1. Purpose
This policy sets out how Sadaqah Jariyah Funeral Services protects personal information and meets its responsibilities under UK data protection law.
2. Scope
It applies to trustees, staff, volunteers, contractors, systems and records used for donations, Gift Aid, funeral support, funeral wishes, volunteers, events, orders, communications and administration.
3. Principles
Personal information must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained only as long as required; and protected by appropriate security.
4. Responsibilities
Trustees retain overall accountability. People with access to personal information must follow this policy, use approved systems, keep credentials secure, report incidents promptly and complete appropriate training.
5. Special category and sensitive information
Religious, health, safeguarding and funeral-related information requires particular care, restricted access and a documented lawful basis.
6. Access control and security
Access must be based on role and need. Administrators should use strong unique passwords, multi-factor authentication where available, secure devices, supported software, encrypted connections and reliable backups.
7. Sharing and processors
Information may only be shared where lawful and necessary. Suppliers processing information for the charity must be appropriately assessed and bound by suitable contractual and confidentiality requirements.
8. Retention and disposal
Records must follow an approved retention schedule. When no longer required, information must be securely deleted, anonymised or destroyed.
9. Individual rights
Requests relating to personal information must be sent promptly to sadaqah786@mail.com and handled within the applicable legal timescale.
10. Personal data breaches
Suspected loss, unauthorised disclosure, alteration or access must be reported immediately. The charity will assess risk, contain the incident, document its response and notify affected people or the Information Commissioner’s Office where required.
11. Review
This policy is reviewed regularly and after significant legal, operational or technology changes.
