Your church database holds more than a retailer's and is guarded worse
Addresses, giving, children's allergies, and confessed sin. Four tiers of member data, who sees what, where counseling notes must never live, and the breach plan an elder board can write in an hour.
Updated
Your church database knows where the widow lives alone, which child has an epinephrine pen, which household gave $40,000 last year, and which marriage nearly ended in March. A retailer holding this much would face an audit. Most congregations hold it in a system where four staff logins share one password and nobody has reviewed permissions since the software was installed.
This is a pastoral problem carried by a technical system. The membership roll is a record of souls under care, and a member who learns their giving amount was mentioned in a staff meeting has learned something true about how the church regards them.
Sort what you hold into four tiers
Write the list. Everything the church stores about a person goes into one of these, and the tier determines who can see it.
Tier one, directory information. Name, household, address, phone, email, birthday, membership date. Visible to staff and to members through a directory, if members have consented to appear in it. Ask before publishing anyone. A woman who left an abusive marriage has a reason to be unlisted, and she should not have to explain it to the church secretary.
Tier two, operational records. Attendance, serving assignments, group membership, children’s check-in and allergy notes, background check status. Visible to staff and to the specific leaders who need it. The children’s director sees allergies. The finance committee does not.
Background check status belongs in this tier and the report behind it does not. Federal law gives churches a route to a real check: under the National Child Protection Act, a state “may have in effect procedures” requiring qualified entities to request “a nationwide background check” on people who will have responsibility for children, and the Attorney General runs a program for qualified entities in states without such procedures (34 U.S.C. 40102). Use the route your state actually operates and ask what it returns. Then store the returned report the way control nine below describes, because a criminal history summary on a volunteer is the single most damaging file in the building if it leaks, and it is usually the least protected.
Tier three, financial records. Giving amounts by name, pledges, benevolence received. Visible to the financial secretary and to whichever officer your governing documents specify, and to nobody else by default. Many congregations deliberately keep the preaching elder out of this record entirely so that no sermon can be suspected of following the money. That is a decision your elders should make on purpose and write down, rather than inherit from whatever the software defaulted to.
Tier four, pastoral and confidential. Counseling notes, discipline proceedings, disclosures of sin, abuse reports, health crises. This tier does not belong in your church management system at all.
The rule about counseling notes
Do not put counseling notes in the ChMS. Not in a custom field, not in the notes tab, not marked private.
Three reasons, and any one is sufficient.
The permission model is not built for it. Note privacy in most church software is a checkbox, and a checkbox is one administrator’s mistake away from being visible in a report, an export, or a merged household record.
Exports are indiscriminate. The day you migrate to a new system, everything comes out in a CSV that sits in someone’s downloads folder.
Legal exposure runs both directions. Notes stored in a shared system are harder to defend as confidential, and their absence is harder to explain if a court asks what the church knew. Clergy are designated mandatory reporters of child abuse in many states, with a clergy-penitent privilege exception written differently in each, and the Child Welfare Information Gateway maintains the state-by-state summary in its publication Clergy as Mandatory Reporters of Child Abuse and Neglect, last published May 2023. Read your own state’s entry, then talk to an attorney in your state about how the privilege and the reporting duty interact for your situation, and then write your own policy. Do not take a policy from the internet, including this page, as legal advice.
What to do instead: keep pastoral notes minimal, on paper, in a locked drawer in the office of the person who wrote them, with a written retention period. Abuse reports follow your state’s mandatory reporting law immediately, and that is a separate track from anything described here.
Twelve controls that cover most of the risk
None of these require a consultant.
- Every person has their own login. Shared accounts make every action untraceable and survive every staff departure.
- Two-factor authentication on the ChMS, the giving platform, the email account, and the domain registrar. Those four, at minimum, today.
- A church-owned password manager. One vault, church billing, two administrators. Passwords in a shared Google Sheet are the most common serious weakness in a church office.
- Written offboarding. The day someone leaves staff or rotates off a team, a named person removes their access from every system on a checklist. Do this for volunteers too, especially children’s check-in.
- Quarterly permission review. Print the user list, read it out loud in a staff meeting, and remove people. It takes ten minutes and it always finds something.
- Church-owned accounts for everything. The website, the domain, the streaming channel, the social accounts, the Google or Microsoft tenant. Anything registered to a personal address is one resignation away from being lost.
- Restrict giving visibility by policy, not by trust. Set it in the software so the question never comes up.
- Do not store payment card numbers. Ever, anywhere, including a paper file of authorization forms in a drawer. PCI DSS applies to “entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD) or could impact the security of the cardholder data environment” (PCI Security Standards Council). A church that writes card numbers on a form has put itself inside that scope for no benefit. Let the processor hold them, and pick the processor with that in mind using what giving platforms actually cost your church.
- Background check documents live in one locked place with a retention period. They contain the most sensitive information about your volunteers and they are often the least protected file in the building.
- Children’s check-in data gets a purge schedule. You do not need last year’s pickup codes.
- A real backup you have tested. Export the full database quarterly to encrypted church-owned storage, and once a year actually open the file and confirm the data is in it.
- Devices with a lock screen. The office laptop and the check-in tablets. A tablet left unlocked in a lobby is your whole children’s roster.
Consent, plainly stated
Members should know what you collect and what you do with it. One paragraph on the website and in the membership packet:
What you collect, why you collect it, who inside the church can see it, what appears in the directory, whether the directory is printed or online, how to be excluded, how to correct a record, and how to be removed after leaving.
Then honor it. Do not add a visitor to the all-church email list because they filled out a prayer card, which is both a trust failure and the point at which CAN-SPAM’s opt-out duties attach to you; the capture side of that is in a guest follow-up system one volunteer can run. Do not sell, trade, or share the roll with anyone outside the church, including denominational bodies, without asking.
Do not publish photographs of children without written parental permission on file, and keep a list of the families who said no where the person posting to social media will actually see it. Be honest with yourselves about why. COPPA’s definition of personal information does include “a photograph, video, or audio file where such file contains a child’s image or voice,” but its definition of a covered operator “explicitly excludes nonprofit entities that are exempt from Federal Trade Commission Act coverage” (16 CFR 312.2). So this is not federal compliance, it is a promise your church makes to parents and keeps. That holds better than a misremembered legal threat, and the practical workflow is in social media for a church with no media team.
The breach plan, written before you need it
One page, approved by the elders, kept where the office can find it. Six lines:
- Who to call first. One named person with a phone number. Usually the administrator, with the chairman of elders as backup.
- Contain. Reset the affected passwords, revoke the affected sessions, take the affected system offline if needed.
- Preserve. Do not delete anything. Screenshot what you saw, note the time, keep the logs.
- Determine scope. Which tier of data, how many people, over what window.
- Notify. Breach notification is a state matter and the coverage is effectively total: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches” (National Conference of State Legislatures). The statutes differ on who is covered, what data triggers a duty, and how fast you must act, and NCSL notes those requirements vary by jurisdiction rather than sharing one deadline. Read your own state’s statute now, while nothing is on fire, and have counsel identified in advance rather than searching for one during the incident.
- Tell the congregation the truth, promptly, in plain words. What happened, what was exposed, what you are doing, what they should do. A church that hides a breach loses far more than the data.
What this is protecting
A church asks its people to be known. Membership means the elders keep a list with your name on it, that someone notices when you are absent, that your sin is not a private matter, and that your household is under care. That request only holds if the church is trustworthy with what it learns.
Every control above exists so that a member can tell the truth in this room without wondering where it goes. Set the permissions this month, and the harder conversations get easier for years.
For the office systems these records live in, start with choosing church management software and its export test, because a system you cannot export from is a system you cannot audit either. If your church is running on free tiers, free church management software states where each one stops, which matters here because permission controls are often the first thing a free tier withholds. For the donation side see what giving platforms actually cost your church, and for the domain and account ownership half of this, website options for a small church.
Attendance records deserve one caution of their own. Counting well needs names attached to weeks, which is exactly the sort of record that should be governed rather than accumulated. The method in average attendance hides whether your church is growing or shrinking is deliberately approximate for that reason.
Sources
- 34 U.S.C. 40102, National Child Protection Act background checks, via Cornell Legal Information Institute. Checked 29 July 2026.
- Child Welfare Information Gateway, Clergy as Mandatory Reporters of Child Abuse and Neglect, published May 2023. Checked 29 July 2026.
- 16 CFR 312.2, COPPA definitions, via Cornell Legal Information Institute. Checked 29 July 2026.
- PCI Security Standards Council, PCI DSS, who must comply. Checked 29 July 2026.
- National Conference of State Legislatures, Security Breach Notification Laws. Checked 29 July 2026.
CISA’s multi-factor authentication resource page returned HTTP 403, so control two above cites no risk-reduction percentage. Turn on two-factor anyway. None of this is legal advice.


