The rule: who says a youth club must keep safeguarding records
Three sources shape the expectations, but their legal status differs. Working Together to Safeguard Children 2026, the statutory guidance, says that voluntary, charity, social enterprise and faith-based organisations and sports clubs “provide education and activities for children as part of their work” and that their staff and volunteers “can often be the first trusted adult to whom a child reports abuse or the first to notice signs of potential neglect and/or abuse” (paragraph 86). Every such organisation “should have policies in place to safeguard and protect children from harm. These should be followed, and systems should be in place to ensure compliance in this” (paragraph 358); “all practitioners … are subject to the same safeguarding responsibilities, whether paid or a volunteer” (paragraph 357); and every one “should have in place the arrangements described in this chapter” (paragraph 359), which include “a clear line of accountability”, “a senior board level lead”, “a designated practitioner”, “clear whistleblowing procedures”, “clear escalation policies” and “arrangements which set out clearly the processes for sharing information” (paragraph 259).
The DfE’s non-statutory guidance for providers of out-of-school settings – after-school clubs, community activities, tuition, sports and youth groups – is the document Working Together points these organisations to. It says providers should “have a written safeguarding and child protection policy, with written procedures in place”, appoint “a suitably trained designated safeguarding lead (DSL)”, have “a staff behaviour policy (sometimes called a code of conduct)”, “report any allegations of harm to a child to both your local authority designated officer (LADO) and the police as soon as reasonably practicable”, and “know if the legal duty to refer to the Disclosure and Barring Service applies to you”. It defines “staff” to “mean a paid employee or unpaid worker or volunteer”. And on records: the DSL “should record: any concerns about abuse and neglect; what they have done about them; the reason for their decisions”; providers should have “a clear record of the safeguarding training provided to staff”; and “you should record any safeguarding incidents and store the information securely, ideally in a private office. Only the DSL, or other relevant senior colleagues, should have access to the records. Only keep records for as long as necessary.”
For a group that is a charity, the Charity Commission’s safeguarding guidance requires trustees to make sure the charity “keeps accurate records” and “handle[s] and record[s]” any incident “in a secure and responsible way”, and the Commission “can check that trustees followed this guidance and the law”. Clubs affiliated to a national governing body of sport or a national youth organisation carry that body’s rules on top.
The records a club or group must keep
The safeguarding policies and procedures say what the group will do; the records show that it did. Seven, and a small group that works with children and young people can keep all of them in one locked drawer or one restricted folder:
- The concern record: every worry about a child, however small, from any volunteer, with what was done about it. The NSPCC and the DfE both prefer a standard form.
- The child protection file: where a concern about a particular child leads anywhere, a separate file for that child; the NSPCC advises keeping concerns and referrals “in a separate child protection file for each child, rather than in one ‘concern log’”, started “as soon as you become aware of any concerns”.
- The allegations record: concerns about a volunteer, coach, leader or trustee, what was reported to the LADO and the police, and the outcome, kept on the adult’s file and apart from the children’s.
- Recruitment and checks: the application, references, interview note, the DBS record (see below), the risk assessment for the role and any disclosure, and the date the person started.
- Training: who did which safeguarding training, when, at what level, and when the refresher is due.
- Registers, consents and contacts: who attended each session and which adults were present, the parental consents, emergency contacts, medical and additional-needs information, and the adult-to-child ratio.
- Governance records: the policy and its review dates, the committee or trustee minutes that approved it and received the safeguarding lead’s reports, and the record of any serious incident report to the Charity Commission or the governing body.
Two rules from the NSPCC’s retention and storage guidelines about what not to keep. “You shouldn’t store copies of criminal records check certificates unless there is a dispute about the results of the check”; instead keep “the date the check was completed, the level and type of check …, the reference number of the certificate, [and] the decision made about whether the person was employed (with reasons)”, and certificate information only for the justified period, normally no longer than six months after the recruitment decision; follow DBS guidance if an exceptional reason requires longer retention. Review medical and additional-needs information when attendance ends. Delete what is no longer needed, but preserve relevant information where it forms part of an incident, safeguarding record, claim or other justified retention requirement.
What a concern record contains
The NSPCC’s list is the sector standard and fits on one form. “Keep an accurate record of:”
- “the date and time of the incident/disclosure”
- “the date and time of the report”
- “the name and role of the person to whom the concern was originally reported and their contact details”
- “the name and role of the person making the report (if this is different to the above) and their contact details”
- “the names of all parties who were involved in the incident, including any witnesses”
- “the name, age and any other relevant information about the child who is the subject of the concern (including information about their parents or carers and any siblings)”
- “what was said or done and by whom”
- “any action taken to look into the matter”
- “any further action taken (such as a referral being made)”
- “the reasons why the organisation decided not to refer those concerns to a statutory agency (if relevant)”
Parents and carers are told, through the policy and the privacy notice, that the group records concerns and may share them, and who the nominated safeguarding lead is; a reporting form that every volunteer can find, on paper in the register box or online, is what turns a worry into a record. Then the rules for writing it: “Make sure the report is factual. Any interpretation or inference drawn from what was observed, said or alleged should be clearly reported as such. The record should always be signed and dated by the person making the report.” The child’s own words go in as spoken; the volunteer’s view of what they mean is labelled as a view. The last item on the list is the one groups most often leave blank and the one a later review most wants: why the lead decided not to refer, on what information, and who was consulted. A concern that was passed to the local safeguarding partnership is recorded with the referral reference and what came back; a concern that was not is recorded with the reason, because the DfE’s guidance asks the DSL to record “the reason for their decisions”.
Where the concern is a disclosure, the DfE’s guidance adds the rule that protects the record’s value: “It is important not to investigate the disclosure yourself as this may jeopardise a police or social care investigation and possibly the prosecution of the offender.” The volunteer listens, reassures, does not promise secrecy, does not ask leading questions, writes it down as soon as they can, and passes it to the lead the same day.
Who keeps the records, who may see them, and how long
Storage. “Whether your child protection records are electronic or paper-based, they should be kept confidential and stored securely. Electronic files should be password protected” (NSPCC); “ideally in a private office. Only the DSL, or other relevant senior colleagues, should have access” (DfE). In a group that meets in a hired hall the records go home with the safeguarding lead in a locked case or live in a restricted online folder the group controls, and the policy says which. Sessional volunteers see the register and the consents for their session and nothing else.
Sharing. Consent is not normally the appropriate lawful basis for sharing information to safeguard a child. Identify the applicable lawful basis, share necessary and proportionate information promptly with the right agency, and record what was shared and why. Be open with the child and family where safe, but do not let seeking consent delay protection. See the DfE information-sharing advice. Share relevant information proactively where needed; use secure transfer and record receipt rather than waiting for another organisation to ask.
Retention. The NSPCC gives the periods most voluntary organisations adopt: “In England, Scotland and Wales, the [child protection] file should be kept until the child is 25 (this is seven years after they reach the school leaving age)”; for concerns about an adult’s behaviour around children, “keep the records in their personnel file at least until they reach their normal retirement age or for 10 years – whichever is longer”, whether the adult was paid or a volunteer; and “organisations should keep any records that could be needed by an official inquiry”, which “will issue directions for records to be retained and these must be followed” – the Independent Inquiry into Child Sexual Abuse’s retention instructions are the standing example. Where a record is kept longer than the schedule, “files should be clearly marked with the reasons for the extension period”. Registers, consents and training records are kept for the period the group’s retention schedule sets, which is typically years rather than months because they show who was present and who was trained when a concern arose.
Data protection. These records contain personal data and may include special category data or criminal-offence information, and the group is the controller. UK GDPR requires an Article 6 lawful basis and, where special category information is involved, an Article 9 condition with any applicable Data Protection Act 2018 requirements. Criminal-offence information needs its own safeguards, a privacy notice that tells parents what is kept and why, security proportionate to the sensitivity, and a retention schedule that is actually applied. A group that keeps everything forever and a group that shreds the file when the child leaves have both got it wrong.

Concerns about adults: the LADO, the DBS and the record that outlives the volunteer
A concern that a volunteer, coach or leader may have harmed a child or may pose a risk goes to the local authority designated officer, and the DfE’s guidance is direct: “If there is an allegation against a member of staff or volunteer, the DSL should contact their local authority designated officer”, who “coordinates all allegations and concerns made against a person who works with children”, and “the DSL should also inform the police if a crime may have been committed.” The club does not investigate first, and it does not decide the allegation is unfounded before making the call. Concerns that fall below that threshold – the leader who is over-familiar, the coach who messages players directly – are still recorded and still reviewed for a pattern, in the way schools now handle low-level concerns.
The record of an allegation is kept on the adult’s file with the outcome, whatever it was, and the NSPCC’s retirement-age-or-ten-years rule applies. Where the organisation provides regulated activity and removes someone because they harmed or posed a risk to a child, or they leave before that decision, the Safeguarding Vulnerable Groups Act 2006 imposes a legal duty to refer to the Disclosure and Barring Service; the DfE guidance asks every provider to “know if the legal duty to refer … applies to you and ensure you make referrals when appropriate”. The referral and the reasons for it are part of the record. For a charity, the same event is usually a serious incident report to the Charity Commission.
None of this can be done well from memory. A club that has kept the concern record, the register that shows who was present, the training record and the recruitment file can answer the LADO’s questions the same day; a club that has kept only a policy cannot.
The concern that is first raised in the volunteers’ group chat
Now look at how concerns arrive in a real youth club. A volunteer on the Friday session messages the leaders’ WhatsApp group at ten that night: “anyone else notice J was really withdrawn tonight, and he had a bruise on his arm he didn’t want to talk about?” Two others reply that they noticed. The safeguarding lead sees it on Saturday morning and messages the volunteer directly for more. A parent messages the coach she has the number of about another coach. The chair and the lead agree in a chat that a helper should not be on the rota next week. The concern record, when it is eventually written, begins “On Saturday the DSL was made aware …”, and the actual first raising – the words the volunteer used, the time, the two who agreed – is on four personal phones.
Working Together asks for “a culture of listening to children” and for clear routes for concerns; the DfE asks the lead to record the concern, the action and the reason. The culture exists – people spoke up – and the group cannot show it. It cannot produce the messages when the LADO, the local authority or a review years later asks what was first said and when, because the messages are in an app the group does not run, on handsets it does not own, and it needs a lawful, proportionate process for obtaining relevant work messages while protecting unrelated personal information. And the pattern that three volunteers each half-noticed is invisible to a record that holds only what reached the lead.
Use a restricted reporting route, with access limited to the people who need the information. A recorded message is not proof that someone has read or acted on a concern: follow the safeguarding procedure, contact the responsible person directly when action is urgent, and use the local authority or emergency route when required. Add the relevant information and decisions promptly to the formal safeguarding record.
The club cannot stop volunteers using their phones; that is how volunteers talk, and the leaders’ group is often the only way a Friday-night club runs at all. It can move the raising of concerns onto a channel the club owns, where the safeguarding lead is in the conversation from the first message, where every volunteer in it has been told it is on the record, and where the volunteer’s words, the time, and the lead’s reply are the record rather than a reconstruction of it. The question for the committee is whether the club’s policy names such a channel, or whether it assumes the lead is in the hall.
Official guidance and your next step
The primary sources are the DfE’s Keeping children safe in out-of-school settings (the safeguarding guidance for providers), Working Together to Safeguard Children 2026 (paragraphs 86 to 87, 259 and 354 to 359, and the information-sharing chapter), the Charity Commission’s Safeguarding and protecting people for charities and trustees, and the NSPCC’s child protection records retention and storage guidelines (2023). The local safeguarding children partnership publishes the referral route and thresholds; the NSPCC’s Child Protection in Sport Unit and the National Youth Agency publish sector-specific templates.
This guide is a summary of published guidance for England, not a substitute for it and not legal advice. Clubs affiliated to a national governing body or a national youth organisation must follow that body’s safeguarding rules as well; groups in Wales, Scotland and Northern Ireland have their own statutory guidance.
Then do one thing: open the concern record and find the last three entries. For each, ask where the concern was first raised, and whether the club could produce that today.
We build ComplyChat for the work conversations organisations need to keep. The organisational archive described here is available on paid plans, with a connected Microsoft 365 tenant and retention configured by the organisation. A youth club whose safeguarding lead is a volunteer with a day job needs a route that works from a personal phone on a Friday night, and that is what ComplyChat is: a channel the club owns, on a compatible phone, on the record from the first message with every volunteer told so, filing into the club’s own Microsoft 365 once the tenant is connected and kept under the club’s own retention rules, with volunteers, committee members and parents who have no account on any of the club’s systems joining by verified mobile number. It is not a concern record or a case system; it is where a concern and the response can be recorded. A volunteer’s own messages stay in their own apps. There is no WhatsApp, Signal or Meta anything in the path.
How it works · Why us · Pricing · FAQ



