. Attempt to undermine the security of systems (including undertaking an unauthorised penetration testing or vulnerability scanning of any University systems).
      8. Install or use unauthorised software or hardware or use software which is only licensed for limited purposes for other purposes, thereby breaching software licensing agreements.
    8. Operational and Resource Violations

      1. Users must not deliberately use University systems in ways that waste other people’s time or unnecessarily use University resources, such as storage, bandwidth, or support services.
      2. Where external networks are accessed through University networks, any abuse of the acceptable use policy of that external network will be regarded as unacceptable use of the University networks.
    9. Prohibited Content and Communications

      1. Viewing, accessing, transmitting, posting, downloading, uploading, or distributing any of the following materials may constitute gross misconduct capable of resulting in disciplinary action:
        Category Description
        Discriminatory, Offensive or Harmful Content - Any material that is sexist, racist, homophobic, xenophobic, pornographic, paedophilic, extremist, or otherwise discriminatory, offensive, or harmful.
        - Content that is obscene, threatening, harassing, or likely to cause distress, anxiety, or embarrassment to individuals or the University.
        - Material that could damage the University’s reputation or promote radicalisation, terrorism, or violent extremism.
        Defamatory, False or Deceptive Content - Material that defames individuals or organisations, contains false or misleading statements, or is intended to deceive. - Content created to impersonate others or falsely represent the University or another organisation. - Material intended to defraud or mislead third parties.
        Harassment, Bullying and Privacy Violations - Communications that harass, bully, or victimise others, whether intentional or not. - Material that invades someone’s privacy or misrepresents individuals unfairly. - Statements made to annoy, inconvenience, or harm others.
        Confidential, Copyrighted or Restricted Material - The sharing or unauthorised use of confidential University information. - Material that breaches copyright, intellectual property rights, or contractual obligations.
        Inappropriate Commercial Use and Gambling - Unauthorised or unsolicited advertising, spam, or chain messages. - Use of University systems for online gambling or other non-University commercial activities.
        Activities Creating Legal Risk - Any activity that could result in criminal or civil liability for you or the University.
    10. Halls and Residents- Network Access

      1. Students in University accommodation are responsible for all network activity originating from their assigned room connection. Network access must not be shared with others.
      2. Personal wireless devices connected to the halls network must be used only by the registered occupant and should be secured to prevent unauthorised access.
      3. Students shall not engage in activities that negatively affect the performance or reliability of the University network. This includes the use of peer-to-peer file sharing or excessive media streaming. The University reserves the right to rate-limit or block such activities to protect network performance for all users.
      4. Students shall not breach copyright by making copies of, or providing for copying, any copyrighted electronic works (including music, films, TV or radio programs) without copyright owner consent. This includes downloading and sharing. Availability for copying does not indicate legal permission to copy.
    11. Public Workstation Areas

      1. Access to University workstations and facilities should only be granted to authorised University account holders for teaching, learning, research, or other approved University activities. Users must respect bookings and not enter areas during scheduled teaching unless they are part of the group. Some spaces may be reserved for priority use by specific University groups.
      2. Users should only carry out activities related to learning, teaching, research, or authorised social use. Behaviour that prevents others from using the workstations, creates unreasonable noise, displays offensive content, endangers others, or causes untidiness (including smoking, drinking, or eating) shall not be allowed.
      3. Users should log out or lock their workstations when away, especially during busy periods, and must not hold onto sessions longer than necessary if others are waiting.
      4. Only authorised peripheral devices may be connected to University equipment. University devices should not be disconnected or altered without permission. Personal computers may only connect at designated points.
      5. Users should respect copyright laws and only copy electronic works if they have the owner’s consent. This includes downloading, storing, sharing, or reproducing material in any form. Being able to access content does not mean users have permission to copy it, and users are responsible for ensuring they have the legal right to do so.
    12. Exceptions

      1. An exception may be allowed for material that has genuinely been obtained for the purposes of legitimate academic research that is related to your area of study and where the acquisition of such material has been made known to the University in advance.
      2. It is recognised that academics will sometimes need to download material that could fall into one of the categories stated above. A member of staff involved in such research areas would be acting sensibly in making clear his or her intention Controlled Document 9 of 10 Version 2.0 | October 2025 to download such material and the reasons for this before proceeding, to reduce the possibility of criminal investigation by an external body.
      3. Any potential research involving material which contravenes this policy should be raised with the University’s Information Governance and Information Security teams.
    13. Breaches

      1. If a member of the University community believes they may have encountered breaches of any of the above, they should report this to the University’s Legal Services team and/or Executive Director of iSolutions.
      2. If a member of the University community believes they may have encountered a breach of personal data, they must report this within 72 hours of discovering the breach, using the University’s Breach Reporting Form http://go.soton.ac.uk/breach.
  6. Compliance with this policy

    1. For employees, failure to comply with this and the other related policies in the ISMS may result in disciplinary action being taken against you under the relevant University procedures up to and including summary dismissal and/or in the withdrawal of permission to use the University’s facilities. If there is anything in this policy that you do not understand, please discuss it with your line manager.
    2. For non-employees, failure to comply with this and the other related policies in the ISMS may result in your network access being revoked until the non-compliance is rectified.
    3. The University reserves the right to audit compliance with this and the other related policies in the ISMS.
    4. Where evidence that a criminal offence may have been committed as a result of any misuse of the University’s information technology and communications systems, this may be referred to the police or the appropriate regulatory authority.
  7. Roles and responsibilities

    Human Resources Human Resources is responsible for ensuring that all new users are made aware of the Acceptable Use Policy as part of the onboarding process. HR must collaborate with Information Security to ensure appropriate records of acknowledgement are maintained and that compliance is monitored. HR also supports the enforcement of the policy through performance management procedures where breaches of acceptable use are identified.
    Cyber Security and Information Governance Teams The Cyber Security and Information Governance Teams are responsible for maintaining the Acceptable Use Policy and ensuring it remains aligned with current legal, regulatory, and information security requirements. They provide guidance on Controlled Document 10 of 10 Version 2.0 | October 2025 the interpretation and application of the policy, monitor reported breaches or misuse, and advise stakeholders on trends, risk areas, and required mitigations.
    Line Manager Line Managers are responsible for promoting awareness of the Acceptable Use Policy within their teams. They must ensure that team members understand and comply with the policy and take appropriate action in response to any unacceptable use. Line Managers should escalate concerns where non-compliance is identified and support staff in understanding how the policy applies to their roles and digital behaviors.
    Users (as per scope in section 4) All users (as defined in the scope in Section 4) are responsible for always complying with the Acceptable Use Policy. They must use University systems, data, and networks lawfully, safely, and responsibly, and must not engage in activities that contravene policy requirements. Users are expected to remain informed about applicable acceptable use standards, report any breaches or misuse, and seek clarification where needed.
  8. Governance, Review, Oversight and Improvement

    1. The Acceptable Use Policy shall be reviewed every two years to ensure alignment with ISO/IEC 27001 requirements, applicable legislation, emerging technologies, and evolving digital risks.
    2. The Cyber Security team should collect and review user feedback and incident data to identify areas where the policy may require clarification or strengthening.
    3. The University may engage external experts to review the policy, controls, and associated practices to ensure continued relevance, compliance, and effectiveness.