handbook/handbook/security/employee-termination-security-policy.md
This policy ensures the secure handling of company assets and information when an employee departs from Tuist GmbH. The policy defines procedures to mitigate any security risks associated with terminated employees, including the revocation of access, return of assets, and preservation of confidentiality.
This policy applies to all employees, contractors, and temporary workers who have been granted access to Tuist GmbH’s systems, data, and physical assets.
Upon termination of employment, Tuist GmbH shall:
Revoke Access: All access to company systems, networks, applications, and data shall be revoked immediately upon the termination of an employee’s contract. This includes the deactivation of all user accounts, password access, and physical keys.
Return of Company Assets: All company-owned equipment, including but not limited to laptops, mobile devices, access cards, and documents, shall be returned to the company in a timely manner.
Data Security: Any sensitive data in the possession of the terminated employee, whether stored physically or digitally, must be returned, deleted, or encrypted in accordance with company data protection procedures.
Non-Disclosure and Confidentiality: The terminated employee shall continue to be bound by any non-disclosure agreements (NDAs) and confidentiality commitments made during their employment. They must not disclose, distribute, or use confidential company or customer data.
Revocation of Access:
Exit Interviews:
Documentation:
Any failure to comply with this policy may result in the following actions:
Requests for exceptions to this policy must be submitted in writing to the HR Manager and the IT Manager for review and approval.
The version history of this document can be found in Tuist's handbook repository.