Charity Data Retention and Destruction: Free Policy Template

UK GDPR's storage limitation principle means charities must not keep personal data 'just in case'; every record type needs a justified retention period and deletion date. Gift Aid records must be kept for at least six years after the relevant accounting period, and accounting records for at least six years from the financial year end under the Charities Act 2011. Safeguarding records are the main exception: abuse-related allegations should be retained for up to 75 years rather than deleted on a standard schedule.

Why retention needs a schedule (UK GDPR storage limitation)

Trustees ask me this one a lot: how long do we actually have to keep it all — Gift Aid declarations, old accounts, HR files, safeguarding notes? Short answer: it depends on the record type, which is exactly why every charity needs a written data retention policy with a schedule behind it. UK GDPR’s storage limitation principle prohibits keeping personal data for longer than necessary, and “we might need it one day” is not a lawful justification. The longer answer decides how defensible you are when challenged: a schedule turns that vague obligation into fixed, defensible deletion dates for each record type, which protects the charity from both an ICO complaint and a Charity Commission governance finding.

The ICO’s guidance on principle (e), storage limitation, is explicit that UK GDPR sets no fixed time limits itself. It is up to each organisation to decide, and be able to justify, how long it keeps personal data for the purpose it was collected for. That means a charity holding old donor lists, historic volunteer applications or ex-employee files with no active purpose is exposed twice over: it is processing data unlawfully, and it is increasing the size and value of what a hacker could steal in a breach (our data breach playbook covers the first 72 hours, if that day ever comes).

A retention schedule does three jobs at once. First, it sets out how long you legally must keep each category of record (accounts, Gift Aid, HR, safeguarding). Second, it sets the point at which you should securely destroy records you no longer need. Third, it gives trustees and staff a single reference document so retention decisions are not made ad hoc by whoever happens to be tidying a filing cabinet. If your charity has not yet documented its wider approach to lawful processing, pair this schedule with a full data protection policy and work through our GDPR checklist for charities before you publish either document — both sit within the wider charity compliance handbook.

The retention schedule (big sourced table)

A charity data retention schedule lists every record type the organisation holds, the minimum period each must be kept, and the legal or regulatory basis for that period — so trustees can set defensible deletion dates instead of guessing. The schedule below covers the record types every UK charity holds, from Gift Aid declarations to safeguarding files. Where a period is set by statute or a regulator, we’ve cited the source; where it is a matter of professional judgement, we’ve flagged it as such.

Record type Minimum retention period Basis / source
Gift Aid declarations and claim records 6 years from the end of the accounting period they relate to (charitable companies); trusts should keep the later of 6 years from the relevant tax year or 12 months after the claim HMRC, Claim Gift Aid online guidance
GASDS (Gift Aid Small Donations Scheme) records 6 years, including collection totals, dates and paying-in dates HMRC Gift Aid and GASDS guidance
Statutory accounting records and annual accounts At least 6 years from the end of the financial year in which they were made Charities Act 2011, section 130
Gift Aid declarations still in active use (enduring/ongoing donors) Retained for the life of the declaration, then 6 years after it lapses or the donor stops giving HMRC Gift Aid guidance
HR files: general employment records Commonly 6 years after employment ends, reflecting the standard limitation period for contract claims Limitation Act 1980 (general limitation principle); sector HR guidance
Payroll and tax records At least 3 years from the end of the tax year they relate to HMRC PAYE record-keeping requirements
Disciplinary and grievance records Typically retained for a defined period after employment ends, commonly cited as up to 7 years Sector HR guidance; confirm against your own HR advisor’s current recommendation
Right to work checks 2 years after employment ends Home Office right-to-work guidance
Safeguarding records: allegations or concerns linked to abuse Up to 75 years, or permanently in some cases · do not apply a standard deletion schedule Independent Inquiry into Child Sexual Abuse (IICSA) recommendations; NSPCC Learning, child protection records retention guidance
Safeguarding: allegations against staff (substantiated or not) Until the person reaches normal pension age, or 10 years if longer NSPCC Learning child protection records retention guidance
Legacy and in-memoriam records (case files, correspondence, wills) Case-by-case, often 12 years to align with limitation periods for claims against an estate; retain executry correspondence longer where litigation risk exists Confirm the exact period with your charity’s legal advisor — limitation rules for probate claims vary by circumstance
Gift Aid audit trail from HMRC compliance checks 6 years minimum from the relevant accounting period, longer if a check is ongoing HMRC Gift Aid audit guidance
Trustee minutes and governance records Permanently, or at minimum for the life of the charity Charity Commission good governance guidance

Two things stand out. The default rhythm across financial and HR records is 6 years, which lines up neatly with both the Charities Act 2011 accounting requirement and HMRC’s Gift Aid rules, so most charities can standardise around that figure and only carve out exceptions — it’s what I’ve done with my own charity’s schedule. Safeguarding is the one category where “6 years” would be actively dangerous: destroying an abuse-related record early can remove evidence a survivor needs decades later, so those files sit outside the normal schedule entirely.

Secure destruction: paper and digital

Secure destruction means disposing of records so the personal data cannot be reconstructed or recovered, not simply deleting a file or putting paper in the recycling bin. For paper, that means cross-cut or micro-cut shredding (or a contracted confidential waste service with a certificate of destruction); for digital records, it means certified data wiping to a recognised standard, or physical destruction of the drive, not just moving a file to the recycling bin or reformatting a laptop before it’s sold on.

In practice, most charities need three destruction routes covered in policy:

  • Paper records: use a cross-cut shredder on-site for small volumes, or a contracted confidential waste provider for bulk destruction (old HR files, donor correspondence, physical Gift Aid forms). Insist on a certificate of destruction for anything containing special category data, such as safeguarding or health information.
  • Laptops, phones and removable media: before disposal or resale, use certified data-wiping software or, for end-of-life drives, physical destruction (degaussing or shredding) via a provider that gives you a destruction certificate. Simply factory-resetting a phone is not sufficient for special category data.
  • Cloud and SaaS data: deletion inside an application (a CRM, an email platform, a case management tool) does not always remove data from backups immediately. Check the supplier’s own retention and backup-purge cycle, and record it in your policy so you’re not claiming a deletion date you can’t actually evidence.

The cyber security pillar covers device disposal and access controls in more depth. If your charity uses volunteers to handle physical destruction, brief them specifically — it’s a step I’d never let slide. A well-meaning volunteer binning unshredded donor bank details is one of the most common small-charity data incidents reported to the ICO.

Special cases: safeguarding records, legacies

Safeguarding and legacy records are the two categories where a standard retention period is the wrong answer, because both can resurface as evidence years or decades after the events they describe, so charities need bespoke rules rather than the default 6-year cycle. Getting this wrong in either direction, keeping too little or destroying too early, is a recognised governance failure the Charity Commission has flagged in serious incident reports.

For safeguarding, current sector guidance — informed by the Independent Inquiry into Child Sexual Abuse — recommends that records relating to allegations or cases of child sexual abuse be retained for 75 years, reflecting how long it can take a survivor to come forward. Records of allegations against a member of staff, whether substantiated, unsubstantiated or unfounded, should generally be kept until that person reaches normal pension age or for 10 years, whichever is longer, per NSPCC Learning’s records retention and storage guidance. Genuinely unfounded allegations with no ongoing relevance should still be reviewed and can, in narrow circumstances, be removed from a person’s personnel file, but the underlying safeguarding case record is treated differently from an HR file and should not be deleted on the same schedule. As the person who manages the safeguarding policy at my own charity, this is the one area where I always take the cautious side of any retention question — and your safeguarding policy should cross-reference these retention rules so the two documents agree.

For legacies, retention needs to cover the possibility of a challenge to a will or a dispute with an estate’s executors, which can surface years after a gift is received. Many charities apply a longer period, commonly cited around 12 years, to align with limitation periods for claims connected to an estate, but the right figure depends on the specifics of each legacy and your charity’s legal advice. Treat the exact period as one to confirm with your charity’s legal advisor, because getting it wrong either destroys evidence you need to defend a claim, or keeps sensitive family and financial data for far longer than storage limitation allows.

Free policy template

Below is a full, ready-to-adapt data retention and destruction policy in plain text. I drafted it myself, and it follows the same shape as the retention paperwork I keep for my own charity — trimmed to what the ICO and Charity Commission actually expect a small organisation to be able to produce. Copy it into your own document, add your charity’s name and review date, and take it to trustees for sign-off. It mirrors the schedule above so you don’t need to maintain two separate documents.

Section Content to include
1. Purpose “This policy sets out how [Charity Name] decides how long to keep personal data and records, and how it destroys them securely once no longer needed, in line with UK GDPR’s storage limitation principle and the Charities Act 2011.”
2. Scope Applies to all records held in any format (paper, digital, cloud) relating to donors, beneficiaries, staff, volunteers, trustees and third parties.
3. Retention schedule Insert the table from this post, or your charity’s own version, listing each record type, retention period and source/basis.
4. Roles and responsibilities Name who owns this policy (typically the CEO or a designated Data Protection Lead), who actions destruction, and how trustees are assured it’s being followed (e.g. an annual report to the board).
5. Destruction methods State the approved method for each format: cross-cut shredding or certified confidential waste for paper; certified wiping or physical destruction for digital media and devices; documented deletion (including backups) for cloud/SaaS data.
6. Destruction logging Require a destruction log entry for every batch destroyed: date, record type/category, volume or description, method, and who authorised and who carried it out.
7. Exceptions List categories exempt from standard destruction dates: safeguarding records linked to allegations of abuse (retain per current sector guidance, currently up to 75 years); records subject to a live legal claim, FOI request, subject access request, or Charity Commission inquiry (retain until resolved).
8. Review State that the policy and schedule will be reviewed at least every two years, or sooner if legislation or regulator guidance changes.
9. Sign-off Date, approving trustee/board reference, and version number.

This is deliberately built as an on-page template so you can use it immediately, no email gate required, though if you’d like it as an editable document plus the wider compliance toolkit, that’s part of what’s on the CharityIQ compliance waitlist.

Proving it: destruction logs

A destruction log is a simple record of what personal data was destroyed, when, how and by whom, and it matters because a retention policy without evidence of it being followed is worth very little to an ICO investigator or a Charity Commission inquiry after an incident. Trustees are frequently asked to demonstrate compliance with the storage limitation principle, and a documented deletion trail is the clearest way to do that, per ICO guidance on storage limitation, which lists retention schedules and deletion logs among the evidence organisations should be able to produce.

At minimum, each destruction log entry should capture:

  • The date of destruction.
  • The category and rough volume of records destroyed (e.g. “127 paper Gift Aid declarations, 2018 accounting period”).
  • The destruction method used (shredding, confidential waste contractor, certified digital wipe).
  • Who authorised the destruction and who carried it out.
  • A reference to the retention schedule clause that justified the destruction date.

A one-line spreadsheet entry per batch is enough. What matters is that the log exists, is kept up to date, and can be produced quickly if a regulator or auditor asks “how do you know you’re not holding data past its retention date?”

Review the log at the same cadence as your retention schedule, at least annually — I pair the review with the annual return in the calendar so neither gets forgotten — and report a summary to trustees so oversight of data retention sits where governance responsibility actually lives, not solely with whoever manages the filing cabinet or shared drive.

From experience: A data retention policy only earns its keep if someone actually follows it. Managing the data protection paperwork at my own charity, what works is a short schedule — one page, only the record types we genuinely hold — plus a spreadsheet destruction log reviewed once a year. Trustees tend to over-worry about choosing the perfect retention period and under-worry about whether deletion ever actually happens; a defensible period applied consistently beats a perfect period nobody actions.

What to do next

Turning this into a working policy takes four concrete steps, most of which can be done from your desk this week without external advice for the majority of record types.

  1. Copy the template above into your own document, insert your charity’s name, and adapt the retention schedule for any record types specific to your work (e.g. clinical notes, research data, membership records).
  2. Audit what you currently hold against the schedule, flagging anything already past its retention date for secure destruction, and anything safeguarding-related for permanent retention rather than routine deletion — our data protection self-check checklist gives you the starting list.
  3. Set up a destruction log, even a simple spreadsheet, and assign someone to update it every time records are destroyed.
  4. Take the policy to trustees for formal sign-off, and diarise a review in two years or sooner if HMRC, the Charity Commission or the ICO update their guidance — the charity deadlines calendar can hold the date alongside your filings.

Want compliance tooling that tracks retention dates and flags destructions automatically, instead of a spreadsheet you maintain by hand? Join the CharityIQ compliance module waitlist →

Frequently asked questions

Charity trustees must preserve accounting records for at least 6 years from the end of the financial year in which they were made, under section 130 of the Charities Act 2011. If a charity ceases to exist within that period, the last trustees remain responsible for the records unless the Charity Commission agrees in writing to their destruction.

HMRC guidance says charitable companies should keep Gift Aid declarations and claim records for 6 years after the end of the accounting period they relate to. Charitable trusts should keep the later of 6 years after the relevant tax year or 12 months after the claim was made. Enduring declarations from ongoing donors should be kept for as long as the donor keeps giving, plus 6 years.

Securely destroying data means disposing of it so it cannot be reconstructed: cross-cut shredding or a certified confidential waste contractor for paper, and certified data wiping or physical destruction for digital devices and drives. For cloud and SaaS platforms, check the supplier's backup purge cycle so your deletion date is accurate, and always log what was destroyed, when and by whom.

Old staff and volunteer email accounts often contain personal data (donor correspondence, HR discussions, safeguarding notes) well past its retention date, so they need including in the schedule, not treated as an afterthought. Set a policy for when leaver accounts are archived, reviewed against retention rules, and permanently deleted, and check whether anything in them should be reclassified as a safeguarding or legacy record before deletion.

Not necessarily separate documents, but they do need distinct content: a data protection policy explains the lawful basis and principles you follow, while a retention schedule sets specific deletion dates per record type. Many charities combine both into one policy document, as this template does, provided the retention schedule is detailed enough to be actionable.

Trustees hold ultimate responsibility for data protection compliance, including retention, even though day-to-day actions are usually delegated to a CEO or designated Data Protection Lead. Best practice is for trustees to receive at least an annual summary confirming the retention schedule is being followed and the destruction log is up to date.