Guides · POPIA

POPIA for churches: the practical checklist.

If your church keeps a list of names, POPIA applies to you. This is the plain-language checklist for getting it right: who is accountable, what you may keep, what kids' ministry needs, and what to do when something goes wrong.

General information, not legal advice. For rulings on your specific situation, speak to a privacy practitioner.

The one-minute version

What POPIA means for a church.

The Protection of Personal Information Act covers every organisation in South Africa that processes personal information, and a church processes plenty: member details, kids registers, giving records, prayer requests, photos. Religious beliefs are special personal information, and POPIA specifically allows a church to process its own members' beliefs, but every other duty in the Act still applies in full. The good news: for a congregation of ordinary size, compliance is mostly discipline, not expense. The checklist below is the discipline.

The checklist

Eight steps, in order.

01

Name your information officer

By default this is the head of the organisation, and the role can be delegated in writing. Register the information officer with the Information Regulator, and make sure the church council knows who it is.
02

Map what you collect

List every place member information lives: the ChMS, spreadsheets, paper forms, personal phones, old email threads. You cannot protect what you have not found, and most churches are surprised by their own list.
03

Collect less, delete sooner

Keep only what you actually use, and set a retention habit: when someone leaves and asks to be removed, or a record has served its purpose, delete it. Fewer copies in fewer places is half of POPIA.
04

Get consent for children's information

Kids' ministry information needs the consent of a parent or guardian, and a published photo of a child counts as processing. Collect consent at registration, record it, and honour it everywhere.
05

Honour opt-outs on every channel

Give people a working way out of your messages and respect it the first time. If you promote anything to people outside your congregation, POPIA's direct-marketing rules apply and consent matters even more.
06

Lock down access

The worship team does not need giving records. Access should follow the role, member lists should not float around personal inboxes, and anything sensitive deserves encryption and a proper backup.
07

Put your providers on the record

Every system that touches member data is your operator under POPIA, and your church stays the responsible party. Ask each provider in writing: where does the data live, who can see it, how do we export or delete it?
08

Know your breach drill

If personal information is accessed or lost, POPIA expects you to notify the Information Regulator and the affected people as soon as reasonably possible. Decide today who makes that call and from what records you would recover.

Print this page or save it as a PDF, and work through it with your leadership team.

Where Church Flow fits

Most of this checklist is a setting we already shipped.

  • One system instead of scattered spreadsheets: your map in step 02 gets very short.
  • Role-gated visibility: finance sees details, pastors see totals, volunteers see nothing they should not.
  • Everything encrypted in transit and at rest, with each church's data isolated through row-level security.
  • Encrypted off-site backups, integrity-verified on a weekly schedule, for the day the breach drill imagines.
  • Records live in a cloud data centre in South Africa, and administrative actions are audit-logged.
  • Opt-outs honoured automatically on the channels you message through, WhatsApp included.
  • Your church stays the responsible party; Church Flow acts as an operator, processing on your instructions.
  • Export or delete your congregation's data at any time. It is yours, full stop.

Read the full security and data-care page for how we treat your data end to end.

Common questions.

Yes. POPIA applies to anyone who processes personal information in South Africa, and a membership list, a kids register or a giving record is personal information. Size does not exempt a church, but the effort scales with your risk: a small congregation with tidy records and a named information officer covers most of the ground quickly.
We operate POPIA-first. Under POPIA your church remains the responsible party for its congregation's personal information, and Church Flow acts as an operator: we process it on your instructions, to provide the service. Everything is encrypted in transit and at rest, each church's data is isolated through row-level security, administrative actions are audit-logged, records live in a cloud data centre in South Africa, and you can export or delete your data at any time.
Children's personal information gets special protection under POPIA: as a rule you need the consent of a parent or guardian before processing it, and a photo of a child that you publish counts as processing. Collect consent when families register, record it, and honour it in every ministry that touches kids.

Data care is pastoral care.

The people on your list trusted you with their names. Run them on a system that takes that seriously.

Start your 30-day free trial