The rule: the email belongs to the charity's business, wherever it is stored
There is no retention period for trustee email as such. What exists is a set of rules that attach to the content of the email, and one principle that decides whose responsibility it is.
The principle comes from data protection law. The charity, the school's governing body or the academy trust is the controller of the personal data it handles, and trustees handle that data on its behalf. The ICO, the data protection regulator, puts the consequence plainly in its guidance on subject access, written about staff but resting on the same reasoning: "If you do permit staff to hold personal information on their own devices, they may be holding it on your behalf." An email about a volunteer, a beneficiary or a complaint does not stop being the charity's information because it arrived in a trustee's personal inbox.
The retention rules then come from the content:
- Money. Under section 131 of the Charities Act 2011 the trustees of an unincorporated charity must preserve accounting records for at least six years from the end of the financial year in which they are made; charitable companies, whose trustees are usually also its directors, and CIOs have equivalent duties. An email approving a payment, agreeing a grant condition or explaining a transaction is part of what those records have to show and explain.
- Decisions. A CIO must record decisions its trustees make "otherwise than in meetings" and keep them for at least six years under regulation 37 of the CIO (General) Regulations 2012. A decision agreed by a chain of replies is exactly that kind of decision.
- Personal data. The storage limitation principle in UK GDPR says personal data is kept no longer than is necessary for its purpose. That cuts the other way: it is a reason to delete, not to hoard.
- Claims. Most contract claims can be brought for six years under section 5 of the Limitation Act 1980, so correspondence that would be the evidence in such a claim is usually kept for that long after the contract ends.
Read together, the rule is simple to state and hard to follow: trustee email is kept according to what it records, by the organisation, somewhere the organisation can reach.
What trustee email actually contains
Most boards underestimate how much of their governance now runs through the trustees' inboxes. A year of a typical trustee's charity email includes:
- approvals given between meetings: the chair agreeing an urgent spend, three trustees saying yes to a policy change, the board signing off accounts by reply;
- board papers and the draft minutes circulated as attachments, often in several versions;
- correspondence with the Charity Commission, the auditor or independent examiner, the bank, funders and, for schools, the local authority or the Department for Education;
- employment matters forwarded to the chair or the HR lead trustee: grievances, disciplinary outcomes, sickness absence, a settlement;
- safeguarding concerns raised with the designated trustee, and the replies that decided what happened next;
- complaints from beneficiaries, parents or members of the public;
- personal data about donors, volunteers and service users, much of it in attachments nobody opened twice;
- routine logistics that record nothing: dates, venues, apologies, "running ten minutes late".
Only the last category is safe to lose. Everything above it is either part of a statutory record, personal data the charity is responsible for, or evidence it may one day need. The retention question is therefore not "how long do we keep trustee email" but "which of these does each message belong to, and where does it get filed".
Trustees using personal email addresses
It is common, especially in small charities, for trustees to use their personal or work email addresses for board business. It is rarely a considered decision; it is simply what happened when each trustee joined. The difficulty is that every duty above assumes the organisation can reach the email, and a personal account is the one place it cannot.
Four problems follow.
- Subject access. The ICO's guidance says that if you have good reason to think staff hold personal information about the requester on their personal devices, "you should ask them to search their private emails, devices or instant messaging applications, as appropriate", and that "It is not usually appropriate for your staff to hold information about customers, contacts or other employees on their personal devices (eg in private email accounts, smartphones, home computers or private instant messaging applications)". A charity answering a request from a former employee may have to ask six volunteer trustees to search their own inboxes, and can only take their word for the result.
- Freedom of information, for schools and academy trusts. Maintained school governing bodies and academy trusts are public authorities under the Freedom of Information Act 2000; most charities are not. The ICO's guidance on official information held in non-corporate communications channels lists private email accounts among the places official information can be held on the authority's behalf, and says that "As far as reasonably practicable, you should always ensure that you use corporate channels for official business." It also reminds authorities that erasing, destroying or concealing information to prevent its disclosure after a request has been received is a criminal offence under section 77 of the Act.
- Security. A personal account may be shared with a partner, protected by a password reused elsewhere, or read on a family tablet. The National Cyber Security Centre's guidance for small organisations recommends passkeys, or a strong password with two-step verification, on email accounts as a priority. The charity cannot enforce any of that on an account it does not run.
- Continuity. When the trustee leaves, the only copy of their board correspondence leaves with them. The charity keeps what was copied to someone else, if anyone thought to.
The fix is organisational, not technical. Give every trustee an address the charity controls, either a mailbox per person or, for very small boards, role addresses such as the chair's and the treasurer's that pass from one holder to the next. Say in the trustee code of conduct or the IT policy that board business is conducted there and not auto-forwarded to a personal account. Where the board decides to tolerate personal addresses for a while, record that decision and the rule that goes with it: decisions, personal data and anything about money are sent to or copied into a charity mailbox, so the record exists somewhere the charity can search.
How long to keep trustee email
Retention works by content, so the schedule has rows for what the email records rather than a single period for the mailbox. A workable starting point for a charity in England, to be checked against your own governing document, funders' terms and sector schedule:
- Decisions and approvals made by email: file with the minutes and keep them as long as the minutes. Our guide to board minutes retention sets out the ten-year company rule, the six-year CIO rule and why most boards keep signed minutes permanently.
- Financial correspondence that explains a transaction: at least six years from the end of the financial year it relates to, with the accounting records it supports, including any Gift Aid correspondence HMRC may ask to see.
- Contracts, leases and grant agreements, with the correspondence that varied them: six years after the agreement ends, 12 years for a deed, and longer where property or a continuing liability is involved.
- Employment matters: with the personnel file, commonly six years after the person leaves.
- Safeguarding concerns: with the safeguarding record, for the much longer period sector guidance sets. Never delete these under a general email rule.
- Complaints: with the complaint record, for the period your complaints procedure states.
- Board papers and drafts: the approved version is kept with the minutes; circulated drafts need not be kept once the final is approved, unless a dispute is live.
- Logistics and chatter: delete routinely, for example after a year.
Two rules override the schedule. Anything relating to a live or pending dispute, claim, investigation, subject access request, information request or serious incident report is kept until the matter closes, whatever its row says; deleting it after a request has arrived is the worst available outcome. And a message is kept once, in the right place: the email approving a contract variation belongs in the contract file, not in five trustees' inboxes for five different lengths of time.
A retention period is also a destruction date, and good practice is to record the disposal as well as schedule it, so the charity can show what was deleted and when. A charity that keeps every trustee email indefinitely has not solved the problem; it has swapped a records gap for a storage limitation problem and a larger subject access search. Our guide to writing a data retention policy covers building the schedule itself.

When a trustee joins, and when a trustee leaves
Most trustee email problems are created on the first day and discovered on the last. A short lifecycle, agreed once and recorded in the board's induction pack, prevents most of them.
On joining, the new trustee is given a charity address and told what it is for, signs or acknowledges the policy that says board business stays there, and sets up two-step verification before the first board pack arrives.
While serving, decisions are made or confirmed where they can be filed, and papers are shared from a location the charity controls rather than as attachments that multiply.
On leaving:
- the trustee hands back anything the charity needs to keep, and confirms in writing that charity personal data held in any personal account or device has been deleted;
- access to the charity mailbox and shared folders is removed on the day, and the password or passkey for any role address is changed;
- the mailbox itself is kept, not deleted, and handled under the retention schedule, so that a request or claim arriving next year can still be answered;
- the leaving is recorded in the minutes and the register of trustees, with the date access ended.
If a departing trustee cannot be reached or will not confirm deletion, record the attempts. The charity cannot compel a former volunteer to search a personal inbox, and the record of having asked is what it will be able to show.
Losing control of charity data is itself a governance event. The Charity Commission's guidance on reporting a serious incident asks trustees to report if "you discover that there has been a significant data breach or loss within your charity", and says "all trustees bear ultimate responsibility for ensuring their charity makes a report, and does so in a timely manner." A personal data breach may also have to be reported to the ICO without undue delay and, where feasible, within 72 hours of the charity becoming aware of it. A trustee's compromised personal account, holding three years of board email, is the kind of breach nobody plans for.
The board business that no longer arrives by email
Everything above assumes the board's business is in email at all. On many boards it has quietly moved. The chair's approval of the urgent spend is a message on a Saturday. The designated safeguarding trustee hears about a concern in a text from the manager. The treasurer and the chair agree how to answer the auditor's query in a thread on their personal phones, and the email that follows records the answer without the reasoning.
The rules have not moved with it. The ICO's list of non-corporate channels that can hold official information runs from private email accounts to private messaging apps and text messages on mobile phones, and a subject access request reaches a message about the requester in the same way it reaches an email. The difference is practical: a charity that has given its trustees charity mailboxes can at least search them, while the messages sit in an end-to-end-encrypted consumer app on phones the charity does not own, under whatever deletion setting each trustee chose, and they leave with the trustee.
One answer is to give those conversations a channel the organisation owns. ComplyChat is built for that: a mobile number verified by SMS is an identity on it, so volunteer trustees with no charity account can take part; everyone added is told the channel is on the record and can object or leave; and messages are recorded on the server as they are sent rather than collected from handsets afterwards. On paid plans the lasting record files into the organisation's own Microsoft 365 once its tenant is connected, under the retention rules it already sets for email, so the Saturday approval sits in the same schedule as the email that should have carried it. ComplyChat Free is personal messaging with one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive; it does not meet a retention duty. And if every trustee already works in charity mailboxes and the board's discussion genuinely stays there, the first step is enforcing that, not adding another tool.
A question for the next board meeting: if a former employee's subject access request arrived tomorrow, which trustees would have to search a personal inbox or phone, and how would the charity know the search was complete?
Official guidance and your next step
The ICO's guidance on finding and retrieving information for a subject access request covers personal devices and private accounts, and its guidance on non-corporate communications channels is the reference for schools and academy trusts. The Charity Commission's serious incident guidance covers data loss, and the National Cyber Security Centre's small organisations guide covers securing email accounts. The Data (Use and Access) Act 2025 has amended UK GDPR and the Data Protection Act 2018, and all its data protection provisions are now in force, so check the date on any ICO page you rely on; quotations here are from the pages as published on 25 September 2026.
This guide is a summary for charities, schools and academy trusts in England, not legal advice. Scottish and Northern Irish charity law differ in detail, and a live request or dispute should be handled on advice.
Then do one thing: list your trustees and, beside each name, the address they actually use for board business. Every personal address on that list is a mailbox the charity is responsible for and cannot open.
We build ComplyChat for the work conversations organisations need to keep. Trustee correspondence is a clear case: it carries decisions and personal data the charity is answerable for, and it usually sits in accounts and on phones the charity does not control. Explore Free personal messaging, or compare the paid plans if your board needs a lasting Microsoft 365 record.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Section 131 of the Charities Act 2011 legislation.gov.uk
- Regulation 37 of the CIO (General) Regulations 2012 legislation.gov.uk
- Section 5 of the Limitation Act 1980 legislation.gov.uk
- Official information held in non-corporate communications channels ico.org.uk
- Reporting a serious incident gov.uk
- Finding and retrieving information for a subject access request ico.org.uk
- Small organisations guide ncsc.gov.uk


