What the Charity Commission expects, and whether a policy is required
The Commission published Charities and social media on 18 September 2023. It is guidance rather than law, and it opens with a point that is easy to miss: nothing requires a charity to use social media at all. What it does say is that if a charity uses social media, "you and the other trustees are responsible for: agreeing and putting in place a social media policy", and for having "internal controls that are appropriate and proportionate for your charity's needs and which are clear to everyone at the charity using social media". A charity with one Facebook page run by a volunteer needs a page of rules. A national charity with a communications team needs rather more. Proportionate is the operative word, and the Commission uses it deliberately.
The guidance was written to help trustees, not to catch them out. The Commission had seen the same incidents recur across the charity sector: a post that provoked a pile-on, a trustee's personal account read as the charity's voice, a UK charity engaging on an emotive issue without having decided that it should. Its answer was to say what good social media policies already contain, based on policies from across the charity sector, so that a charity creating a social media policy for the first time is not starting from a blank page, and one that already has a policy in place can check it. The Commission's view is that charities can use social media effectively and that a social media presence helps many of them deliver their purpose; the guidance is about using social media platforms in riskier contexts without losing control of them.
The responsibility sits with the trustees because it is a corollary of duties they already carry. Trustees must act in the charity's best interests, manage its resources responsibly, act with reasonable care and skill and protect its reputation, and the guidance frames social media use as an ordinary application of those duties to a particular risk. The press release that accompanied it put the point plainly: "trustees must understand their legal responsibilities even if delegating tasks". Delegating the posting is expected. Delegating the decision about what may be posted, by whom, and what happens when it goes wrong, is not.
So is a social media policy a legal requirement? Not in statute. But the Commission's guidance is what it will measure a charity against if a post, a pile-on or a rogue account leads to a complaint, a serious incident report or a regulatory compliance case, and a charity that uses social media without a policy will find the absence is the first thing it is asked about. For a small charity, the policy is also the document that lets a volunteer say yes or no to a request without ringing the chair.
One more framing point before the content. The guidance is about the charity's use of social media, and it is careful to say that trustees, staff and volunteers "have the right to exercise their freedom of expression within the law" in their own accounts. The policy governs what the charity does, and what people do in the charity's name; it sets expectations, not surveillance, for what people do as themselves. Section 03 comes back to that line.
What the policy must cover: the Commission's checklist, in order
A social media policy template from NCVO or CharityComms will give you the headings. It will not tell you which of your volunteers may share content from the shop account, or whether your chair may name the charity on their own profile, and those are the decisions that make it your policy rather than a downloaded one. Creating a social media policy is mostly the work of answering the checklist below for your own charity; adapting a template to fit your organisation is the fast way to do that, provided every section is actually read and adapted.
The guidance ends with a checklist, and a policy that answers each item is a policy the Commission would recognise. Grouped as the guidance groups them:
- How social media will be used. What the charity is trying to achieve on each platform, which platforms it uses, and the kind of content it will and will not post. The guidance asks the policy to "explain how using social media will help deliver the charity's purpose": an account with no stated purpose is the one that drifts.
- Oversight and control. Who can post, when a post needs approval and from whom, who moderates comments and replies, and how and when content can be deleted. This is where a small charity writes the sentence that matters most: the named person who holds the keys, and the named person who can take them back.
- The conduct expected of the people running the accounts. That they understand the policy, have the skills and knowledge for the platforms they use, and know the law that applies to what they post.
- How the policy relates to personal use by trustees, employees and volunteers. Section 03.
- What happens when something goes wrong. When an issue is reported to the trustees, how complaints are handled, and when the charity must "report it to the Commission" as a serious incident.
Two things belong in the policy that the checklist implies rather than states. The first is an account register: every account held in the charity's name, who has the login, whether two-factor authentication is on, and what happens on the day that person leaves. Charities lose control of accounts far more often through a departed volunteer's phone than through a hack. The second is a review date. The guidance asks trustees to set aside time to review the policy's continued suitability, and a policy written for Facebook and Twitter in 2019 is not one that covers TikTok, Threads and the charity's WhatsApp Channel.
Resist the temptation to make the policy long. The Commission's own word is proportionate, and a document nobody reads protects nobody. The test is whether a new volunteer given the page could answer, without asking, whether they may post the photograph they have just taken.
Purpose of each account. Who posts, who approves, who moderates. What we never post. What staff and volunteers may say about us on their own accounts. Who to tell when something goes wrong, and who decides whether the Commission is told. Where the logins live and what happens when someone leaves. Review date. That is a policy; the rest is commentary.
Personal accounts: trustees, staff and volunteers
This is the section that generates the most anxiety, and the guidance is more relaxed than the anxiety. "There is no expectation that trustees monitor personal social media accounts." The concern the Commission does name is narrower: "the potential for an individual's personal use of social media to impact on the charity if they choose to disclose their place of work", or, in the press release's words, the risk that content posted by people connected to the charity in their personal capacity "may negatively impact the charity by association". The guidance's answer is guidelines rather than monitoring: say whether people may name the charity on a personal account, and ask that where they do, "individuals should make clear on their personal social media accounts that their views are their own and not the charity's".
In practice the line is drawn by seniority and by subject. A chair or chief executive who names the charity in a profile is, to a reader, speaking for it, whatever the disclaimer says, and the policy should say so. A volunteer who mentions the shop they help in on a Saturday is not. On subject, the policy should name the topics on which a person connected to the charity should take particular care in their own name: the charity's beneficiaries, its funders, its staff, and any live dispute or complaint. That is not a gag. It is the same care an employee owes an employer under an ordinary contract, written down so that nobody discovers it after the event.
Where a policy does need teeth is conduct that would be misconduct anywhere: harassment of colleagues or beneficiaries, disclosure of confidential information, discriminatory content. A charity's disciplinary and volunteer agreements already cover those, and the social media policy should point at them rather than duplicate them. Trustees are in a different position again, because a trustee who brings the charity into disrepute raises a question about their suitability as a trustee, and the policy should say that the board will deal with it as a governance matter.
The one group the guidance does not mention and the policy must is beneficiaries. Where a charity works with children or with adults at risk, its safeguarding policy will already say that staff and volunteers do not befriend, follow or message beneficiaries from personal accounts. The social media policy should repeat that rule in one sentence and cross-refer, because it is the personal-account rule most likely to be broken with good intentions.
Emotive issues, campaigning, and content the charity must not post
Charities exist because of things people feel strongly about, and the guidance does not ask them to pretend otherwise. "Charities can engage on emotive issues if this is a way of achieving its charitable purpose and is in the charity's best interests." The two conditions are the whole test. A homelessness charity posting about a change in housing policy is furthering its purpose. The same charity's account weighing in on an unrelated controversy because a trustee feels strongly is not, and the second post is the one the policy exists to stop. The guidance asks trustees to weigh the risks before engaging, including "the impact on your resources and staff, for example of receiving a significant number of complaints or negative attention", and to be able to show that they did.
Campaigning is permitted and party politics is not, and social media does not change either rule. The guidance says that "campaigning and political activity by charities are subject to additional rules" and points to the Commission's CC9 guidance: a charity may campaign, including on social media, to further its purposes, but it may not support or oppose a political party or candidate, and in an election period it must take particular care that its content cannot be read as doing so. Reposting, liking and following count. A policy should say who decides whether a campaigning post goes out and should name the election-period rules explicitly, because the person posting at nine in the evening will not look them up.
The guidance then lists what the charity must never post or share, and the list is short enough to reproduce. Content which is harmful; inconsistent with the charity's purpose; not in the charity's best interests; or in breach of the law, which includes defamation, copyright, data protection, harassment and the rules on fundraising. A photograph of a beneficiary without the consent the privacy notice promised is a data protection breach as well as a safeguarding failure, and the policy should make the consent step explicit for images of people.
The Online Safety Act 2023 belongs in this section for a different reason. Its duties fall on the platforms, not on the charities that use them, but it gives every platform a reporting route for illegal and harmful content that a charity's own accounts can be the target of. The policy should say who reports abuse aimed at the charity or its people, who decides to block or restrict an account, and that screenshots are taken before anything is reported, because the platform may remove the evidence with the post.

When it goes wrong: complaints, negative attention and serious incidents
Most social media incidents at charities are small: a post that was tactless, a reply that was sharper than it should have been, a comment thread that turned. The policy earns its keep by making the response boring. One person speaks for the charity; everyone else is told not to reply in the charity's name or their own; the original post is not silently deleted while a complaint is live, because a deleted post looks like an admission and destroys the record; and the chair or a nominated trustee is told the same day if the issue involves a beneficiary, a funder, a member of staff or the press.
Some incidents are not small, and the guidance asks trustees to "make sure you know if you need to report it to the Commission". The Commission's serious incident reporting guidance sets the threshold: significant harm to the charity's beneficiaries, staff, volunteers or others, significant loss of money or property, or significant damage to the charity's reputation or work. A viral post that leads to a safeguarding disclosure, a pile-on that costs a major donor, or an account takeover that solicits money from supporters are all reportable. The decision is the trustees', it should be made quickly, and a note of the decision, either way, belongs in the minutes.
Keep a log. Date, platform, what was posted or received, who responded and how, what was reported to whom, and the outcome. A charity that can produce that log answers a complaint in an afternoon. One that cannot reconstructs it from screenshots on three people's phones, which is the situation the next section is about.
The social media the policy forgets: private groups and direct messages
Read almost any charity social media policy and it is a policy about broadcasting: the public page, the feed, the post that a stranger can see. But the social media a charity's people use most is private. The staff WhatsApp group where the rota is agreed and the difficult client is discussed. The volunteers' Facebook group. The trustees' thread where the decision that will later appear in the minutes is actually made. The direct message from a supporter, or a beneficiary, to whoever runs the account. None of that is public, and almost none of it appears in the policy, and it is where the charity's real conversations happen.
Three things are true of those conversations that the policy should say. They are the charity's business conducted on personal devices, so the personal-account rules of section 03 cannot simply apply: a message in the staff group is not a personal view. They contain personal data about beneficiaries, staff and supporters, so UK GDPR applies to them, including the right of a person to ask for what has been said about them, and the charity is responsible for what it cannot see. And for many charities they are records: a safeguarding concern first raised in the group, a trustee decision taken in the thread, a complaint received by direct message, each of which a regulator, an auditor, a tribunal or a subject access request may one day ask for.
Consumer messaging apps cannot produce those records, and that is by design rather than by fault. End-to-end encryption means nobody but the participants can ever retrieve the conversation, the history lives on the phone of whoever happens to be in the group, and a volunteer who leaves takes the record with them. A policy can say that private groups are not to be used for decisions or for beneficiaries, and should, but the honest observation is that the conversation moves to wherever people already are, and a rule that fights that will be broken by the most conscientious people first.
So the question for the board is not whether to ban the group. It is a records question, and it belongs in the same meeting as the policy review: when a concern about a beneficiary, or a decision about the charity, is first raised in a message between our people, where does that message go, who can produce it in a year, and does our policy say?
Official guidance and your next step
The primary source is the Charity Commission's Charities and social media, published 18 September 2023, read alongside CC9: campaigning and political activity guidance for charities, How to report a serious incident in your charity, and The essential trustee (CC3) for the underlying duties. NCVO's social media guidance for charities and CharityComms' social media policy template were both updated after the Commission's guidance; use either as a starting structure rather than adopting it unread. Quotations are from the Commission's guidance as published on GOV.UK on 13 September 2026.
This guide is a practical starting point for charities in England and Wales, not legal advice about any particular post, dispute or incident. Charities registered in Scotland and Northern Ireland answer to OSCR and the Charity Commission for Northern Ireland, whose guidance differs in detail.
Then do one thing: take your current policy, if you have one, and check it against the five checklist items in section 02 and the private-messaging question in section 06. Whichever it does not answer is the agenda item for the next board meeting.
We build ComplyChat for the work conversations organisations need to keep. A charity's private groups are the part of its social media that carries the most risk and the least oversight, and a policy that ignores them is not proportionate, it is incomplete. Explore Free personal messaging, or compare the paid plans if your charity needs a lasting Microsoft 365 archive.

