Use IT facilities responsibly, keeping activity academic and authorised, with personal use allowed only when it doesn’t disrupt work or break University rules.
Protect your identity, never sharing passwords, avoiding password reuse, and locking or securing devices whenever you step away.
Respect IT systems and security, avoiding damage, unauthorised changes, or bypassing controls, following CIS guidance, and never letting others use your device.
Handle information safely, protecting University data, not accessing others’ information, reporting incidents, respecting copyright, and avoiding harmful or illegal content.
Understand the consequences, as misuse can lead to loss of access, disciplinary action, cost recovery, law‑enforcement involvement, or monitored IT use.
Report security incidents, data breaches, lost devices, suspicious activity, vulnerabilities, scams etc
The aim of these regulations is to ensure that Durham University’s IT Facilities can be used safely, lawfully and equitably.
1.1 These regulations apply to all Durham University students, including external learners, that connect to or use the University IT Facilities (including hardware, software, data, network access, third party services, online services or IT credentials) provided or arranged by Durham University.
2.1 You may use a University IT Facility provided that:
You are an Authorised User, having been assigned a Durham University IT Account or been given, in accordance with University processes, express permission to use University IT Facilities.
You have not been required to cease use of the IT Facility or of activities involving University IT Facilities by an Authorised Representative; and
You comply with the IT Regulations set out below.
2.2 The University IT Facilities are to be used only by authorised users in support of academic work and normal University duties in the course of their employment and education, or for other recognised roles or activities for which access to these facilities is granted.
2.3 You must not use the University IT Facilities for any unsanctioned commercial activity. Any use of University IT Facilities for non-institutional commercial activity requires express written permission from the Chief Information Officer.
2.4 Use of the University IT Facilities for personal activities is permitted, provided that it does not breach any of these regulations, and does not interfere with the requirements of your course of study. You should avoid using university email accounts for personal use.
3.1 Your use of the University IT Facilities must comply with the law. Ignorance of the law is not considered a valid excuse for any acts in contravention of the law, and it is your responsibility to ensure you are complying with the relevant laws.
3.2 When accessing University IT Facilities while in another country you are responsible for familiarising yourself with and adhering to the laws applicable in that country and must also comply with UK law.
3.3 You are bound by the Statutes, Ordinances and Regulations of the University when using the University IT Facilities. You must also adhere to the University’s published policies, standards, procedures and guidance relevant to the use of University IT Facilities.
3.4 You must abide by the end user terms published by any other organisation whose services you access, including but not limited to Jisc and Eduserv. See definitions for further information.
3.5 You must adhere to the terms and conditions of all service and licence agreements relating to the University IT Facilities that you use including websites, software, equipment or any other service used. In the event that you have any questions regarding the terms of any software or third-party service provided to authorised users, you should contact the IT Service Desk or the department which provided access to the software or service.
3.6 When accessing Durham University facilities via Eduroam, you are subject to both the IT Regulations of Durham University and the institution where you are accessing services.
3.7 Breach of any applicable law or third party regulation will be regarded as a breach of these regulations.
3.8 The University is under a duty to prevent extremism in accordance with the Counter-Terrorism and Security Act 2015. You must not engage in any activity which could incite or promote terrorist activity including, but not limited to, accessing websites or social media content that might be associated with extreme or terrorist organisations and which could attract criminal liability. For procedures relating to research involving such material, see clause 6.5.
3.9 The University has a responsibility to safeguard children and vulnerable adults who are on its premises or in contact with its staff/learners, and it recognises the risks presented by online activity. As such, everyone has a duty to be vigilant and report any behaviour online which would indicate a risk to vulnerable parties. The University has a Safeguarding Policy, which details how concerns can be escalated. Such behaviour includes, but is not restricted to, accessing or distributing abusive imagery of children. For procedures relating to research involving such material, see clause 6.5.
4.1 You must take all reasonable precautions to safeguard any IT credentials (for example, a username and password or other tokens for authentication) issued to you. You must not allow anyone else to use your IT credentials. Nobody has the authority to ask you for your password and you must not disclose it to anyone.
4.2 You must not use your University password on non-University websites and systems.
4.3 You must not attempt to obtain or use anyone else’s credentials.
4.4 You must not impersonate someone else or actively disguise your identity in order to undertake any wrongful act when using the University IT Facilities, or such that activities carried out on University IT Facilities cannot be audited.
4.5 You must not log on to a University IT Facility and leave it unattended such that it could be used by another person.
4.6 In the event that you wilfully or negligently allow your IT credentials to be used by another individual, for example by sharing your password or leaving an IT facility logged in and unattended, you may be liable for activity carried out using your account.
5.1 You must not knowingly do anything to jeopardise the integrity of the University IT Facilities or expose the University to risk, including, but not limited to, doing any of the following without authorisation:
Damaging or reconfiguring equipment.
Deliberately or recklessly introducing or transmitting malware, for example by browsing websites or downloading or opening files that could reasonably be considered likely to pose a risk of infection.
Scanning University IT Facilities or other networks and attached devices for vulnerabilities, or attempting to exploit vulnerabilities.
Operating a service that redistributes access or any other University resource to others. This includes connecting to the university network, without explicit authority, any equipment which routes, bridges, switches or repeats traffic from other devices or networks, including but not limited to network hubs, switches, routers, firewalls and wireless access points (WAPs), or any device (such as a PC or server) that has been configured to perform these functions.
Connecting to the University network any device offering a service to others, including but not limited to file, print, media, gaming and peer-to-peer servers.
Attempting to disable access or gain unauthorised access.
Attempting to disrupt or circumvent IT security measures.
5.2 You must immediately cease using an item of software or hardware connected to University IT Facilities in the event that the University or its Authorised Representative has requested that you do so.
5.3 You must follow advice from CIS to install, reconfigure or upgrade software and hardware where necessary to ensure security.
5.4 You must comply with the University’s IT Device Standard when connecting your own IT device to the University IT Facilities.
5.5 Devices should be logged out, locked or preferably powered off when not in use or left unattended.
5.6 You must not attempt to monitor the use of the University IT Facilities without explicit authority.
6.1 You must take all reasonable steps to ensure the security of University information, in particular personal or commercially valuable data. You are responsible for complying with all relevant laws, regulations or commercial contracts that govern the collection, use, storage, transmission and deletion of such information. You must observe the University’s Data Protection and Information Security policies.
6.2 You must report any information security breach or weakness of which you become aware, including loss of equipment or suspected compromise of a device or system.
6.3 You must not attempt to violate the privacy of others or access, delete, modify or disclose other users’ information without their permission, or without explicit approval in accordance with the University’s IT Monitoring and Access Policy.
6.4 You must not breach copyright legislation or infringe the intellectual property rights of another person or organisation, for example use of software without an appropriate licence. You must also observe the University’s Intellectual Property regulations.
6.5 You must not access, create, download, store or transmit unlawful material, or data that contain (or are capable of being resolved into) indecent, offensive, obscene, defamatory, threatening or discriminatory content. This includes material that might be subject to provisions of the Counter-Terrorism and Security Act 2015. If you wish to undertake any research or scholarly activity involving such material you must observe the appropriate University procedures to gain approval before commencing such activity and should speak to your supervisor for advice in the first instance.
6.6 You must not create or transmit material with the intent to defraud.
6.7 You must not process, store or transmit any payment card data unless authorised to do so. This does not include use of your own personal payment cards.
6.8 You must return, and not retain copies of, all information belonging to the University at the end of your period of study except where an explicit exemption has been granted for you to retain it. This includes all personal data for which the University is identified as the Data Controller under data protection legislation and any data not classified as Public.
7.1 In using the University IT Facilities, you must not:
Do so in such a way as could reasonably be considered likely to cause any needless offence, concern or annoyance to others, or to perform any act which could reasonably be considered likely to amount to causing any individual or group any form of harassment (including bullying and sexual harassment), alarm or distress.
Act in a way that could reasonably be considered likely to jeopardise the University’s institutional integrity or to bring the University into disrepute.
Present any statement or representation as the view or opinion of the University unless you have been explicitly authorised to do so. Any statement or opinion piece given must make clear that the views are that of the individual and not of the University.
7.2 You must not send spam (unsolicited bulk email). Internal bulk emails, to staff and/or student groups, may be sent only in relation to sanctioned University business. For communications regarding research activities, you must ensure you have gained approval from your supervisor and any other relevant parties before proceeding.
7.3 You must not consume IT resources such as processing power, storage, bandwidth or consumables, to an extent that could reasonably be considered excessive or that wastes the University’s or another organisation’s resources to investigate or resolve.
7.4 You must not use the IT Facilities in a way that interferes with or disrupts others’ valid use of them. This includes, but is not limited to, corrupting or destroying other users’ data and denying service to other users.
7.5 You must not breach the terms of use of any services accessed via the University IT Facilities. Any deliberate or persistent breach of such terms will be regarded as a breach of these Regulations.
8.1 If you are found to have breached these regulations, the University reserves the right to:
Suspend access to University IT Facilities to enable a disciplinary investigation to take place
Consider your case in accordance with the University’s Non-Academic Disciplinary Procedure.
8.2 Material found to be in breach of these regulations will be removed from University IT Facilities. If you have posted such material elsewhere, you may be required to do as much as is in your power to remove it.
8.3 You may be liable for any direct costs incurred as a result of a breach of these regulations for which you are responsible.
8.4 In the event that the University has reason to believe that you are participating in illegal activities using the IT Facilities, information will be passed to appropriate law enforcement agencies.
8.5 If you become aware that you or anyone else has breached these regulations, whether intentionally or otherwise, you should report this via the IT Service Desk directly.
9.1 Durham University reserves the right to monitor and record the use of its IT Facilities, including but not limited to system use, for the purposes set out in the University’s IT Monitoring and Access policy. Use of University IT Facilities constitutes consent by the user to IT monitoring and access in accordance with this policy.
9.2 Durham University uses a range of tools and techniques to detect potential threats to or compromises of IT Facilities. In the event that potential indicators of compromise are detected, your IT account, device or connection could be temporarily suspended for investigation, in order to protect the University, its systems, staff, students and visitors.
9.3 Durham University will comply with lawful requests for information including for example requests made under Freedom of Information or Data Protection laws or from government and law enforcement agencies.