POPIA for churches: a practical guide for South African ministries

Every church holds personal information: member records, giving history, prayer requests, children's details. The Protection of Personal Information Act (POPIA) sets the rules for how you collect, use, store and share it. Here is what it means for a church, and how to put it into practice.

In this guide

Does POPIA apply to my church?

Yes. POPIA applies to any public or private body that processes personal information in South Africa, and churches, ministries and non-profit organisations are included. Processing covers almost anything you do with the information: collecting it on a visitor card, keeping it in a database, emailing it, or deleting it.

In POPIA's terms your church is the "responsible party": the organisation that decides why and how personal information is processed. Software you use to do that work, GraceHub included, acts as your "operator", processing information on your behalf and under your instructions.

The Act's main provisions took effect on 1 July 2020, and organisations had until 30 June 2021 to comply. The Information Regulator now enforces it.

Religious beliefs and children: the rules that matter most to churches

POPIA treats a person's religious or philosophical beliefs as "special personal information" and prohibits processing it, with exceptions. Section 28 provides the one churches rely on: the prohibition does not apply when a religious organisation processes information about people who belong to it, or where it is necessary to achieve the organisation's aims. With conditions, it also covers members' family members, as long as the church keeps regular contact with them and they have not objected in writing.

There is an important limit. Section 28(3) says information about a person's religious beliefs may not be supplied to third parties without that person's consent. Sharing a member list with another organisation, or publishing who attends, needs consent.

Children's personal information has its own rules. Under section 35 a child's information may be processed with the prior consent of a competent person, usually a parent or guardian, or on one of the other grounds the section lists. For a children's ministry that means capturing a parent's consent when a child is registered, and keeping allergy, medical and pickup details only for the reasons you collected them.

Your Information Officer

Every responsible party has an Information Officer. By default it is the head of the organisation; for a church that is usually the senior pastor or the chairperson of the board, who may delegate the work to a deputy.

The Information Officer is responsible for compliance: developing a compliance framework, handling requests from people who want to see or correct their information, and working with the Regulator. Information Officers must be registered with the Information Regulator, which you do on the Regulator's online portal.

Keeping information safe, and what to do if something goes wrong

Section 19 requires appropriate, reasonable technical and organisational measures to protect personal information: limiting who can see what, keeping devices and passwords secure, and checking that the systems you use do the same.

If personal information is accessed or acquired by someone without authority, section 22 requires you to notify the Information Regulator and the affected people as soon as reasonably possible.

Sending personal information outside South Africa is governed by section 72. It is allowed where, for example, the recipient is bound by laws or agreements giving adequate protection, or the person consents. When you choose software, ask where your data is stored.

A POPIA checklist for your church

Work through these with your leadership team. Most take an afternoon, not a project.

The tools are built in, so the checklist is easier to keep

GraceHub doesn't make a church compliant on its own; your policies and people do that. It gives you the controls those policies rely on.

Access by role

168 permissions decide who can see members, giving, pastoral notes and children's records. Counselling and children's access never come automatically with a broader role.

Your Information Officer on record

Record your Information Officer, choose whether POPIA, GDPR or both apply, and acknowledge your church's role as the responsible party.

Consent on record

Sign-up records a versioned acceptance of the terms and of your church's privacy notice, and GraceHub gives you a privacy notice template to adapt.

Deletion that respects the law

Members can ask for their account to be deleted from the website. Their identity is erased, while giving records are anonymised and kept for the period tax law requires.

Database in Johannesburg

GraceHub's main database runs in Google Cloud's Johannesburg region. Our privacy policy lists the other service providers we use and where they operate.

An audit log

Key administrative actions are recorded, so you can see who changed what.

Common questions about POPIA in churches

Do we need consent to keep a member database?

Not always. Section 28 allows a religious organisation to process information about its own members, including their religious beliefs. You still need a lawful reason for everything you collect, and consent before you share members' information with third parties.

Can we put photos of children on social media?

Only with the prior consent of a parent or guardian, under section 35. Record that consent, and respect it when a parent withdraws it. In GraceHub, parents record photo consent on their child's record, and a child without it is marked on their name tag.

Who should be our Information Officer?

By default, the head of the church. They can delegate the day-to-day work to a deputy Information Officer, but both should be registered with the Information Regulator.

Is our church data safe if it's in the cloud?

It can be, if the provider uses strong security and you control access properly. Ask where the data is stored, who can access it, and how breaches are handled. GraceHub's main database runs in Johannesburg, and you decide who sees what with role-based access.

More on protecting church data

Make POPIA part of how your church already works.

Start a GraceHub workspace and set up roles, consent and retention from day one, or talk to us about moving your records across safely.

Start your church's workspace or talk to our team.

This guide is general information, not legal advice. For advice on your church's situation, speak to a legal professional or contact the Information Regulator (inforegulator.org.za).