Data Protection in the Church

Data protection can sometimes feel like an area of church administration which is complicated and easy to put off. Here, we explore what legal requirements churches have and where to start.

PreviewDownload preview

Data Protection in the Church

Data protection can sometimes feel like an area of church administration which is complicated and easy to put off. Here, we explore what legal requirements churches have and where to start.

Data Protection in the Church

Data protection can sometimes feel like an area of church administration which is complicated and easy to put off. Here, we explore what legal requirements churches have and where to start.

Data Protection in the Church

Data Protection in the Church

Data protection can sometimes feel like an area of church administration which is complicated, technical and easy to put off. However, churches handle personal information every day – from the contact details of members and volunteers to prayer requests, pastoral information and details about children and young people. Data is a huge part of church life.

Rather than looking at data protection simply as another piece of legislation that churches need to follow, perhaps we should ask a different question: how can we adequately care for the information that people have entrusted to us?

People trust churches with their personal information, sometimes sharing things that are deeply personal and sensitive. Good data protection is therefore not just about compliance; it is also about being responsible with that trust.

What legally do we have to do?

The Data Protection Act 2018 and the UK GDPR form the core of the UK's data protection framework. These rules have been amended by more recent legislation, including the Data (Use and Access) Act 2025 (DUAA).

The DUAA received Royal Assent in June 2025 and introduces a range of changes to the UK's data protection framework. These include changes relating to areas such as research, privacy notices, automated decision-making and cookie rules, alongside other amendments to the UK GDPR and Data Protection Act 2018. The changes have different commencement dates, so churches should make sure they are working from current guidance. To read more about this, the Information Commissioner’s Office has written about it here.

Churches, like other organisations that process personal data, need to understand the requirements that apply to their activities and put appropriate measures in place.

Two policies and procedures that would be helpful for churches to have are a Data Protection Policy and a Data Retention Policy. These can help set out how personal data should be protected, how information should be handled and how long different types of information should be kept.

However, having policies in place is only part of the picture. It is important that staff and volunteers understand what those policies mean in practice and that the church regularly reviews how it collects, stores, uses and disposes of personal information.

Where could I start?

One helpful place to start when thinking about what data your church currently holds would be to carry out a data audit.

You could begin by asking:

1. What information do we hold?

2. Where is it stored?

3. Why do we hold it?

4. Who has access to it?

5. How long do we keep it?

6. Are we collecting more information than we need?

7. What happens when someone asks us to provide, change or remove their information?

8. What would we do if information was accidentally lost or disclosed?

Answering these questions may help you understand what information your church currently holds about members, volunteers and others, as well as whether all of that information is still needed.

It may also highlight information that has been collected over the years without a clear purpose, is being stored in places it shouldn't be, or is accessible to more people than necessary.

A data audit doesn't have to be complicated. The important thing is to start asking questions about the information your church holds and whether you are looking after it appropriately.

Want to explore data protection further?

If you want to look into data protection more, we have a variety of resources available for you to check out.

Listen to this podcast episode: Gavin talks with Leanne and Harry from the Information Commissioner's Office (ICO), bringing them questions from churches about navigating data protection in a church setting.

The ICO is also hosting its Data Protection Practitioners' Conference online on 13 October 2026. The free virtual event is open to people at all levels of experience, whether you are new to data protection or have more experience in the area. The conference will include practical workshops, panels and information directly from the regulator.

Find out more and register here.

At The Church Office, we don't currently have any dedicated data protection templates. However, one external resource we recommend churches consider is Edward Connor Solicitors' GDPR Pack. It contains model documents designed to help organisations work towards GDPR compliance and maintain their ongoing data protection arrangements. There is a fee for the pack, but to find out more, please click here.

Rachel Stacey
Rachel Stacey
Rachel works for the Church Office, helping with the social media and research for documents and resources. She is passionate about helping with the behind-the-scenes work of church life and all that entails.

Other Document Templates

Sign up and subscribe here to get monthly newsletters about what The Church Office is up to, our latest material and how you can be praying for us!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.