{"id":317,"date":"2026-09-01T13:00:00","date_gmt":"2026-09-01T13:00:00","guid":{"rendered":"https:\/\/missiondefend.com\/blog\/?p=317"},"modified":"2026-07-31T19:55:38","modified_gmt":"2026-07-31T19:55:38","slug":"background-check-records-retention","status":"publish","type":"post","link":"https:\/\/missiondefend.com\/blog\/background-check-records-retention\/","title":{"rendered":"Background Checks: Who Holds Them, For How Long, and How to Destroy Them"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">There is a drawer in most church offices that nobody thinks about.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It holds background-check results. Every volunteer who has ever worked with children, going back as far as the church has been screening people. Some of them are printouts stapled at the corner. Some are in a folder on the shared drive called <em>Screening<\/em>. Most of them, if we&#8217;re honest, are still sitting in the office administrator&#8217;s email as PDF attachments, because that&#8217;s how the screening company delivered them and nobody ever moved them anywhere else.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You did the screening because you take child safety seriously. That was the right call, and your insurer and your denomination probably required it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the screening created something new: a small, concentrated archive of the most sensitive personal information your organization will ever touch, held by an office that was never set up to hold it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This post is about what to do with that archive.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What&#8217;s actually inside one of those reports<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A background check is not a yes-or-no answer. It&#8217;s a document, and the document is dense.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the provider and the level of check, it typically contains the person&#8217;s full legal name and any former names, date of birth, current and previous home addresses, and often all or part of a Social Security number &mdash; because that number is how the provider matches records to the right human being. Then it contains the results: county and state criminal records, sex offender registry checks, sometimes driving records, sometimes credit information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That combination is unusual. Plenty of organizations hold names and addresses. Far fewer hold a name plus a date of birth plus a Social Security number plus a home address, all in one file, for dozens of people at once.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>That specific combination is everything someone needs to open credit in another person&#8217;s name.<\/strong> It is, in practical terms, the highest-value data a small church holds &mdash; more valuable to a thief than your giving records.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And there&#8217;s a second harm on top of the financial one. These files may contain criminal history for volunteers your church screened, considered, and welcomed anyway. A leak doesn&#8217;t just expose an identity. It exposes something a person told you in confidence, about the hardest part of their life, in order to serve. Losing that is a pastoral failure as much as a technical one.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where these files actually end up<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">None of the following is negligence. Every one of them is what happens when a small office handles a task it was given without being given a system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In an inbox, forever.<\/strong> The screening company emails a PDF &mdash; a <strong>PDF<\/strong> is just a document file, and one that keeps its formatting and can be opened by anyone, with no protection unless someone deliberately adds it. It arrives, gets read, gets acted on, and stays in the mailbox. Five years later it&#8217;s still searchable by typing a volunteer&#8217;s last name, and if that mailbox is ever compromised, so is every report in it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In a shared drive folder open to everyone.<\/strong> Cloud drives default to convenient, not restrictive. A folder created by one person is very often visible to every staff account, and sometimes to every volunteer who was ever added to the team drive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In a filing cabinet in an unlocked office.<\/strong> The cabinet may lock. The question is whether it is locked at 4pm on a Thursday when the building is open for choir practice and a dozen people are walking past the door.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For people who left a decade ago.<\/strong> This is the most common one. Nobody ever decided to keep the file of a nursery volunteer who moved away in 2014. Nobody decided to delete it either. Absent a decision, records simply accumulate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>On a former administrator&#8217;s laptop.<\/strong> Someone downloaded the reports to work from home during a busy screening season. That laptop left with them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The rule that fixes most of this<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here it is, and it&#8217;s simpler than any policy document:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Keep the decision. Don&#8217;t keep the report.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Your organization needs to be able to prove that a volunteer was screened, when, by whom, and that they were approved. That&#8217;s a single line in a roster: <em>Name &mdash; screened 14 March 2026 &mdash; provider &mdash; cleared &mdash; approved by [name].<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What your organization almost never needs is the underlying report sitting in your building. The screening company already has it. That&#8217;s their business, they&#8217;re built for it, and they carry insurance for it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the default should be: <strong>the provider holds the report; you hold the record of the decision.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most screening platforms let you view results in their portal rather than emailing them out, and many will let you turn off attachment delivery entirely. Ask your provider two questions: <em>Can results stay in your system instead of being emailed to us?<\/em> and <em>How long do you retain them, and can we retrieve them later if we need to?<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the answer to the first is yes, you have just removed the entire problem from your building.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where you genuinely must keep something &mdash; because your insurer, your denomination, or your state&#8217;s volunteer rules require a copy &mdash; keep the smallest version that satisfies the requirement, and store it in one place, not four.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What the law expects, in general terms<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some real caution here: this is the shape of the rules, not advice about your situation. Requirements differ meaningfully by state, by whether you use a screening company, by the type of work the volunteer does, and by whether the person is an employee or a volunteer. <strong>Your attorney and your insurance carrier should confirm your policy before you adopt it.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With that said, three things are worth knowing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Reports from a screening company are usually &#8220;consumer reports.&#8221;<\/strong> When you buy a background check from a third-party screening company, that report generally falls under the <strong>Fair Credit Reporting Act (FCRA)<\/strong> &mdash; the federal law governing how consumer reporting information is obtained, used, and disposed of. The FTC and EEOC&#8217;s joint guidance for employers walks through the obligations that come with it, including giving the person a clear written notice and getting written permission before you run the check, and giving them a copy of the report and a statement of their rights before you turn them down because of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>There is a federal rule specifically about throwing these away.<\/strong> The FTC&#8217;s <strong>Disposal Rule<\/strong> (16 CFR Part 682) requires anyone who maintains or possesses consumer information for a business purpose to dispose of it &#8220;by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.&#8221; The FTC&#8217;s own business guidance states plainly that &#8220;any business or individual who uses a consumer report for a business purpose is subject to the requirements of the Disposal Rule,&#8221; and names employers among them. Its examples of reasonable measures: &#8220;burn, pulverize, or shred papers,&#8221; and &#8220;destroy or erase electronic files or media&#8221; so the information &#8220;cannot be read or reconstructed.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Retention floors exist and they&#8217;re shorter than you&#8217;d guess.<\/strong> The FTC\/EEOC guidance points to the EEOC&#8217;s requirement that personnel and employment records be &#8220;preserved for one year after the records were made, or after a personnel action was taken, whichever comes later.&#8221; That is an employment rule, and whether it reaches your organization at all depends on your size, on whether the person is an employee or a volunteer, and on how the exemptions for religious employers apply to you. Other floors may apply too &mdash; from your state, your denomination, or your insurer. Ask. But notice the direction of the surprise: the legal floor is often low, and the reason churches keep these files for fifteen years is habit, not law.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a retention rule you&#8217;ll actually follow<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A retention policy that lives in a binder is not a control. Keep it to five sentences someone can act on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Name two people.<\/strong> Access to screening results is limited to two named individuals &mdash; typically the safeguarding lead and one other. Not &#8220;the office.&#8221; Not &#8220;staff.&#8221; Two people, by name, written down. Everyone else sees the roster line, not the report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Pick one location.<\/strong> One folder, one cabinet, one portal. Multiple copies in multiple places is the actual failure mode, because you can clean up the one you remember and miss the three you don&#8217;t.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Write the period down.<\/strong> Something like: <em>background-check results are retained for [X] years after the volunteer&#8217;s service ends, then destroyed<\/em>, with X confirmed by your attorney and insurer. The number matters less than the fact that a number exists.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Put it on the calendar.<\/strong> A recurring annual reminder &mdash; &#8220;review screening files&#8221; &mdash; is what turns a policy into a practice. Without it, nothing is ever destroyed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Write down what you&#8217;ll keep forever.<\/strong> Usually just the roster: who was screened, when, and that they were cleared. That&#8217;s the record that protects the church years later, and it contains no Social Security numbers at all.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Destroying them properly<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Destruction is where good intentions quietly fail, because &#8220;delete&#8221; means less than people think.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>On paper:<\/strong> cross-cut shred, or use a bonded destruction service that gives you a certificate. Do not put them in the recycling bin. Do not put them in the dumpster behind the fellowship hall.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In email:<\/strong> deleting the message is not enough. Empty the trash or deleted-items folder too, and remember that most mail systems keep a further recoverable copy for a period after that. Check whether your provider offers a permanent-delete option, and if attachments were forwarded to anyone, delete them from those mailboxes as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>On a shared drive:<\/strong> delete the file, then empty the drive&#8217;s own trash, which usually runs on a separate timer from your email trash. Then check whether anyone downloaded a copy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In backups:<\/strong> this is the one everyone forgets. Your backup exists precisely to make deletion reversible. A file removed today may sit in backups for months. You usually can&#8217;t and shouldn&#8217;t surgically remove it, and that&#8217;s fine &mdash; but you should know the rotation period, and note that the file isn&#8217;t fully gone until that period has passed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>On old hardware:<\/strong> a retiring laptop or copier can hold every report ever printed. Have drives wiped or destroyed before anything leaves the building.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What to do this week<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Search your own mailbox for the name of your screening provider, and see how many reports come back. That number, whatever it is, is the honest starting point &mdash; and finding it takes about five minutes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then do one thing: call the provider and ask whether they can stop emailing results and let you view them in their portal instead. That single change stops the pile from growing while you decide what to do about the files you already have.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sensitive records are one of several places churches carry more risk than they realise. MissionDefend&#8217;s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts &mdash; including where sensitive records like these actually live &mdash; and returns a baseline score with a ranked list of what to fix first.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-35f06ea7 wp-block-buttons-is-layout-flex\">\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/missiondefend.com\/#notify\" style=\"border-radius:999px\">Join the launch list &rarr;<\/a><\/div>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">No spam and no sales calls &mdash; just one email when it&#8217;s live.<\/p>\n\n\n\n<h2 class=\"wp-block-heading md-related\">Related reading<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/data-retention-deletion\/\">building a retention rule you will actually follow<\/a><\/li>\n\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/pastoral-counseling-notes\/\">the care files that deserve the same restraint<\/a><\/li>\n\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/breach-notification-nonprofits\/\">what exposure of a Social Security number triggers<\/a><\/li>\n\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sources:<\/strong> Federal Trade Commission and Equal Employment Opportunity Commission, <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/background-checks-what-employers-need-know\" target=\"_blank\" rel=\"noopener\">Background Checks: What Employers Need to Know<\/a>; Federal Trade Commission, <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/disposing-consumer-report-information-rule-tells-how\" target=\"_blank\" rel=\"noopener\">Disposing of Consumer Report Information? Rule Tells How<\/a>; Electronic Code of Federal Regulations, <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-F\/part-682\/section-682.3\" target=\"_blank\" rel=\"noopener\">16 CFR \u00a7 682.3 &mdash; Proper disposal of consumer information<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Volunteer background checks hold Social Security numbers and dates of birth. Who should keep them, for how long, and how to destroy them properly.<\/p>\n","protected":false},"author":1,"featured_media":235,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[96,98,88,99,97],"class_list":["post-317","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-protecting-information","tag-background-checks","tag-fcra","tag-records-retention","tag-secure-disposal","tag-volunteer-screening"],"_links":{"self":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/comments?post=317"}],"version-history":[{"count":1,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/317\/revisions"}],"predecessor-version":[{"id":358,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/317\/revisions\/358"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media\/235"}],"wp:attachment":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media?parent=317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/categories?post=317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/tags?post=317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}