Church Member Directory GDPR: What Small Churches Actually Need to Get Right
A church member directory falls under GDPR the moment it holds names, contact details, or photos of identifiable people — even if your church is small, volunteer-run, and has never thought of itself as "a data company." In practice, that means picking a lawful basis for holding the data, only collecting what you genuinely need, letting members control what's visible, and being able to answer an access or deletion request properly. This guide covers each of those in plain terms.
If you're the pastor, church administrator, or the one volunteer who "does the computer stuff," you may already be the person legally responsible for how your congregation's data is handled — whether or not anyone ever said that out loud. That's not meant to alarm you. Most of what GDPR asks of a church member directory is common sense once it's spelled out, and a well-built directory system does most of the heavy lifting for you. This is general information to help you think it through, not legal advice — for anything specific to your congregation, a data-protection advisor or your national data protection authority is the right place to confirm the details.
Your church is a "data controller" — yes, even a small one
Under GDPR, a "data controller" is whoever decides why and how personal data is collected and used. If your church keeps a directory of members' names, phone numbers, email addresses, or photos, your church — not a software vendor, not a volunteer acting alone — is the data controller. Size doesn't exempt you: a congregation of forty people run entirely by volunteers carries the same basic controller responsibilities as a large organisation.
That puts the responsibility with church leadership (often named legally as the pastor, elder board, or registered church entity), not with whichever volunteer happens to maintain the spreadsheet. It's worth deciding, on paper, who holds that responsibility, so it isn't quietly resting on whoever set up the file five years ago and has since moved away.
Choosing a lawful basis for the directory
GDPR requires a lawful basis for holding any personal data. For a church member directory, two bases usually apply, and which one fits depends on how the directory is used:
- Consent. The clearest basis for a member directory, especially where entries include things members might not want fully public — a home address, a mobile number, a photo. Consent should be a genuine, freely-given yes, not a box ticked automatically at membership sign-up, and members need an easy way to withdraw it later.
- Legitimate interest. This can apply to more limited, internal uses — for example, a rota system needing a volunteer's phone number to text them a reminder, or pastoral staff needing to see who's in a small-group. Legitimate interest still requires you to weigh the church's need against the member's reasonable expectations, and it doesn't cover uses a member would be surprised or uncomfortable to learn about.
A practical rule: use consent for anything visible to the whole congregation (a public directory entry, a photo, a small-group listing shared beyond the immediate team), and reserve legitimate interest for narrow, operational uses a member would expect as normal church administration. When in doubt, ask — a short opt-in question at sign-up ("Can we include your name and phone number in the members' directory, visible only to other members?") solves most of this in one sentence.
Data minimisation: don't collect what you don't need
One of GDPR's simplest and most practical principles is data minimisation — only hold the personal data you actually use. Church directories tend to accumulate fields over the years because "it might be useful someday": birthdates, spouse names, employer details, home addresses collected once for a mailing that stopped years ago. Each unused field is pure liability with no corresponding benefit.
A useful annual exercise: go through your directory's fields and ask, for each one, "what would we do if this field disappeared tomorrow?" If the honest answer is "nothing," remove it. This is especially important for sensitive data — health conditions, prayer requests involving medical or family details, safeguarding notes — which GDPR treats as a "special category" requiring extra care and, in most cases, explicit consent to record at all. If your prayer-request system captures details like this, it deserves the same scrutiny as the directory itself, not an informal exemption because it "feels pastoral rather than administrative."
Consent for directory visibility and photo use
Two specific decisions come up in almost every church directory: who can see an entry, and whether a photo is included.
Visibility isn't all-or-nothing. A well-designed directory lets a member be listed to the whole congregation, to their small group only, or to staff/leadership only for pastoral-care purposes — and lets them choose that themselves rather than inheriting a single default that may not fit their situation (a member going through a difficult family situation, for instance, may reasonably want their entry visible to leadership but not the wider congregation).
Photos deserve their own consent, separate from the basic directory entry. Someone might be entirely happy having their name and phone number visible to fellow members but uncomfortable with their photo appearing — or vice versa. Bundling photo consent into a single "join the directory: yes/no" toggle removes a choice members are entitled to make individually.
Access and erasure requests: where a spreadsheet quietly fails
Under GDPR, any member can ask what personal data your church holds on them (a "subject access request") or ask you to delete it ("right to erasure"). Both requests have to be honoured within a reasonable timeframe, and both require you to actually know where that person's data lives.
This is where a shared spreadsheet, a mix of paper forms, and a few volunteers' personal notebooks genuinely struggle. If someone leaves the church and asks for their data to be deleted, can you say with confidence that it's gone from the directory, the rota system, the check-in log, the email list, and whatever backup copy someone made eighteen months ago? In most volunteer-run setups, honestly, nobody fully knows — the data has spread further than anyone intended, and no single person remembers where all the copies live.
A proper church management system handles this by design: one member record feeds the directory, rota, and check-in modules instead of three separate copies, so a deletion request touches one place, not five. Look for software that can generate an export of everything held on a member (for access requests) and perform a full, verifiable deletion (for erasure requests) without a volunteer needing to hunt through every corner of the system by hand.
What to look for in church member directory software
When you're evaluating a system to hold your church's member data, a few features separate genuine GDPR-supporting software from a spreadsheet with a login screen:
- Granular visibility controls — per-member, per-field, so someone can be listed without every field being public.
- Separate consent tracking for directory inclusion versus photo use, ideally with a record of when consent was given (and an easy way to withdraw it).
- Audit logs showing who viewed or changed a member's record, so you can answer "who had access to this" honestly if it's ever asked.
- Export and delete tools that produce a complete, member-specific export or deletion in one action, rather than requiring a manual search across modules.
- EU hosting / data residency — where your members' data is physically stored matters for GDPR compliance and for your own peace of mind; EU-based hosting keeps that data under EU data protection law rather than a jurisdiction with weaker guarantees.
None of this needs to be complicated for a congregation of fifty or a hundred people. It needs to be built into the system from the start, so the church administrator isn't personally responsible for remembering to do the right thing every time — the software does the remembering.
Ekkli's member management is built with this in mind: EU-hosted data, a GDPR double opt-in consent engine for anything the church communicates about, and a private self-service profile where each member manages their own consent and data directly — rather than a church office fielding every request by hand. Members can also request their own data export under GDPR's right to portability, generated straight from their record. To be precise about what this is: it's an admin-facing membership database with self-service consent, not a public member database members browse each other in — see our member management page for the full detail. Start free — no card required. Ekkli's six-month free trial includes presentation and worship display, a subdomain website, the member database, rota and scheduling, event registration, push notifications, and a sermon-audio player with a rolling 2-hour storage window, for up to 50 people. Set up your church's free Ekkli account and see the consent controls for yourself.
Frequently asked questions
Does GDPR apply to small, volunteer-run churches?
Yes. GDPR applies based on what data is held and how it's used, not the size of the organisation holding it. A congregation of thirty people run entirely by volunteers is a data controller in exactly the same way a large organisation is, once it holds identifiable members' personal data.
What lawful basis should a church use for its member directory?
Most churches rely on consent for anything visible beyond core staff — a public directory entry, a photo, a small-group listing — and legitimate interest for narrow operational uses like a rota reminder. This is general guidance; confirm the specifics with a data-protection advisor or your national data protection authority for your church's exact situation.
Can a church member ask to be removed from the directory?
Yes. Under the GDPR right to erasure, a member can ask for their personal data to be deleted, and a church should be able to honour that request within a reasonable timeframe. Software that keeps one member record across your membership database and rota, plus a genuine self-service data export, makes this far closer to a single action than a manual search through several systems.
Do we need separate consent for photos in the directory?
It's good practice to treat photo consent separately from basic directory inclusion. A member might be comfortable with their name and contact details being visible but not their photo, or the reverse — bundling both into one yes/no choice takes away a decision they're entitled to make individually.
What counts as "sensitive" data in a church context?
GDPR treats health information and similar details as a "special category" requiring extra care and, generally, explicit consent. Prayer requests or pastoral notes that mention medical conditions, mental health, or family crises fall into this category, even though they may feel like ordinary pastoral care rather than formal data collection.
Where can we read the actual GDPR text or get official guidance?
The European Commission's official GDPR portal at ec.europa.eu is a good neutral starting point, and your national data protection authority can answer questions specific to your country and congregation.
Ready to give your church a member directory that treats privacy as a feature, not an afterthought? Start free — no card required. Create your church's free Ekkli account and set your first visibility and consent settings today.
Română (România)
Português do Brasil (pt-BR)
Polski (PL)
Dutch (nl-NL)
French (fr-FR)
Spanish (es-ES)
Deutsch (Deutschland)
English (United Kingdom)