Skip to main content

Information and communications

Records Retention and Disposal Policy

Al-Waris Foundation creates and receives records relating to its:

Current version 2.0

1. Policy Statement

Al-Waris Foundation creates and receives records relating to its:

  • governance;
  • finances;
  • donations;
  • fundraising;
  • beneficiaries;
  • projects;
  • volunteers;
  • safeguarding;
  • complaints;
  • contractors;
  • communications;
  • website;
  • regulatory obligations.

The charity is committed to keeping records for appropriate periods and securely disposing of information when it is no longer reasonably required.

Records must not be:

  • destroyed prematurely;
  • retained indefinitely without justification;
  • altered to conceal activity;
  • disposed of to obstruct an investigation;
  • stored insecurely.

2. Purpose

This policy establishes a framework for:

  • record creation;
  • retention;
  • storage;
  • archiving;
  • deletion;
  • secure destruction;
  • legal holds;
  • digital records;
  • paper records;
  • project evidence;
  • financial records;
  • governance records;
  • personal data.

3. Scope

This policy applies to records held by or on behalf of Al-Waris Foundation.

It applies to:

  • trustees;
  • staff where applicable;
  • volunteers;
  • authorised representatives;
  • contractors handling charity records;
  • systems operated for the charity.

It applies regardless of whether information is held:

  • electronically;
  • on paper;
  • in email;
  • in cloud storage;
  • in databases;
  • in messaging applications;
  • in photographs or video;
  • in accounting systems;
  • in website systems.

4. Core Principles

Al-Waris Foundation will seek to ensure that records are:

  • accurate where necessary;
  • relevant;
  • appropriately organised;
  • accessible to authorised persons;
  • protected against unauthorised access;
  • retained for an appropriate period;
  • securely disposed of when no longer required.

5. Responsibility

The Board of Trustees retains overall responsibility for appropriate records governance.

Operational responsibility may be delegated to authorised persons responsible for:

  • administration;
  • finance;
  • safeguarding;
  • fundraising;
  • projects;
  • data protection;
  • technology.

6. Record Ownership

Records created or received in the course of authorised Al-Waris Foundation activity normally belong to the charity rather than the individual who created them.

This may include records stored temporarily on:

  • personal devices;
  • personal email accounts;
  • messaging applications.

Important charity records should be transferred into appropriate charity-controlled storage where reasonably practicable.

7. Data Minimisation

The charity should not retain personal information merely because storage is available.

Records containing personal data should be limited to information reasonably required for legitimate purposes.

8. Retention Decisions

Retention periods should take account of:

  • legal obligations;
  • Charity Commission requirements;
  • HMRC requirements;
  • accounting requirements;
  • safeguarding;
  • contractual requirements;
  • limitation periods;
  • insurance;
  • regulatory expectations;
  • operational need;
  • historical value.

9. Retention Schedule

The schedule in this policy provides Al-Waris Foundation's normal internal retention framework.

A record may be retained for longer where there is a legitimate reason.

A statutory requirement or legal obligation takes precedence over an internal period stated in this policy.

10. Permanent Governance Records

The following should normally be retained permanently:

  • governing document and amendments;
  • Charity Commission registration records;
  • trustee appointment and resignation records;
  • signed trustee resolutions of lasting significance;
  • formal constitutional changes;
  • records of mergers or dissolution where applicable;
  • significant regulatory decisions.

11. Trustee Meeting Minutes

Approved trustee and Board meeting minutes should normally be retained permanently.

Supporting meeting papers may be retained according to their continuing governance, legal or historical significance.

12. Policies

Superseded versions of significant governance policies should normally be retained to provide an audit trail.

Records should identify where reasonably practicable:

  • version;
  • approval date;
  • approving body;
  • review date.

13. Conflict of Interest Records

Registers and declarations of trustee conflicts should normally be retained for at least 6 years after they cease to be current, unless a longer period is justified.

Records connected to a significant governance matter may be retained longer.

14. Annual Reports and Accounts

Final annual reports, annual accounts and submitted regulatory returns should normally be retained permanently as part of the charity's historical governance record.

15. Accounting Records

Accounting records should normally be retained for at least 6 years after the end of the relevant financial period, subject to applicable legal or tax requirements.

These may include:

  • ledgers;
  • bank statements;
  • invoices;
  • receipts;
  • payment records;
  • reconciliations;
  • expense records;
  • supporting financial documentation.

16. Bank Records

Bank statements, reconciliations and material supporting banking records should normally be retained for at least 6 years after the relevant financial period.

Records connected to unresolved transactions or disputes should be retained longer where necessary.

17. Donation Records

Donation transaction records should normally be retained for at least 6 years after the relevant financial period.

This may include:

  • amount;
  • date;
  • transaction reference;
  • donation designation;
  • payment status;
  • refund status.

Personal donor information should not be retained longer than necessary merely because transaction records must be retained.

18. Restricted Fund Records

Records demonstrating the creation, receipt, application and closure of restricted funds should normally be retained for at least 6 years after the fund has been fully applied or otherwise lawfully resolved.

Material records may be retained longer where necessary to demonstrate compliance with donor restrictions.

19. Gift Aid Records

Where Gift Aid is operated, declarations and associated records should be retained for the period required by applicable HMRC rules.

The current HMRC requirement should be checked when Gift Aid functionality is activated or administered.

20. Fundraising Appeals

Material fundraising records should normally be retained for at least 6 years after the relevant Appeal or campaign closes.

These may include:

  • published fundraising wording;
  • target;
  • restriction;
  • surplus-fund wording;
  • amount raised;
  • key decisions;
  • closure records.

This helps demonstrate what donors were told when donations were received.

21. Cause Records

Records concerning permanent or long-term Causes may remain active for as long as the Cause operates.

Historical versions of material fundraising terms should be retained where necessary to understand earlier donations.

22. Project Records

Material project records should normally be retained for at least 6 years after project completion.

Records may include:

  • project number;
  • budget;
  • approvals;
  • supplier or contractor;
  • invoices;
  • completion evidence;
  • monitoring;
  • photographs;
  • project reports.

23. Water Project Records

Al-Waris Foundation should maintain a durable record for each completed water installation.

The record should normally include:

  • AWF project number;
  • project location;
  • GPS/location where appropriate;
  • installation type;
  • depth/specification where applicable;
  • completion date;
  • contractor;
  • photographs/video;
  • cost/invoice;
  • maintenance information;
  • warranty information;
  • plaque or project-identification evidence.

Core records identifying the installation and its location may be retained for the operational life of the installation and beyond where useful for accountability and historical project records.

24. Water Maintenance Records

Maintenance, repair and warranty records should be retained for as long as they remain relevant to the installation.

Significant records may be linked permanently to the project's core record.

25. Food Distribution Records

Material food-distribution records should normally be retained for at least 6 years where required for financial or project accountability.

Records may include:

  • purchase information;
  • quantities;
  • package composition;
  • distribution date;
  • location;
  • evidence;
  • expenditure.

Beneficiary-identifying information should only be retained where genuinely required.

26. Emergency Project Records

Emergency and disaster-response records should normally be retained for at least 6 years after completion.

Longer retention may be appropriate where the activity involves:

  • significant restricted funds;
  • safeguarding;
  • regulatory reporting;
  • litigation;
  • major public interest.

27. Procurement Records

Material procurement records should normally be retained for at least 6 years after completion of the transaction or contract.

These may include:

  • specifications;
  • quotations;
  • evaluations;
  • approvals;
  • contracts;
  • invoices;
  • contractor due diligence.

28. Contracts

Contracts should normally be retained for the duration of the agreement and for at least 6 years after termination or expiry, unless a longer period is appropriate.

Contracts executed as deeds or involving longer legal limitation periods may require longer retention.

29. Supplier Records

Routine supplier information should be retained for as long as the relationship remains active and thereafter only for as long as necessary for:

  • accounting;
  • tax;
  • legal;
  • fraud prevention;
  • contractual purposes.

30. Contractor Due Diligence

Due-diligence records for significant contractors should normally be retained for at least 6 years after the relationship or relevant project ends.

High-risk or disputed relationships may justify longer retention.

31. Grant Records

Records relating to grants made by Al-Waris Foundation should normally be retained for at least 6 years after the grant is completed or closed.

This may include:

  • application;
  • due diligence;
  • approval;
  • conditions;
  • payments;
  • monitoring;
  • completion evidence.

32. Expense Records

Expense claims and supporting evidence should normally be retained for at least 6 years after the relevant financial period.

33. Cash Collection Records

Records relating to public or street collections should normally be retained for at least 6 years where they form part of financial records.

This may include:

  • permit;
  • collection date;
  • location;
  • collector records where appropriate;
  • cash count;
  • reconciliation;
  • banking record.

34. Payment Processor Records

Material payment-processor records should normally be retained in line with financial-record requirements.

The charity does not need to duplicate information indefinitely where reliable records remain available elsewhere and appropriate access is assured.

35. Volunteer Records

Routine volunteer records should normally be retained for the duration of the volunteer relationship and for an appropriate period afterward.

A general retention period of up to 6 years after the relationship ends may be appropriate where records remain relevant to:

  • disputes;
  • insurance;
  • safeguarding;
  • claims;
  • governance.

Unnecessary personal information should be removed earlier where appropriate.

36. Volunteer Applications

Unsuccessful volunteer applications should normally be retained only for a limited period unless there is a legitimate reason for longer retention.

As a general internal period, they should normally be deleted within 6 to 12 months after the recruitment process ends.

37. Recruitment Records

Recruitment records should be retained according to:

  • legal requirements;
  • equality considerations;
  • safeguarding;
  • potential claims;
  • operational need.

Unsuccessful applicant records should not be retained indefinitely.

38. DBS and Criminal Record Information

Information relating to criminal-record checks requires particular care.

The charity should not routinely retain copies of DBS certificates longer than necessary.

Where appropriate, the charity may record limited information such as:

  • check completed;
  • date;
  • certificate reference where permitted;
  • decision.

Applicable DBS handling requirements should be followed.

39. Safeguarding Records

Safeguarding records may require significantly longer retention than ordinary administrative records.

Retention should consider:

  • nature of concern;
  • age of person affected;
  • possible future allegations;
  • statutory guidance;
  • insurance;
  • regulatory expectations.

Safeguarding records must not be automatically deleted under a routine six-year rule.

40. Safeguarding Record Review

Where a safeguarding record reaches a proposed disposal date, an appropriately authorised person should assess whether deletion is safe and appropriate.

Professional safeguarding or legal advice should be obtained where necessary.

41. Serious Incident Records

Records concerning serious incidents should normally be retained for at least 6 years after closure, and longer where:

  • safeguarding is involved;
  • legal proceedings remain possible;
  • the Charity Commission has been involved;
  • significant governance lessons remain relevant.

42. Complaints

Routine complaint records should normally be retained for at least 3 years after closure.

A longer period may be appropriate where the complaint involves:

  • safeguarding;
  • litigation;
  • serious misconduct;
  • regulatory reporting;
  • repeated complaints.

43. Whistleblowing Records

Whistleblowing records should be retained according to the seriousness and outcome of the concern.

Material substantiated matters may require retention for at least 6 years or longer.

Records should be kept confidential and access restricted.

44. Fraud and Financial Crime Records

Records relating to suspected or confirmed:

  • fraud;
  • bribery;
  • corruption;
  • money laundering concerns;
  • sanctions concerns;

should normally be retained for at least 6 years after closure, unless legal, regulatory or investigative requirements justify longer retention.

45. Sanctions Screening

Material sanctions or financial-crime due-diligence records should be retained for an appropriate period demonstrating the checks undertaken.

The appropriate period should reflect the nature and risk of the relationship.

46. Health and Safety Records

Routine accident and health and safety records should normally be retained for at least 3 years from the relevant incident, subject to longer applicable requirements.

Longer retention may be required where:

  • a child is involved;
  • an occupational condition is involved;
  • litigation remains possible;
  • insurance requirements apply.

47. Insurance Records

Current insurance policies should be retained throughout their period of cover.

Historic policies and significant claims records should be retained where they may be relevant to future claims.

Some liability claims may arise many years after the relevant event, so potentially relevant historic insurance evidence should not be destroyed without appropriate consideration.

48. Premises Records

Material premises records should be retained for the duration of occupation and for an appropriate period afterward.

These may include:

  • lease;
  • landlord correspondence;
  • utility matters;
  • insurance;
  • significant maintenance;
  • disputes.

Legal or financial records should follow the applicable longer retention period.

49. Utility Disputes

Records connected to a disputed utility liability or enforcement matter should be retained until:

  • the matter is conclusively resolved;
  • relevant limitation periods have been considered;
  • there is no reasonable continuing need for the evidence.

Such records must not be destroyed merely because the charity leaves the premises.

50. Legal Claims and Disputes

Records relevant to actual or reasonably anticipated legal proceedings must not be destroyed while they may remain relevant.

This applies even where their normal retention period has expired.

51. Legal Hold

Where litigation, regulatory investigation, safeguarding investigation, fraud investigation or another serious dispute is reasonably anticipated, relevant deletion should be suspended.

This is referred to in this policy as a legal hold.

52. Scope of Legal Hold

A legal hold may apply to:

  • emails;
  • messages;
  • financial records;
  • photographs;
  • video;
  • contracts;
  • logs;
  • paper documents;
  • system records.

Relevant records should be preserved until the hold is formally lifted.

53. Data Subject Requests

Records relevant to an active data-protection request should not be deleted merely because a routine deletion date occurs during processing.

The charity should preserve what is reasonably necessary to respond properly.

54. Data Protection Records

Records demonstrating data-protection compliance should be retained for as long as reasonably necessary.

These may include:

  • data-breach records;
  • consent records;
  • data-processing agreements;
  • legitimate-interest assessments;
  • data-subject requests;
  • privacy decisions.

55. Personal Data Breach Records

Records of personal-data breaches should be retained for an appropriate period sufficient to demonstrate:

  • circumstances;
  • effects;
  • remedial action;
  • notification decisions.

Material incidents may warrant retention for at least 6 years.

56. Consent Records

Where processing or publication relies upon consent, evidence of that consent should normally be retained for as long as the relevant processing continues and for an appropriate period afterward.

A record of withdrawal should also be retained where necessary to ensure the withdrawal continues to be respected.

57. Beneficiary Records

Beneficiary information should be retained only for as long as necessary for:

  • delivering assistance;
  • project accountability;
  • safeguarding;
  • fraud prevention;
  • legal obligations;
  • legitimate monitoring.

Beneficiary data should not automatically be retained for six years merely because financial records relating to the same project are retained for six years.

58. Beneficiary Identity Documents

Copies of identity documents should only be retained where genuinely necessary.

Where verification can be recorded without retaining a complete identity document, this may reduce risk.

59. Photography and Video

Project photographs and videos should be retained according to:

  • evidential purpose;
  • consent;
  • safeguarding;
  • historical value;
  • fundraising need;
  • privacy.

Not every raw media file needs to be retained permanently.

60. Core Project Media

A limited selection of important project evidence may be retained for longer periods where it provides a legitimate historical or accountability record.

Sensitive beneficiary imagery should receive separate consideration.

61. AI-Generated Media

AI-generated illustrations that do not contain personal data may be retained according to ordinary content-management needs.

They should remain distinguishable from genuine project evidence where confusion could otherwise arise.

62. Website Content

Published website content may be retained while current.

Material historical versions should be preserved where they are relevant to:

  • fundraising representations;
  • governance;
  • legal obligations;
  • public accountability.

63. CMS Version History

The charity's CMS may retain previous content versions to support:

  • rollback;
  • audit;
  • accountability;
  • investigation.

Version history should not become an indefinite repository for personal data that should otherwise have been deleted.

64. Appeal Pages

A completed fundraising Appeal may remain publicly available as a historical record where appropriate.

The charity should consider removing or updating:

  • outdated calls to donate;
  • unnecessary beneficiary personal data;
  • inaccurate status information.

65. Social Media Content

Social-media posts may remain publicly available where they continue to serve a legitimate purpose.

Older posts should be reviewed where they contain:

  • outdated appeals;
  • sensitive beneficiary information;
  • incorrect information;
  • expired contact details.

66. Emails

Email should not automatically be treated as permanent storage.

Important emails should be retained according to their content rather than merely because they exist in a mailbox.

Routine low-value correspondence may be deleted when no longer needed.

67. Transactional Emails

Emails forming evidence of:

  • contracts;
  • disputes;
  • approvals;
  • financial transactions;
  • safeguarding;
  • significant governance decisions;

should be retained according to the underlying record category.

68. Messaging Applications

Important charity decisions or evidence should not rely indefinitely on personal messaging history.

Where messages contain material records, relevant information should be transferred or preserved appropriately.

69. Social Media Direct Messages

Messages involving:

  • complaints;
  • safeguarding;
  • donations;
  • significant enquiries;
  • disputes;

should be transferred into appropriate charity records where necessary.

70. Website Enquiries

Routine enquiries should be retained only as long as necessary to respond and administer the matter.

Where an enquiry develops into another record category, such as:

  • complaint;
  • volunteer application;
  • safeguarding concern;
  • donation dispute;

the applicable retention period should then apply.

71. Newsletter Records

Marketing subscription records should be retained while necessary to administer the subscription.

Where someone unsubscribes, sufficient suppression information may need to be retained to ensure they are not inadvertently resubscribed without an appropriate basis.

72. Cookie and Analytics Records

Analytics data should be retained only for a reasonable period consistent with:

  • stated privacy information;
  • configuration;
  • legitimate analytical needs;
  • applicable consent requirements.

73. Audit Logs

System audit logs should be retained for a period proportionate to:

  • security risk;
  • investigation needs;
  • accountability;
  • storage.

Critical financial or administrative audit information may require longer retention than ordinary technical logs.

74. Security Logs

Security logs should normally be retained long enough to support investigation of incidents that may not be discovered immediately.

The exact period may vary according to:

  • system;
  • risk;
  • provider;
  • cost;
  • technical capability.

75. Backups

Backups are for recovery and must not be used as a means of deliberately retaining data indefinitely beyond its proper retention period.

Deletion from backups may occur through normal backup rotation where immediate selective deletion is technically impracticable, provided deleted data is not restored into active use improperly.

76. Paper Records

Paper records containing confidential information should be:

  • stored securely;
  • accessible only where appropriate;
  • protected from avoidable loss or damage.

77. Scanning

Paper records may be digitised where appropriate.

Before destroying an original after scanning, the charity should consider whether:

  • the original has legal significance;
  • signatures are important;
  • evidential value may be reduced;
  • another requirement mandates retention.

78. Duplicate Records

Unnecessary duplicates should not be retained indefinitely.

Where a reliable master record exists, redundant copies may be securely deleted.

79. Draft Documents

Routine drafts may normally be deleted once a final version is approved.

Drafts should be retained where they have material evidential, legal or governance significance.

80. Temporary Files

Temporary exports, downloads and working copies containing confidential information should be deleted when no longer required.

Particular care should be taken with:

  • CSV exports;
  • spreadsheets;
  • donor lists;
  • beneficiary lists;
  • database exports.

81. Personal Devices

Charity records stored on personal devices remain subject to this policy.

When the information is transferred to appropriate charity storage, unnecessary local copies should be deleted where reasonably practicable.

82. Former Trustees and Volunteers

When a person leaves Al-Waris Foundation, they should return or transfer charity records within their possession or control.

They should not retain confidential charity information without a legitimate reason and appropriate authority.

83. Cloud Services

Deletion from cloud systems should take account of:

  • provider retention;
  • recycle bins;
  • version history;
  • backups;
  • shared copies.

The charity should use available controls proportionately.

84. Secure Disposal

Records containing confidential or personal information must be disposed of securely.

Appropriate methods may include:

  • secure deletion;
  • shredding;
  • confidential waste disposal;
  • cryptographic erasure;
  • secure device wiping.

85. Ordinary Recycling

Confidential paper records must not be placed intact into ordinary recycling where unauthorised people could access them.

86. Device Disposal

Before selling, donating, recycling or disposing of devices used for charity records, information should be securely removed where reasonably practicable.

A normal file deletion may not be sufficient.

87. Storage Media

Storage devices containing highly sensitive charity information should be:

  • securely erased;
  • destroyed;
  • otherwise rendered inaccessible;

before disposal where appropriate.

88. Disposal Register

For routine records, individual deletion records are not always necessary.

For significant bulk or sensitive destruction, the charity may maintain a disposal record identifying:

  • record category;
  • date;
  • method;
  • authorising person.

89. Automatic Deletion

Systems may use automated retention and deletion where appropriate.

Automated rules should be:

  • understood;
  • documented where material;
  • reviewed;
  • capable of suspension where a legal hold applies.

90. Destruction Authorisation

Material governance, safeguarding, legal or financial records should not be destroyed casually.

Where there is uncertainty, an appropriately authorised person should review the proposed disposal.

91. Prohibition on Concealment

No record may be destroyed, altered or hidden for the purpose of:

  • concealing wrongdoing;
  • preventing trustee scrutiny;
  • obstructing an audit;
  • avoiding regulatory disclosure;
  • frustrating legal proceedings;
  • hiding a safeguarding concern.

92. Investigations

Records potentially relevant to an internal or external investigation should be preserved.

This may include investigations involving:

  • fraud;
  • safeguarding;
  • complaints;
  • whistleblowing;
  • data breaches;
  • financial misconduct.

93. Freedom of Information

Al-Waris Foundation is not automatically subject to the Freedom of Information Act merely because it is a registered charity.

However, other disclosure obligations may apply depending on circumstances.

Records should not be destroyed merely because a person has requested information.

94. Charity Commission Requests

Records reasonably required by the Charity Commission should be preserved and supplied where the charity is lawfully required to do so.

95. HMRC and Tax Records

Applicable HMRC retention requirements take precedence over shorter internal periods.

Current requirements should be checked where necessary.

96. Insurance Requirements

Where an insurer requires records to be retained for a particular period, relevant records should be preserved accordingly.

97. Historical Archive

Al-Waris Foundation may retain selected records permanently because of legitimate historical value.

Examples may include:

  • annual reports;
  • major project summaries;
  • significant photographs;
  • founding records;
  • major milestones.

Historical retention should still consider privacy and safeguarding.

98. Anonymisation

Where the informational value of a record can be preserved without identifying individuals, anonymisation may allow longer-term statistical or historical use.

Anonymisation should be sufficiently robust that individuals are no longer reasonably identifiable.

99. Pseudonymisation

Pseudonymisation may reduce risk but does not necessarily make information anonymous.

Pseudonymised personal data remains subject to data-protection requirements where re-identification remains reasonably possible.

100. Retention Reviews

The charity should periodically review significant record categories.

Reviews should identify:

  • records due for deletion;
  • records requiring continued retention;
  • unnecessary duplicates;
  • outdated personal information;
  • legal holds.

101. System Design

Where reasonably practicable, new digital systems should support appropriate:

  • retention;
  • deletion;
  • export;
  • audit history;
  • access control.

Records governance should be considered when systems are designed rather than only after data has accumulated.

102. Database Deletion

Deleting information from a user interface does not necessarily remove every database record.

Technical deletion procedures should reflect:

  • legal requirements;
  • financial-record preservation;
  • audit requirements;
  • data-subject rights.

103. Donor Account Deletion

Where a donor requests deletion of their account, the charity may still need to retain certain transaction records for:

  • accounting;
  • legal;
  • fraud-prevention;
  • regulatory purposes.

Unnecessary profile information should be deleted or anonymised where appropriate.

104. Financial Record Integrity

Records necessary to demonstrate genuine charitable transactions must not be deleted merely because an associated person requests account deletion.

The charity should instead minimise or separate personal information where possible while preserving required financial evidence.

105. Record Accuracy

Where records must be retained, reasonable steps should be taken to correct materially inaccurate personal information where required.

Historical records may sometimes preserve the original entry together with a correction rather than silently rewriting the historical record.

106. Access to Records

Access should be based on legitimate need.

Examples include:

  • financial records for authorised finance personnel;
  • safeguarding records for appropriate safeguarding personnel;
  • governance records for trustees;
  • project records for authorised operational personnel.

107. Trustee Access

Trustees should be provided with information reasonably necessary to discharge their governance duties.

This does not require unrestricted technical or operational access to every underlying system.

108. Confidentiality

Retention does not mean unrestricted availability.

Sensitive retained records should continue to receive appropriate confidentiality protection for their entire retention period.

109. Security

Digital and physical records should be protected according to the Information Security and Cybersecurity Policy.

Long-term archives should not become forgotten unsecured repositories.

110. Data Breaches

Improper disposal may constitute a personal-data breach.

Examples include:

  • confidential records placed in public waste;
  • devices sold without secure wiping;
  • public links left active;
  • beneficiary records discarded insecurely.

Such incidents should be assessed under the Data Protection and UK GDPR Policy.

111. Contractors

Where a contractor stores charity records, contractual arrangements should address appropriate:

  • confidentiality;
  • security;
  • retention;
  • return;
  • deletion.

The charity should not assume a contractor automatically deletes information when the relationship ends.

112. Overseas Records

Records created during overseas operations remain subject to appropriate Al-Waris Foundation governance.

Practical local constraints may affect how evidence is initially collected, but material records should be transferred into suitable charity systems where reasonably practicable.

113. Cross-Border Storage

Where personal data is stored or accessed internationally, applicable data-protection requirements concerning international transfers should be considered.

114. Training and Awareness

People handling significant charity records should understand:

  • what should be retained;
  • where records should be stored;
  • what should not be deleted;
  • how to dispose of records securely;
  • when to escalate uncertainty.

115. Policy Breaches

Breaches may include:

  • premature destruction;
  • unauthorised disclosure;
  • deliberate concealment;
  • insecure disposal;
  • excessive unnecessary retention;
  • failure to preserve evidence.

Appropriate action may include:

  • access restriction;
  • corrective action;
  • volunteer management action;
  • governance action;
  • investigation;
  • regulatory reporting.

116. Related Al-Waris Foundation Policies

This policy should be read alongside:

  • Constitution;
  • Data Protection and UK GDPR Policy;
  • Confidentiality Policy;
  • Information Security and Cybersecurity Policy;
  • Financial Controls and Reserves Policy;
  • Fundraising Policy;
  • Procurement and Purchasing Policy;
  • Expenses Policy;
  • Safeguarding Children Policy;
  • Safeguarding Adults at Risk Policy;
  • Photography, Video and Beneficiary Consent Policy;
  • Volunteer Policy;
  • Complaints Policy;
  • Whistleblowing Policy;
  • Anti-Fraud, Bribery and Corruption Policy;
  • Serious Incident Reporting Policy;
  • Overseas Operations and Partner Due Diligence Policy.

117. Review

This policy will be reviewed:

  • at least annually;
  • following significant changes in applicable record-keeping requirements;
  • following a significant data-protection incident;
  • following material changes to the charity's digital systems;
  • where retention controls are found to be inadequate;
  • following significant operational expansion.

118. Approval

Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027

Essential cookies keep secure account and donation features working. With your permission, Google Analytics helps us understand how public pages are used. It is not loaded unless you accept.

Read our cookie information