One page that prevents most problems.
WHAT TO COVER
Which tools are approved What may be sent to them What must never be sent What must be reviewed before use Who is accountable
WHAT MAY NEVER BE SENT
Customer personal data, unless specifically permitted Financial records Contracts and negotiations Staff matters Passwords or credentials
WHAT MUST BE REVIEWED
Anything customer-facing Anything containing figures or claims Anything published
WHAT MAY NEVER BE GENERATED
Testimonials and reviews Statistics Case study facts Anything presented as first-hand experience
THE ACCOUNTABILITY LINE
Whoever sends or publishes is responsible, whatever produced the draft.
State that explicitly.
WHY NOT BAN IT
Staff use it anyway, on personal accounts, with no record and no oversight.
A permissive policy with clear limits produces better control.
LENGTH
One page. Longer is not read.
FOR NIGERIAN BUSINESSES
Sending customer personal data to a third party carries obligations under the NDPR.
Visit zillionkinghost.com for further information, and take proper advice.