Information Assurance Policy


Effective Date: 8th October 2025
Last Reviewed: 8th October 2025
Next Review Due: 8th October 2026


The purpose of this policy is to establish a clear approach to protecting the confidentiality, integrity, and availability of information held by Ashford Borough Citizens Advice This policy ensures that information is handled securely and responsibly in compliance with:

  • The UK General Data Protection Regulation (UK GDPR)
  • The Data Protection Act 2018
  • Charity Commission guidance
  • Other applicable legal and regulatory requirements

This policy applies to:

  • All staff, trustees, volunteers, contractors, and third-party providers who access or handle charity information
  • All data and information assets owned or managed by [Charity Name]
  • All formats: paper, electronic, verbal, or digital
  • All devices and systems used to store or transmit information (e.g. computers, phones, cloud services)

3. Definitions

  • Information Assurance (IA): The practice of managing risks related to the use, processing, storage, and transmission of information.
  • Information Asset: Any piece of data or information that has value to the organisation (e.g., donor records, volunteer details, service user data).
  • Data Owner: The person responsible for ensuring proper handling of a particular set of data (e.g., HR data, donor records).
  • Personal Data: Any information that can identify a living individual.
  • Sensitive Data: Includes health data, racial or ethnic background, political opinions, etc.

4. Principles of Information Assurance

We are committed to the following IA principles:

  1. Confidentiality – Ensuring information is accessible only to authorised individuals
  2. Integrity – Ensuring the accuracy and completeness of data
  3. Availability – Ensuring authorised users can access information when needed
  4. Accountability – Ensuring users understand and fulfil their data responsibilities
  5. Compliance – Meeting legal and regulatory requirements for data handling

5. Responsibilities

RoleResponsibility
TrusteesOverall governance and policy approval
Chief Executive / DirectorEnsures implementation and compliance
Data Protection Officer (if applicable)Advises on legal compliance and monitors practices
Staff & VolunteersFollow procedures, report concerns or breaches
Third-Party ProvidersMeet contractual and legal obligations for data protection

6. Risk Management

We assess information risks as part of our operational planning and risk register. Steps include:

  • Identifying key information assets and potential threats
  • Applying proportional controls to reduce risks
  • Reviewing risks annually or when systems change

7. Access Control

  • Access to systems and data is based on job roles and need-to-know
  • User accounts are protected by strong passwords, 2FA (where possible), and account lockouts
  • Former staff or volunteers have access promptly revoked
  • Shared logins are prohibited

8. Data Protection and Privacy

We comply fully with the UK GDPR and maintain a separate Data Protection Policy and Privacy Notices that explain:

  • What data we collect
  • How we process it
  • Lawful basis for processing
  • How long we retain data

Sensitive data (e.g., health information of beneficiaries or volunteers) is handled with extra care and minimal access.


9. Information Handling

  • Paper records are kept in locked storage and disposed of via secure shredding
  • Electronic records are stored on secure, backed-up systems with encryption
  • We avoid storing data on personal devices; where necessary, devices must have password protection and encryption

10. Training and Awareness

All staff and volunteers receive appropriate data protection and information security training:

  • At induction
  • Refresher training annually or when significant changes occur
  • Tailored training for those with access to sensitive information

11. Incident Reporting and Breaches

All actual or suspected data breaches (e.g., lost laptop, accidental email to wrong recipient) must be reported immediately to the [Designated Officer / DPO].

We will:

  • Contain and assess the breach
  • Notify the ICO if required (within 72 hours)
  • Inform affected individuals if there is a high risk to their rights and freedoms
  • Document and review all breaches

12. Use of Technology

  • Anti-virus and firewall protections must be enabled on all devices
  • Software updates must be applied regularly
  • Use of cloud services (e.g., Microsoft 365, Google Workspace) must be approved and configured securely
  • Personal devices used for charity work must be approved and protected

13. Third-Party and Supplier Assurance

Where we share data with third-party providers (e.g. CRM systems, donation platforms), we will:

  • Carry out due diligence before engagement
  • Ensure contracts include data protection clauses
  • Monitor supplier performance and security

14. Retention and Disposal

We retain information only as long as necessary, based on our Data Retention Schedule. When no longer needed, data is securely deleted or destroyed.


15. Monitoring and Review

This policy will be reviewed annually or:

  • After a significant information security incident
  • When new legal or regulatory requirements arise
  • When we change our systems or processes

16. Related Policies and Documents

  • Data Protection Policy
  • GDPR Privacy Notice
  • Data Breach Procedure
  • IT and Acceptable Use Policy
  • Volunteer Agreement
  • Safeguarding Policy

Approved by: [Name or Board]
Date: [Insert Date]
Next Review Date: [Insert Date]