Skip to main content

Information and communications

Data Protection and UK GDPR Policy

Al-Waris Foundation is committed to protecting personal data and respecting the privacy rights of individuals whose information it processes.

Current version 2.0

1. Policy Statement

Al-Waris Foundation is committed to protecting personal data and respecting the privacy rights of individuals whose information it processes.

The charity will process personal data lawfully, fairly, transparently and securely in accordance with applicable data protection law, including the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.

Al-Waris Foundation recognises that responsible data protection is essential to maintaining the trust of donors, beneficiaries, volunteers, supporters, trustees and other people who interact with the charity.

The Board of Trustees has ultimate responsibility for ensuring that appropriate data protection governance is maintained.

Operational responsibilities may be delegated to authorised individuals, but the Board retains overall accountability.

2. Scope

This policy applies to personal data processed by or on behalf of Al-Waris Foundation.

It applies to:

  • trustees;
  • staff;
  • volunteers;
  • contractors;
  • consultants;
  • authorised administrators;
  • project workers;
  • service providers where applicable;
  • any other person processing personal data on behalf of the charity.

It applies regardless of whether information is held:

  • electronically;
  • on paper;
  • in databases;
  • in cloud systems;
  • in email;
  • through the website;
  • on approved devices;
  • through payment systems;
  • through third-party platforms;
  • in photographs or video;
  • in project records.

3. Key Definitions

3.1 Personal Data

Personal data means information relating to an identified or identifiable living individual.

Examples include:

  • name;
  • address;
  • email address;
  • telephone number;
  • date of birth;
  • IP address;
  • online identifiers;
  • donation history;
  • account information;
  • photographs where a person is identifiable;
  • correspondence;
  • volunteer application information.

3.2 Special Category Data

Special category personal data includes information revealing or concerning:

  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data used for identification;
  • health;
  • sex life;
  • sexual orientation.

Additional legal conditions apply to processing this information.

3.3 Criminal Offence Data

Personal data relating to criminal convictions, offences or related security measures is subject to additional legal requirements.

3.4 Processing

Processing includes collecting, recording, organising, storing, accessing, changing, using, sharing, transmitting, restricting, deleting or destroying personal data.

3.5 Data Subject

A data subject is the living individual to whom personal data relates.

3.6 Controller

A controller determines why and how personal data is processed.

Al-Waris Foundation will normally act as controller for personal data collected for its own charitable activities.

3.7 Processor

A processor processes personal data on behalf of a controller.

External technology and service providers may act as processors for Al-Waris Foundation.

4. Data Protection Principles

Al-Waris Foundation will process personal data in accordance with the UK GDPR principles.

Personal data must be:

4.1 Lawful, Fair and Transparent

Personal data must be processed lawfully, fairly and in a way individuals can reasonably understand.

4.2 Collected for Specified Purposes

Personal data must be collected for specified, explicit and legitimate purposes and not subsequently used incompatibly with those purposes.

4.3 Adequate, Relevant and Limited

The charity should collect only the personal data reasonably necessary for the relevant purpose.

4.4 Accurate

Reasonable steps should be taken to ensure personal data is accurate and, where necessary, kept up to date.

4.5 Retained Only as Long as Necessary

Personal data must not be kept indefinitely without a legitimate reason.

Retention requirements should be documented.

4.6 Secure

Appropriate technical and organisational measures must protect personal data against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • inappropriate disclosure;
  • unlawful processing.

4.7 Accountable

Al-Waris Foundation must be able to demonstrate appropriate compliance with these principles.

5. Lawful Bases

Before processing personal data, the charity must identify an appropriate lawful basis.

Depending on the circumstances, this may include:

Consent

The individual has given valid consent for a specified purpose.

Contract

Processing is necessary to enter into or perform a contract with the individual.

Legal Obligation

Processing is necessary to comply with a legal obligation.

Vital Interests

Processing is necessary to protect someone's life.

Public Task

Processing is necessary for a task in the public interest where the relevant legal requirements are met.

Legitimate Interests

Processing is necessary for a legitimate interest pursued by the charity or another person, provided those interests are not overridden by the individual's rights and interests.

The charity must not automatically rely on consent where another lawful basis is more appropriate.

6. Special Category Personal Data

Special category personal data must only be processed where:

  1. an Article 6 lawful basis applies; and
  1. an appropriate Article 9 condition also applies.

Where required, an additional condition under the Data Protection Act 2018 must also be identified.

Examples of situations where Al-Waris Foundation may encounter special category data include:

  • safeguarding;
  • beneficiary support;
  • accessibility requirements;
  • health-related charitable activities;
  • volunteer information;
  • equality monitoring;
  • religious donation intentions where these reveal beliefs.

Access to special category data must be restricted appropriately.

7. Criminal Offence Data

Criminal offence data must only be processed where there is lawful authority to do so.

This may arise in connection with:

  • safeguarding;
  • safer recruitment;
  • DBS checks;
  • allegations of misconduct;
  • fraud investigations;
  • regulatory obligations.

Such information must be subject to appropriate access and security controls.

8. Categories of People Whose Data We May Process

Al-Waris Foundation may process personal data relating to:

  • donors;
  • prospective donors;
  • supporters;
  • beneficiaries;
  • prospective beneficiaries;
  • volunteers;
  • volunteer applicants;
  • trustees;
  • staff where applicable;
  • job applicants where applicable;
  • contractors;
  • suppliers;
  • partner organisations and their representatives;
  • website users;
  • donor-account holders;
  • people making enquiries;
  • complainants;
  • event participants;
  • newsletter subscribers;
  • fundraisers;
  • regulators and professional contacts;
  • other people who interact with the charity.

9. Types of Personal Data

Depending on the relationship and purpose, Al-Waris Foundation may process:

  • names;
  • contact information;
  • addresses;
  • dates of birth;
  • communication preferences;
  • donation records;
  • transaction references;
  • donor intentions or designations;
  • recurring donation information;
  • Gift Aid information where applicable;
  • account details;
  • authentication-related information;
  • volunteer application information;
  • safeguarding information;
  • complaint information;
  • enquiry records;
  • project and beneficiary records;
  • photographs and video;
  • consent records;
  • attendance records;
  • website usage information;
  • device and browser information;
  • IP addresses;
  • security logs;
  • audit records;
  • correspondence.

The charity should not collect information merely because it may be useful in the future.

10. Donor Information

Donor information may be processed for purposes including:

  • processing donations;
  • allocating donations to the selected charitable purpose;
  • issuing confirmations and receipts;
  • maintaining financial records;
  • managing recurring donations;
  • responding to donor enquiries;
  • preventing fraud;
  • meeting accounting and regulatory obligations;
  • providing donor accounts where requested;
  • communicating about supported projects where lawful and appropriate.

The charity will not sell donor personal data.

Payment-card information should be handled by approved payment processors rather than unnecessarily stored by Al-Waris Foundation.

11. Beneficiary Information

Beneficiary data requires particular care because individuals may be experiencing hardship or vulnerability.

Only information reasonably required for:

  • assessing eligibility;
  • delivering assistance;
  • safeguarding;
  • project administration;
  • monitoring;
  • accountability;
  • legal or regulatory purposes;

should be collected.

Beneficiary information must not be collected merely for publicity.

Access should be restricted to people who genuinely require it.

A person's receipt of charitable assistance should not normally be publicly disclosed without an appropriate basis.

12. Volunteer Information

Volunteer information may include:

  • identity and contact information;
  • application information;
  • references;
  • availability;
  • role history;
  • training;
  • safeguarding information;
  • DBS-related information where applicable;
  • emergency contact details;
  • performance or conduct records.

Access must be limited appropriately.

Information collected for safer recruitment must be handled in accordance with applicable legal requirements.

13. Website and Donor Accounts

The Al-Waris Foundation website may process information relating to:

  • account registration;
  • email verification;
  • authentication;
  • password recovery;
  • security;
  • multi-factor authentication;
  • donation history;
  • supported projects;
  • preferences;
  • enquiries;
  • volunteer applications;
  • complaints;
  • newsletter subscriptions;
  • administrative activity.

Access controls must ensure that users cannot access another person's private information merely by manipulating URLs or requests.

Administrative access must be appropriately restricted.

14. Payment Processing

Al-Waris Foundation may use external payment processors, including Stripe, to process online donations.

Payment processors may process personal data independently or on behalf of the charity according to the circumstances and their contractual terms.

Al-Waris Foundation should avoid storing complete payment-card details where they are processed securely by the payment provider.

Payment information must only be accessible to authorised persons where required for legitimate purposes.

Production payment credentials must never be exposed in:

  • public source code;
  • client-side application bundles;
  • repositories;
  • public logs;
  • publicly accessible documentation.

15. Technology Providers

Al-Waris Foundation may use reputable technology providers to operate its services.

These may include providers for:

  • website hosting;
  • databases;
  • authentication;
  • payment processing;
  • transactional email;
  • analytics;
  • domain and email hosting;
  • security;
  • backups;
  • communications.

Current providers may include systems such as:

  • Hostinger;
  • Supabase;
  • Stripe;
  • Resend;
  • Google Analytics;

where these services are actively configured and used.

The use of a named provider in this policy does not permanently authorise that provider.

Appropriate due diligence and contractual arrangements must be maintained according to the nature of the processing.

Where practical, operational records should maintain the current list of processors and relevant data-processing arrangements so this policy does not require amendment every time a provider changes.

16. Privacy Information

Al-Waris Foundation must provide appropriate privacy information explaining how personal data is processed.

Privacy information should include, where applicable:

  • identity of the controller;
  • contact information;
  • purposes of processing;
  • lawful bases;
  • categories of recipients;
  • international transfers;
  • retention information;
  • data subject rights;
  • complaint rights;
  • whether information is required;
  • relevant automated decision-making information where applicable.

Website privacy information should be readily accessible.

17. Consent

Where consent is relied upon, it must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • demonstrated by a clear affirmative action.

Consent must not be inferred from silence or pre-ticked boxes.

Records of consent should be maintained where appropriate.

People must be able to withdraw consent as easily as they gave it.

Withdrawal does not invalidate processing lawfully undertaken before withdrawal.

18. Children and Personal Data

Personal data relating to children requires additional care.

The charity should consider:

  • the child's age;
  • capacity to understand the processing;
  • parental or guardian involvement where appropriate;
  • safeguarding;
  • necessity;
  • transparency;
  • privacy;
  • risks of publication.

Privacy information intended for children should be understandable to the intended audience.

See the Safeguarding Children Policy and Photography, Video and Beneficiary Consent Policy.

19. Photography and Video

Photographs and video may constitute personal data where individuals are identifiable.

Before collecting or publishing identifiable imagery, the charity must consider:

  • purpose;
  • lawful basis;
  • consent where relied upon;
  • safeguarding;
  • dignity;
  • privacy;
  • vulnerability;
  • whether identifying information is necessary;
  • where and how the content will be published;
  • retention.

Receiving charitable assistance must not be made conditional on agreeing to publicity unless there is a legitimate and lawful reason for doing so.

See the Photography, Video and Beneficiary Consent Policy.

20. Direct Marketing and Fundraising Communications

Marketing and fundraising communications must comply with applicable data protection and electronic communications requirements.

Where required, valid consent must be obtained.

Individuals must be provided with an appropriate method to opt out.

Opt-out and suppression records may need to be retained to ensure the charity does not contact people who have asked not to receive marketing.

Operational or transactional communications should not be incorrectly treated as marketing merely because they are sent electronically.

21. Email Communications

Personal information must be handled carefully when using email.

People acting for the charity should:

  • verify recipients before sending sensitive information;
  • use BCC appropriately for group communications;
  • avoid unnecessarily attaching sensitive personal data;
  • use approved organisational accounts where available;
  • avoid forwarding charity information to personal accounts without legitimate reason and appropriate protection;
  • report misdirected emails containing personal data.

Sensitive personal data should not be sent insecurely merely for convenience.

22. Access Controls

Access to personal data must be based on legitimate organisational need.

The charity should apply the principle of least privilege.

Appropriate controls may include:

  • individual user accounts;
  • role-based permissions;
  • multi-factor authentication;
  • secure passwords;
  • session controls;
  • restricted administrative access;
  • logging and audit trails;
  • timely removal of access when responsibilities end.

Shared administrative accounts should be avoided where reasonably practicable.

23. Passwords and Authentication

Passwords must not be:

  • stored in plain text;
  • shared unnecessarily;
  • committed to repositories;
  • included in public documentation.

Where authentication is provided by a secure identity platform, password handling should remain within that system rather than being recreated unnecessarily by the charity.

Multi-factor authentication should be used for sensitive administrative systems where available and proportionate.

24. Information Security

Al-Waris Foundation will maintain technical and organisational security measures proportionate to:

  • sensitivity of the data;
  • volume of data;
  • potential harm;
  • nature of processing;
  • available technology;
  • organisational risk.

Measures may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • access controls;
  • multi-factor authentication;
  • secure backups;
  • software updates;
  • malware protection;
  • logging;
  • vulnerability management;
  • secure development practices;
  • least-privilege access;
  • incident response;
  • secure disposal.

This replaces reliance on named legacy encryption products or software.

See the Information Security and Cybersecurity Policy.

25. Personal Devices

Where personal devices are used for legitimate charity purposes, appropriate safeguards must be maintained.

Sensitive information should not be stored permanently on personal devices unless necessary and appropriately protected.

Relevant safeguards may include:

  • device passcodes;
  • encryption;
  • current software updates;
  • screen locking;
  • secure storage;
  • restricted local downloads;
  • secure deletion.

Loss or theft of a device containing charity personal data must be reported promptly.

26. Paper Records

Where personal data is held on paper:

  • access must be restricted;
  • records should be securely stored;
  • sensitive records should not be left unattended;
  • transportation should be minimised and protected;
  • disposal should use an appropriately secure method.

27. Data Sharing

Personal data must not be shared merely because another person or organisation requests it.

Before sharing, the charity should consider:

  • purpose;
  • lawful basis;
  • necessity;
  • proportionality;
  • recipient;
  • security;
  • transparency;
  • contractual requirements;
  • safeguarding considerations.

Data-sharing agreements should be used where appropriate.

28. Safeguarding and Information Sharing

Data protection law does not prevent appropriate safeguarding information sharing.

Where a child or adult may be at risk, the charity should consider whether information needs to be shared with:

  • police;
  • social care;
  • safeguarding authorities;
  • regulators;
  • health professionals;
  • other appropriate organisations.

Consent may not always be required.

The reason for significant safeguarding information-sharing decisions should be recorded.

29. Processors

Where another organisation processes personal data on behalf of Al-Waris Foundation, the charity must consider whether a legally compliant processor arrangement is required.

Processor contracts should address applicable matters required by UK GDPR, including:

  • processing instructions;
  • confidentiality;
  • security;
  • subprocessors;
  • assistance with data subject rights;
  • breach assistance;
  • deletion or return of data;
  • compliance information.

The charity should conduct due diligence proportionate to the risk.

30. International Data Transfers

Al-Waris Foundation will not assume that personal data remains within the United Kingdom merely because a service is accessed from the UK.

Cloud, email, analytics, hosting, payment and other providers may process information internationally.

Where personal data is transferred to a country outside the United Kingdom, the charity must determine whether the transfer is permitted under UK data protection law.

Appropriate mechanisms may include:

  • UK adequacy regulations;
  • appropriate safeguards;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to recognised standard contractual clauses;
  • another legally permitted transfer mechanism.

Where required, an appropriate transfer risk assessment or data protection test should be completed.

International transfers must be documented appropriately.

31. Overseas Projects

Overseas charitable activities may involve personal data concerning:

  • beneficiaries;
  • contractors;
  • partners;
  • volunteers;
  • project representatives;
  • evidence of project delivery.

Only information reasonably necessary for legitimate purposes should be transferred between countries.

Sensitive beneficiary data should not routinely be transferred to the UK merely because a project takes place overseas.

Where project evidence can be provided using anonymised or less identifiable information, this should be considered.

32. Data Minimisation in Project Evidence

Al-Waris Foundation may maintain evidence relating to projects, including:

  • photographs;
  • video;
  • invoices;
  • completion evidence;
  • location information;
  • project identifiers;
  • monitoring records.

Accountability does not require unnecessary disclosure of beneficiary personal data.

Public transparency records should therefore distinguish between:

  • information required internally for audit and accountability; and
  • information appropriate for public disclosure.

33. Accuracy

Reasonable steps must be taken to keep personal data accurate where accuracy is relevant to its use.

Individuals should be provided with appropriate ways to correct inaccurate information.

Material corrections should be reflected across relevant systems where reasonably practicable.

34. Data Retention

Personal data must be retained only for as long as necessary for:

  • the purpose for which it was collected;
  • legal obligations;
  • financial and accounting requirements;
  • safeguarding;
  • dispute resolution;
  • regulatory requirements;
  • legitimate organisational needs.

Different categories of information may require different retention periods.

Detailed periods should be maintained in the Records Retention and Disposal Policy or Schedule.

Information must not simply be retained forever because storage is inexpensive.

35. Secure Disposal

When personal data no longer needs to be retained, it should be securely deleted or destroyed.

Appropriate methods may include:

  • secure electronic deletion;
  • deletion from active systems;
  • managed expiry of backups where applicable;
  • shredding or secure destruction of paper records;
  • secure disposal of storage devices.

The charity should recognise that immediate deletion from every backup may not always be technically possible. Backup retention and expiry should therefore be appropriately controlled.

36. Data Subject Rights

Depending on the circumstances, individuals may have rights including:

  • the right to be informed;
  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restrict processing;
  • the right to data portability;
  • the right to object;
  • rights relating to automated decision-making.

Not every right applies in every circumstance.

Requests must be assessed under the applicable law rather than automatically accepted or rejected.

37. Subject Access Requests

An individual may request access to personal data held about them.

Requests do not need to use particular legal wording to be valid.

Anyone receiving a request that may constitute a subject access request should promptly refer it to the person responsible for data protection.

The charity will:

  • verify identity where reasonably necessary;
  • identify relevant information;
  • conduct appropriate searches;
  • consider third-party information;
  • apply lawful exemptions where relevant;
  • respond within the applicable statutory timeframe.

Records should be maintained of the request and response.

38. Rectification

Where personal data is inaccurate or incomplete, individuals may request correction.

The charity should correct inaccurate data without undue delay where required.

Where relevant, recipients of inaccurate information may also need to be informed.

39. Erasure

Individuals may have a right to request deletion of personal data.

This right is not absolute.

The charity may need to retain information for reasons including:

  • legal obligations;
  • financial records;
  • safeguarding;
  • establishment, exercise or defence of legal claims;
  • other lawful exemptions.

For example, deleting a donor account does not necessarily require deletion of financial transaction records that the charity is legally required to retain.

40. Objections and Restriction

Requests to object to processing or restrict processing must be assessed promptly.

Direct marketing objections must be respected where applicable.

The charity may retain limited suppression information to ensure that a person who has opted out is not inadvertently contacted again.

41. Automated Decision-Making

Al-Waris Foundation will not make solely automated decisions producing legal or similarly significant effects on individuals unless the processing is lawful and appropriate safeguards are provided.

If such processing is introduced in future, the charity must assess the legal and privacy implications before deployment.

42. Data Protection by Design and Default

Privacy and data protection should be considered when designing or changing:

  • website functionality;
  • donation systems;
  • donor accounts;
  • administrative tools;
  • forms;
  • project databases;
  • analytics;
  • email systems;
  • integrations;
  • beneficiary systems.

The default configuration should avoid collecting or exposing unnecessary personal information.

43. Data Protection Impact Assessments

A Data Protection Impact Assessment (DPIA) should be considered where processing is likely to result in a high risk to individuals' rights and freedoms.

Examples may include:

  • significant processing of sensitive beneficiary information;
  • new technologies;
  • large-scale monitoring;
  • high-risk profiling;
  • significant safeguarding databases;
  • systematic processing involving vulnerable people.

Where a DPIA is required, it should be completed before the relevant high-risk processing begins.

44. Cookies and Similar Technologies

The website may use cookies or similar technologies.

Strictly necessary technologies may be used where legally permitted without consent.

Non-essential technologies, including analytics or advertising technologies where consent is required, must not be activated before valid consent is obtained.

Users should be provided with meaningful choices.

Withdrawing consent should be reasonably straightforward.

The website's cookie information should accurately reflect the technologies actually in use.

45. Analytics

Where Al-Waris Foundation uses analytics services such as Google Analytics, they must be configured consistently with applicable privacy and electronic communications requirements.

Where consent is required:

  • analytics must remain disabled before consent;
  • rejecting analytics must not prevent ordinary access to the website;
  • users must be able to change their preference.

Analytics should not be configured to intentionally collect unnecessary personal information.

46. Data Breaches

A personal data breach is a security incident resulting in accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure of;
  • unauthorised access to;

personal data.

Examples may include:

  • sending personal data to the wrong recipient;
  • losing an unprotected device;
  • unauthorised account access;
  • exposing private database records;
  • ransomware;
  • accidentally publishing confidential information;
  • inappropriate internal access.

All suspected personal data breaches must be reported internally without unnecessary delay.

47. Breach Response

When a suspected breach occurs, the charity should:

  1. contain the incident where possible;
  1. protect affected systems and individuals;
  1. preserve relevant evidence;
  1. determine what information was involved;
  1. determine how many people may be affected;
  1. assess likely consequences;
  1. assess the risk to individuals' rights and freedoms;
  1. document the assessment;
  1. determine whether regulatory notification is required;
  1. determine whether affected individuals must be informed;
  1. implement corrective action.

The charity must not automatically notify the Information Commissioner's Office of every incident.

48. ICO Notification

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the charity must notify the Information Commissioner's Office where required by UK GDPR.

Where notification is required, it should be made without undue delay and, where feasible, within 72 hours after the charity becomes aware of the breach.

If notification is made later than required, the reason for delay should be documented.

Where a breach is unlikely to result in risk to individuals, ICO notification may not be required, but the breach and assessment should still be documented appropriately.

49. Notification to Individuals

Where a breach is likely to result in a high risk to an individual's rights and freedoms, affected individuals must be informed where required by law.

Communications should explain clearly:

  • the nature of the breach;
  • likely consequences;
  • action taken;
  • steps the person can take;
  • how to obtain further information.

50. Breach Register

Al-Waris Foundation should maintain an appropriate record of personal data breaches.

The record should include:

  • what happened;
  • date discovered;
  • data involved;
  • people potentially affected;
  • risk assessment;
  • containment action;
  • notification decision;
  • remedial action;
  • lessons learned.

The register should include relevant breaches even where ICO notification was not required.

51. Complaints About Data Protection

People may raise privacy or data protection concerns directly with Al-Waris Foundation.

The charity should attempt to investigate and resolve legitimate concerns appropriately.

Individuals also have the right to complain to the Information Commissioner's Office where applicable.

The charity must not obstruct or penalise a person for exercising their data protection rights.

52. Accountability Records

Al-Waris Foundation should maintain documentation proportionate to its processing activities.

This may include:

  • privacy notices;
  • processor agreements;
  • retention schedules;
  • consent records;
  • breach records;
  • data subject request records;
  • DPIAs;
  • international transfer assessments;
  • security policies;
  • access-control records;
  • training records;
  • records of processing activities where required or appropriate.

53. Training and Awareness

Trustees, staff and volunteers who handle personal data should receive information and training proportionate to their responsibilities.

Training may include:

  • confidentiality;
  • phishing;
  • secure email use;
  • password security;
  • data subject rights;
  • safeguarding information;
  • breach reporting;
  • appropriate use of systems;
  • handling sensitive information.

Training should be refreshed periodically.

54. Contractors and Volunteers

Anyone given access to charity personal data must:

  • use it only for authorised purposes;
  • maintain confidentiality;
  • protect account credentials;
  • follow security requirements;
  • report incidents;
  • return or securely dispose of information when access is no longer required.

Access must be revoked promptly when a person's role ends or no longer requires it.

55. Governance and Oversight

The Board of Trustees has ultimate responsibility for data protection governance.

The Board should receive proportionate assurance concerning significant privacy and security risks.

A formal Data Protection Officer will be appointed where legally required.

Where Al-Waris Foundation is not legally required to appoint a statutory Data Protection Officer, responsibility for coordinating data protection compliance may be assigned to an appropriately authorised person without inaccurately representing that person as a statutory DPO.

56. Data Protection Contact

The charity should maintain an appropriate contact route for privacy and data protection enquiries.

The current contact details should be published through the charity's Privacy Notice and maintained centrally rather than unnecessarily hard-coded throughout this policy.

General organisational contact information may be available at:

https://alwarisfoundation.org

57. Information Commissioner's Office

Al-Waris Foundation recognises the Information Commissioner's Office as the UK's independent regulator for data protection and information rights.

Current regulatory contact and complaint information should be obtained directly from the ICO rather than hard-coded into this policy where it may become outdated.

58. Policy Breaches

Failure to comply with this policy may result in:

  • additional training;
  • restriction or removal of system access;
  • disciplinary action where applicable;
  • termination of volunteering or contractual arrangements;
  • removal from duties;
  • regulatory notification;
  • legal action where appropriate.

Serious or deliberate misuse of personal data will be treated seriously.

59. Related Al-Waris Foundation Policies

This policy should be read alongside, where applicable:

  • Confidentiality Policy;
  • Information Security and Cybersecurity Policy;
  • Records Retention and Disposal Policy;
  • Safeguarding Children Policy;
  • Safeguarding Adults at Risk Policy;
  • Safer Recruitment Policy;
  • Photography, Video and Beneficiary Consent Policy;
  • Social Media and Digital Communications Policy;
  • Complaints Policy;
  • Volunteer Policy;
  • Serious Incident Reporting Policy;
  • Overseas Operations and Partner Due Diligence Policy;
  • Risk Management Policy.

60. Review

This policy will be reviewed:

  • at least annually;
  • following a significant personal data breach;
  • following a material change to the charity's processing activities;
  • when significant new technology or systems are introduced;
  • following significant changes to applicable law or regulatory guidance;
  • where an audit or incident identifies a material weakness.

Changes must be approved in accordance with Al-Waris Foundation's governance arrangements.

61. Approval

Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027

Essential cookies keep secure account and donation features working. With your permission, Google Analytics helps us understand how public pages are used. It is not loaded unless you accept.

Read our cookie information