- What the policy applies to and who it covers
- Acceptable use during work hours
- Content the business owns
- Confidential information and IP
- Posts about the business, colleagues, or clients
- Use of branding, logos, and templates
- Approval workflow for business posts
- Responding to negative posts, complaints, and crises
- Breach and disciplinary consequences
- Optional or situational clauses
- How Artificer Legal would draft or review this policy
- Tie the policy to the employment contract
You have an employee handbook template open, you have reached the social media section, and the placeholder text is two paragraphs of generic warnings about "professional conduct online". You know that is not enough — your team posts about the business on LinkedIn, a junior contractor runs the Instagram, and a former employee still has the password to the TikTok account you set up last year. The policy you write here is the document a manager will reach for when something goes wrong.
A social media policy is an internal workplace policy that lives inside the employee handbook. It is not an employment contract on its own. Its operative force comes from a clause in the employment contract that requires the employee to comply with the handbook's policies — that contractual hook is what lets you treat a breach as misconduct. The policy sets the expected behaviour, defines what content the business owns, and gives managers a written reference point when a post causes a problem. It supplements the contract; it does not replace it.
What the policy applies to and who it covers
Open with a scope clause. Without it, every later provision is ambiguous about whether it bites on a personal account posted from a home laptop, a work-issued phone used at lunch, or a contractor's LinkedIn profile that lists your business as their employer.
A serviceable scope clause names:
- the platforms covered (named where possible, with a catch-all for new platforms)
- the accounts covered — business-owned, employee-personal-but-identifying-the-business, and personal accounts that comment on the business or colleagues
- the people covered — permanent, casual, contractors, interns, board members
- whether out-of-hours posting on a personal account is in scope (it usually is, where the post identifies the business or a colleague)
The trap: drafters narrow this to "use of the company's social media accounts" and the policy then has nothing to say when an employee posts a slur from a private Facebook account naming a colleague. That is the fact pattern most policies are written to address.
Acceptable use during work hours
This clause sets the time-and-attention rule: how much personal social media use is permitted during paid working hours and on work devices. Be specific. "Reasonable use" is the default and it gets argued over every time it is enforced.
The drafting choice that matters is whether you set a hard limit (no personal social media on work devices, no exceptions) or a soft one (incidental personal use is permitted, provided it does not interfere with duties). Hard limits are easier to enforce and harder for staff to comply with. Soft limits are realistic but require managers to make judgement calls, which means inconsistency.
If you monitor employee computer use to enforce this clause, the monitoring is regulated. In NSW, the Workplace Surveillance Act 2005 requires written notice to employees at least 14 days before computer surveillance begins, and the notice has to specify the kind of surveillance, how it will be carried out, and when it will start. Other states have analogous regimes. Build the notice requirement into the policy if you intend to monitor.
Content the business owns
This is where most disputes actually arise — not at the time of posting, but at the end of employment. The clause should state plainly that:
- content created by employees in the course of their employment for the business's social media accounts is the business's property
- the business owns the accounts themselves, including the login credentials, the follower list, and any direct-message history
- on termination, the employee must hand over credentials and stop posting on or from those accounts
The variant the other side will push for: a carve-out for "personal brand" content the employee created while employed but that mentions the business. Resist it for any account the business funded, ran, or holds out as official. Accept it only for genuinely personal accounts that pre-date the employment.
The trap: silence on direct-message archives. A departing salesperson who keeps access to the business's Instagram DMs has a client list. Spell out that DMs are business records and access ends on the last day.
Confidential information and IP
The handbook does not replace the IP and confidentiality clauses in the employment contract — it reinforces them. The social media clause should restate, in plain terms, that employees must not post:
- pricing, customer lists, supplier terms, or unreleased product information
- code, technical specifications, designs, or other intellectual property
- internal communications, meeting content, or photographs taken inside the workplace where these would disclose confidential information
- anything subject to a confidentiality obligation owed to a client
Cross-reference the contract's confidentiality clause explicitly. If a court is later asked whether the employee knew the information was confidential, two consistent documents — contract and handbook — are stronger evidence than one.
Posts about the business, colleagues, or clients
The clause most often tested in the Fair Work Commission. It needs to cover:
- comments that disparage the business, its leadership, or its clients
- comments that could damage the business's reputation, even where not directly disparaging
- harassment, bullying, or discrimination directed at colleagues or third parties, whether the post is on a work or personal account
- conduct that breaches the business's separate workplace bullying, sexual harassment, or discrimination policies
A short bulleted list of examples helps. The clause should not try to ban all criticism — an employee complaining online about a tax change is not the same as one calling a manager a racial slur — but it should make clear that posts identifying the business or colleagues are workplace conduct, not private speech.
Define the consequences in the same clause: that breaches may lead to disciplinary action up to and including termination. Without that link, the contractual route from "policy breach" to "valid reason for dismissal" is harder to walk.
Use of branding, logos, and templates
If employees post on behalf of the business, they will at some point use the logo, a product image, or a templated graphic. This clause should set out:
- which assets are approved for staff use and where to get the current versions
- whether employees may use the logo on their personal profiles (e.g. LinkedIn headers)
- the rules for pre-launch products, rebrand transitions, or embargoed content
- the consent requirement before identifying a client, supplier, or colleague in a post
The trap: an employee uses an old logo or an outdated tagline in an external post, the post goes viral, and the business looks careless. A single sentence directing staff to a central brand folder solves it.
Approval workflow for business posts
For accounts the business runs, the policy should describe — or cross-reference — the approval workflow. At a minimum:
- who can draft, who must approve, and who hits publish
- which categories of post need legal or compliance sign-off (regulated industries, financial product references, health claims, comparative advertising)
- the record kept of the approval (an email is enough; a verbal sign-off is not)
The variant junior marketers push for: blanket pre-approval for "routine" posts. Acceptable for a content calendar agreed in advance; unacceptable for one-off reactive posts, which is where most reputational incidents start.
Responding to negative posts, complaints, and crises
A small section on what happens when a customer complains publicly, a post lands badly, or a competitor responds. The policy is not the crisis plan, but it should tell staff:
- not to respond personally to negative posts about the business
- who to escalate complaints to (named role, not named person)
- whether to remove a problematic internal post, leave it, or seek advice first
- that screenshots and timestamps should be preserved before any deletion
The trap: a junior employee replies defensively to a public complaint, the reply becomes the story, and the original complaint is forgotten. A one-line escalation rule prevents most of these.
Breach and disciplinary consequences
Close the substantive clauses with a clear statement of consequences. Repeat that a breach may result in disciplinary action up to and including summary dismissal where the conduct is serious. Reference the business's separate disciplinary policy if one exists.
This is the clause that connects everything else to enforcement. Without it, a manager who relies on the policy to dismiss faces an argument that the employee was never warned that breach was a sackable offence.
Optional or situational clauses
A handful of clauses are worth including only when the business and its risk profile call for them:
- Endorsement and disclosure clause — required where employees post about the business in a way that engages the ACCC's guidance on misleading testimonials and influencer disclosure; the clause directs employees to disclose the employment relationship in any post promoting a product
- Political and activist speech clause — relevant for businesses with public-facing brands or government clients, where employee posts on political topics could be attributed to the business
- Personal use of generative AI clause — covers staff who use AI tools to draft posts, with rules on disclosure of business information into prompts
- Cross-platform direct-messaging clause — for businesses where sales happen by DM, treating DMs as work records subject to retention and handover rules
- Influencer or brand-ambassador clause — where employees are themselves the public face of the brand, governing posts after termination and use of the personal-brand following built during employment
Don't pad the policy with clauses that don't apply. A four-clause policy that fits the business is more useful than a twelve-clause one that lists every conceivable scenario.
How Artificer Legal would draft or review this policy
When we draft a social media policy for a client, we work backwards from the cases that have actually been decided. The Fair Work Commission's reasoning in Stutsel v Linfox Australia Pty Ltd [2011] FWA 8444 — upheld through to the Full Court of the Federal Court in Linfox Australia Pty Ltd v Fair Work Commission [2013] FCAFC 157 — turned on the absence of a social media policy at all. The Commissioner observed that in the current electronic age, it was not sufficient for a large employer to have no policy. The lesson for a small business is sharper, not softer: the policy is the document the Commission will look for first.
The clauses we push hardest on:
- the scope clause — narrow it and the rest of the policy loses force
- the content-ownership and credentials-handover clause — drafted with a specific list of accounts and a written acknowledgement at induction
- the link between policy breach and disciplinary consequence — drafted alongside the employment contract's compliance clause so they read as one instrument
The variants we push back on are usually proposed by employees on the way in, not on the way out: carve-outs for personal-brand content, "reasonable use" wording so vague it cannot be enforced, and silence on direct messages. We also review the policy against the business's other handbook policies — bullying, sexual harassment, confidentiality, IT acceptable use — to make sure they do not contradict each other. If you would like help drafting or reviewing your social media policy, our employment law team can work through it with you.
Tie the policy to the employment contract
The clause that most often decides the outcome of a social media dispute is the one connecting the handbook to the contract: the contractual obligation to comply with workplace policies. Without it, the policy is guidance. With it, a breach is a breach of contract — and the disciplinary, dismissal, and ownership consequences flow from there. Drafters who spend hours on the scope and content clauses but leave the compliance hook to a generic template are writing a policy that looks complete and enforces nothing.
A social media policy in the employee handbook works when scope, ownership, conduct, monitoring, and consequences are all spelled out and tied back to the employment contract. Start with who and what the policy covers. Be specific about who owns business accounts and the content posted to them. Restate the confidentiality and IP obligations in plain terms. Set out the rules for posts about the business and colleagues, and link a breach to disciplinary action. Add only the situational clauses your business actually needs, and review the policy against the cases the Commission has already decided.