CharityControl.org

Policy templates / Document Retention & Disposal Policy

Charity Document Retention & Disposal Policy Template (Free, UK)

free template · For Trustees, treasurer, charity administrator or data protection lead · England & Wales · Sources checked 2026-08-01

Not sure which size? Size it by your charity number

Highlighted parts are yours to complete. A starting point to adapt, not legal advice.

Small charity
Use in CharityControl

1. Purpose and scope

This policy sets out how long [your charity] keeps its records and how we destroy them safely when we no longer need them. It applies to every record we hold, on paper or electronically, including emails, whether it is kept in our office, on a laptop, or in a cloud service.

Keeping records for the right length of time helps us meet our legal duties, answer questions from funders and regulators, and protect the people we work with. Keeping records for too long, especially personal information, creates risk and can breach data protection law.

This is a starting point, not legal advice. Check your own funders, insurers and, if in doubt, take advice.

2. Who is responsible

The trustees own this policy and are responsible for making sure [your charity] follows it. Day to day, [role, for example the charity administrator or treasurer] keeps the retention schedule up to date, arranges secure destruction, and answers questions about it.

Everyone who handles our records, including trustees, staff and volunteers, must follow this policy. They must not keep records we no longer need, or destroy records they should be keeping, outside this policy.

3. How long we keep records

We keep each type of record for the period shown below, then destroy it securely. Where the law sets a minimum, we keep the record for at least that long. Where no legal period applies, we keep it only for as long as we have a clear reason to. This schedule is the master record of our retention periods, including for personal data, so we set each period in one place and do not let different policies drift apart.

Record typeHow long we keep itWhy
Governing document and any amendmentsPermanentlyOur core constitutional record
Trustee and members' meeting minutes, including the AGMPermanentlyEvidence of decisions; good practice
Statutory registers (members, trustees or directors, charges)For the life of the charityCompany law and good governance
Annual accounts and Trustees' Annual ReportsPermanentlyPublic accountability
Accounting records (invoices, receipts, bank statements)At least 6 years from the end of the financial year1Charities Act 2011 s.131 for non-company charities; for charitable companies, HMRC tax rules and Commission guidance point to 6 years even though company law alone sets 32
Gift Aid declarations and claim recordsAt least 6 years after the end of the accounting period the claim relates to; keep enduring declarations while you still rely on them4HMRC requirement
Contracts, leases and funding agreements6 years after the agreement ends, or 12 years if it was signed as a deed, or the funder's stated period if that is longer7Limitation Act 1980; funder terms
Payroll and PAYE recordsAt least 3 years after the end of the tax year5HMRC requirement
Pension auto-enrolment records6 years6Pensions law
Personnel files6 years after employment endsLegal claim limits; good practice
Recruitment records for unsuccessful candidates12 months after the decision, then deleteDiscrimination claim limits; good practice
Supporter and donor recordsAt least 6 years after the end of the accounting period the last donation relates to, so Gift Aid claims are covered, then delete or anonymise4UK GDPR storage limitation; Gift Aid
Volunteer records3 years after they stop volunteering, unless a safeguarding matter means we keep it longerStorage limitation; good practice
Beneficiary recordsFor as long as we work with the person and then a defined period afterwards (as a starting point, 3 years; adjust to your service), unless safeguarding means we keep it longerUK GDPR storage limitation
Other personal data (members, enquiries, mailing lists)Only for as long as we have a current reason to hold it, then we delete or anonymise it3UK GDPR storage limitation (ICO)
Safeguarding and DBS recordsKept far longer than other records, often for decades, and never destroyed in an ordinary clear-out8. We set the exact periods in our safeguarding policy and follow those.Safeguarding evidence may be needed many years later
Insurance policiesWhile a claim could still be made against the policyProtects us against later claims
Property title deeds and leasesPermanently, or for the life of the interestProof of ownership

These periods are a starting point. Check any specific requirements in your funding agreements, insurance policies and contracts, and adjust the schedule to match. In this policy, a financial year runs to [your charity's financial year end date].

4. Personal data: keep only as long as we need it

Data protection law says we must not keep personal information for longer than we need it3. This applies to information about supporters, donors, beneficiaries, members, staff and volunteers. The set periods for each type sit in the schedule at clause 3, which is our single master list.

  • We only keep personal data while we have a genuine, current reason to, for example an active membership, a Gift Aid declaration we still rely on, or a legal duty to keep the record.
  • When that reason ends, we delete or anonymise the information at the next review, unless a period in the schedule requires us to keep it.
  • We review the personal data we hold at least once a year and remove what we no longer need.

If someone asks us to delete their personal data, we handle the request under our data protection policy.

5. Where we keep records and what happens when people leave

We keep each record in one agreed official place, for example [named shared drive or system], so we know where it lives and can apply this policy to it. Everyone keeps their working copies to a minimum and deletes them once the work is finished.

This matters because deleting the official copy achieves nothing if duplicates survive elsewhere. A record we think we have destroyed can live on in a downloaded spreadsheet, a local folder on someone's laptop, or an old backup drive in a drawer. So we avoid scattering copies in the first place, and when we destroy a record, or tell someone their information has been erased, we include those copies too.

When a trustee, staff member or volunteer leaves, [role, or the trustees] makes sure any charity records they hold are handed back or deleted, so nothing we should keep goes missing and no copy is left behind.

6. Destroying records securely

When a record reaches the end of its retention period, we destroy it so the information cannot be recovered or seen by anyone who should not see it.

  • Paper records containing personal or confidential information are shredded, or destroyed by a confidential waste service, not put in ordinary recycling.
  • Electronic records are deleted permanently, including from email, shared drives, backups and any cloud service, so far as we reasonably can.
  • If we ask an outside company to destroy records for us, we make sure they do it securely and, for personal data, under a written agreement.

We pause any destruction, even if the retention period has passed, if the record could be relevant to a live or reasonably expected legal claim, complaint, insurance claim, audit or investigation. We only go ahead once [role, or the trustees] confirms the record is no longer needed.

7. Reviewing this policy

The trustees review this policy and the retention schedule at least every two years, and sooner if the law changes or [your charity] takes on a new activity, funder or system. We record the date of each review and any changes we make.

What you'll fill in (5)

Replace or confirm each highlighted part before your board adopts it:

  • your charity
  • role, for example the charity administrator or treasurer
  • your charity's financial year end date
  • named shared drive or system
  • role, or the trustees

See how CharityControl fills these →

Use in CharityControl

More about this policy

When you need it

Some of what this policy covers is a legal duty, not a matter of choice:

  • Charities must keep their accounting records for at least six years[1] (Charities Act 2011, section 131; for charitable companies, HMRC tax rules and Charity Commission guidance point to the same six-year minimum).
  • Charities claiming Gift Aid must keep the records that support each claim[4] (HMRC).
  • Any charity that holds personal data must not keep it for longer than it is needed and must dispose of it securely[3] (the UK GDPR storage limitation principle, enforced by the ICO).

Writing these rules down in a retention policy is good practice rather than a legal requirement in its own right. But because the underlying record-keeping and data protection duties are mandatory, in practice every charity that holds money or personal information needs one. The Charity Governance Code expects boards to look after their information and records properly. A small charity can meet the duty with a short policy and a simple schedule; it does not need a large charity's records-management framework. This template is a starting point, not legal advice. Check your own funders, insurers and, if in doubt, take advice.

What it protects against5 examples

Supporter, volunteer and beneficiary records pile up in the shared drive and old inboxes and never get deleted. Years of personal data no one uses is still sitting there when a subject access request or a data breach happens.

The policy sets a clear 'keep until' date for each type of personal record and makes deleting old data a routine job, so the charity only holds what it still has a reason to hold.

Someone doing a tidy-up deletes records the charity is legally required to keep: accounts and receipts (6 years plus the current year), Gift Aid declarations, payroll and pension records, or trustee minutes.

The schedule lists the legal minimum for each of these and marks them 'do not delete early', so a keen clear-out cannot destroy records HMRC, the auditor or the Commission may ask for.

A complaint, safeguarding allegation, insurance claim, HMRC check or Charity Commission enquiry is live, and the normal delete-after-X-years rule quietly destroys records that matter to it.

The policy has a legal hold step. Once a dispute or investigation is known, routine deletion stops for anything connected to it until the matter is closed.

Safeguarding records get deleted or heavily cut down after a few years because they were treated like any other file.

Safeguarding records are marked as a special case with a very long retention, in line with IICSA guidance, and are never caught by the ordinary clear-out.

The same records exist in several places: the shared drive, a trustee's personal Gmail, a coordinator's phone, an old USB stick. Deleting the official copy changes nothing, and data walks out when a trustee or volunteer leaves.

The policy says where each record officially lives, keeps personal copies to a minimum, and includes a leaver step to recover or delete copies held on personal accounts and devices.

Swipe or scroll for more

How to enforce it

Practical steps to make it live, not just filed:

  • Write one retention schedule as a single table (record type, how long to keep it, where it lives, who deletes it) and name one person who owns it, for example the office manager or a named trustee.
  • Put an annual clean-up on the compliance calendar. One person spends an afternoon going through the shared drive and folders, deletes what is past its date, and writes a short note of what was cleared.
  • Keep records in known places, the shared drive or the charity's systems, not personal inboxes or devices, and use a leaver checklist so files are recovered, access removed and local copies deleted when someone moves on.
  • If a complaint, claim or enquiry comes in, the policy owner sends a short 'do not delete anything about X' note, and the annual clean-up skips those records until the matter is closed.
  • Log deletions by category, not file by file: a one-line record such as 'cleared 2019 supporter data on this date', so you can show the ICO or the Commission the policy is actually run.
What larger charities add5

Pull one in only when it matches something you actually do:

  • Legal holds: suspending disposal Mid-size (£1m to £10m)+
  • Managing electronic records, email and backups Mid-size (£1m to £10m)+
  • Records inventory Mid-size (£1m to £10m)+
  • Records management framework and information asset owners Large (£10m+)+
  • Archiving, authorised disposal and audit Large (£10m+)+
What people get wrong
  • Copying a large charity's full records-management framework, with information asset owners, disposal logs and annual audits, into a small charity that cannot run it.. Use only the small-band clauses: a short policy, the starter retention schedule, secure disposal, and a review date. Add the framework clauses (11 and 12) only when you have the staff to operate them.
  • Keeping the accounting rule but setting no rule for personal data, so supporter, volunteer, beneficiary and old applicant records pile up, are never deleted, and are still sitting there when a subject access request or a data breach happens.. Set a period for every kind of personal data in the schedule at clause 3, then follow clause 4 (delete personal data you no longer need) and clause 6 (secure disposal). Both are legal duties for any charity holding personal information, not optional extras for larger charities.
  • Assuming the 3-year company-law period covers your accounting records because you are a charitable company.. Company law alone sets 3 years, but HMRC's tax record rules and Charity Commission guidance make 6 years the safe minimum for charities. Keep accounting records for at least 6 years.
  • Destroying records on schedule while a complaint, claim or investigation is live or likely.. Pause disposal whenever a record could be relevant to a dispute, insurance claim, audit or investigation, and only resume once someone with authority confirms it is safe to.
  • Adopting the schedule once and never revisiting it, or leaving no one in charge of it.. Name an owner (clause 2) and set a review date (clause 7) so the schedule keeps pace with new funders, systems and legal changes.
Terms used here4
storage limitation
The data-protection rule that you must not keep personal data for longer than you actually need it.
ICO
The Information Commissioner's Office, the UK regulator for data protection. Serious data breaches are reported to it within 72 hours.
DBS
Disclosure and Barring Service, the UK criminal-record check for people working with children or adults at risk.
IICSA
The Independent Inquiry into Child Sexual Abuse, whose recommendations set long retention periods for safeguarding records.
Sources10
Suggest a change to this template

Spotted something missing, out of date, or wrong for a charity of a given size? Tell us. We read every suggestion and keep these current.

Free to use and adapt for your charity. Not legal advice; check the cited sources for the current rules.