IT Acceptable Use Policy
Official School Policy Document
Acceptable Use of Technology, Artificial Intelligence (AI), Online Safety and Cyber Security Policy
SV Academy - September 2026
Policy Title | Acceptable Use of Technology, Artificial Intelligence (AI), Online Safety and Cyber Security Policy |
|---|---|
Applies To | Students, Staff, Volunteers, Contractors, Visitors and Third-Party Users |
Policy Owner | Executive Headteacher |
Operational Lead | Headteacher |
Safeguarding Lead | Designated Safeguarding Lead (DSL) |
Technical Lead | IT Lead / IT Support |
Approved By | Directors / Proprietor |
Date Approved | September 2026 |
Next Review | September 2027, or earlier if guidance, technology or risk changes |
Version | 4.0 |
1. Statement of Intent
SV Academy is committed to providing a safe, secure, inclusive and effective digital environment for teaching, learning, safeguarding, communication and administration. Technology, including artificial intelligence (AI), can create significant educational benefits, but it must be used lawfully, ethically and in ways that protect children, young people, staff, personal data and Academy systems.
This policy sets out the standards expected when using Academy devices, networks, internet access, cloud services, communications systems, digital platforms, AI tools and any personal device that connects to Academy systems or is used for Academy business.
The Academy will balance educational access with proportionate safeguarding, filtering, monitoring, cyber security and data protection controls. No technical control is completely effective on its own, so safe use also depends on staff supervision, education, professional judgement and prompt reporting of concerns.
2. Scope and Key Principles
This policy applies to all students, staff, volunteers, contractors, visitors and third parties who use SV Academy technology or access Academy systems.
Technology must be used for legitimate educational, safeguarding, professional or authorised Academy purposes.
Users must act lawfully, respectfully and in accordance with safeguarding, data protection, equality and intellectual property requirements.
Access to systems and information will be limited to what each user reasonably needs for their role or learning.
Students must be supported to develop age-appropriate digital literacy, critical thinking and safe online behaviour.
AI outputs must be treated as potentially inaccurate, biased or incomplete and must be checked before use.
Personal or confidential information must not be entered into unapproved public AI tools, websites or services.
Safeguarding concerns take priority over confidentiality where information must be shared to protect a child or another person.
3. Legal and Guidance Framework
This policy should be read in the context of current legislation and national guidance, including:
Keeping Children Safe in Education 2026 (KCSIE).
Department for Education digital and technology standards, including the 2026 filtering and monitoring and cyber security core standards.
Department for Education guidance on generative AI in education and generative AI product safety standards.
UK GDPR, the Data Protection Act 2018 and relevant amendments introduced by the Data (Use and Access) Act 2025.
Computer Misuse Act 1990.
Copyright, Designs and Patents Act 1988 and other intellectual property law.
Equality Act 2010.
Prevent duty guidance and SV Academy safeguarding arrangements.
Current JCQ, examination board and awarding organisation rules on AI, malpractice and assessment integrity where qualifications are involved.
4. Leadership and Responsibilities
Directors / Proprietor
Provide strategic assurance that appropriate online safety, filtering, monitoring and cyber security arrangements are in place.
Receive assurance that significant risks and actions are reviewed and addressed.
Executive Headteacher
Holds strategic oversight of digital technology, AI governance, cyber risk and implementation of this policy.
Ensures appropriate resources, accountability and escalation arrangements are in place.
Approves significant exceptions, high-risk technology use and major policy changes where appropriate.
Headteacher
Leads day-to-day implementation of this policy across the Academy.
Ensures staff and students understand expectations and that breaches are addressed consistently.
Works with the DSL, IT support, SENCO and Data Protection Officer or Lead when risks overlap.
Designated Safeguarding Lead (DSL)
Leads safeguarding and online safety responses, including concerns identified through monitoring.
Reviews relevant alerts and reports and ensures safeguarding action is taken in line with KCSIE and Academy procedures.
Works with senior leaders and IT support on filtering and monitoring reviews.
IT Lead / IT Support
Maintains technical security, user accounts, devices, filtering and monitoring systems and relevant logs.
Provides reports and technical assurance to senior leaders and the DSL.
Implements authorised changes and reports material vulnerabilities or incidents promptly.
All Users
Use technology responsibly and follow this policy and any user agreement issued by SV Academy.
Protect accounts, data and devices and report concerns, mistakes or suspected incidents without delay.
5. Acceptable Use of Academy Equipment and Services
Academy technology is provided primarily for education, safeguarding, administration and approved Academy activities.
Users must:
Take reasonable care of devices and equipment and report faults or damage promptly.
Use only approved software, apps, browser extensions, cloud services and peripherals.
Lock or log out of devices when unattended and log out of shared devices after use.
Store Academy work in approved locations and follow retention and backup requirements.
Follow staff instructions and classroom expectations when using technology.
Users must not:
Deliberately damage, disable, alter or interfere with devices, security controls or network services.
Connect unauthorised equipment, access points or storage devices to Academy systems.
Install software, change system settings or reconfigure network connections without permission.
Use Academy systems to carry out illegal, fraudulent, abusive, discriminatory or malicious activity.
Attempt to discover or exploit security weaknesses except as part of an explicitly authorised security activity.
6. Accounts, Passwords, Authentication and Access
Accounts are personal to the authorised user and must not be shared.
Users must keep passwords, passkeys, recovery codes and authentication tokens confidential.
Staff accounts with access to cloud services or remote access, and IT administrative accounts, must use multi-factor authentication (MFA) where required by the DfE cyber security standard.
Access rights will follow the principle of least privilege: users receive only the access needed for their role.
Accounts must be created, changed and disabled promptly as people join, change roles or leave.
Users must report suspected compromise, unexpected MFA prompts or unusual account activity immediately.
Users must never access another person's account or information without explicit authorisation.
7. Internet Access, Filtering and Monitoring
SV Academy will maintain appropriate filtering and monitoring arrangements to support its safeguarding duties. Filtering is used to restrict access to illegal, harmful or inappropriate content. Monitoring is used to identify activity that may require safeguarding, technical or disciplinary action.
Filtering and monitoring will be proportionate to the Academy's student risk profile, including age, SEND, EAL, curriculum needs and use of AI-enabled services.
Different filtering profiles may be applied to students, staff and guests where appropriate.
Users must not use proxies, VPNs, anonymisers, alternate browsers, tethering or other methods to bypass Academy filtering or monitoring unless specifically authorised for a legitimate purpose.
Staff must continue active classroom supervision when students use devices; technical monitoring does not replace professional supervision.
Where technical monitoring is used, high-risk alerts will be escalated promptly and routine reports will be reviewed in line with the Academy monitoring plan.
Filtering and monitoring provision will be reviewed at least once every academic year and also when safeguarding risk, technology, working practice or network configuration materially changes.
Users will be informed that use of Academy systems and managed devices may be logged or monitored for safeguarding, security and operational purposes.
Access to monitoring data will be limited to authorised personnel and handled in accordance with data protection requirements.
8. Online Safety Education
Online safety is part of safeguarding and the curriculum. SV Academy will help students understand how to identify and manage online risks rather than relying solely on blocking technology.
Online bullying, harassment and harmful communication.
Grooming, exploitation and unsafe contact.
Misinformation, disinformation, manipulated media and deepfakes.
Online fraud, scams, phishing and social engineering.
Privacy, digital footprints, consent and sharing images or personal information.
Extremist or terrorist material and the risks of online radicalisation.
Sexualised content, image-based abuse and other safeguarding risks.
Critical evaluation of search results and AI-generated content.
Healthy technology habits and digital wellbeing.
9. Artificial Intelligence (AI)
SV Academy supports safe and purposeful use of AI where it improves education, accessibility or administration without undermining safeguarding, privacy, fairness, professional judgement or assessment integrity.
Approved use may include:
Brainstorming, planning, revision and study support.
Drafting or improving non-confidential teaching and administrative materials.
Coding support, data-free examples and explanations.
Accessibility and differentiation where the tool is appropriate for the learner.
Creating practice questions, quizzes or resources that are checked by a competent member of staff.
AI must not be used to:
Submit AI-generated work as a learner's own assessed work or circumvent assessment rules.
Make high-stakes decisions about a student or staff member without appropriate human oversight and a lawful basis.
Upload confidential, safeguarding, special category or personally identifiable data to an unapproved AI service.
Generate or distribute abusive, discriminatory, sexual, violent, extremist, deceptive or unlawful material.
Create deepfakes, impersonations, fabricated evidence or misleading media involving real people without a legitimate authorised purpose.
Automate communications or decisions where the user has not checked the accuracy, tone, context and potential impact.
AI tools used by students must be age-appropriate and used in accordance with the provider's age restrictions and Academy safeguards. New AI products or significant new uses should be assessed for safeguarding, data protection, cyber security, accessibility, bias and educational value before adoption.
Users remain responsible for work, advice, communications and decisions made in their name. AI outputs must be fact-checked and sources verified where accuracy matters.
10. AI, Coursework and Assessment Integrity
Learners must follow the rules of the relevant awarding organisation, examination board and SV Academy assessment policies.
Where AI use is permitted, it must be acknowledged or referenced as required.
AI-generated content must not be presented as wholly the learner's own work where this would breach assessment rules.
Teachers and assessors should design and supervise assessment in ways that support authenticity and should retain appropriate evidence of the learner's own work where required.
Suspected misuse of AI in assessed work will be considered under the Academy's malpractice and fair assessment procedures and the applicable awarding organisation rules.
Automated AI-detection outputs should not normally be treated as sole proof of malpractice; concerns should be considered alongside other evidence.
11. Data Protection, Privacy and Confidential Information
Personal data must be accessed, used and shared only where authorised and necessary.
Staff must use approved systems for personal, safeguarding, SEND, health, financial or other confidential information.
Personal data should not be entered into generative AI tools unless the specific use has been approved and the data protection risks have been assessed.
A Data Protection Impact Assessment (DPIA) will be considered before introducing technology likely to create a high risk to individuals, including new monitoring, profiling or AI-enabled systems.
Privacy notices will explain relevant monitoring and technology processing where required.
Any suspected personal data breach must be reported immediately through the Academy data breach procedure.
12. Email, Messaging, Social Media, Images and Video
Academy communications must be respectful, professional and appropriate to the audience.
Staff must maintain professional boundaries and use approved channels when communicating with students.
Users must not send abusive, threatening, discriminatory, sexual, harassing or malicious communications.
Confidential information must not be sent to unauthorised recipients or insecure personal accounts.
Images or videos of students must only be created, stored and shared in accordance with safeguarding, consent or other lawful-basis requirements and Academy procedures.
Users must not create or share manipulated images, deepfakes or impersonation content that could mislead, humiliate, exploit or harm another person.
Staff and students must not represent personal views as official SV Academy statements unless authorised.
13. Cyber Security Controls
SV Academy will maintain proportionate technical and organisational controls and will work towards or maintain the Department for Education cyber security core standard.
A cyber risk assessment will be completed at least annually and revisited each term and after significant incidents or changes.
Security updates and vulnerability fixes will be applied within appropriate timescales and unsupported systems will be removed, isolated or risk-managed.
Network-connected devices will be securely configured, protected by appropriate firewalls and anti-malware controls where relevant.
Administrative and remote access will be restricted and protected using strong authentication.
Staff will receive cyber security awareness training at least annually and new or temporary staff will receive appropriate guidance.
Phishing, suspicious links, unexpected attachments and unusual login requests must be reported promptly.
Removable media will be restricted or scanned in accordance with technical controls and must not be used to circumvent approved storage or security arrangements.
Cyber security incidents will be recorded, contained, investigated and escalated in line with the Academy incident response, business continuity and data breach procedures.
14. Backups, Storage and Business Continuity
Important Academy data must be stored in approved systems rather than relying solely on local device storage.
The Academy will maintain a documented backup and recovery plan linked to business continuity and disaster recovery.
Important data should be protected through multiple backup copies on separate systems, including an off-site copy, with appropriate protection against ransomware and unauthorised alteration.
Backups and restoration capability will be tested and logged at least termly, or following significant changes.
Users must follow retention requirements and avoid keeping unnecessary duplicate or personal files on Academy systems.
15. Personal Devices, BYOD and Remote Working
Personal devices may only connect to Academy services or networks where permitted and must comply with applicable security and safeguarding controls.
Academy confidential information should not be downloaded to unmanaged personal devices unless explicitly authorised and appropriately protected.
Remote access must use approved methods and MFA where required.
Users must take particular care when working in public places, using public Wi-Fi or displaying confidential information on screen.
Loss or theft of a device containing or providing access to Academy information must be reported immediately.
16. Reporting and Responding to Concerns
Concerns must be reported promptly. Users should not delay reporting because they are worried they made a mistake.
Concern | Report to / Immediate Action |
|---|---|
Safeguarding or online safety concern | DSL or Deputy DSL immediately; follow safeguarding procedures. |
Cyber security incident or suspicious activity | IT Lead / IT Support and Headteacher; preserve evidence and do not continue interacting with suspicious content. |
Personal data breach | Data Protection Officer or Lead and Headteacher immediately. |
AI misuse in assessed work | Teacher / Assessor and Quality Assurance or Exams Lead under assessment and malpractice procedures. |
Illegal or immediately dangerous activity | Escalate to senior leadership and emergency or statutory agencies where required. |
The Academy may preserve logs, isolate accounts or devices, restrict access and take other proportionate steps to protect people, systems and evidence while an incident is investigated.
17. Sanctions and Misuse
A breach of this policy may result in educational, disciplinary, safeguarding, employment or contractual action depending on the circumstances. Possible responses include advice or retraining, restricted access, removal of technology privileges, behaviour sanctions, disciplinary action, assessment malpractice procedures, or referral to the police, local authority, awarding organisation, regulator or other agency where required.
The Academy will consider age, intent, harm, previous conduct, SEND, safeguarding context and any reasonable adjustments when deciding an appropriate response.
18. Training, Monitoring and Review
This policy will be shared with staff and students in an age-appropriate form and reflected in induction and acceptable-use agreements.
Online safety, filtering and monitoring responsibilities will form part of safeguarding training.
Cyber security awareness training will be refreshed at least annually.
AI expectations will be reviewed as technology, awarding organisation rules and DfE guidance develop.
Filtering and monitoring provision will be formally reviewed at least annually and material changes will trigger an earlier review.
The effectiveness of the policy will be informed by safeguarding incidents, cyber events, monitoring reports, data breaches, behaviour records, assessment concerns and user feedback.
The policy will be reviewed annually or sooner following significant changes in law, statutory guidance, technology or Academy risk.
Appendix A - Student Acceptable Use Summary
I will use Academy technology for learning and other authorised purposes.
I will keep my account and password secure and will not use another person's account.
I will not try to bypass filtering, monitoring or security controls.
I will communicate respectfully and will not bully, harass or impersonate others online.
I will not access, create or share illegal, harmful or inappropriate content.
I will use AI only when permitted and will not submit AI-generated work as my own.
I will not share personal or confidential information with unapproved websites or AI tools.
I will report online safety, cyber security or safeguarding concerns to a member of staff promptly.
I understand that Academy devices, networks and services may be filtered, logged and monitored.
Appendix B - Staff AI and Technology Check
Before using a new digital or AI tool for Academy work, staff should consider:
Is the tool approved or has approval been obtained?
Is the tool appropriate for the age and needs of the students who may use it?
Will any personal, confidential or safeguarding information be entered or generated?
Does the use require advice from the DSL, DPO or IT Lead or a DPIA?
Are filtering, monitoring, supervision and account controls appropriate?
Could the output be inaccurate, biased, harmful, misleading or discriminatory?
Does the use comply with copyright, assessment and awarding organisation rules?
Has a human checked the final output before it is used or communicated?
Is there a clear educational or operational benefit that justifies the use?
Reference Framework
Policy reviewed and revised: September 2026 | Next scheduled review: September 2027