← Policies

Data Privacy Policy (POPIA Compliant)

v1.0
Updated 182 days ago

POPIA compliance isn't optional for South African churches — and the fines for getting it wrong are real. This ready-to-adopt privacy policy covers everything your church needs to handle member data lawfully, transparently, and with the dignity your congregation deserves.

# Data Privacy Policy **[CHURCH_NAME]** **Effective Date:** [EFFECTIVE_DATE] **Information Officer:** [INFORMATION_OFFICER] **Contact:** [INFORMATION_OFFICER_EMAIL] **Review Date:** [REVIEW_DATE] --- ## 1. Introduction and Legal Framework [CHURCH_NAME] is committed to protecting the privacy and personal information of all members, visitors, volunteers, and staff. This policy has been prepared in compliance with the **Protection of Personal Information Act 4 of 2013 (POPIA)**, which came into full effect on 1 July 2021. This policy explains how we collect, use, store, and protect your personal information, and what your rights are under POPIA. --- ## 2. Who We Are **Responsible Party:** [CHURCH_NAME] **Physical Address:** [CHURCH_ADDRESS] **Registration Number (if applicable):** [CHURCH_REG_NUMBER] **Information Officer:** [INFORMATION_OFFICER] **Email:** [INFORMATION_OFFICER_EMAIL] **Phone:** [CHURCH_PHONE] As a Responsible Party, we determine the purpose and means of processing your personal information. --- ## 3. What Personal Information We Collect We may collect and process the following categories of personal information: ### 3.1 Basic Contact Information - Full name - Home address and/or postal address - Email address - Phone numbers (mobile and/or home) ### 3.2 Demographic Information - Date of birth - Gender - Marital status - Family structure (spouse name, children's names and ages) ### 3.3 Ministry-Related Information - Church membership status and date - Ministry team participation - Baptism and confirmation records - Small group/Life group participation - Volunteering history ### 3.4 Financial Information - Tithing and donation records (required for Section 18A tax certificates in South Africa) - Bank details (only where direct debit is set up for giving, stored securely) ### 3.5 Special Categories of Information The following special categories are only collected with explicit consent and where strictly necessary: - Health information (for pastoral care, prayer ministry) - Criminal record information (for volunteer screening) - Information about minors (with parental consent) --- ## 4. Why We Collect Your Information (Purpose) We collect and process personal information for the following purposes: 1. **Church membership administration** — maintaining accurate membership records 2. **Communication** — sending newsletters, event information, and pastoral communications 3. **Financial administration** — processing donations, issuing Section 18A tax certificates, financial record-keeping 4. **Ministry operations** — coordinating volunteers, small groups, and ministry teams 5. **Pastoral care** — providing appropriate care and support to members 6. **Event management** — registering and communicating with event attendees 7. **Child safety** — carrying out child protection screening 8. **Legal obligations** — complying with South African law, including SARS requirements 9. **Photography and media** — sharing images and video for ministry promotion (subject to separate consent) We will not process your information for any purpose beyond those listed above without your prior consent. --- ## 5. Legal Basis for Processing Under POPIA, we process personal information on the following grounds: - **Consent:** Where you have given us explicit consent (e.g., for photography, marketing emails) - **Contractual necessity:** Where processing is necessary for membership or employment - **Legal obligation:** Where required by South African law (e.g., financial record-keeping, mandatory reporting) - **Legitimate interest:** Where we have a legitimate interest that is not overridden by your rights (e.g., pastoral care communications with members) --- ## 6. How We Store and Protect Your Information ### 6.1 Storage Systems Your personal information is stored in: - **Church Management System:** [CHURCH_MANAGEMENT_SYSTEM] (password-protected, access-controlled) - **Email platform:** [EMAIL_PLATFORM] - **Financial system:** [FINANCIAL_SYSTEM] - **Physical records:** Locked filing cabinets, accessible only to authorised staff ### 6.2 Security Measures We take reasonable technical and organisational measures to protect your information, including: - Password protection and access controls on all digital systems - Two-factor authentication on administrative accounts - Regular software updates and security patching - Limiting access to personal information on a need-to-know basis - Training staff on data privacy obligations ### 6.3 Retention Periods | Information Type | Retention Period | |-----------------|------------------| | Active member records | Duration of membership + 5 years | | Financial/donation records | 7 years (SARS requirement) | | Volunteer screening records | Duration of service + 3 years | | Event registration records | 2 years | | Employment records | 5 years after termination | | Pastoral counselling notes | 3 years after last session | | Photography consent forms | 5 years or until withdrawn | At the end of the retention period, records will be securely deleted or destroyed. --- ## 7. Sharing Your Information We do not sell, rent, or trade your personal information. We may share information in the following limited circumstances: 1. **Service providers:** Third-party service providers (e.g., church management software, email platform) under data processing agreements that bind them to POPIA-equivalent standards 2. **Legal requirements:** Where required by South African law or court order 3. **Child protection:** Where mandatory reporting obligations require disclosure to SAPS or the Department of Social Development 4. **With your consent:** Where you have expressly authorised us to share your information Where we share information with third parties outside South Africa, we ensure equivalent protection is in place. --- ## 8. Your Rights Under POPIA As a data subject, you have the following rights: 1. **Right to access:** Request a copy of the personal information we hold about you 2. **Right to correction:** Request correction of inaccurate or incomplete information 3. **Right to deletion:** Request deletion of your information (subject to legal retention obligations) 4. **Right to object:** Object to the processing of your information 5. **Right to withdraw consent:** Withdraw consent for processing at any time 6. **Right to complain:** Lodge a complaint with the Information Regulator of South Africa **To exercise any of these rights, contact:** [INFORMATION_OFFICER] at [INFORMATION_OFFICER_EMAIL] We will respond to requests within 30 days. ### Contact the Information Regulator If you are not satisfied with our response: - **Information Regulator of South Africa** - **Website:** www.inforegulator.org.za - **Email:** inforeg [at] justice.gov.za - **Phone:** 012 406 4818 --- ## 9. Data Breach Notification In the event of a data breach involving personal information: 1. We will assess the breach immediately upon discovery 2. If the breach poses a risk to your rights, we will notify the Information Regulator within the timeframe required by POPIA 3. We will notify affected data subjects as soon as reasonably possible 4. We will document the breach and corrective measures taken 5. A breach response plan is maintained by [INFORMATION_OFFICER] To report a suspected breach, contact [INFORMATION_OFFICER_EMAIL] immediately. --- ## 10. Cookies and Online Tracking If [CHURCH_NAME] operates a website at [CHURCH_WEBSITE], we may use cookies and analytics tools. Our website privacy notice (available at [PRIVACY_NOTICE_URL]) provides full details of online data collection. --- ## 11. Children's Information We collect information about children only with verifiable parental or guardian consent. Children's data is treated with additional care and stored separately where practical. Parents may request access to or deletion of their child's information at any time by contacting [INFORMATION_OFFICER_EMAIL]. --- ## 12. Changes to This Policy This policy will be reviewed annually. Significant changes will be communicated to members via [COMMUNICATION_CHANNEL]. The current version is always available at [POLICY_LOCATION]. --- *Last updated: [EFFECTIVE_DATE]* *[CHURCH_NAME] — Registered Information Officer: [INFORMATION_OFFICER]*
Download raw .md (Free)
Or fill in every field manually before downloading

Fill in your details

Preparing PDF...

# Data Privacy Policy

**[CHURCH_NAME]** **Effective Date:** [EFFECTIVE_DATE] **Information Officer:** [INFORMATION_OFFICER] **Contact:** [INFORMATION_OFFICER_EMAIL] **Review Date:** [REVIEW_DATE] ---

1. Introduction and Legal Framework

[CHURCH_NAME] is committed to protecting the privacy and personal information of all members, visitors, volunteers, and staff. This policy has been prepared in compliance with the **Protection of Personal Information Act 4 of 2013 (POPIA)**, which came into full effect on 1 July 2021. This policy explains how we collect, use, store, and protect your personal information, and what your rights are under POPIA. ---

2. Who We Are

**Responsible Party:** [CHURCH_NAME] **Physical Address:** [CHURCH_ADDRESS] **Registration Number (if applicable):** [CHURCH_REG_NUMBER] **Information Officer:** [INFORMATION_OFFICER] **Email:** [INFORMATION_OFFICER_EMAIL] **Phone:** [CHURCH_PHONE] As a Responsible Party, we determine the purpose and means of processing your personal information. ---

3. What Personal Information We Collect

We may collect and process the following categories of personal information: ### 3.1 Basic Contact Information - Full name - Home address and/or postal address - Email address - Phone numbers (mobile and/or home) ### 3.2 Demographic Information - Date of birth - Gender - Marital status - Family structure (spouse name, children's names and ages) ### 3.3 Ministry-Related Information - Church membership status and date - Ministry team participation - Baptism and confirmation records - Small group/Life group participation - Volunteering history ### 3.4 Financial Information - Tithing and donation records (required for Section 18A tax certificates in South Africa) - Bank details (only where direct debit is set up for giving, stored securely) ### 3.5 Special Categories of Information The following special categories are only collected with explicit consent and where strictly necessary: - Health information (for pastoral care, prayer ministry) - Criminal record information (for volunteer screening) - Information about minors (with parental consent) ---

4. Why We Collect Your Information (Purpose)

We collect and process personal information for the following purposes: 1. **Church membership administration** — maintaining accurate membership records 2. **Communication** — sending newsletters, event information, and pastoral communications 3. **Financial administration** — processing donations, issuing Section 18A tax certificates, financial record-keeping 4. **Ministry operations** — coordinating volunteers, small groups, and ministry teams 5. **Pastoral care** — providing appropriate care and support to members 6. **Event management** — registering and communicating with event attendees 7. **Child safety** — carrying out child protection screening 8. **Legal obligations** — complying with South African law, including SARS requirements 9. **Photography and media** — sharing images and video for ministry promotion (subject to separate consent) We will not process your information for any purpose beyond those listed above without your prior consent. ---

5. Legal Basis for Processing

Under POPIA, we process personal information on the following grounds: - **Consent:** Where you have given us explicit consent (e.g., for photography, marketing emails) - **Contractual necessity:** Where processing is necessary for membership or employment - **Legal obligation:** Where required by South African law (e.g., financial record-keeping, mandatory reporting) - **Legitimate interest:** Where we have a legitimate interest that is not overridden by your rights (e.g., pastoral care communications with members) ---

6. How We Store and Protect Your Information

### 6.1 Storage Systems Your personal information is stored in: - **Church Management System:** [CHURCH_MANAGEMENT_SYSTEM] (password-protected, access-controlled) - **Email platform:** [EMAIL_PLATFORM] - **Financial system:** [FINANCIAL_SYSTEM] - **Physical records:** Locked filing cabinets, accessible only to authorised staff ### 6.2 Security Measures We take reasonable technical and organisational measures to protect your information, including: - Password protection and access controls on all digital systems - Two-factor authentication on administrative accounts - Regular software updates and security patching - Limiting access to personal information on a need-to-know basis - Training staff on data privacy obligations ### 6.3 Retention Periods | Information Type | Retention Period | |-----------------|------------------| | Active member records | Duration of membership + 5 years | | Financial/donation records | 7 years (SARS requirement) | | Volunteer screening records | Duration of service + 3 years | | Event registration records | 2 years | | Employment records | 5 years after termination | | Pastoral counselling notes | 3 years after last session | | Photography consent forms | 5 years or until withdrawn | At the end of the retention period, records will be securely deleted or destroyed. ---

7. Sharing Your Information

We do not sell, rent, or trade your personal information. We may share information in the following limited circumstances: 1. **Service providers:** Third-party service providers (e.g., church management software, email platform) under data processing agreements that bind them to POPIA-equivalent standards 2. **Legal requirements:** Where required by South African law or court order 3. **Child protection:** Where mandatory reporting obligations require disclosure to SAPS or the Department of Social Development 4. **With your consent:** Where you have expressly authorised us to share your information Where we share information with third parties outside South Africa, we ensure equivalent protection is in place. ---

8. Your Rights Under POPIA

As a data subject, you have the following rights: 1. **Right to access:** Request a copy of the personal information we hold about you 2. **Right to correction:** Request correction of inaccurate or incomplete information 3. **Right to deletion:** Request deletion of your information (subject to legal retention obligations) 4. **Right to object:** Object to the processing of your information 5. **Right to withdraw consent:** Withdraw consent for processing at any time 6. **Right to complain:** Lodge a complaint with the Information Regulator of South Africa **To exercise any of these rights, contact:** [INFORMATION_OFFICER] at [INFORMATION_OFFICER_EMAIL] We will respond to requests within 30 days. ### Contact the Information Regulator If you are not satisfied with our response: - **Information Regulator of South Africa** - **Website:** www.inforegulator.org.za - **Email:** inforeg [at] justice.gov.za - **Phone:** 012 406 4818 ---

9. Data Breach Notification

In the event of a data breach involving personal information: 1. We will assess the breach immediately upon discovery 2. If the breach poses a risk to your rights, we will notify the Information Regulator within the timeframe required by POPIA 3. We will notify affected data subjects as soon as reasonably possible 4. We will document the breach and corrective measures taken 5. A breach response plan is maintained by [INFORMATION_OFFICER] To report a suspected breach, contact [INFORMATION_OFFICER_EMAIL] immediately. ---

10. Cookies and Online Tracking

If [CHURCH_NAME] operates a website at [CHURCH_WEBSITE], we may use cookies and analytics tools. Our website privacy notice (available at [PRIVACY_NOTICE_URL]) provides full details of online data collection. ---

11. Children's Information

We collect information about children only with verifiable parental or guardian consent. Children's data is treated with additional care and stored separately where practical. Parents may request access to or deletion of their child's information at any time by contacting [INFORMATION_OFFICER_EMAIL]. ---

12. Changes to This Policy

This policy will be reviewed annually. Significant changes will be communicated to members via [COMMUNICATION_CHANNEL]. The current version is always available at [POLICY_LOCATION]. --- *Last updated: [EFFECTIVE_DATE]* *[CHURCH_NAME] — Registered Information Officer: [INFORMATION_OFFICER]*

Fill in your details

Preparing PDF...