Acceptable Use Policy
What people may and may not do with your organization's systems, devices and data.
Association of Digital Trust Practitioners
The Association brings together the people who keep organizations' data, systems and AI trustworthy, across privacy, security, risk, compliance and AI governance.
Associate Membership is free and open to anyone. Whether you already work in privacy, security, risk, compliance or AI governance, or you are building the skills to move into it, it is how you join the Association.
The work sits across security, privacy, audit, legal, IT and now AI, and rarely has a home of its own. The standing people build inside one employer does not travel with them. The Association exists to change that.
A code of ethics and the Digital Trust Common Framework: one control language across the standards and obligations practitioners meet.
Course certificates and ADTP credentials examined on real work, each with an ID anyone can verify.
A community of people who do this work, and a standing that stays yours when roles and employers change.
Governing AI so it stays accountable, and using it well in the trust work itself.
What you can use from your first day as a member.
Each built around a task you do at work, ending in a deliverable and a certificate anyone can verify.
Getting ready for an industry certification? Each one has a readiness check, flashcards and explained practice questions, for 27 certifications, including CISSP, CISM, CISA, CIPP/E, CIPP/US, AIGP and ISO 27001.
Complete documents for your organization. Add your organization's name, adjust what you need, and adopt them as your own.
What people may and may not do with your organization's systems, devices and data.
How staff may use AI tools at work, including what information must never go into them.
The behavior your organization expects, conflicts of interest, and how to raise a concern.
The rules for passwords and signing in to your systems.
How to use email and chat safely: what to share, what to keep, and what to do with suspicious messages.
The checklists, records and registers practitioners use day to day, ready to fill in.
One page per share: what data, with whom, channel, purpose, end date, how access is revoked and what copies remain afterwards.
Preparing a diligence or vendor data room, watermarking and permissions, and the close-out that removes access, exports and cached copies.
Everything a departing person or contractor may hold: devices, personal cloud, shared links, mailboxes, backups and analytics extracts.
The obligations your role touches, who owns each, and the evidence that proves it. You build your first one in DTF-120, Reading a Regulation Without a Lawyer.
Joining with colleagues? Set up your organization for seats, assignments and completion evidence.