Skip to main content

Information and communications

Social Media and Digital Communications Policy

Al-Waris Foundation uses social media and digital communications to:

Current version 2.0

1. Policy Statement

Al-Waris Foundation uses social media and digital communications to:

  • communicate with supporters;
  • promote charitable work;
  • share project updates;
  • support fundraising;
  • recruit volunteers;
  • provide public information;
  • respond to enquiries;
  • demonstrate transparency;
  • build awareness of the charity's purposes.

The charity is committed to communicating online in a way that is:

  • accurate;
  • respectful;
  • lawful;
  • secure;
  • transparent;
  • safeguarding-conscious;
  • consistent with the charity's values and charitable purposes.

Digital communications must not knowingly mislead donors, beneficiaries, regulators or the public.

2. Purpose

This policy establishes expectations for:

  • official social-media accounts;
  • website communications;
  • email communications;
  • messaging platforms;
  • digital fundraising;
  • content publication;
  • beneficiary content;
  • account security;
  • moderation;
  • personal use by representatives;
  • artificial intelligence;
  • digital incidents;
  • records and approvals.

3. Scope

This policy applies to:

  • trustees;
  • staff where applicable;
  • volunteers;
  • authorised social-media administrators;
  • content creators;
  • fundraisers;
  • contractors;
  • project representatives;
  • anyone communicating publicly on behalf of Al-Waris Foundation.

It applies to platforms including:

  • TikTok;
  • Instagram;
  • Facebook;
  • YouTube;
  • X or similar services;
  • LinkedIn;
  • messaging applications;
  • email;
  • charity websites;
  • future digital platforms.

4. Trustee Responsibility

The Board of Trustees retains overall responsibility for ensuring appropriate communication and reputational controls exist.

Operational communications may be delegated to:

  • the Chair;
  • authorised administrators;
  • volunteers;
  • content teams;
  • other appropriately appointed persons.

Trustees are not required to approve every routine post.

Significant or higher-risk communications should receive proportionate review.

5. Official Accounts

Official social-media accounts should be created and maintained for legitimate Al-Waris Foundation purposes.

Accounts should use consistent:

  • branding;
  • organisation name;
  • contact information;
  • website links;
  • descriptions.

Where verification is available and appropriate, the charity may seek account verification.

6. Ownership of Accounts

Official social-media accounts are assets of Al-Waris Foundation.

They do not belong personally to the individual who created or manages them.

The charity should retain appropriate access and recovery arrangements.

7. Account Access

Access should be limited to authorised persons.

The charity should maintain an appropriate record of:

  • account owners;
  • administrators;
  • recovery information;
  • relevant access permissions.

Access should be removed promptly when no longer required.

8. Multi-Factor Authentication

Multi-factor authentication should be enabled for official social-media and digital communications accounts where available.

Stronger authentication should be prioritised for accounts capable of:

  • publishing publicly;
  • accessing direct messages;
  • managing advertising;
  • changing security settings;
  • adding administrators.

9. Password Security

Official accounts should use:

  • strong passwords;
  • unique passwords;
  • appropriate password-management tools where practicable.

Passwords should not be shared unnecessarily.

See the Information Security and Cybersecurity Policy.

10. Recovery Arrangements

Critical accounts should not depend entirely on one person's personal:

  • phone number;
  • email;
  • device;

where reasonable alternatives exist.

Recovery information should remain current.

11. Official Email Addresses

Official Al-Waris Foundation email addresses should normally be used for charity communications where available.

Functional mailboxes may include:

  • general enquiries;
  • donations;
  • volunteering;
  • support;
  • administration;
  • other approved purposes.

Messages should be routed according to their subject and operational need.

12. Website as Authoritative Source

Where appropriate, the Al-Waris Foundation website should act as the authoritative source for:

  • official fundraising pages;
  • project information;
  • policies;
  • reports;
  • contact information;
  • donation links.

Social-media posts may direct users to the website for fuller information.

13. Accuracy

Public digital content must be materially accurate.

The charity must not knowingly publish false information concerning:

  • projects;
  • beneficiaries;
  • fundraising totals;
  • appeal status;
  • project completion;
  • expenditure;
  • impact;
  • partners;
  • regulatory status.

14. Verification of Claims

Material factual claims should be checked before publication where reasonably practicable.

This is particularly important for:

  • donation amounts;
  • beneficiary numbers;
  • emergency claims;
  • project completion;
  • financial figures;
  • water project specifications;
  • public statements involving another organisation.

15. Estimates

Where a figure is an estimate, target or projection, this should be clear from the context.

An estimate must not be presented as a verified fact merely because a more precise figure would appear more persuasive.

16. Project Status

Digital content should distinguish appropriately between projects that are:

  • planned;
  • fundraising;
  • funded;
  • in progress;
  • completed.

A planned project must not be presented as completed.

17. Appeals

Social-media content promoting an Appeal should link to or clearly identify the relevant official fundraising destination where practical.

Closed or fulfilled Appeals should not continue to be promoted as active without a legitimate reason.

18. Causes and Projects

Communications should preserve the distinction between:

  • permanent Causes;
  • temporary Appeals;
  • actual Projects.

This helps donors understand whether they are supporting:

  • a broad area of work;
  • a particular fundraising campaign;
  • specific implementation.

19. Fundraising Content

All digital fundraising must comply with the Fundraising Policy.

Posts should clearly avoid:

  • false urgency;
  • fabricated totals;
  • fabricated beneficiary stories;
  • misleading use of images;
  • pressure or intimidation.

20. Donation Links

Official posts should use approved donation links.

Administrators should verify important links before publication.

The charity should be alert to:

  • fake fundraising pages;
  • malicious redirects;
  • altered QR codes;
  • impersonation.

21. Payment Information

Social-media posts should not request donors to send money to an individual's personal account unless an exceptional arrangement has been properly authorised and clearly explained.

Approved charity payment channels should normally be used.

22. QR Codes

QR codes used in digital or printed fundraising should be checked to ensure they direct users to the intended official destination.

Outdated or incorrect QR codes should be withdrawn.

23. Operations Contributions

Where an optional operational contribution forms part of an online donation process, public communications should not misrepresent it as part of the donor's designated project amount where it is separately allocated.

24. Zakat and Religious Giving

Where digital communications refer to:

  • Zakat;
  • Sadaqah;
  • other religious donation classifications;

the charity should ensure its operational handling supports the claim being made.

Religious terminology must not be used merely as a marketing label where the charity cannot reasonably administer the donation accordingly.

25. Beneficiary Dignity

Digital communications must protect beneficiary dignity.

The charity should avoid:

  • humiliating captions;
  • demeaning language;
  • unnecessary exposure of hardship;
  • content designed primarily to shock;
  • language treating beneficiaries as inferior.

26. Beneficiary Consent

Identifiable beneficiary media must be handled under the Photography, Video and Beneficiary Consent Policy.

Receiving aid should not normally be made conditional on participation in social-media content.

27. Children

Content involving children requires enhanced safeguarding consideration.

The charity should avoid unnecessarily publishing combinations of:

  • full name;
  • exact location;
  • school;
  • home details;
  • sensitive personal circumstances;
  • identifiable images.

28. Adults at Risk

Posts involving adults who may be vulnerable should consider:

  • dignity;
  • informed participation;
  • privacy;
  • coercion;
  • possible consequences of publication.

29. Sensitive Personal Information

The charity must not casually publish:

  • health information;
  • safeguarding details;
  • financial hardship details;
  • identity documents;
  • addresses;
  • telephone numbers;
  • personal correspondence.

30. Photography and Video

Visual content should be checked before publication for:

  • consent;
  • accuracy;
  • project attribution;
  • safeguarding;
  • visible personal information;
  • location information;
  • dignity.

31. AI-Generated Content

Al-Waris Foundation may use AI-generated content for:

  • design;
  • illustrations;
  • concepts;
  • social-media graphics;
  • drafting;
  • planning.

AI-generated content must not be knowingly represented as genuine evidence of real charitable activity.

32. AI-Generated People

A fictional AI-generated person must not be described as an actual Al-Waris Foundation beneficiary.

Where realistic AI imagery could reasonably be mistaken for documentary photography, the context should make clear that it is illustrative.

33. AI Project Evidence

AI-generated content must never be used to fabricate:

  • project completion;
  • distributions;
  • water installations;
  • beneficiary testimonials;
  • photographs of actual work;
  • other documentary evidence.

34. AI-Generated Text

AI-generated text should be reviewed before publication.

It should not be assumed accurate merely because it is fluent or professionally written.

Particular attention should be given to:

  • legal claims;
  • statistics;
  • financial information;
  • religious claims;
  • emergency information;
  • medical or safety claims.

35. Content Approval

Routine low-risk content may be published by authorised communications personnel.

Higher-risk content may require additional review.

Examples include:

  • serious incidents;
  • safeguarding matters;
  • disputed projects;
  • significant financial statements;
  • legal disputes;
  • controversial matters;
  • emergency fundraising involving uncertain facts.

36. CMS Content

Where public website content is created through the charity's CMS, authorised users should use appropriate:

  • draft;
  • preview;
  • review;
  • publication;
  • scheduling;
  • archive;

workflows.

37. Scheduled Posts

Scheduled posts should be reviewed where circumstances materially change before publication.

An automated post should not remain live merely because it was scheduled earlier if its content has become inaccurate or inappropriate.

38. Corrections

Where the charity publishes a material factual error, it should correct it promptly and transparently where appropriate.

The form of correction should reflect:

  • seriousness;
  • audience;
  • reach;
  • potential harm.

39. Deleting Posts

A post may be removed where:

  • inaccurate;
  • outdated;
  • unsafe;
  • unlawful;
  • misleading;
  • inappropriate;
  • no longer required.

Where a significant post is removed because of a material error, the charity should consider whether a correction is also necessary.

40. Historical Content

Historical project posts may remain online where they accurately represent completed work.

Old posts should be reviewed where they contain:

  • obsolete donation links;
  • outdated calls to action;
  • sensitive beneficiary information;
  • inaccurate information.

41. Personal Accounts

Trustees and volunteers are generally free to use personal social-media accounts in their private capacity.

They should avoid creating a false impression that personal views are official Al-Waris Foundation statements.

42. Charity Association

People publicly identifying themselves as Al-Waris Foundation trustees, volunteers or representatives should recognise that serious online misconduct may affect the charity.

Private conduct should only become a charity governance matter where there is a genuine material connection to:

  • safeguarding;
  • discrimination;
  • confidentiality;
  • serious reputational risk;
  • legal duties;
  • trustee suitability.

43. Personal Opinions

A personal opinion should not be presented as an official charity position unless authorised.

Where necessary, wording such as "views are my own" may help distinguish personal communications, but it does not excuse disclosure of confidential information or serious misconduct.

44. Political Content

Al-Waris Foundation must remain independent of party politics.

Official charity accounts must not be used to:

  • endorse political parties;
  • endorse candidates;
  • make party-political donations;
  • campaign primarily for electoral purposes.

Legitimate charity campaigning must further the charity's purposes and comply with charity law.

45. Personal Political Activity

Trustees and volunteers may participate in politics privately, subject to applicable law.

They must not falsely imply that Al-Waris Foundation endorses their personal political activity.

46. Religious Communications

The charity may communicate appropriately regarding religious giving or values where this is consistent with its activities and purposes.

Communications should not:

  • misrepresent legal obligations;
  • unlawfully discriminate;
  • pressure beneficiaries into religious participation as a condition of ordinary aid.

47. Equality and Respect

Official digital communications should not contain unlawful discriminatory, harassing or abusive material.

The charity should communicate respectfully about:

  • beneficiaries;
  • donors;
  • communities;
  • other charities;
  • religious groups;
  • protected characteristics.

48. Harassment

Official accounts must not be used to:

  • harass;
  • threaten;
  • intimidate;
  • target individuals abusively;
  • encourage dogpiling or mob harassment.

49. Criticism

The charity may respond to criticism or misinformation where appropriate.

Responses should remain:

  • factual;
  • proportionate;
  • professional.

The charity should avoid escalating routine criticism into unnecessary public disputes.

50. Defamation

Users must not knowingly publish false statements that could seriously harm the reputation of another person or organisation.

Where a proposed statement creates significant legal risk, professional advice should be considered.

51. Copyright

Content published by Al-Waris Foundation must respect copyright.

Images, video, music, graphics and text should only be used where the charity has:

  • created them;
  • obtained permission;
  • obtained an appropriate licence;
  • another lawful basis.

Content being visible online does not mean it is free to reuse.

52. Music and Social Platforms

Where music is used in social-media content, the charity should use:

  • platform-authorised libraries;
  • appropriately licensed audio;
  • other lawful sources.

Commercial or charity-account restrictions may differ from personal-account permissions.

53. Trademarks and Branding

Al-Waris Foundation branding should be used consistently and appropriately.

Third-party logos should not be used in a way that falsely implies:

  • partnership;
  • endorsement;
  • sponsorship;
  • approval.

54. Charity Logo

Official Al-Waris Foundation logo files should be controlled through approved brand assets.

Administrators should avoid modifying the logo in ways that undermine:

  • legibility;
  • consistency;
  • professional presentation.

55. Impersonation

The charity should monitor material impersonation where reasonably practicable.

Potential impersonation may include:

  • fake charity accounts;
  • fake donation pages;
  • fake staff or volunteer profiles;
  • fraudulent emails.

Evidence should be preserved before reporting or requesting removal.

56. Verified Accounts

Where platform verification is available and proportionate, Al-Waris Foundation may seek verification to reduce impersonation risk and improve public confidence.

Verification does not replace other security measures.

57. Direct Messages

Direct messages may contain:

  • donation enquiries;
  • volunteer enquiries;
  • safeguarding disclosures;
  • beneficiary requests;
  • complaints.

Administrators should route significant matters into the appropriate charity process rather than managing complex cases entirely within social-media messages.

58. Safeguarding Disclosures

If a safeguarding concern is received through:

  • direct message;
  • comment;
  • email;
  • other digital channel;

it should be escalated under the relevant safeguarding policy.

The disclosure should not be publicly discussed in comment threads.

59. Complaints

Complaints received through social media should be:

  • acknowledged appropriately;
  • directed to the Complaints Policy where necessary;
  • removed from public discussion where sensitive personal information is involved.

60. Volunteer Enquiries

Volunteer enquiries received through digital channels should be directed to the appropriate volunteer process and official contact route.

Sensitive application information should not be collected publicly through comments.

61. Donation Enquiries

Donation-related support should be routed to the appropriate donations function.

Administrators should not request:

  • passwords;
  • full card details;
  • other unnecessary security credentials.

62. Account Support

Users with website-account or login problems should be directed to an appropriate support route.

Social-media administrators should not attempt to reset passwords manually by requesting confidential credentials.

63. Messaging Applications

Messaging applications may be used for legitimate operational communications.

Important decisions, safeguarding matters, complaints or project evidence should be transferred into appropriate charity records where necessary.

64. Disappearing Messages

Disappearing-message features should not be used where the charity has a legitimate requirement to retain the communication.

This is particularly relevant to:

  • safeguarding;
  • significant financial decisions;
  • complaints;
  • whistleblowing;
  • project approvals.

65. Group Chats

Official group chats should only include people who need access.

Participants should avoid sharing unnecessary:

  • beneficiary data;
  • donor information;
  • passwords;
  • sensitive financial information.

66. Email Communications

Official email communications should be:

  • professional;
  • accurate;
  • appropriately routed;
  • secure.

Sensitive email should follow the Confidentiality and Information Security policies.

67. Email Signatures

Official email signatures may include:

  • charity name;
  • charity number;
  • website;
  • role;
  • appropriate contact details.

Signatures should not falsely imply authority beyond the sender's role.

68. Bulk Email

Bulk communications should comply with applicable marketing and privacy requirements.

Recipients' email addresses should not be exposed unnecessarily.

69. Marketing Consent

A person's:

  • donation;
  • enquiry;
  • volunteer application;
  • account registration;

does not automatically authorise unrestricted marketing.

Applicable consent and lawful-basis requirements must be respected.

70. Newsletter

Newsletter subscriptions should be handled according to the Data Protection and UK GDPR Policy.

Unsubscribe requests should be honoured appropriately.

71. Analytics

Digital communications may use analytics to understand performance.

Analytics must comply with:

  • privacy;
  • cookie;
  • consent;
  • security;

requirements.

72. Engagement Metrics

Metrics such as:

  • likes;
  • views;
  • shares;
  • followers;
  • conversion;

may inform communications strategy.

They should not incentivise:

  • misleading claims;
  • exploitative imagery;
  • unsafe content;
  • sensationalism.

73. Paid Advertising

Where the charity uses paid advertising, campaigns should comply with the same standards as organic content.

Ads must not knowingly contain:

  • false claims;
  • fabricated impact;
  • misleading urgency.

74. Sponsored Content

Where influencers, creators or other third parties are paid or otherwise incentivised to promote Al-Waris Foundation, appropriate disclosure requirements should be followed.

The charity should provide accurate approved information.

75. Influencer Fundraising

Influencers fundraising for Al-Waris Foundation should use approved:

  • donation links;
  • charity information;
  • campaign claims;
  • branding.

Material relationships should be documented where appropriate.

76. TikTok and Short-Form Video

Short-form platforms may encourage simplified messaging.

Al-Waris Foundation should still maintain:

  • factual accuracy;
  • beneficiary dignity;
  • proper donation routing;
  • appropriate disclosures.

A short character limit does not justify materially misleading content.

77. Live Streaming

Live streaming should receive additional care because content may be published without prior review.

Live streams involving beneficiaries should consider:

  • consent;
  • privacy;
  • safeguarding;
  • accidental disclosure;
  • comments;
  • location.

78. Moderation

Al-Waris Foundation may moderate:

  • comments;
  • messages;
  • community spaces;

to maintain safe and constructive channels.

79. Content That May Be Removed

The charity may remove, hide or report content that includes:

  • threats;
  • abuse;
  • harassment;
  • unlawful discrimination;
  • spam;
  • scams;
  • personal information;
  • explicit material;
  • impersonation;
  • malicious links.

80. Criticism Must Not Be Removed Merely for Being Negative

Legitimate criticism should not automatically be deleted simply because it is unfavourable.

The charity should distinguish between:

  • criticism;
  • abuse;
  • misinformation;
  • threats;
  • spam.

81. Misinformation

Where significant misinformation about the charity is circulating, Al-Waris Foundation may respond with:

  • factual clarification;
  • evidence;
  • official links.

Responses should avoid unnecessarily amplifying trivial claims.

82. Comments About Beneficiaries

Comments exposing or attacking beneficiaries should be moderated where necessary to protect:

  • privacy;
  • dignity;
  • safeguarding.

83. Blocking Users

Users may be blocked where reasonably necessary because of:

  • repeated harassment;
  • threats;
  • spam;
  • fraud;
  • malicious impersonation.

Blocking should not be used merely to prevent legitimate scrutiny.

84. Security Incidents

Potential social-media security incidents include:

  • unauthorised posts;
  • account takeover;
  • changed recovery information;
  • malicious direct messages;
  • stolen credentials.

Such incidents should be handled under the Information Security and Cybersecurity Policy.

85. Compromised Account

If an official account is suspected to be compromised:

  1. secure or recover the account;
  2. revoke unauthorised sessions;
  3. change credentials;
  4. review administrators;
  5. review recent content;
  6. preserve evidence;
  7. assess any data exposure;
  8. communicate publicly if necessary.

86. Unauthorised Post

An unauthorised post should be:

  • removed or corrected where appropriate;
  • investigated;
  • documented if material.

The charity should determine whether credentials or permissions need to be changed.

87. Social Engineering

Administrators should be cautious of people impersonating:

  • platform support;
  • Meta;
  • TikTok;
  • donors;
  • contractors;
  • trustees.

Official support organisations should not normally require users to disclose passwords.

88. Third-Party Tools

Before linking an official social-media account to a third-party management or scheduling service, the charity should consider:

  • permissions requested;
  • security;
  • reputation;
  • data access;
  • continued need.

Unused integrations should be removed.

89. Automation

Automated posting tools may be used where appropriately configured.

Automation should not publish unchecked sensitive content or continue posting outdated emergency information.

90. Artificial Intelligence Automation

AI may assist with:

  • caption drafts;
  • scheduling;
  • content ideas;
  • translations;
  • image generation.

Human review should be used for material public content.

91. Translation

Translations should preserve the substance of the charity's communication.

Sensitive or important translations should receive additional review where practical.

92. Accessibility

Digital content should be made reasonably accessible where practicable.

Measures may include:

  • alternative text;
  • captions;
  • readable layouts;
  • sufficient contrast;
  • clear language.

93. Captions and Subtitles

Video content should use captions or subtitles where reasonably practicable, particularly where important information is communicated verbally.

94. Alternative Text

Meaningful images on the website should include appropriate alternative text where relevant.

Decorative images should not be given unnecessary repetitive descriptions.

95. Privacy

Digital content should comply with the Data Protection and UK GDPR Policy.

Personal information should not be published merely because it is useful for engagement.

96. Location Sharing

Real-time precise location information should be used cautiously where it could expose:

  • beneficiaries;
  • volunteers;
  • high-risk projects;
  • aid supplies.

97. Overseas Communications

Content concerning overseas work should avoid:

  • compromising beneficiary safety;
  • exposing sensitive routes or locations;
  • making claims unsupported by local evidence;
  • misrepresenting local circumstances.

98. Emergency Communications

During disasters or emergencies, facts may change quickly.

Posts should be updated or corrected where material circumstances change.

Unverified reports should not be presented as established facts.

99. Public Statements During Incidents

Significant incidents should normally have a coordinated communications approach.

Only authorised persons should make official statements concerning:

  • serious safeguarding incidents;
  • fraud investigations;
  • litigation;
  • serious cybersecurity incidents;
  • major regulatory matters.

100. Legal Advice

Where a proposed publication creates significant:

  • defamation;
  • privacy;
  • regulatory;
  • contractual;

risk, professional advice should be considered.

101. Record Keeping

Material digital communications should be retained where necessary for:

  • governance;
  • fundraising;
  • complaints;
  • legal matters;
  • project evidence;
  • serious incidents.

Not every routine social-media post requires permanent internal duplication.

102. Social-Media Archive

The charity may retain selected copies or records of important posts where useful for:

  • fundraising history;
  • project evidence;
  • significant announcements.

103. Deleted Content Records

Where a material post is removed because of:

  • error;
  • complaint;
  • incident;
  • legal concern;

the charity may retain an internal copy where there is a legitimate accountability reason.

104. Personal Data in Messages

Direct messages and email should not become long-term repositories of unnecessary personal information.

Important records should be transferred into the appropriate system and unnecessary copies deleted where appropriate.

105. Departing Administrators

When a person stops managing digital communications:

  • account permissions should be removed;
  • shared credentials should be changed where necessary;
  • charity files should be returned;
  • scheduled content should be reviewed.

106. Contractors

External social-media or communications contractors should receive:

  • appropriate access only;
  • brand guidance;
  • security requirements;
  • confidentiality requirements;
  • content restrictions.

107. Ownership of Content

Contracts should clarify ownership or permitted use of content produced for the charity where necessary.

108. Complaints and Corrections

Digital communications complaints should be handled under the Complaints Policy.

Content should be corrected or removed where the complaint identifies a genuine material issue.

109. Safeguarding

Digital communication must comply with:

  • Safeguarding Children Policy;
  • Safeguarding Adults at Risk Policy.

Online interaction can itself create safeguarding concerns and must be treated accordingly.

110. Whistleblowing

Official digital channels must not be used to retaliate against or publicly attack someone who raises a legitimate whistleblowing concern.

111. Serious Incidents

A significant digital communications failure may require consideration under the Serious Incident Reporting Policy.

Examples may include:

  • serious safeguarding disclosure;
  • major privacy breach;
  • widespread fraudulent fundraising;
  • material account compromise.

112. Policy Breaches

Breaches may result in:

  • content removal;
  • correction;
  • restricted account access;
  • removal of publishing permissions;
  • volunteer management action;
  • contractor action;
  • governance action;
  • investigation;
  • regulatory reporting where required.

113. Training

People managing official digital communications should receive proportionate guidance concerning:

  • brand standards;
  • safeguarding;
  • fundraising;
  • data protection;
  • cybersecurity;
  • content accuracy;
  • escalation.

114. Review of Access

Official account access should be reviewed periodically.

Inactive or unnecessary administrators should be removed.

115. Review of Published Content

The charity should periodically review important public digital information for:

  • accuracy;
  • outdated appeals;
  • old contact details;
  • broken links;
  • privacy issues;
  • inappropriate beneficiary content.

116. Related Al-Waris Foundation Policies

This policy should be read alongside:

  • Constitution;
  • Trustee Code of Conduct;
  • Fundraising Policy;
  • Photography, Video and Beneficiary Consent Policy;
  • Safeguarding Children Policy;
  • Safeguarding Adults at Risk Policy;
  • Data Protection and UK GDPR Policy;
  • Information Security and Cybersecurity Policy;
  • Confidentiality Policy;
  • Complaints Policy;
  • Whistleblowing Policy;
  • Serious Incident Reporting Policy;
  • Records Retention and Disposal Policy;
  • Volunteer Policy;
  • Equality, Diversity and Inclusion Policy.

117. Review

This policy will be reviewed:

  • at least annually;
  • following a significant digital communications incident;
  • following a social-media account compromise;
  • following a serious safeguarding concern arising online;
  • following material changes to the charity's digital communications strategy;
  • where controls are found to be inadequate;
  • following relevant legal, regulatory or platform changes.

118. Approval

Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027

Essential cookies keep secure account and donation features working. With your permission, Google Analytics helps us understand how public pages are used. It is not loaded unless you accept.

Read our cookie information