Christian Ethics Article | AURP-2026-005
Data, Privacy, and the Care of Souls: A Christian Ethic of Congregational Information
Institutional author: Abide University
Series: Abide University Research Papers | Published: 2026-07-12
Abstract
Congregations hold some of the most sensitive information about people that any institution collects: records of confession and pastoral crisis, addiction and mental illness, marital breakdown, immigration status, sexuality, financial distress, and the whereabouts of people fleeing violence. They hold it with less governance than a small clinic and often with none at all. This article develops a Christian ethic of congregational information from the biblical vocabulary of knowing and being known, the tradition of confession and the seal, and the pastoral obligation to the vulnerable. It argues that data minimization is a pastoral discipline rather than a regulatory imposition: information a congregation does not hold cannot be leaked, subpoenaed, misused by a future leader, or weaponized in a dispute. It examines the specific tension between confidentiality and safeguarding, which cannot be resolved by treating either as absolute, and sets out how the boundary should be drawn and disclosed in advance. It then addresses pastoral records, engagement analytics, giving records, photographs of children, breach response, third-party processors, and retention. The article concludes that the governing question for any congregational data practice is whether it serves the person the information is about, and that a congregation which cannot answer that question should not hold the information.
Research Question and Scope
What ethical obligations does a congregation incur by holding sensitive information about the people in its care, how should the tension between pastoral confidentiality and the protection of the vulnerable be resolved, and what governance follows from a theological rather than merely regulatory account of privacy?
Method and Source Selection
The study develops its normative framework from three sources in sequence: the biblical vocabulary of knowledge, disclosure, and concealment; the historical development of confession and the seal in Christian pastoral practice across traditions; and the contemporary pastoral obligations that arise where congregations hold information about vulnerable people. Scriptural texts are cited by book, chapter, and verse so that each reading can be examined directly.
Contemporary data protection regimes are described generically rather than by jurisdiction, because obligations differ substantially between legal systems and any specific account would be inaccurate somewhere. The article treats regulatory requirements as a floor that frequently coincides with pastoral obligation rather than as the source of that obligation, and it identifies several points at which the pastoral standard is more demanding than the legal one.
No congregational records, incident reports, or safeguarding files were examined, and no organization is assessed. Descriptions of failure patterns are drawn from published guidance, from the findings of public inquiries into institutional abuse where those are matters of public record, and from the general literature on information governance. The article offers no legal advice and does not attempt to state reporting duties, which vary by jurisdiction and profession.
1. What congregations actually hold
An honest inventory is the necessary starting point, and most congregations have never made one. A typical church holds names, addresses, telephone numbers, and dates of birth for members and their children; attendance and participation records; giving records tied to individuals; prayer requests that frequently disclose diagnoses, bereavements, and family crises; pastoral notes of varying formality; safeguarding records; employment and volunteer files including background check outcomes; membership applications that may record religious history and conversion accounts; and correspondence of every kind.
Much of this falls into categories that data protection regimes treat as requiring heightened protection, and which pastoral judgment would identify as sensitive without any regulatory prompting: information about health, religious belief, sexual orientation, criminal records, and children. Congregations frequently hold all five, about the same individuals, in systems designed for none of them, accessible to volunteers who have signed nothing, and retained indefinitely because no one has ever considered deleting anything.
The risk is not hypothetical, and its most serious forms are pastoral rather than technical. A prayer chain that circulates a member's cancer diagnosis to people they did not choose to tell has caused a specific harm. A church directory that lists the address of a member who has fled a violent partner can endanger a life. A pastoral note recording a disclosure of abuse, stored in a shared folder, can be read by the person the disclosure concerns. Records of immigration status can expose people to consequences the congregation never contemplated.
Congregations also hold information under conditions of unusual trust. People disclose to clergy what they disclose to almost no one, often at the worst moments of their lives, and they do so on an assumption about confidentiality that has usually never been stated explicitly and may not match what the congregation actually practices. That gap between the assumed and the actual is the source of a large proportion of the harm examined in this article, and closing it requires saying out loud what is normally left implicit.
The first practical step is therefore an inventory: what is held, where, by whom, why, who can see it, and for how long. Congregations that undertake this typically discover holdings they had forgotten - an old membership database on a former administrator's laptop, a filing cabinet of counselling notes from a previous minister, a spreadsheet of pastoral concerns emailed among elders for a decade. Discovering these is uncomfortable and is the necessary condition of governing them.
2. Knowing and being known: the biblical vocabulary
Scripture's account of knowledge between persons is neither a celebration of transparency nor a defence of concealment. It holds two things together. God's knowledge of persons is complete and is presented as a comfort rather than a threat: you have searched me and known me, you know when I sit down and when I rise up, you discern my thoughts from far away (Psalm 139:1-6). The psalm's response to being wholly known is not alarm but wonder, and it ends with an invitation to further searching (Psalm 139:23-24).
Human knowledge of other humans is treated quite differently. It is partial, easily corrupted, and frequently weaponized. The Lord does not see as mortals see; they look on the outward appearance, but the Lord looks on the heart (1 Samuel 16:7). Paul writes that now we see in a mirror, dimly, and know only in part (1 Corinthians 13:12), and elsewhere refuses to judge even himself, leaving that to the Lord who will bring to light the things now hidden in darkness (1 Corinthians 4:3-5). Human beings are not equipped to hold complete knowledge of one another well.
This distinction has direct governance consequences. The comfort of being wholly known by God does not transfer to being wholly known by an institution, because the institution lacks God's love, God's justice, and God's discretion. A congregation that accumulates comprehensive knowledge of its members has not thereby imitated divine care; it has assumed a position it is not competent to occupy. The appropriate posture toward information about another person is therefore restraint rather than completeness.
Scripture is correspondingly severe about the misuse of information. The commandment against false witness (Exodus 20:16) addresses testimony, but the wider tradition extends to gossip: a gossip goes about telling secrets, but one who is trustworthy in spirit keeps a confidence (Proverbs 11:13); whoever goes about slandering reveals secrets, so do not associate with a babbler (Proverbs 20:19). Leviticus places the prohibition on slander directly alongside the obligation not to profit by the blood of your neighbour (Leviticus 19:16), which indicates how seriously disclosure was regarded.
At the same time, Scripture refuses to make concealment a virtue in itself. Nothing is hidden that will not be disclosed (Luke 8:17; 12:2-3). Sin concealed does not prosper, but one who confesses and forsakes obtains mercy (Proverbs 28:13). Confession to one another is commanded (James 5:16). The tradition therefore supports neither an institutional practice of accumulating information about people nor an institutional practice of concealing wrongdoing, and the two are frequently confused: churches have often protected the privacy of perpetrators while exposing the vulnerability of victims, which inverts both principles simultaneously.
3. Confession, the seal, and the traditions of pastoral confidence
Christian traditions have developed markedly different accounts of pastoral confidentiality, and congregations should know which one they actually operate under rather than assuming a shared standard. In the Roman Catholic tradition the sacramental seal is absolute: the confessor may not disclose what is confessed for any reason, and canon law treats violation with the gravest penalties. The Orthodox tradition maintains a comparable, though not identically formulated, obligation. Anglican practice historically recognizes a strong seal, with the extent of any exception contested and addressed differently by different provinces.
Protestant traditions without sacramental confession generally treat pastoral confidentiality as a strong but defeasible professional obligation rather than an absolute seal. The practical result is that a member disclosing something to a Baptist pastor, a Catholic priest in the confessional, and a Presbyterian elder is operating under three different regimes, and almost none of them will have been told which. This is a failure of disclosure that congregations can remedy cheaply by stating their policy in writing and referring to it before, rather than after, a disclosure occurs.
Civil law adds a further layer that varies substantially. Many jurisdictions recognize some form of clergy-penitent privilege, but its scope, the communications it covers, who holds it, and its interaction with mandatory reporting obligations differ widely, and several jurisdictions have narrowed or removed the exemption for child abuse disclosures following public inquiries. Clergy should know the position in their own jurisdiction with precision, because acting on a general impression is unsafe in both directions - it risks both unlawful concealment and unnecessary breach.
The theological rationale for a strong seal deserves to be understood rather than dismissed, because it is not merely institutional self-protection. The argument is that a penitent must be able to confess without calculation if confession is to be honest, that a confessor who might disclose becomes an investigator rather than a minister of absolution, and that the practice of confession itself would collapse if its confidentiality were contingent. These are serious claims, and they have weight even for traditions that reach a different conclusion.
The counter-argument is equally serious and has been pressed forcefully by inquiries into institutional abuse: that an absolute seal has in practice permitted ongoing abuse to continue with the knowledge of clergy, and that the harm to children has been concrete while the benefit to penitents is speculative. This article does not adjudicate between traditions on the sacramental question. It does insist that every congregation, whatever its position, must be able to state clearly what it will and will not keep confidential, and must say so before someone discloses in reliance on a assumption the congregation does not share.
4. Safeguarding: where confidentiality yields and how to say so
Outside sacramental confession, the boundary that matters most is safeguarding. Where a disclosure indicates that a child or a vulnerable adult is at risk, the obligation to protect ordinarily overrides the obligation to keep confidence, and in many jurisdictions this is a legal duty rather than a matter of discretion. Congregations should treat this as settled rather than as a difficult judgment to be made under pressure by whoever happens to receive the disclosure.
The practical requirement is advance disclosure of the limit. Anyone who might receive a disclosure - clergy, elders, youth workers, small group leaders, pastoral visitors - should be able to say, before a conversation becomes serious, that they will keep what is said confidential except where someone is at risk of serious harm, and that in that case they will have to tell a specific person. Saying this in advance is not a deterrent to disclosure; the evidence from safeguarding practice generally suggests that clarity about limits increases rather than decreases trust, because it removes the fear of unpredictable betrayal.
A common and damaging failure is the promise that cannot be kept. A leader who says that whatever you tell me stays between us, and then must report, has both broken a promise and taught the person that Christian assurances are unreliable at the moment they matter. The remedy is to train everyone in a pastoral role never to offer unconditional confidentiality, and to give them a form of words they can use naturally. This is a small training intervention with disproportionate effect.
Where a disclosure must be passed on, the person should be told what will happen, by whom, and when, unless doing so would increase risk. Being reported without knowledge compounds the loss of control that abuse has already inflicted, and survivors consistently identify it as a further harm. Where their wishes cannot be followed, the reason should be explained rather than concealed behind procedure. The obligation to protect does not license treating the person disclosing as an item of information rather than a person.
Records of safeguarding matters require the strictest handling a congregation applies to anything. They should be written contemporaneously, factually, distinguishing what was observed from what was inferred, stored separately from general pastoral records with restricted access, retained according to the applicable retention requirements which are often long, and never discussed with people who have no role in the response. Congregations that circulate safeguarding concerns among leadership generally, or that discuss them in meetings with minutes, have created a document trail that will damage the very people it was meant to protect.
5. Minimization as pastoral discipline
The single most effective information practice available to a congregation is to hold less. Information not collected cannot be breached, subpoenaed, misused by a successor, circulated in a dispute, or discovered by the wrong person. Data protection regimes express this as minimization and purpose limitation - collect what is necessary for a stated purpose and no more - but the pastoral case is stronger than the regulatory one and rests on the theological point made earlier: a congregation is not competent to hold comprehensive knowledge of its members.
The discipline is applied by asking, of each item collected, what decision it enables and what would go wrong if it were not held. Membership forms that ask for conversion narratives, previous church discipline, medical history, or family circumstances should be able to answer this. Frequently they cannot, and the item is there because the form was inherited or because someone thought it might be useful. Useful-in-principle is not a purpose, and it is the reasoning by which congregations accumulate holdings they later cannot defend.
Prayer requests are the clearest case where minimization and pastoral practice interact directly. A request circulated to a list can disclose a diagnosis, a pregnancy loss, a mental health crisis, or a family member's addiction to dozens of people. The remedy is not to stop praying for one another but to obtain specific consent about what may be shared and with whom, to default to the minimum - a name and a request for prayer without detail - and to distinguish clearly between what is prayed for publicly, what circulates on a list, and what a single person holds.
Aggregation deserves particular attention because it creates sensitivity that no individual item possesses. A name, an address, an attendance pattern, a giving level, and a set of prayer requests are each modest; combined, they constitute a detailed profile of a person's life, beliefs, finances, and vulnerabilities. Congregations should therefore govern access at the level of the combined record rather than item by item, and should resist the convenience of systems that present everything about a person on one screen to anyone with a login.
Minimization also applies to time. Information that was necessary for a purpose ceases to be necessary when the purpose ends, and continuing to hold it converts a legitimate collection into an indefinite one. A congregation that deletes volunteer applications after a defined period, closes pastoral files when a matter concludes, and removes former members' records on a schedule has substantially reduced its risk without any technical investment. The obstacle is almost never capability; it is the absence of a decision that anything should ever be deleted.
6. Consent, power, and members who cannot easily refuse
Consent is the usual justification for collecting information, and in congregational settings it is frequently not what it appears to be. Consent is meaningful only where refusal is realistically available without cost. A member asked by their pastor to complete a detailed form, a young person asked to sign a photography release in front of their peers, a person receiving material assistance asked for information by the people providing it, and an employee asked by their employing church are all in positions where refusal carries social or material cost.
The theological frame for this is the New Testament's repeated concern about the exercise of power in the church. Leaders are not to lord it over those in their charge (1 Peter 5:3; Mark 10:42-45), and Paul repeatedly refuses to use authority he possesses in order to avoid placing an obstacle in anyone's way (1 Corinthians 9:12). Applied to information, this suggests that a congregation should not rely on consent from people whose position makes refusal difficult, and should instead ask whether the collection would be justified without consent.
Practical safeguards follow. Forms should mark clearly which fields are optional and mean it. Alternatives should exist for people who decline - a directory entry without an address, participation without a photograph, assistance without a detailed application. Requests should come with a stated purpose and a stated retention period. And the person asking should not be the person with authority over the outcome where that can be avoided, since separating the request from the power reduces the pressure without reducing the information's usefulness.
Particular care is owed to people in acute need. Someone seeking emergency financial help, food, shelter, or immigration advice is in no position to negotiate about data, and congregations providing such services should collect the minimum required to provide them, should not condition help on information unrelated to it, and should be especially careful about retention. Records of who received assistance are sensitive indefinitely, and their existence can expose people long after the need has passed.
Children present a distinct problem because consent is normally given by a parent for a person who will later have views of their own. A photograph taken at nine and published permanently was consented to by someone else. Congregations should therefore apply a higher threshold to children's information than parental permission alone provides: minimize what is recorded, avoid publishing identifiable images with names, provide a straightforward route for a young person to withdraw material about themselves when they are older, and treat the young person's own reluctance as decisive even where a parent has agreed.
7. The pastoral record: what should be written, and what should not
Clergy and pastoral workers keep notes, and the practice is defensible: memory is unreliable, continuity of care requires some record, and in safeguarding contexts contemporaneous notes are essential. But pastoral notes are also uniquely dangerous, because they combine sensitive disclosure with the writer's private judgments, and because they will be read in circumstances the writer did not anticipate - by a successor, by a court, by the person concerned exercising a right of access, or by a congregation in the aftermath of a dispute.
A workable discipline distinguishes three kinds of content. Facts about what happened and what was agreed are appropriate to record and are the reason for keeping notes at all. Clinical or quasi-clinical judgments - speculation about diagnoses, assessments of a person's mental state, theories about family dynamics - are generally inappropriate for pastoral notes because the writer is not qualified to make them and the record will carry more authority than the judgment deserves. Personal opinions about the person's character are inappropriate in every case.
The test that most reliably improves pastoral notes is to write as though the person concerned will read them, because in many jurisdictions they have a right to and in practice they often do. This discipline eliminates a large proportion of the material that causes harm, and it rarely removes anything useful. Where something genuinely cannot be written in a form the person could read, that is usually an indication that it should be discussed with a supervisor rather than recorded.
Storage and succession require deliberate arrangement. Notes held in a minister's personal email, on a personal device, or in a private notebook pass out of the congregation's control entirely and typically leave with the minister, which is a problem for continuity and a worse problem if they are retained. Congregations should specify where pastoral records are kept, who may access them, what happens on a change of minister, and what is destroyed rather than transferred. A departing minister taking a decade of pastoral notes to their next post is a common and serious failure.
Finally, congregations should be candid that some things are better not written at all. A disclosure made in confidence that carries no safeguarding implication and requires no institutional action may not need a record, and creating one converts a pastoral conversation into a permanent document. The judgment is genuinely difficult and depends on tradition, jurisdiction, and circumstance, but it should be made deliberately according to a stated policy rather than by the habits of whoever holds the pen.
8. Analytics, engagement scoring, and the temptation to surveil
Church management systems increasingly offer analytics: attendance patterns, engagement scores, giving trends, predicted disengagement, and dashboards ranking members by involvement. The stated purpose is pastoral - to notice who is drifting before they disappear - and that purpose is genuine. The tools nonetheless deserve scrutiny, because a mechanism designed to notice absence is structurally identical to a mechanism designed to monitor compliance, and the difference lies entirely in how it is used and who can see it.
The pastoral case for noticing is strong and biblical. The shepherd leaves the ninety-nine to seek the one that is lost (Luke 15:4-7); the New Testament assumes leaders know their people well enough to warn the idlers, encourage the fainthearted, and help the weak (1 Thessalonians 5:14). A congregation past a certain size cannot do this from memory. A record that prompts someone to notice that a member has not been seen for six weeks, and to make a phone call, is doing something the New Testament plainly wants done.
The concerns are equally concrete. An engagement score is an institutional judgment about a person, usually computed from proxies that measure availability rather than devotion, and it is frequently visible to more people than any pastoral judgment should be. It systematically disadvantages members whose circumstances limit participation - carers, shift workers, people with chronic illness or disability, the poor - and it can convert a pastoral relationship into a performance record. Where scores influence eligibility for roles or membership, the effect is a quantified spiritual hierarchy that the New Testament's account of gifts and body membership contradicts directly.
Reasonable practice can be specified. Analytics should trigger a human contact rather than an assessment, and the output should be a question rather than a conclusion. Scores should not be visible to anyone without a pastoral responsibility for the person, should not be shown to the person's peers, and should not determine access to ministry roles. Where a system produces a ranking, congregations should ask whether they would be comfortable showing each member their own record and its position, since the answer indicates whether the tool is serving the person or the institution.
A deeper caution concerns what measurement does to attention. Metrics direct pastoral effort toward what is measured, and what is measured is what the software counts: attendance, giving, group membership, service. The members whose needs are invisible to such systems - the isolated attender who comes every week and speaks to no one, the person whose crisis has not yet produced any change in behaviour - become correspondingly harder to see. A congregation adopting analytics should deliberately maintain practices that surface what the data cannot, since the data's silence is not evidence of wellbeing.
9. Giving records and the discipline of not knowing
Individual giving records are among the most sensitive holdings a congregation has, and they are also the ones most likely to be accessible to leaders who have no operational need for them. The pastoral argument for restricting access is straightforward and rests on a text that addresses the situation directly: James condemns a congregation that treats the person with gold rings and fine clothes differently from the poor person in dirty clothes, and calls it judging with evil thoughts (James 2:1-4).
The practice adopted by many congregations - that the preaching minister does not have access to individual giving records - is a structural safeguard rather than a statement about any individual's integrity. Knowledge of what a member gives affects pastoral relationships in ways that are largely unconscious and therefore not correctable by good intentions. It affects who is consulted, whose objection carries weight, whose call is returned first, and what a preacher feels able to say. Structural ignorance removes the effect at its source.
Traditions differ on this, and there are serious arguments on the other side: that giving is a discipleship matter about which a pastor should be able to speak, that a sudden cessation of giving may indicate financial crisis and therefore pastoral need, and that separating the minister from financial reality is unhealthy. These arguments have force. They can largely be accommodated by having someone other than the preaching minister monitor for pastorally significant changes and raise them without disclosing amounts, which captures the benefit without the exposure.
Whatever the policy, it should be written and communicated to givers. People are entitled to know who can see what they give, and many assume a confidentiality that does not exist. Access should be limited to named roles, logged where systems permit, and reviewed. Giving records should never be used to construct member rankings, to select people for leadership, or to determine who is invited to consultations about the congregation's direction, and a congregation should be able to demonstrate that they are not.
Fundraising practice raises a related issue. Techniques imported from the nonprofit sector - wealth screening, donor segmentation, cultivation of major gifts - apply commercial logic to a relationship the New Testament describes in quite different terms. A congregation that segments its members by giving capacity and directs pastoral attention accordingly has adopted the practice James condemns, however professionally it is executed. Congregations should be able to state clearly which fundraising techniques they use and why they consider them compatible with treating members impartially.
10. Children, images, and the permanence of publication
Photographs and video of children are among the most common congregational data practices and among the least governed. Images are taken at services, camps, and children's activities, and published on websites and social platforms, frequently with names, sometimes with the activity and location, and almost always permanently. Each of these elements individually is minor; together they can identify a child, establish where they can be found at predictable times, and create a permanent record the child never agreed to.
Safeguarding guidance across many denominations and national bodies has converged on a set of practices that are neither burdensome nor controversial: obtain permission specific to the intended use rather than a blanket release, do not publish full names alongside identifiable images, avoid images that indicate where and when a child can regularly be found, use images that do not focus on individual children where a group image serves, and provide a simple mechanism to withdraw permission that actually results in removal.
Congregations should also recognize the special categories where publication can endanger. Children in foster care or subject to custody arrangements, children of parents fleeing domestic violence, children in families with insecure immigration status, and children from religious backgrounds where a Christian association carries risk to their family may all be harmed by a photograph that would be harmless for another child. Since a congregation cannot reliably know which children fall into these categories, the safe default is restraint applied generally rather than exceptions granted on request, which requires families to disclose their situation in order to be protected.
The permanence question deserves separate attention because it is genuinely new. A child photographed today may be identifiable through that image for their entire life, in contexts and by technologies that cannot be anticipated. Consent given by a parent cannot meaningfully cover that horizon. Congregations should therefore take a deliberately conservative position on publishing identifiable images of minors, should honour requests from young adults to remove childhood material, and should recognize that convenience for the congregation's communications is a weak interest against a lifelong exposure for the child.
The same principles extend, with modification, to vulnerable adults and to anyone whose participation might carry risk: people in recovery, people who have recently converted from another religious tradition, asylum seekers, and people escaping abusive relationships. A congregation that films its services should have a clearly marked area outside camera range, should announce that recording is taking place, and should not treat presence at a public service as consent to being broadcast. These measures cost almost nothing and prevent harms that cannot be undone afterward.
11. Security, breach, and the duty to tell the truth
Technical security in congregations is generally weak, and the reasons are structural rather than negligent: systems are administered by volunteers, budgets are small, and staff turnover is high. The measures that address the majority of realistic risk are nonetheless within reach of any congregation. Multi-factor authentication on every account holding personal data, individual rather than shared logins, prompt removal of access when someone's role ends, encrypted devices, current software, and backups that are tested rather than assumed will together prevent most common incidents.
Access control deserves emphasis because it is where congregations most often fail. Shared administrator passwords circulated among volunteers, accounts belonging to people who left years ago, and systems where every user can see every record are extremely common. The remedy is a documented list of who has access to what, reviewed periodically, and a defined process for revoking access when a person's role changes. This is administrative rather than technical work and requires no expertise.
Breach response should be planned before it is needed, since the decisions are difficult to make well under pressure. A plan should identify who is notified internally, who assesses the scope, what the containment steps are, what regulatory notification obligations apply and within what deadline, and how affected individuals are informed. The default should be that people whose information was exposed are told, promptly and specifically, what was disclosed and what they should do.
The theological argument against concealing a breach is the same one that applies to every other institutional failure. A community that claims to walk in the light (1 John 1:7), that is warned that nothing hidden will remain undisclosed (Luke 8:17), and whose credibility depends on being seen to tell the truth about itself cannot conceal a disclosure of members' sensitive information without forfeiting something more valuable than it protects. Concealment also removes the affected person's ability to take protective action, which converts an accident into a harm the congregation has chosen.
Insurance and legal advice are practical necessities rather than a failure of trust, and congregations should confirm whether their existing policies cover data incidents, which many do not. Denominational bodies can serve small congregations substantially here by negotiating cover, publishing model policies, and providing an incident response contact, since a congregation facing its first breach on a weekend has neither the expertise nor the composure to work out what to do from first principles.
12. Vendors, platforms, and where the information actually lives
Very little congregational data now sits only in the church building. Church management systems, email providers, giving platforms, video conferencing services, social platforms, cloud storage, and communication applications all hold members' information on infrastructure the congregation does not control and under terms it has usually not read. This is not inherently wrong, and self-hosting is generally worse for security in the hands of volunteers, but it does mean the congregation has made decisions about members' data that it may not know it has made.
The basic diligence is modest. A congregation should know which providers hold personal data, what the contract says about ownership and use, whether the provider uses the data for its own purposes, where it is stored geographically, what happens on termination, and whether the data can be exported in a usable form. The last of these is more important than it appears, since a congregation that cannot extract its records is captive to a provider's pricing and continued existence.
Free services warrant particular scepticism, because the business model has to be somewhere. A platform that costs nothing and holds a congregation's contact list, communications, and engagement records may be monetizing the data, and congregations should read the terms rather than assume that a service marketed to churches operates on charitable principles. Using a general-purpose social platform as the primary repository of pastoral communication is a decision with consequences that should be examined rather than drifted into.
Congregations should also consider what they publish about members without thinking of it as data. Rotas naming who is on duty, newsletters listing prayer concerns, sermon illustrations drawn from members' lives, and social posts identifying attenders are all disclosures. Sermon illustrations deserve specific mention: a preacher describing a pastoral encounter, even anonymized, is frequently identifiable to the congregation, and members who recognize themselves learn that their disclosures may become public material. Explicit permission should be sought, and the answer accepted.
Where a congregation transfers data to another party - a denomination, a mission agency, a background-check provider, an external counsellor - the basis for the transfer and the recipient's obligations should be established in writing. This is a common gap: information collected for congregational purposes is passed to affiliated bodies on the assumption that they are part of the same family, when they are legally and practically separate organizations with their own retention and use practices.
13. Retention, deletion, and letting people leave
Congregations delete almost nothing, and the accumulated result is a holding of information about people who left decades ago, records of resolved matters, and files whose subjects are dead. Some retention is required - safeguarding records typically have long mandated periods, and financial and employment records have their own - but the great majority is retained because deletion was never considered rather than because it was decided.
A retention schedule is the remedy and is not difficult to produce: a list of record types, the period each is held, the trigger that starts the clock, and what happens at the end. Producing one forces the useful question of why each holding exists. Applying it requires someone to be responsible, since schedules that exist without an owner are aspirational documents that change nothing. Annual review, with actual deletion performed and recorded, is what converts policy into practice.
The pastoral dimension of deletion is more significant than it first appears. People leave congregations, sometimes after conflict, sometimes after being hurt, sometimes because they have left the faith. Continuing to hold detailed records about them, to contact them, and to retain notes of their pastoral crises is a refusal to let them go. Where a former member asks for their information to be removed, congregations should comply so far as their obligations allow, and should explain clearly what must be retained and why rather than treating the request as a difficulty.
This connects to a broader posture about how congregations treat those who depart. The New Testament's discipline procedures contemplate exclusion in serious cases (Matthew 18:17; 1 Corinthians 5:11-13), and also the restoration of the person who repents, whom the community is urged to forgive and console so that they are not overwhelmed by excessive sorrow (2 Corinthians 2:6-8). Neither is served by an indefinite institutional memory of the matter, and the congregation that reaffirms love while retaining a permanent file has not fully done the former.
Death raises its own questions that congregations rarely address. Records about a deceased member typically fall outside data protection regimes but remain sensitive to surviving family, and pastoral notes recording a person's confessions, doubts, or family conflicts can cause serious harm if read by relatives. Congregations should have a policy on what is retained after death, who may access it, and what is destroyed, and should consider that the deceased person's own interest in the confidentiality of their disclosures does not end with them.
14. A governance framework for congregational information
The framework that emerges is organized around a single question applied to every holding: does this serve the person the information is about? A congregation that can answer this affirmatively and specifically for each category it holds has a defensible practice. Where the honest answer is that the information serves the institution's convenience, its planning, or its fundraising, the holding requires separate justification and usually requires reduction.
Operationally, six elements constitute adequate governance for a congregation of any size. An inventory of what is held, where, and why. A named person accountable for information practice, with the authority to enforce it. A written statement of pastoral confidentiality and its limits, communicated before disclosures rather than after. A retention schedule that is actually applied. Access controls reviewed periodically. And a breach response plan with the presumption that affected people are told.
Three further practices address the specifically pastoral risks. Prayer requests default to the minimum and are shared only with specific consent. Individual giving records are restricted from the preaching ministry and from any process determining roles or influence. Images of children are published sparingly, without names, and removable on request. Each of these is a small operational constraint that prevents a category of harm the congregation would otherwise inflict without intending to.
None of this requires technical sophistication, and congregations should resist the assumption that information governance is a matter for specialists. The failures examined in this article are overwhelmingly failures of decision rather than of capability: nobody decided what would be kept confidential, nobody decided what would be deleted, nobody decided who could see the giving records, and nobody decided whether the prayer list would circulate a diagnosis. Making the decisions is the work.
The theological centre holds all of it together. A congregation exists to care for people, and information is one of the instruments of that care and one of the instruments by which people are harmed. Scripture's account of human knowledge - partial, corruptible, easily turned into gossip and judgment - counsels restraint rather than accumulation, and its account of confidence - keeping a secret is the mark of one trustworthy in spirit (Proverbs 11:13) - identifies the discipline required. A church that holds less, tells people clearly what it holds, and can be trusted with what it does hold has met the standard the tradition actually sets.
Limitations
- Data protection law, mandatory reporting duties, clergy-penitent privilege, and safeguarding requirements differ substantially between jurisdictions and are actively changing in several. Nothing in this article constitutes legal advice, and congregations must establish their obligations under their own applicable law before adopting any practice described here.
- Christian traditions hold materially different positions on the sacramental seal of confession, and this article deliberately declines to adjudicate between them. Its requirement is procedural rather than doctrinal: that each congregation be able to state its position clearly and communicate it before disclosures are made in reliance on assumptions the congregation does not share.
- No congregational records, safeguarding files, incident reports, or church management systems were examined for this study, and no product, provider, or organization is evaluated. Descriptions of common failure patterns are drawn from published guidance and from public inquiry findings that are matters of public record.
- The technical security recommendations describe well-established general practice rather than a current threat assessment, and specific tools and platform behaviours change quickly enough that any product-level guidance would be obsolete before it was useful. Congregations handling unusually high-risk information should obtain specialist advice.
- The article assumes a congregation operating in a legal environment where records are not themselves a source of danger to members. Churches in contexts of surveillance or persecution, where membership records can expose believers to arrest or violence, face a different threat model in which minimization becomes a matter of physical safety and much of the administrative guidance here is inadequate.
Conclusion
Congregations hold information of a sensitivity that few institutions match, under governance that few institutions would accept, and they do so because the holdings accumulated without anyone deciding that they should. The remedy is not primarily technical. It is the making of decisions that have never been made: what is kept confidential, what is written down, what is deleted, who can see it, and what happens when it goes wrong.
The theological argument for restraint is stronger than the regulatory one. Scripture presents complete knowledge of a person as something only God holds well, treats human knowledge of others as partial and easily corrupted, and is severe about the disclosure of confidences. A congregation that accumulates comprehensive knowledge of its members has not imitated divine care but assumed a competence it does not have, and minimization is therefore a pastoral discipline before it is a compliance obligation.
The tension between confidentiality and safeguarding cannot be resolved by treating either as absolute, and it should not be resolved under pressure by whoever receives a disclosure. It should be settled in advance, written down, taught to everyone in a pastoral role, and stated to people before they disclose. The promise that cannot be kept is the specific failure to eliminate, and the form of words that prevents it takes ten seconds to learn.
The governing test for every practice examined here is whether it serves the person the information is about. Prayer requests, pastoral notes, engagement analytics, giving records, and photographs of children each pass or fail that test on their particulars, and a congregation willing to apply it honestly will find that it should hold less, share less, and keep less than it does. Holding less is not a diminished form of care. Given what congregations are actually trusted with, it is a condition of deserving the trust.
References
- The Holy Bible, New Revised Standard Version Updated Edition. (2021). National Council of Churches.
- Gregory the Great. (c. 590). The Book of Pastoral Rule (Regula Pastoralis).
- McNeill, J. T. (1951). A History of the Cure of Souls. Harper & Brothers.
- Tentler, T. N. (1977). Sin and Confession on the Eve of the Reformation. Princeton University Press.
- Catholic Church. (1997). Catechism of the Catholic Church (2nd ed.), sections 1467 and 2488-2492 on the sacramental seal and respect for reputation and privacy.
- Code of Canon Law. (1983). Canons 983-984 on the inviolability of the sacramental seal.
- Swinton, J. (2007). Raging with Compassion: Pastoral Responses to the Problem of Evil. Eerdmans.
- Osmer, R. R. (2008). Practical Theology: An Introduction. Eerdmans.
- Nissenbaum, H. (2010). Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Press.
- Solove, D. J. (2008). Understanding Privacy. Harvard University Press.
- Campbell, H. A. (Ed.). (2020). Digital Ecclesiology: A Global Conversation. Digital Religion Publications, Texas A&M University.
- Waltke, B. K. (2004-2005). The Book of Proverbs (New International Commentary on the Old Testament, 2 vols.). Eerdmans.
- Second Vatican Council. (1965). Dignitatis Humanae: Declaration on Religious Freedom.
- Second Vatican Council. (1965). Gaudium et Spes: Pastoral Constitution on the Church in the Modern World, section 26 on the rights of the person.