Policy templates / Document Retention & Disposal Policy
Charity Document Retention & Disposal Policy Template (Free, UK)
Highlighted parts are yours to complete. A starting point to adapt, not legal advice.
1. Purpose and scope
This policy sets out how long [your charity] keeps its records and how we destroy them safely when we no longer need them. It applies to every record we hold, on paper or electronically, including emails, whether it is kept in our office, on a laptop, or in a cloud service.
Keeping records for the right length of time helps us meet our legal duties, answer questions from funders and regulators, and protect the people we work with. Keeping records for too long, especially personal information, creates risk and can breach data protection law.
This is a starting point, not legal advice. Check your own funders, insurers and, if in doubt, take advice.
2. Who is responsible
The trustees own this policy and are responsible for making sure [your charity] follows it. Day to day, [role, for example the charity administrator or treasurer] keeps the retention schedule up to date, arranges secure destruction, and answers questions about it.
Everyone who handles our records, including trustees, staff and volunteers, must follow this policy. They must not keep records we no longer need, or destroy records they should be keeping, outside this policy.
3. How long we keep records
We keep each type of record for the period shown below, then destroy it securely. Where the law sets a minimum, we keep the record for at least that long. Where no legal period applies, we keep it only for as long as we have a clear reason to. This schedule is the master record of our retention periods, including for personal data, so we set each period in one place and do not let different policies drift apart.
| Record type | How long we keep it | Why |
|---|---|---|
| Governing document and any amendments | Permanently | Our core constitutional record |
| Trustee and members' meeting minutes, including the AGM | Permanently | Evidence of decisions; good practice |
| Statutory registers (members, trustees or directors, charges) | For the life of the charity | Company law and good governance |
| Annual accounts and Trustees' Annual Reports | Permanently | Public accountability |
| Accounting records (invoices, receipts, bank statements) | At least 6 years from the end of the financial year1 | Charities Act 2011 s.131 for non-company charities; for charitable companies, HMRC tax rules and Commission guidance point to 6 years even though company law alone sets 32 |
| Gift Aid declarations and claim records | At least 6 years after the end of the accounting period the claim relates to; keep enduring declarations while you still rely on them4 | HMRC requirement |
| Contracts, leases and funding agreements | 6 years after the agreement ends, or 12 years if it was signed as a deed, or the funder's stated period if that is longer7 | Limitation Act 1980; funder terms |
| Payroll and PAYE records | At least 3 years after the end of the tax year5 | HMRC requirement |
| Pension auto-enrolment records | 6 years6 | Pensions law |
| Personnel files | 6 years after employment ends | Legal claim limits; good practice |
| Recruitment records for unsuccessful candidates | 12 months after the decision, then delete | Discrimination claim limits; good practice |
| Supporter and donor records | At least 6 years after the end of the accounting period the last donation relates to, so Gift Aid claims are covered, then delete or anonymise4 | UK GDPR storage limitation; Gift Aid |
| Volunteer records | 3 years after they stop volunteering, unless a safeguarding matter means we keep it longer | Storage limitation; good practice |
| Beneficiary records | For as long as we work with the person and then a defined period afterwards (as a starting point, 3 years; adjust to your service), unless safeguarding means we keep it longer | UK GDPR storage limitation |
| Other personal data (members, enquiries, mailing lists) | Only for as long as we have a current reason to hold it, then we delete or anonymise it3 | UK GDPR storage limitation (ICO) |
| Safeguarding and DBS records | Kept far longer than other records, often for decades, and never destroyed in an ordinary clear-out8. We set the exact periods in our safeguarding policy and follow those. | Safeguarding evidence may be needed many years later |
| Insurance policies | While a claim could still be made against the policy | Protects us against later claims |
| Property title deeds and leases | Permanently, or for the life of the interest | Proof of ownership |
These periods are a starting point. Check any specific requirements in your funding agreements, insurance policies and contracts, and adjust the schedule to match. In this policy, a financial year runs to [your charity's financial year end date].
4. Personal data: keep only as long as we need it
Data protection law says we must not keep personal information for longer than we need it3. This applies to information about supporters, donors, beneficiaries, members, staff and volunteers. The set periods for each type sit in the schedule at clause 3, which is our single master list.
- We only keep personal data while we have a genuine, current reason to, for example an active membership, a Gift Aid declaration we still rely on, or a legal duty to keep the record.
- When that reason ends, we delete or anonymise the information at the next review, unless a period in the schedule requires us to keep it.
- We review the personal data we hold at least once a year and remove what we no longer need.
If someone asks us to delete their personal data, we handle the request under our data protection policy.
5. Where we keep records and what happens when people leave
We keep each record in one agreed official place, for example [named shared drive or system], so we know where it lives and can apply this policy to it. Everyone keeps their working copies to a minimum and deletes them once the work is finished.
This matters because deleting the official copy achieves nothing if duplicates survive elsewhere. A record we think we have destroyed can live on in a downloaded spreadsheet, a local folder on someone's laptop, or an old backup drive in a drawer. So we avoid scattering copies in the first place, and when we destroy a record, or tell someone their information has been erased, we include those copies too.
When a trustee, staff member or volunteer leaves, [role, or the trustees] makes sure any charity records they hold are handed back or deleted, so nothing we should keep goes missing and no copy is left behind.
6. Destroying records securely
When a record reaches the end of its retention period, we destroy it so the information cannot be recovered or seen by anyone who should not see it.
- Paper records containing personal or confidential information are shredded, or destroyed by a confidential waste service, not put in ordinary recycling.
- Electronic records are deleted permanently, including from email, shared drives, backups and any cloud service, so far as we reasonably can.
- If we ask an outside company to destroy records for us, we make sure they do it securely and, for personal data, under a written agreement.
We pause any destruction, even if the retention period has passed, if the record could be relevant to a live or reasonably expected legal claim, complaint, insurance claim, audit or investigation. We only go ahead once [role, or the trustees] confirms the record is no longer needed.
7. Reviewing this policy
The trustees review this policy and the retention schedule at least every two years, and sooner if the law changes or [your charity] takes on a new activity, funder or system. We record the date of each review and any changes we make.
More about this policy
When you need it
Some of what this policy covers is a legal duty, not a matter of choice:
- Charities must keep their accounting records for at least six years[1] (Charities Act 2011, section 131; for charitable companies, HMRC tax rules and Charity Commission guidance point to the same six-year minimum).
- Charities claiming Gift Aid must keep the records that support each claim[4] (HMRC).
- Any charity that holds personal data must not keep it for longer than it is needed and must dispose of it securely[3] (the UK GDPR storage limitation principle, enforced by the ICO).
Writing these rules down in a retention policy is good practice rather than a legal requirement in its own right. But because the underlying record-keeping and data protection duties are mandatory, in practice every charity that holds money or personal information needs one. The Charity Governance Code expects boards to look after their information and records properly. A small charity can meet the duty with a short policy and a simple schedule; it does not need a large charity's records-management framework. This template is a starting point, not legal advice. Check your own funders, insurers and, if in doubt, take advice.
What it protects against5 examples
Supporter, volunteer and beneficiary records pile up in the shared drive and old inboxes and never get deleted. Years of personal data no one uses is still sitting there when a subject access request or a data breach happens.
The policy sets a clear 'keep until' date for each type of personal record and makes deleting old data a routine job, so the charity only holds what it still has a reason to hold.
Someone doing a tidy-up deletes records the charity is legally required to keep: accounts and receipts (6 years plus the current year), Gift Aid declarations, payroll and pension records, or trustee minutes.
The schedule lists the legal minimum for each of these and marks them 'do not delete early', so a keen clear-out cannot destroy records HMRC, the auditor or the Commission may ask for.
A complaint, safeguarding allegation, insurance claim, HMRC check or Charity Commission enquiry is live, and the normal delete-after-X-years rule quietly destroys records that matter to it.
The policy has a legal hold step. Once a dispute or investigation is known, routine deletion stops for anything connected to it until the matter is closed.
Safeguarding records get deleted or heavily cut down after a few years because they were treated like any other file.
Safeguarding records are marked as a special case with a very long retention, in line with IICSA guidance, and are never caught by the ordinary clear-out.
The same records exist in several places: the shared drive, a trustee's personal Gmail, a coordinator's phone, an old USB stick. Deleting the official copy changes nothing, and data walks out when a trustee or volunteer leaves.
The policy says where each record officially lives, keeps personal copies to a minimum, and includes a leaver step to recover or delete copies held on personal accounts and devices.
Swipe or scroll for more
How to enforce it
Practical steps to make it live, not just filed:
- Write one retention schedule as a single table (record type, how long to keep it, where it lives, who deletes it) and name one person who owns it, for example the office manager or a named trustee.
- Put an annual clean-up on the compliance calendar. One person spends an afternoon going through the shared drive and folders, deletes what is past its date, and writes a short note of what was cleared.
- Keep records in known places, the shared drive or the charity's systems, not personal inboxes or devices, and use a leaver checklist so files are recovered, access removed and local copies deleted when someone moves on.
- If a complaint, claim or enquiry comes in, the policy owner sends a short 'do not delete anything about X' note, and the annual clean-up skips those records until the matter is closed.
- Log deletions by category, not file by file: a one-line record such as 'cleared 2019 supporter data on this date', so you can show the ICO or the Commission the policy is actually run.
What larger charities add5
Pull one in only when it matches something you actually do:
- Legal holds: suspending disposal Mid-size (£1m to £10m)+
- Managing electronic records, email and backups Mid-size (£1m to £10m)+
- Records inventory Mid-size (£1m to £10m)+
- Records management framework and information asset owners Large (£10m+)+
- Archiving, authorised disposal and audit Large (£10m+)+
What people get wrong
- Copying a large charity's full records-management framework, with information asset owners, disposal logs and annual audits, into a small charity that cannot run it.. Use only the small-band clauses: a short policy, the starter retention schedule, secure disposal, and a review date. Add the framework clauses (11 and 12) only when you have the staff to operate them.
- Keeping the accounting rule but setting no rule for personal data, so supporter, volunteer, beneficiary and old applicant records pile up, are never deleted, and are still sitting there when a subject access request or a data breach happens.. Set a period for every kind of personal data in the schedule at clause 3, then follow clause 4 (delete personal data you no longer need) and clause 6 (secure disposal). Both are legal duties for any charity holding personal information, not optional extras for larger charities.
- Assuming the 3-year company-law period covers your accounting records because you are a charitable company.. Company law alone sets 3 years, but HMRC's tax record rules and Charity Commission guidance make 6 years the safe minimum for charities. Keep accounting records for at least 6 years.
- Destroying records on schedule while a complaint, claim or investigation is live or likely.. Pause disposal whenever a record could be relevant to a dispute, insurance claim, audit or investigation, and only resume once someone with authority confirms it is safe to.
- Adopting the schedule once and never revisiting it, or leaving no one in charge of it.. Name an owner (clause 2) and set a review date (clause 7) so the schedule keeps pace with new funders, systems and legal changes.
Terms used here4
- storage limitation
- The data-protection rule that you must not keep personal data for longer than you actually need it.
- ICO
- The Information Commissioner's Office, the UK regulator for data protection. Serious data breaches are reported to it within 72 hours.
- DBS
- Disclosure and Barring Service, the UK criminal-record check for people working with children or adults at risk.
- IICSA
- The Independent Inquiry into Child Sexual Abuse, whose recommendations set long retention periods for safeguarding records.
Sources10
Numbered to match the [n] citations in the template.
- Charities Act 2011, section 131: preservation of accounting records (at least 6 years) legal duty
- Companies Act 2006, section 388: where and for how long records must be kept (charitable companies) legal duty
- ICO: storage limitation (how long you can keep personal data) legal duty
- HMRC: claiming Gift Aid as a charity or CASC (records you must keep) legal duty
- HMRC: running payroll, keeping records (at least 3 years) legal duty
- The Pensions Regulator: automatic enrolment record-keeping (6 years) legal duty
- Limitation Act 1980: time limits for legal claims (basis for contract retention periods) good practice
- Independent Inquiry into Child Sexual Abuse (IICSA): reports and recommendations on retaining safeguarding records Commission guidance
- Charity Commission: charity reporting and accounting, the essentials (CC15d) Commission guidance
- Charity Governance Code: managing information and records well good practice