Development policy

Records and retention

A useful record should explain what happened and why without collecting someone’s entire life simply because storage is cheap.

VersionDraft 0.1
Prepared4 August 2026
Current ownerFounder during development
ApprovalRequired before services begin

Record-keeping principles

  • Record only what is necessary for a defined purpose
  • Separate fact, the person’s account, professional opinion and decision
  • Use respectful, relevant and child-focused language
  • Date entries and identify the person making them
  • Correct errors transparently without silently rewriting the original record
  • Restrict access by role and review it regularly
  • Delete or anonymise information securely when the purpose ends

What future case records may contain

If one-to-one or group support begins, records may include contact details, accessibility needs, consent and boundaries discussed, dates and purpose of contact, agreed actions, signposting, safeguarding concerns, information-sharing decisions, complaints and supervision actions. Full court bundles and medical records will not be routinely accepted.

Provisional retention schedule

RecordProposed period
General unanswered or completed enquiriesUp to 12 months after the last meaningful contact
Partnership and training correspondenceUp to 3 years after the relationship or activity ends
Complaints and responsesUp to 3 years after closure, longer where risk or legal advice requires
Routine peer-support attendance and minimal notesProposed 12 months after support ends
Safeguarding concerns and decisionsNot fixed yet; a specialist schedule and legal advice are required before case support begins
Anonymised statisticsMay be kept longer where individuals can no longer be identified

Important: These periods are provisional. Safeguarding, insurance, contractual, employment and legal requirements must be checked before operational approval. No sensitive case-record system should begin on the strength of this draft alone.

Security and disposal

Approved systems will use strong authentication, limited access, backups and secure disposal. Personal information must not remain in downloads, personal notebooks or volunteer devices. A breach-response process will cover containment, risk assessment, notification and learning.

Access and review

People may have data-protection rights in relation to their personal information, subject to lawful exemptions and the rights of others. Requests will be logged, identity checked proportionately and answered within the applicable legal timeframe.

Guidance informing this draft

ICO storage-limitation guidance and ICO data-minimisation guidance.