The rule: a group chat is not a board meeting
A board's WhatsApp group has no decision-making power of its own; a charity board takes formal decisions in the way its governing document sets out. The Charity Commission's Decision-making for charity trustees (CC27) says: "Your charity's governing document explains how your charity must make decisions. You must follow this." It adds: "Usually, your governing document will say you must make decisions at meetings. However, sometimes it may say you can make decisions in other ways."
CC48 sets the minimum for a meeting. If the governing document does not set out details about meetings, "you should make sure that everyone at your meeting can see and hear each other. If you do not, any decisions you make may not be valid." A thread of typed replies meets neither half of that test.
The board also acts as one body. CC27: "As a group of trustees, you have a duty to make decisions 'jointly' or 'collectively'", and "you are jointly responsible for decisions that are made even if you do not" attend the meeting, take part in the decision or vote for it. A trustee who muted the group shares responsibility for any decision taken on the strength of it.
The lawful routes between meetings are in our guide to trustee decisions between meetings.
School governing bodies have less room still. For maintained schools in England, regulation 14 of the School Governance (Roles, Procedures and Allowances) (England) Regulations 2013 says "Every question to be decided at a meeting of the governing body is to be determined by a majority of the votes of the governors present and voting on the question", and regulation 13 has the clerk convene meetings with written notice and papers at least seven clear days ahead, unless the chair shortens the period for matters "demanding urgent consideration". The governing body "may approve alternative arrangements for governors to participate or vote at meetings", but those are arrangements for a meeting, not a replacement for one; the emergency exception is chair's action under regulation 8, covered in our guide to chair of governors responsibilities. Academy trust boards follow their articles: the DfE's Academy trust governance guide says "Boards can decide how to hold meetings, as allowed in their articles of association."
What the group is for, and what stays out of it
Legitimate uses carry no board business in the message itself:
- meeting dates, venues, joining links and changes to them
- apologies and whether the meeting will be quorate
- a note that the papers have been sent to trustees' charity email, without attaching them
- training dates, induction and visits
- informal communication that would be as comfortable read aloud at the next meeting
What stays out is anything the board would minute, anything about a named person, and anything a trustee may need to declare an interest in:
- proposals, votes, polls and "any objections?" on board business
- discussions of agenda items between meetings
- board papers and documents, accounts, contracts and legal advice
- names or details of beneficiaries, service users, pupils, parents, staff or volunteers
- complaints, safeguarding concerns, disciplinary matters and serious incidents
- views on the chief executive or headteacher
Three settings make the purpose stick. Name the group for its job ("Board – dates and logistics"). Agree a short statement of what it is for and add it to the board's code of conduct; the DfE's Maintained schools governance guide says "Effective governing bodies create and maintain a code of conduct which is agreed by all governors", and our guides to the trustee code of conduct and the governor code of conduct show where it fits. And give the admin role to the chair and the clerk or secretary, so the group does not belong to whichever trustee set it up. Adding someone to the group is a decision about their personal mobile number, so ask each trustee before adding them.
Conflicts of interest and confidentiality in a group chat
A group chat has no door for a conflicted trustee to walk out of. The Charity Commission's Conflicts of interest: a guide for charity trustees (CC29) defines a conflict as "when what is in the charity's best interests conflicts with, or may conflict with: your personal interests, or the interests of people or organisations connected to you". As a minimum, for a financial conflict, CC29 says the trustee affected should "leave the relevant discussion", "not take part in the decision giving rise to the conflict" and "not be counted in the quorum".
In a meeting, the minute records that the treasurer declared an interest in the contract with her husband's firm and left the room. In the group, she reads every message about that contract, and her thumbs-up sits among the others. CC29 says trustees should "Keep a written record of how you have managed conflicts of interest", including "what the conflict was", "when it was declared" and "how you managed it". For a discussion the conflicted trustee read from start to finish, that record can only show a conflict that was not managed.
Confidentiality fails the same way. Maintained school governing bodies must make their agendas, signed minutes and papers available for inspection, but regulation 15 of the 2013 Regulations lets them exclude material about a named member of staff, a named pupil or "any other matter that, by reason of its nature, the governing body is satisfied should remain confidential". A group chat has no confidential minute: any member can screenshot or forward anything in it.
Personal data about beneficiaries, staff and pupils
Personal data a board handles is the charity's or school's responsibility as controller, and the trustees must see that it is met. The ICO's guidance on controllers and processors gives the UK GDPR definition of a controller: the person or body which, "alone or jointly with others, determines the purposes and means of the processing of personal data". For schools, the DfE's data protection in schools guidance says governors and trustees "are responsible for making sure the school is compliant with the Data Protection Act 2018 and only keeps the data it needs".
Article 5(1)(f) of the UK GDPR requires personal data to be "processed in a manner that ensures appropriate security of the personal data", and Article 32 requires security "appropriate to the risk". Sharing a beneficiary's circumstances into a group on nine personal phones the charity does not manage is hard to square with either. The ICO's right of access guidance is written about staff, not trustees, but its reasoning carries across: "It is not usually appropriate for your staff to hold information about customers, contacts or other employees on their personal devices (eg in private email accounts, smartphones, home computers or private instant messaging applications)."
A screenshot forwarded to the wrong group or a lost phone with the thread open may be a personal data breach. Under Article 33 of the UK GDPR the controller notifies the ICO "without undue delay and, where feasible, not later than 72 hours after having become aware of it", unless the breach "is unlikely to result in a risk to the rights and freedoms of natural persons". The Charity Commission's guidance on how to report a serious incident in your charity lists "significant data breaches/losses" and says "It is the responsibility of the charity trustees to decide whether an incident is significant and should be reported."

Subject access, freedom of information and the trustee who leaves
Board messages about a person can fall within a subject access request. The ICO's right of access guidance, again written about staff, says that where an organisation permits them to hold personal information on their own devices, "they may be holding it on your behalf. This means that this information may be within scope if you receive a SAR." With good reason to think they hold information about the requester, the organisation "should ask them to search their private emails, devices or instant messaging applications, as appropriate", and it "must make a reasonable and proportionate search". For a board, that can mean nine volunteers searching their phones; our guide to subject access requests and WhatsApp messages covers the search.
School governors have a second exposure. The governing body of a maintained school is a public authority under Schedule 1 of the Freedom of Information Act 2000, and so is the proprietor of an academy for information held for its functions under Academy arrangements. The ICO's guidance on official information held in non-corporate communications channels names private messaging accounts "eg WhatsApp, Signal or Telegram" and says: "If the information held in a non-corporate communications channel amounts to public authority business, it is very likely to be held on your behalf". It cites the tribunal's finding in King's College, Cambridge v Information Commissioner that "information held in the private email accounts of the school governors could contain information held on behalf of the public authority", and advises using corporate channels for official business or, where that is not possible, storing official information "on your corporate systems as quickly as possible."
Neither request can be answered from the minutes if the substance was in the group. The minutes are the record the board must keep – CC48 says charitable companies must "store minutes for at least 10 years from the date of the meeting" – and our guide to board minutes retention covers the rest.
Then a trustee leaves. WhatsApp's UK privacy policy says "Typically your messages are stored on your device(s) and not on our servers", and its help centre article How to exit and delete groups as an admin says "Removing a member or deleting a group won't delete the group on other members' devices." Removing a departing trustee stops new messages; what they already have stays on their phone. The charity can ask them to delete it, alongside closing their charity email account (see trustee email retention), but cannot check, and cannot recover a copy it never held.
The real decision was taken in the group, and it is on nine personal phones
On a Sunday evening the chair posts that the chief executive has offered to resign over the audit findings: is the board content to accept? Six of nine reply within the hour, one with a thumbs-up from the trustee whose firm prepared the accounts. On Monday the chair accepts. The next minute reads "The board noted the resignation of the chief executive."
The decision, the reasons, the conflict and the dissent one trustee typed and then softened are all in the thread, and the thread is on nine personal phones. WhatsApp's end-to-end encryption, which it describes as meaning "No one else, not even WhatsApp, can read or listen to them", leaves the charity with no copy it can search, produce or keep. Two of the nine have since left. When the former chief executive makes a subject access request, or the Commission asks how the decision was taken, the charity's answer depends on who still has the thread.
ComplyChat replaces the board's group with a channel the charity owns. Everyone added is told it is on the record and can object or leave, trustees with no account on the charity's systems join with a mobile number verified by SMS, and messages are recorded on the server as they are sent. On paid plans the lasting record files into the charity's own Microsoft 365 once its tenant is connected, under its own retention rules, so the record stays with the charity when a trustee leaves. There is no WhatsApp in the path; trustees' own chats stay in their own apps.
It is not the whole answer. ComplyChat is not a board portal, and a message in a channel is no more a valid decision than one in a WhatsApp group: the governing document decides that. A board whose group only carries dates and venues may not need it. ComplyChat Free is personal messaging with one private group, direct messages and three calendar months of recent history, with no Microsoft 365 archive, so it is not a way to meet a retention duty.
A question for the next board meeting: which decisions has this board taken in its group since the last meeting, and if the charity had to produce the thread tomorrow, whose phone would it have to ask for?
Questions people ask
Can governors use WhatsApp?
Governors can use WhatsApp for logistics such as meeting dates, but not to decide governing body business: in a maintained school, regulation 14 of the 2013 Regulations has questions decided at a meeting "by a majority of the votes of the governors present and voting on the question", and urgent action between meetings goes through the chair under regulation 8. Messages about school business may also be caught by a freedom of information request, because the ICO says information in a private messaging account that amounts to public authority business "is very likely to be held on your behalf".
Can trustees make decisions on WhatsApp?
Only if the charity's governing document allows decisions to be taken that way, and only in the form it sets out; CC48 tells trustees to check whether it allows charity business "on messaging apps". Even then, CC27 says trustees "should record decisions even if they are not made at a meeting", so the agreement still has to be recorded, not left in the thread.
Can a trustee meeting be held on WhatsApp?
Not as a text thread: where the governing document is silent, CC48 says trustees "should make sure that everyone at your meeting can see and hear each other", and that otherwise "any decisions you make may not be valid". A board that wants virtual meetings should amend its governing document so that it "explicitly says you can hold meetings that way".
Are trustees' WhatsApp messages covered by a subject access request?
They can be: the ICO's guidance, written about staff, says information held on personal devices with the organisation's permission "may be within scope if you receive a SAR". The request is to the charity or school, which "must make a reasonable and proportionate search".
What happens to the group's messages when a trustee leaves?
They stay on the departing trustee's phone until the trustee deletes them: WhatsApp says removing a member "won't delete the group on other members' devices". The charity can ask a leaver to delete board messages but cannot verify that they have.
Where to read the official guidance
Charities should read the Commission's Decision-making for charity trustees (CC27), Conflicts of interest (CC29) and Charities and meetings (CC48) with their governing document; schools, the School Governance (Roles, Procedures and Allowances) (England) Regulations 2013 and the DfE's Maintained schools governance guide and Academy trust governance guide. On information requests, the ICO's right of access guidance and its guidance on non-corporate communications channels apply. Quotations are as published on 28 September 2026.
This guide is a summary for England and Wales, not legal advice.
Then do one thing: scroll back through the board's group to the last meeting, list every message that proposed, agreed or objected to something, and put each on the next agenda to be decided or ratified properly.
We build ComplyChat for the work conversations organisations need to keep. A board's group chat is where many of a charity's hardest decisions are really discussed, on phones the charity does not control. Explore Free personal messaging, or compare the paid plans if your board needs a lasting Microsoft 365 archive.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Decision-making for charity trustees (CC27) gov.uk
- School Governance (Roles, Procedures and Allowances) (England) Regulations 2013 legislation.gov.uk
- Academy trust governance guide gov.uk
- Maintained schools governance guide gov.uk
- Conflicts of interest: a guide for charity trustees (CC29) gov.uk
- Guidance on controllers and processors ico.org.uk
- Data protection in schools guidance gov.uk
- UK GDPR legislation.gov.uk
- Article 32 legislation.gov.uk
- Right of access guidance ico.org.uk
- Article 33 of the UK GDPR legislation.gov.uk
- How to report a serious incident in your charity gov.uk
- Freedom of Information Act 2000 legislation.gov.uk
- Official information held in non-corporate communications channels ico.org.uk
- UK privacy policy whatsapp.com
- How to exit and delete groups as an admin faq.whatsapp.com
- Charities and meetings (CC48) gov.uk


