Effective Date: 8th October 2025
Last Reviewed: 8th October 2025
Next Review Due: 8th October 2026
1. Purpose
The purpose of this policy is to establish a clear approach to protecting the confidentiality, integrity, and availability of information held by Ashford Borough Citizens Advice This policy ensures that information is handled securely and responsibly in compliance with:
- The UK General Data Protection Regulation (UK GDPR)
- The Data Protection Act 2018
- Charity Commission guidance
- Other applicable legal and regulatory requirements
2. Scope
This policy applies to:
- All staff, trustees, volunteers, contractors, and third-party providers who access or handle charity information
- All data and information assets owned or managed by [Charity Name]
- All formats: paper, electronic, verbal, or digital
- All devices and systems used to store or transmit information (e.g. computers, phones, cloud services)
3. Definitions
- Information Assurance (IA): The practice of managing risks related to the use, processing, storage, and transmission of information.
- Information Asset: Any piece of data or information that has value to the organisation (e.g., donor records, volunteer details, service user data).
- Data Owner: The person responsible for ensuring proper handling of a particular set of data (e.g., HR data, donor records).
- Personal Data: Any information that can identify a living individual.
- Sensitive Data: Includes health data, racial or ethnic background, political opinions, etc.
4. Principles of Information Assurance
We are committed to the following IA principles:
- Confidentiality – Ensuring information is accessible only to authorised individuals
- Integrity – Ensuring the accuracy and completeness of data
- Availability – Ensuring authorised users can access information when needed
- Accountability – Ensuring users understand and fulfil their data responsibilities
- Compliance – Meeting legal and regulatory requirements for data handling
5. Responsibilities
| Role | Responsibility |
| Trustees | Overall governance and policy approval |
| Chief Executive / Director | Ensures implementation and compliance |
| Data Protection Officer (if applicable) | Advises on legal compliance and monitors practices |
| Staff & Volunteers | Follow procedures, report concerns or breaches |
| Third-Party Providers | Meet contractual and legal obligations for data protection |
6. Risk Management
We assess information risks as part of our operational planning and risk register. Steps include:
- Identifying key information assets and potential threats
- Applying proportional controls to reduce risks
- Reviewing risks annually or when systems change
7. Access Control
- Access to systems and data is based on job roles and need-to-know
- User accounts are protected by strong passwords, 2FA (where possible), and account lockouts
- Former staff or volunteers have access promptly revoked
- Shared logins are prohibited
8. Data Protection and Privacy
We comply fully with the UK GDPR and maintain a separate Data Protection Policy and Privacy Notices that explain:
- What data we collect
- How we process it
- Lawful basis for processing
- How long we retain data
Sensitive data (e.g., health information of beneficiaries or volunteers) is handled with extra care and minimal access.
9. Information Handling
- Paper records are kept in locked storage and disposed of via secure shredding
- Electronic records are stored on secure, backed-up systems with encryption
- We avoid storing data on personal devices; where necessary, devices must have password protection and encryption
10. Training and Awareness
All staff and volunteers receive appropriate data protection and information security training:
- At induction
- Refresher training annually or when significant changes occur
- Tailored training for those with access to sensitive information
11. Incident Reporting and Breaches
All actual or suspected data breaches (e.g., lost laptop, accidental email to wrong recipient) must be reported immediately to the [Designated Officer / DPO].
We will:
- Contain and assess the breach
- Notify the ICO if required (within 72 hours)
- Inform affected individuals if there is a high risk to their rights and freedoms
- Document and review all breaches
12. Use of Technology
- Anti-virus and firewall protections must be enabled on all devices
- Software updates must be applied regularly
- Use of cloud services (e.g., Microsoft 365, Google Workspace) must be approved and configured securely
- Personal devices used for charity work must be approved and protected
13. Third-Party and Supplier Assurance
Where we share data with third-party providers (e.g. CRM systems, donation platforms), we will:
- Carry out due diligence before engagement
- Ensure contracts include data protection clauses
- Monitor supplier performance and security
14. Retention and Disposal
We retain information only as long as necessary, based on our Data Retention Schedule. When no longer needed, data is securely deleted or destroyed.
15. Monitoring and Review
This policy will be reviewed annually or:
- After a significant information security incident
- When new legal or regulatory requirements arise
- When we change our systems or processes
16. Related Policies and Documents
- Data Protection Policy
- GDPR Privacy Notice
- Data Breach Procedure
- IT and Acceptable Use Policy
- Volunteer Agreement
- Safeguarding Policy
Approved by: [Name or Board]
Date: [Insert Date]
Next Review Date: [Insert Date]
