POPIA for churches: a practical guide for South African ministries
Every church holds personal information: member records, giving history, prayer requests, children's details. The Protection of Personal Information Act (POPIA) sets the rules for how you collect, use, store and share it. Here is what it means for a church, and how to put it into practice.
In this guide
- Why a church is a "responsible party" under POPIA
- Religious beliefs and children's information: the special rules
- Your Information Officer and registering them
- Security, breaches and sharing information
- A checklist you can work through this month
Does POPIA apply to my church?
Yes. POPIA applies to any public or private body that processes personal information in South Africa, and churches, ministries and non-profit organisations are included. Processing covers almost anything you do with the information: collecting it on a visitor card, keeping it in a database, emailing it, or deleting it.
In POPIA's terms your church is the "responsible party": the organisation that decides why and how personal information is processed. Software you use to do that work, GraceHub included, acts as your "operator", processing information on your behalf and under your instructions.
The Act's main provisions took effect on 1 July 2020, and organisations had until 30 June 2021 to comply. The Information Regulator now enforces it.
Religious beliefs and children: the rules that matter most to churches
POPIA treats a person's religious or philosophical beliefs as "special personal information" and prohibits processing it, with exceptions. Section 28 provides the one churches rely on: the prohibition does not apply when a religious organisation processes information about people who belong to it, or where it is necessary to achieve the organisation's aims. With conditions, it also covers members' family members, as long as the church keeps regular contact with them and they have not objected in writing.
There is an important limit. Section 28(3) says information about a person's religious beliefs may not be supplied to third parties without that person's consent. Sharing a member list with another organisation, or publishing who attends, needs consent.
Children's personal information has its own rules. Under section 35 a child's information may be processed with the prior consent of a competent person, usually a parent or guardian, or on one of the other grounds the section lists. For a children's ministry that means capturing a parent's consent when a child is registered, and keeping allergy, medical and pickup details only for the reasons you collected them.
Your Information Officer
Every responsible party has an Information Officer. By default it is the head of the organisation; for a church that is usually the senior pastor or the chairperson of the board, who may delegate the work to a deputy.
The Information Officer is responsible for compliance: developing a compliance framework, handling requests from people who want to see or correct their information, and working with the Regulator. Information Officers must be registered with the Information Regulator, which you do on the Regulator's online portal.
Keeping information safe, and what to do if something goes wrong
Section 19 requires appropriate, reasonable technical and organisational measures to protect personal information: limiting who can see what, keeping devices and passwords secure, and checking that the systems you use do the same.
If personal information is accessed or acquired by someone without authority, section 22 requires you to notify the Information Regulator and the affected people as soon as reasonably possible.
Sending personal information outside South Africa is governed by section 72. It is allowed where, for example, the recipient is bound by laws or agreements giving adequate protection, or the person consents. When you choose software, ask where your data is stored.
A POPIA checklist for your church
Work through these with your leadership team. Most take an afternoon, not a project.
- Appoint and register your Information Officer with the Information Regulator
- List the personal information you hold, where it lives, and who can see it
- Publish a privacy notice that says what you collect and why
- Ask for consent where it is needed, and record it: parents for children, members before sharing beyond the church
- Give each volunteer and staff member access only to what their role needs
- Decide how long you keep each kind of record, and delete what you no longer need
- Have a way for people to ask to see, correct or delete their information
- Agree what you will do, and who you will tell, if information is lost or exposed
- Check that your software provider can show how it protects your data and where it stores it
The tools are built in, so the checklist is easier to keep
GraceHub doesn't make a church compliant on its own; your policies and people do that. It gives you the controls those policies rely on.
Access by role
168 permissions decide who can see members, giving, pastoral notes and children's records. Counselling and children's access never come automatically with a broader role.
Your Information Officer on record
Record your Information Officer, choose whether POPIA, GDPR or both apply, and acknowledge your church's role as the responsible party.
Consent on record
Sign-up records a versioned acceptance of the terms and of your church's privacy notice, and GraceHub gives you a privacy notice template to adapt.
Deletion that respects the law
Members can ask for their account to be deleted from the website. Their identity is erased, while giving records are anonymised and kept for the period tax law requires.
Database in Johannesburg
GraceHub's main database runs in Google Cloud's Johannesburg region. Our privacy policy lists the other service providers we use and where they operate.
An audit log
Key administrative actions are recorded, so you can see who changed what.
Common questions about POPIA in churches
Do we need consent to keep a member database?
Not always. Section 28 allows a religious organisation to process information about its own members, including their religious beliefs. You still need a lawful reason for everything you collect, and consent before you share members' information with third parties.
Can we put photos of children on social media?
Only with the prior consent of a parent or guardian, under section 35. Record that consent, and respect it when a parent withdraws it. In GraceHub, parents record photo consent on their child's record, and a child without it is marked on their name tag.
Who should be our Information Officer?
By default, the head of the church. They can delegate the day-to-day work to a deputy Information Officer, but both should be registered with the Information Regulator.
Is our church data safe if it's in the cloud?
It can be, if the provider uses strong security and you control access properly. Ask where the data is stored, who can access it, and how breaches are handled. GraceHub's main database runs in Johannesburg, and you decide who sees what with role-based access.
More on protecting church data
- Security at GraceHub: How GraceHub protects church records, payments and access.
- Your data stays yours: Church-owned records, exports, and deletion.
- Kids check-in: Safe check-in and pickup, with consent and medical details on record.
- GraceHub's privacy policy: How GraceHub itself handles personal information.
Make POPIA part of how your church already works.
Start a GraceHub workspace and set up roles, consent and retention from day one, or talk to us about moving your records across safely.
Start your church's workspace or talk to our team.
This guide is general information, not legal advice. For advice on your church's situation, speak to a legal professional or contact the Information Regulator (inforegulator.org.za).