1. Policy Statement
Al-Waris Foundation is committed to protecting confidential information entrusted to it.
Confidentiality is essential to maintaining the trust of:
- beneficiaries;
- donors;
- volunteers;
- trustees;
- staff where applicable;
- complainants;
- partner organisations;
- contractors;
- supporters;
- members of the public who communicate with the charity.
Confidential information must be handled carefully, accessed only where necessary, and shared only where there is a legitimate, lawful and proportionate reason.
Confidentiality is not absolute.
Information may need to be shared where necessary for:
- safeguarding;
- legal compliance;
- regulatory reporting;
- preventing or detecting crime;
- protecting life or safety;
- proper administration of the charity;
- another lawful and legitimate purpose.
This policy should therefore be applied together with the Data Protection and UK GDPR Policy and relevant safeguarding policies.
2. Purpose
The purpose of this policy is to:
- protect confidential information;
- establish clear expectations for trustees, volunteers and other authorised persons;
- prevent inappropriate disclosure;
- support lawful information sharing;
- protect beneficiaries and donors;
- protect the charity's operations and reputation;
- provide procedures for responding to confidentiality concerns and breaches.
3. Scope
This policy applies to:
- trustees;
- staff;
- volunteers;
- contractors;
- consultants;
- project workers;
- authorised administrators;
- fundraisers;
- partner representatives where applicable;
- anyone else given access to confidential Al-Waris Foundation information.
It applies whether information is:
- spoken;
- written;
- printed;
- emailed;
- stored electronically;
- contained in photographs or video;
- held in databases;
- stored in cloud systems;
- recorded in meeting minutes;
- contained in messages;
- shared during meetings or telephone calls.
4. What Is Confidential Information?
Confidential information includes information that is not intended for unrestricted public disclosure.
Examples may include:
- beneficiary information;
- safeguarding records;
- donor information;
- donation histories;
- volunteer applications;
- complaint records;
- personal contact information;
- health information;
- financial information;
- bank information;
- internal correspondence;
- passwords and credentials;
- security information;
- unpublished projects or appeals;
- draft reports;
- trustee discussions;
- legal advice;
- contracts;
- supplier quotations;
- partner due diligence;
- investigation records;
- disciplinary information;
- information provided in confidence by another organisation.
Information may be confidential even if it is not legally classified as personal data.
5. Personal Data
Where confidential information is personal data, it must also be handled in accordance with:
- UK GDPR;
- Data Protection Act 2018;
- Data Protection and UK GDPR Policy.
Confidentiality does not replace data protection obligations.
The two frameworks overlap but are not identical.
6. General Principles
People handling confidential information must:
- use it only for legitimate charity purposes;
- access only information they reasonably need;
- keep information secure;
- avoid unnecessary copying;
- avoid unnecessary disclosure;
- verify recipients before sharing;
- use approved systems where available;
- report suspected breaches;
- dispose of information securely when no longer required.
Confidentiality must not be used to conceal wrongdoing or prevent lawful safeguarding or regulatory reporting.
7. Need-to-Know Access
Confidential information should be shared internally only with people who reasonably need it for their role.
Trustee status, seniority or familiarity with the charity does not automatically create a right to access all confidential information.
Examples include:
- safeguarding case details;
- donor personal data;
- complaint files;
- beneficiary records;
- payment information.
The Board should receive sufficient information to discharge its governance duties without unnecessary disclosure of identifiable personal information.
8. Beneficiary Confidentiality
Beneficiary information requires particular care.
People may disclose information concerning:
- poverty;
- illness;
- family circumstances;
- safeguarding;
- disability;
- housing;
- financial hardship;
- personal crises.
This information must not be:
- discussed casually;
- shared for entertainment;
- used for personal gain;
- disclosed publicly without a proper basis;
- shared with family or friends simply because they are known to the charity.
Public accountability does not justify unnecessary identification of beneficiaries.
9. Donor Confidentiality
Donor information should be treated as confidential unless appropriately made public by the donor or otherwise lawfully disclosed.
This may include:
- identity;
- contact information;
- amount donated;
- donation history;
- donation designation;
- recurring donation status;
- donor correspondence;
- payment-related information.
The charity must not sell donor information.
Donor information should not be used for personal solicitation by trustees, volunteers or other representatives.
10. Safeguarding Information
Safeguarding information is highly sensitive.
It should normally be shared only with people who need it to:
- protect someone from harm;
- make a safeguarding referral;
- manage the safeguarding response;
- comply with a legal or regulatory requirement.
Absolute confidentiality must never be promised in a safeguarding situation.
A person making a disclosure should be told, where appropriate, that information may need to be shared with people who can help.
See:
- Safeguarding Children Policy;
- Safeguarding Adults at Risk Policy.
11. Complaints
Complaints should be handled confidentially.
Information should normally be shared only with people involved in:
- recording;
- investigating;
- responding to;
- reviewing;
the complaint.
Where a complaint involves safeguarding, fraud, criminal conduct or another serious matter, information may need to be shared outside the ordinary complaint process.
See the Complaints Policy.
12. Trustee Confidentiality
Trustees may have access to sensitive information through their governance role.
Trustees must not disclose confidential Board information without authority.
This may include:
- legal advice;
- financial information;
- contracts;
- safeguarding matters;
- complaints;
- trustee conduct matters;
- negotiations;
- partner due diligence.
The duty of confidentiality continues after a trustee leaves office where the information remains confidential.
13. Board Discussions
Board discussions may include differing opinions, challenge and sensitive information.
Trustees should be free to discuss matters honestly without expecting every comment to be disclosed publicly.
However, confidentiality must not be used to:
- conceal unlawful activity;
- conceal serious safeguarding failures;
- prevent legitimate whistleblowing;
- mislead regulators;
- conceal unauthorised trustee benefits;
- obstruct lawful investigations.
14. Volunteers
Volunteers may encounter confidential information during:
- fundraising;
- project work;
- distributions;
- administration;
- communications;
- beneficiary contact.
Volunteers must only access and use information relevant to their duties.
They must not:
- copy beneficiary lists for personal use;
- retain unnecessary donor details;
- discuss private cases socially;
- post confidential information online;
- use private information for personal business or fundraising.
15. Contractors and Partners
Where contractors or partners require access to confidential information, access should be:
- necessary;
- proportionate;
- appropriately documented;
- subject to contractual confidentiality obligations where appropriate.
The charity should not disclose entire databases or files where only limited information is required.
16. Overseas Operations
Confidentiality requirements apply to overseas work.
Particular care should be taken where:
- local contractors are used;
- beneficiary lists are shared;
- photographs or videos are collected;
- documents move between countries;
- messaging applications are used;
- local community members know beneficiaries personally.
Only information required for legitimate project purposes should be shared.
17. Photography and Video
Photographs and video may reveal confidential or sensitive information.
Before publishing content, the charity should consider whether it reveals:
- identity;
- medical condition;
- disability;
- location;
- family circumstances;
- poverty or hardship;
- safeguarding information.
Consent or another appropriate lawful basis should be established where required.
See the Photography, Video and Beneficiary Consent Policy.
18. Email
Confidential information sent by email must be handled carefully.
Before sending, users should:
- verify the recipient;
- verify attachments;
- avoid unnecessary recipients;
- use BCC where appropriate;
- consider whether the information needs to be sent at all.
Sensitive information should not be sent insecurely where a safer reasonable method is available.
Misdirected emails containing confidential information must be reported promptly.
19. Messaging Applications
Messaging services should not be used casually for confidential charity records.
Where messaging is necessary:
- use approved organisational channels where available;
- share only necessary information;
- avoid unnecessary beneficiary details;
- avoid forwarding information beyond authorised recipients;
- consider whether records need to be transferred to an approved system.
Disappearing messages should not be used where retention is required for safeguarding, complaints, governance or other accountability purposes.
20. Personal Devices
Where personal devices are used for legitimate charity activity, confidential information must be protected.
Users should:
- use device security;
- avoid leaving devices unlocked;
- avoid unnecessary local downloads;
- securely delete information when no longer needed;
- report lost or stolen devices containing charity information.
Confidential charity files should not remain indefinitely on personal devices without a legitimate reason.
21. Paper Records
Paper records containing confidential information must be stored securely.
They should not be:
- left unattended in public areas;
- discarded in ordinary waste where sensitive information remains readable;
- taken off-site unnecessarily.
Secure destruction should be used where appropriate.
22. Meetings and Conversations
Confidential matters should not be discussed where conversations can easily be overheard by unauthorised people.
Care should be taken when discussing sensitive information:
- in public places;
- on public transport;
- in communal areas;
- over speakerphone;
- during online meetings.
23. Working From Home
When handling confidential information remotely:
- screens should not be visible unnecessarily to others;
- paper records should be secured;
- approved accounts should be used;
- confidential calls should be conducted privately where reasonably possible.
24. Passwords and Credentials
Passwords, API keys, recovery codes and other credentials are confidential security information.
They must not be:
- posted publicly;
- sent through insecure channels unnecessarily;
- stored in public repositories;
- shared merely for convenience;
- reused by unauthorised persons.
Access credentials must be revoked when no longer required.
25. Financial Information
Confidential financial information may include:
- bank details;
- payment credentials;
- supplier information;
- donor records;
- internal budgets;
- financial disputes;
- account access information.
Such information must only be accessed and disclosed where appropriate.
Published statutory accounts or approved public financial information are not confidential once properly published.
26. Legal Advice
Legal advice received by Al-Waris Foundation may be confidential and may also be subject to legal professional privilege.
Legal advice should not be circulated more widely than necessary.
Before disclosing legal advice externally, appropriate advice should be obtained where necessary.
27. Information From Other Organisations
Information received confidentially from another organisation must be protected in accordance with:
- any applicable agreement;
- law;
- legitimate expectations;
- safeguarding requirements.
Al-Waris Foundation should not promise confidentiality that would prevent necessary legal or safeguarding disclosures.
28. Public Information
Information that is legitimately public is not automatically confidential.
Examples may include:
- published annual reports;
- published policies;
- public Charity Commission information;
- published appeals;
- public project updates.
However, the existence of some public information does not justify disclosure of additional private information about the same person or matter.
29. Requests From Family Members
Family members do not automatically have a right to receive information about:
- beneficiaries;
- donors;
- volunteers;
- trustees;
- complainants.
Information should only be disclosed where there is appropriate authority, consent, lawful basis or safeguarding justification.
30. Requests From Police or Authorities
Requests from police, regulators or statutory authorities should be assessed appropriately.
The charity should consider:
- legal authority;
- necessity;
- safeguarding;
- data protection;
- scope of the request.
Where urgent action is required to protect life or prevent serious harm, information may need to be shared promptly.
Where appropriate, professional advice should be sought.
31. Safeguarding Overrides
Confidentiality must not prevent reasonable safeguarding action.
Information may be shared without consent where necessary and lawful to protect:
- a child;
- an adult at risk;
- another person.
Only relevant information should be shared.
The decision and reasons should be recorded where appropriate.
32. Crime and Serious Wrongdoing
Confidential information may be disclosed where necessary and lawful in connection with:
- suspected fraud;
- bribery;
- theft;
- money laundering;
- terrorist financing;
- serious criminal offences;
- significant regulatory breaches.
This policy does not require the charity to conceal criminal conduct.
33. Whistleblowing
Nothing in this policy prevents a person from making a protected or legitimate disclosure under the Whistleblowing Policy or applicable law.
Confidentiality clauses must not be used to silence genuine reports of serious wrongdoing.
34. Serious Incident Reporting
Information may need to be disclosed to the Charity Commission where a serious incident is reportable.
Only information reasonably necessary for the regulatory purpose should be provided.
See the Serious Incident Reporting Policy.
35. Data Subject Rights
Where information is personal data, individuals may have rights under data protection law.
A confidentiality obligation does not automatically override those rights.
Equally, an individual's right of access does not necessarily entitle them to confidential personal information about another person.
See the Data Protection and UK GDPR Policy.
36. Access Requests
Requests for access to confidential records must be handled through the appropriate process.
People should not release records informally merely because the requester is:
- a trustee;
- donor;
- beneficiary;
- relative;
- volunteer.
The appropriate legal and governance basis must be considered.
37. Minimum Necessary Disclosure
Where disclosure is justified, only the minimum information reasonably necessary should be shared.
For example, a trustee may need to know:
a serious safeguarding incident occurred and was referred appropriately
without needing the beneficiary's full identifiable case file.
38. Anonymisation
Where practical, confidential reporting to the Board or public should use:
- anonymised information;
- aggregated statistics;
- pseudonyms;
- limited identifiers.
This is particularly important for:
- safeguarding;
- complaints;
- beneficiaries;
- health matters.
39. Internal Records
Confidential decisions and disclosures should be recorded where appropriate.
Records may include:
- reason for disclosure;
- information shared;
- recipient;
- date;
- lawful or safeguarding rationale;
- person authorising disclosure.
Records should themselves remain appropriately confidential.
40. Confidentiality Breach
A confidentiality breach may include:
- sending information to the wrong recipient;
- discussing a private case publicly;
- unauthorised access;
- publishing private information;
- loss of confidential documents;
- unauthorised sharing;
- misuse of beneficiary or donor information.
All suspected significant breaches should be reported promptly.
41. Immediate Response to a Breach
When a breach occurs, reasonable steps should be taken to:
- contain the disclosure;
- recover information where possible;
- prevent further access;
- identify what information was involved;
- identify affected people;
- assess safeguarding, privacy, security and reputational risks;
- notify the appropriate internal person;
- consider whether external reporting is required;
- document the incident;
- implement corrective action.
42. Personal Data Breaches
Where a confidentiality breach involves personal data, it must also be assessed under the Data Protection and UK GDPR Policy.
This includes considering whether:
- the Information Commissioner's Office must be notified;
- affected individuals must be informed.
Not every confidentiality breach requires ICO notification.
43. Safeguarding Breaches
Where disclosure creates or increases a safeguarding risk, safeguarding procedures must be followed immediately.
Examples may include revealing:
- a child's location;
- the identity of an abuse complainant;
- an adult-at-risk address;
- sensitive family information.
44. Disciplinary and Governance Action
A breach of confidentiality may result in:
- guidance;
- additional training;
- restriction of access;
- removal from duties;
- disciplinary action where applicable;
- termination of volunteering;
- termination of a contract;
- trustee governance action;
- regulatory reporting;
- legal action.
The response should reflect:
- seriousness;
- intent;
- harm;
- sensitivity;
- repetition;
- cooperation following the breach.
45. Deliberate Misuse
Deliberate use of confidential information for:
- personal advantage;
- retaliation;
- blackmail;
- harassment;
- business purposes;
- unauthorised fundraising;
will be treated particularly seriously.
46. Training
People who routinely handle confidential information should receive guidance proportionate to their responsibilities.
Training may include:
- data protection;
- safeguarding;
- secure email;
- phishing;
- password security;
- information sharing;
- records handling;
- breach reporting.
47. Induction
Relevant trustees, volunteers, staff and contractors should be informed during induction that:
- charity information may be confidential;
- confidentiality continues beyond their involvement where applicable;
- breaches must be reported;
- safeguarding and legal disclosures may override ordinary confidentiality.
48. Leaving the Charity
When a person's involvement ends, they must:
- return confidential records;
- return devices or property where applicable;
- cease accessing systems;
- delete unauthorised local copies as directed;
- continue respecting confidential information.
Confidentiality obligations do not automatically end when someone stops volunteering, working or serving as trustee.
49. Policy Ownership
The Board of Trustees retains overall responsibility for this policy.
Operational responsibility for confidentiality controls may be delegated.
Significant breaches should be escalated to the Board where appropriate.
50. Related Al-Waris Foundation Policies
This policy should be read alongside:
- Data Protection and UK GDPR Policy;
- Information Security and Cybersecurity Policy;
- Records Retention and Disposal Policy;
- Safeguarding Children Policy;
- Safeguarding Adults at Risk Policy;
- Complaints Policy;
- Whistleblowing Policy;
- Serious Incident Reporting Policy;
- Trustee Code of Conduct;
- Volunteer Policy;
- Photography, Video and Beneficiary Consent Policy;
- Social Media and Digital Communications Policy;
- Overseas Operations and Partner Due Diligence Policy;
- Anti-Fraud, Bribery and Corruption Policy.
51. Review
This policy will be reviewed:
- at least annually;
- following a significant confidentiality breach;
- following a significant personal data breach;
- following a serious safeguarding incident involving information disclosure;
- following material changes to information-handling arrangements;
- following significant changes in applicable law or guidance.
52. Approval
Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027
