Home Articles Get your free assessmentComing soon

Category: Protecting Information

Member records, giving history, counseling notes, background checks and photographs. Where sensitive information lives in a ministry, and how to look after it.

  • If You Lose Member Data, Who Do You Have to Tell?

    If You Lose Member Data, Who Do You Have to Tell?

    It’s a Monday. The office administrator can’t get into her email, and when she finally does, the sent folder contains forty messages she didn’t write.

    Or: the laptop was in the back of the car outside the hospital, and now it isn’t.

    Or: someone calls to say the church’s membership spreadsheet is on a website they’ve never heard of.

    Whatever the route, you now stand in a specific place, and the question in the room is not technical. It is: do we have to tell people?

    The honest answer is: probably, sometimes, and it depends on facts you don’t have yet. Which is deeply unsatisfying — so this post explains the general shape of how these laws work, so you can recognize the situation and act fast enough to handle it properly.

    Everything below is a description of how these rules generally work. It is not legal advice. Requirements vary substantially by state, and you need a lawyer — early.

    These laws are not just for corporations

    Start here, because this is the assumption that gets churches into trouble.

    The National Conference of State Legislatures summarizes the landscape plainly: “All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws requiring private businesses, and in most states, governmental entities as well, to notify individuals of security breaches of information involving personally identifiable information.”

    Nonprofit status is not, by itself, an exemption. These statutes are generally drafted around whoever holds the data rather than around a particular tax classification. Whether a specific state’s law reaches your specific organization is a question with a real answer, and only a lawyer licensed in that state can give it to you. But do not walk into it assuming your 501(c)(3) letter is a shield. It isn’t designed to be one.

    What actually triggers a notice

    Here is the most useful thing in this article, and the part most people have backwards.

    Not every exposure of personal information triggers a notification duty. These laws generally attach to specific, defined categories of data — and a name plus an email address, on its own, very often isn’t one of them.

    NCSL describes the common structure: these laws typically contain “definitions of ‘personal information’ (e.g., name combined with SSN, drivers license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information).”

    In practice, the categories that most commonly appear across state definitions are a person’s name combined with one or more of:

    • Social Security number
    • Driver’s license or state identification number
    • A financial account, credit card, or debit card number, usually together with whatever code would let someone use it
    • In a growing number of states, medical or health insurance information, biometric data such as a fingerprint, or the username and password to an online account

    Look at that list against what your church actually holds. Your membership directory of names, addresses, and emails is sensitive and worth protecting — but its exposure may not trigger a statutory notice. Your payroll file, your background-check drawer, and your donation records with bank account details almost certainly could.

    That distinction is not a reason to relax. It’s a reason to know precisely where your organization keeps the high-consequence categories, before anything goes wrong.

    The obligation usually follows the person, not the church

    This surprises people, and it matters for churches more than for most small organizations.

    These laws are generally written to protect residents of that state. So the question is usually not “which state is the church in?” but “where do the affected people live?”

    A congregation with members who retired to Florida, a college student in another state, and a missionary family supported from a third has, potentially, three sets of rules to satisfy from a single incident. The deadlines may differ. The required content of the letter may differ. Whether a state official has to be told may differ.

    You do not need to memorize any of that. You need to know two things: that the number of applicable laws is driven by your people’s addresses, and that your lawyer will need that address list early. Which is a quiet argument for keeping your member records accurate and for not keeping records of people who left twenty years ago.

    What the notices generally have in common

    Details vary by state — always — but the family resemblance is strong.

    A deadline measured in days from discovery. Some states set a specific number of days; others use a reasonableness standard along the lines of the most expedient time possible and without unreasonable delay. These deadlines are not stable, either — California, which used the reasonableness language for more than twenty years, moved to a fixed 30-calendar-day notification deadline effective 1 January 2026, with notice to the Attorney General due within 15 calendar days after individuals are notified. Either way the clock starts near the beginning of the incident, usually well before you understand what happened. This is the single biggest reason to call counsel on day one rather than day ten, and to ask them what the current deadline is in each state where your people live rather than relying on anything you read a year ago.

    Required content in the notice. States commonly specify what the letter has to say: what happened, what categories of information were involved, what the organization is doing about it, what the individual can do, and who to contact with questions. Some prescribe the format and the delivery method. This is not a letter to draft yourself from a template you found online.

    Notice to a state official. Several states require that the attorney general or a similar office be told, often once the number of affected residents crosses a threshold. California, for example, requires a sample copy of the notice to be submitted to the Attorney General by any organization “required to issue a security breach notification to more than 500 California residents as a result of a single breach of the security system” (Cal. Civ. Code §§ 1798.29(e), 1798.82(f)). Other states set different thresholds, and some set none.

    Notice to the credit bureaus. Some states require the nationwide consumer reporting agencies to be notified once the affected population passes a threshold that state sets. Separately, the FTC’s breach response guidance for businesses says that “if Social Security numbers have been stolen, contact the major credit bureaus for additional information or advice,” regardless of whether a statute compels it.

    And an encryption exemption that is worth real money. This is the most actionable point in the whole area of law. Many state statutes are written around unencrypted personal information. California’s, for example, requires disclosure to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person” — and also where encrypted information was acquired along with the encryption key or security credential (Cal. Civ. Code §§ 1798.29(a), 1798.82(a)). So encryption is not a blanket exemption anywhere, and the details differ by state. Ask your lawyer how it works in the states that apply to you.

    Encryption means the data is stored scrambled, readable only with a key. Turning on full-disk encryption on your laptops is free — it’s built into Windows and macOS — and it takes about ten minutes per machine. It will not stop a phished mailbox. But a laptop stolen from a car is one of the most common ways a small organization loses data, and encryption can be the difference between a stolen laptop and a notifiable breach. That is an extraordinary return on ten minutes, and it is a genuine, concrete reason to do it this month rather than someday.

    The first days: what to do so that you can comply

    Whether you’ll owe notice is a question for later. What you do in the first hours decides whether you’ll be able to answer it.

    Preserve everything. Do not clean up. The instinct — reset the machine, delete the bad messages, wipe it and start fresh — destroys the only record of what happened. The FTC’s guidance for businesses is direct: “Do not destroy any forensic evidence in the course of your investigation and remediation,” and “don’t turn any machines off until the forensic experts arrive.” Disconnect an affected computer from the network by unplugging the cable or switching off Wi-Fi, but leave it running and leave it alone.

    Stop the bleeding without destroying the evidence. Change passwords from a different device, sign out all active sessions, and turn on multi-factor authentication if it wasn’t already on. Preserving evidence does not mean leaving the door open.

    Write down the timeline as it happens. A plain notebook or a single document. When you first noticed something. Who reported it. What time. What you did and when. Who you called. Your lawyer will need this, your insurer will need this, and memory reconstructed three weeks later is not good enough. Start it in the first ten minutes.

    Call your lawyer before you call anyone else you’re tempted to call. Not because you’ve done something wrong, but because the deadline has probably already begun, and because counsel can often direct the investigation in a way that protects the organization. Ask specifically about a legal hold — an instruction to stop any routine deletion of records that might be relevant.

    Call your insurer the same day. Read this twice: many policies impose their own notice deadlines that are shorter than the law’s, and some require you to use their approved forensic and legal panel. Calling them late, or hiring your own investigator first, can jeopardize coverage on a policy you’ve been paying for. If you have cyber liability coverage, the hotline number is the most valuable thing in the policy.

    Report it. If money moved or fraud was attempted, report to the FBI at ic3.gov immediately. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process works far better inside the first 24 to 72 hours. Point affected individuals to identitytheft.gov, which walks them through recovery steps at no cost.

    Say less publicly, sooner privately. Do not speculate from the pulpit about what happened. Do tell your board chair and your leadership immediately.

    Notifying well is a trust-building act

    There’s a fear underneath all of this: that telling the congregation will destroy confidence in the church’s leadership.

    The pattern runs the other way.

    Congregations are generally forgiving about incidents. People understand that criminals exist, that a determined attack can succeed against anyone, and that ministry staff are not security professionals. What congregations do not forgive is finding out later that leadership knew and said nothing. The first is a misfortune. The second is a character question, and it is the one that ends tenures.

    A good notification is short and specific: here’s what happened, here’s what information was involved, here’s what we’ve done, here’s what we recommend you do, here’s who to call with questions, and here’s the change we’re making so it doesn’t happen again. No hedging, no passive voice, no “an incident may have occurred.” Take responsibility for the response even where you couldn’t have prevented the event.

    Handled that way, a breach notification is one of the clearer demonstrations a church can give that it treats people’s information as a trust rather than an asset. That’s not spin. It’s just what integrity looks like on a bad week.

    What to do this week

    Turn on full-disk encryption on every laptop your organization owns — BitLocker or device encryption on Windows, FileVault on Mac. Ten minutes a machine, no cost, and in many states it changes the legal character of a stolen laptop.

    Then write two phone numbers on the same card and put it where your leadership can find it: your attorney, and your insurance carrier’s claims line. Add whether you have cyber liability coverage at all — if nobody in the room knows, that’s this week’s second task, and it’s a five-minute email to your broker.

    Preparing before anything happens is far cheaper than improvising afterwards. MissionDefend’s free assessment asks straightforward questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first — including whether you’d be able to answer the questions above on the worst morning of the year.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: National Conference of State Legislatures, Security Breach Notification Laws; California Office of the Attorney General, Reporting a Data Breach; California Legislature, SB 446, Data breaches: customer notification; Federal Trade Commission, Data Breach Response: A Guide for Business; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Keep It or Delete It? The Security Control Nobody Talks About

    Keep It or Delete It? The Security Control Nobody Talks About

    The shared drive has a folder called Old Stuff. Inside it is a folder called Old Stuff 2.

    Somewhere in there is a spreadsheet from 2011 with the name, home address, phone number, and date of birth of every child who came to vacation Bible school that summer. Those children are adults now. Most of their families moved away. Nobody has opened the file in fifteen years.

    It’s still there because deleting it never felt like anyone’s job, and because deleting things feels vaguely irresponsible — like throwing away the church’s memory.

    Here’s the thing nobody says out loud in security training, and it’s the whole point of this post:

    Data you no longer hold cannot be stolen.

    Not “is harder to steal.” Cannot be stolen. There is no attacker clever enough, no password weak enough, no misconfigured folder careless enough to expose a file that does not exist. Deletion is the only control with a perfect success rate, and it’s the one almost nobody applies.

    Deletion is a security control, not housekeeping

    Every other thing we recommend reduces the probability that something goes wrong. Multi-factor authentication makes an account much harder to break into. Backups make a ransomware attack survivable. Good habits around payment changes make fraud far less likely. All of them are worth doing, and none of them are perfect.

    Deleting data changes something different. It reduces the consequences — the size of the loss if the other controls fail.

    Think about what a breach costs a church. Almost all of it scales with how many people’s information was involved: the notification letters, the phone calls, the pastoral fallout, the trust. A compromised mailbox holding two years of correspondence is a bad afternoon. The same mailbox holding twenty years is a very different event.

    The size of your worst day is decided years in advance, by what you chose to keep.

    Why churches keep everything

    Not carelessness. Four honest reasons.

    Deleting feels like erasing people. A church’s records are its history — baptisms, marriages, funerals, membership rolls. That instinct is correct for the historical record and wrong for the operational one. Nobody is suggesting you throw away the baptismal register. We’re talking about the 2019 volunteer sign-up sheet with everyone’s cell numbers on it.

    Storage got cheap. There’s no longer a filing cabinet filling up to force the decision. Cloud storage — meaning files kept on a provider’s servers rather than a computer in your office — just quietly expands.

    Nobody owns it. Retention is nobody’s job description. It falls between the treasurer, the administrator, and the board, which means it falls on the floor.

    Fear of needing it later. This is the real one. What if we’re audited? What if there’s a dispute? That fear is legitimate, and the answer is not “keep everything forever” — it’s “find out the actual requirement, write it down, and then be free of the question.”

    A framework to start from

    What follows is general information and a starting point for a conversation, not a legal answer. Tax, employment, denominational, and state requirements all set floors, they vary by state, and they change. Confirm every line below with your accountant and your attorney before you adopt it. Two anchors are worth knowing because they come from the IRS guidance written for exempt organizations rather than from general small-business advice. IRS Publication 4221-PC tells public charities they “must keep records for federal tax purposes for as long as they may be needed to document evidence of compliance with provisions of the IRC,” notes that “generally, the statute of limitations runs three years after the date the return is due or filed, whichever is later,” and adds that if an organization has employees, “it must keep employment tax records for at least four years after filing the fourth quarter for the year.”

    Giving and donation records. Long retention. These support your tax filings and your donors’ deduction claims, and your accountant will have a firm view. Keep them — but keep them in your giving platform or accounting system, not as spreadsheets scattered across the drive.

    Member and attendance contact data. Short. This is a live directory, not an archive. If someone left the congregation in 2018, ask whether their cell number and home address need to be in an active file in 2026.

    Children’s and youth records. The most sensitive category and the one requiring the most care in both directions. Many organizations hold these far longer than the tax rules would suggest, because the window in which a claim relating to a minor can be brought is long and varies considerably from state to state — that is usually a decision driven by limitations periods and insurer expectations rather than by a statute telling you to retain the file. Do not guess here. Ask your attorney and your insurer specifically about this category.

    HR and payroll. Governed by employment and tax rules with real floors. Your payroll provider or accountant can tell you what applies. Note that the floors typically cover the tax records, not every email about the hiring process.

    Background-check results. Often among the shortest, and best held by the screening provider rather than by you. Reports from a screening company generally fall under federal consumer-reporting law, which sets its own rules for how they are used and disposed of, so this category deserves its own policy.

    Counseling and pastoral care notes. Special handling. There are confidentiality and privilege considerations that vary by state and by whether the person providing care is licensed. This is a lawyer question before it is an IT question.

    Email. The default here is genuinely wrong in most churches, which is “keep it all forever.” Ask a different question: what does your organization actually need from a mailbox that is five years old? For most staff, the honest answer is nothing.

    Photos and video. Retain the ones you use. Delete the eleven hundred near-duplicates from the 2017 mission trip. Pay particular attention to images of children, and to whether you still hold current permission to use them.

    Board minutes and governing documents. Keep permanently — the IRS guidance for public charities says to keep the application for recognition of exempt status, the determination letter, organizing documents such as articles of incorporation and bylaws, and board minutes indefinitely. These are your corporate memory and your legal backbone, and they contain almost no personal information. This is the category where “keep everything” is right.

    Where deletion quietly fails

    You delete a file. You feel better. The file is still there, in one to five other places.

    Email archives. Many organizations have archiving or journaling turned on — a system that copies every message to separate long-term storage. Deleting from the mailbox does nothing to the archive.

    Trash and recycle bins with their own timers. Deleted email goes to a trash folder. Deleted cloud files go to a drive trash. These are separate systems with separate retention periods, and most business platforms keep a further recoverable copy that only an administrator can see, for a period after that. Deleting once is rarely deleting.

    Backups. Your backup exists specifically to defeat deletion — that’s its job. A file removed today may live in backups for months. You generally shouldn’t try to surgically extract it, and you don’t need to. You do need to know your backup rotation period, so you know the honest date when the data is actually gone.

    The export on someone’s laptop. The volunteer who pulled the full membership list into a spreadsheet to do the Christmas mailing. The treasurer who downloaded giving data to work on the budget at home. These copies are invisible to every policy you write, which is why the policy has to name them: no exports to personal devices, and any working copy is deleted when the task is done.

    Third-party platforms you no longer use. The event-registration site from 2019. The old church management system you migrated away from. The mass-texting service someone trialled. Cancelling a subscription does not necessarily delete the data — many services retain it, sometimes indefinitely, unless you specifically ask. When you stop using a platform, send a written request to delete your data and keep the reply.

    And the “delete” that isn’t a delete at all. Moving a file into a folder called Archive is not deletion. It is deletion’s costume.

    The file is still on the same drive, with the same permissions, visible to the same people, included in the same backups, and exposed to exactly the same attack. Nothing has changed except that you now feel finished.

    The same is true of renaming a folder DO NOT USE, of moving old records to “that laptop in the closet,” and of unplugging a computer that still has a hard drive in it.

    Real deletion means the data is gone from the live system, gone from the trash, and on a known countdown out of backups. Anything short of that is filing.

    One hour, once a year

    A retention policy that requires a committee will never run. Here is a version that runs.

    Put one recurring reminder on the calendar. Same week every year. Call it records review. Give it sixty minutes.

    Do one category per year. Year one: email. Year two: the shared drive. Year three: old platforms and subscriptions. Trying to do all of it at once is how the whole thing gets abandoned in year one.

    Two people, not one. One person who knows where things are, one person who has authority to say delete. That pairing prevents both paralysis and mistakes.

    Write down what you did. Three lines in a document: what you reviewed, what you deleted, what you decided to keep and why. If anyone ever asks whether your organization managed its records responsibly, that log is the answer.

    Start with the easiest win. Old platforms you no longer use. Deleting an account you already stopped paying for is pure gain, and it usually takes ten minutes per service.

    The one time you stop deleting immediately

    There is an exception, and it is absolute.

    If your organization is involved in litigation, or a claim, or a government or denominational investigation — or if any of those becomes reasonably foreseeable — routine deletion stops that day, for everything that might be relevant. This is commonly called a legal hold: an instruction to preserve records that would otherwise be destroyed on schedule.

    The federal rule governing litigation in federal court is blunt. Rule 37(e) applies where “electronically stored information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it.” Note the words anticipation of. The duty can begin before anyone files anything — before you receive a letter, sometimes at the moment a serious allegation is made. State courts have their own rules, and they vary, which is another reason this is a question for your attorney rather than one to settle from a blog post.

    Practically, that means two things. Deleting on a published schedule, before any of this arises, is ordinary responsible practice. Deleting after it arises is a separate and much more serious problem, and the appearance of it is nearly as damaging as the fact.

    So: get your attorney’s guidance on when a hold starts, know how to pause your routine, and if there is any question at all about whether something is in dispute — stop, and ask before you delete.

    What to do this week

    Open the list of software your organization pays for, or used to. Pick one service you no longer use, log in, and delete your data — or email their support address asking them to delete it and save the reply.

    Then put one recurring calendar reminder in place, once a year, sixty minutes, called records review. That reminder is the entire policy. Everything else is detail you can add later.

    Twenty minutes, and you’ve turned “we should really deal with that someday” into something with a date on it.

    MissionDefend’s free assessment works through the same ground in plain English — where your organization’s information actually lives, who can reach it, and what’s still being kept for no reason — and hands you a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Internal Revenue Service, Publication 4221-PC, Compliance Guide for 501(c)(3) Public Charities; Internal Revenue Service, Recordkeeping requirements for exempt organizations; Legal Information Institute, Cornell Law School, Federal Rule of Civil Procedure 37(e).

  • Background Checks: Who Holds Them, For How Long, and How to Destroy Them

    Background Checks: Who Holds Them, For How Long, and How to Destroy Them

    There is a drawer in most church offices that nobody thinks about.

    It holds background-check results. Every volunteer who has ever worked with children, going back as far as the church has been screening people. Some of them are printouts stapled at the corner. Some are in a folder on the shared drive called Screening. Most of them, if we’re honest, are still sitting in the office administrator’s email as PDF attachments, because that’s how the screening company delivered them and nobody ever moved them anywhere else.

    You did the screening because you take child safety seriously. That was the right call, and your insurer and your denomination probably required it.

    But the screening created something new: a small, concentrated archive of the most sensitive personal information your organization will ever touch, held by an office that was never set up to hold it.

    This post is about what to do with that archive.

    What’s actually inside one of those reports

    A background check is not a yes-or-no answer. It’s a document, and the document is dense.

    Depending on the provider and the level of check, it typically contains the person’s full legal name and any former names, date of birth, current and previous home addresses, and often all or part of a Social Security number — because that number is how the provider matches records to the right human being. Then it contains the results: county and state criminal records, sex offender registry checks, sometimes driving records, sometimes credit information.

    That combination is unusual. Plenty of organizations hold names and addresses. Far fewer hold a name plus a date of birth plus a Social Security number plus a home address, all in one file, for dozens of people at once.

    That specific combination is everything someone needs to open credit in another person’s name. It is, in practical terms, the highest-value data a small church holds — more valuable to a thief than your giving records.

    And there’s a second harm on top of the financial one. These files may contain criminal history for volunteers your church screened, considered, and welcomed anyway. A leak doesn’t just expose an identity. It exposes something a person told you in confidence, about the hardest part of their life, in order to serve. Losing that is a pastoral failure as much as a technical one.

    Where these files actually end up

    None of the following is negligence. Every one of them is what happens when a small office handles a task it was given without being given a system.

    In an inbox, forever. The screening company emails a PDF — a PDF is just a document file, and one that keeps its formatting and can be opened by anyone, with no protection unless someone deliberately adds it. It arrives, gets read, gets acted on, and stays in the mailbox. Five years later it’s still searchable by typing a volunteer’s last name, and if that mailbox is ever compromised, so is every report in it.

    In a shared drive folder open to everyone. Cloud drives default to convenient, not restrictive. A folder created by one person is very often visible to every staff account, and sometimes to every volunteer who was ever added to the team drive.

    In a filing cabinet in an unlocked office. The cabinet may lock. The question is whether it is locked at 4pm on a Thursday when the building is open for choir practice and a dozen people are walking past the door.

    For people who left a decade ago. This is the most common one. Nobody ever decided to keep the file of a nursery volunteer who moved away in 2014. Nobody decided to delete it either. Absent a decision, records simply accumulate.

    On a former administrator’s laptop. Someone downloaded the reports to work from home during a busy screening season. That laptop left with them.

    The rule that fixes most of this

    Here it is, and it’s simpler than any policy document:

    Keep the decision. Don’t keep the report.

    Your organization needs to be able to prove that a volunteer was screened, when, by whom, and that they were approved. That’s a single line in a roster: Name — screened 14 March 2026 — provider — cleared — approved by [name].

    What your organization almost never needs is the underlying report sitting in your building. The screening company already has it. That’s their business, they’re built for it, and they carry insurance for it.

    So the default should be: the provider holds the report; you hold the record of the decision.

    Most screening platforms let you view results in their portal rather than emailing them out, and many will let you turn off attachment delivery entirely. Ask your provider two questions: Can results stay in your system instead of being emailed to us? and How long do you retain them, and can we retrieve them later if we need to?

    If the answer to the first is yes, you have just removed the entire problem from your building.

    Where you genuinely must keep something — because your insurer, your denomination, or your state’s volunteer rules require a copy — keep the smallest version that satisfies the requirement, and store it in one place, not four.

    What the law expects, in general terms

    Some real caution here: this is the shape of the rules, not advice about your situation. Requirements differ meaningfully by state, by whether you use a screening company, by the type of work the volunteer does, and by whether the person is an employee or a volunteer. Your attorney and your insurance carrier should confirm your policy before you adopt it.

    With that said, three things are worth knowing.

    Reports from a screening company are usually “consumer reports.” When you buy a background check from a third-party screening company, that report generally falls under the Fair Credit Reporting Act (FCRA) — the federal law governing how consumer reporting information is obtained, used, and disposed of. The FTC and EEOC’s joint guidance for employers walks through the obligations that come with it, including giving the person a clear written notice and getting written permission before you run the check, and giving them a copy of the report and a statement of their rights before you turn them down because of it.

    There is a federal rule specifically about throwing these away. The FTC’s Disposal Rule (16 CFR Part 682) requires anyone who maintains or possesses consumer information for a business purpose to dispose of it “by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.” The FTC’s own business guidance states plainly that “any business or individual who uses a consumer report for a business purpose is subject to the requirements of the Disposal Rule,” and names employers among them. Its examples of reasonable measures: “burn, pulverize, or shred papers,” and “destroy or erase electronic files or media” so the information “cannot be read or reconstructed.”

    Retention floors exist and they’re shorter than you’d guess. The FTC/EEOC guidance points to the EEOC’s requirement that personnel and employment records be “preserved for one year after the records were made, or after a personnel action was taken, whichever comes later.” That is an employment rule, and whether it reaches your organization at all depends on your size, on whether the person is an employee or a volunteer, and on how the exemptions for religious employers apply to you. Other floors may apply too — from your state, your denomination, or your insurer. Ask. But notice the direction of the surprise: the legal floor is often low, and the reason churches keep these files for fifteen years is habit, not law.

    Building a retention rule you’ll actually follow

    A retention policy that lives in a binder is not a control. Keep it to five sentences someone can act on.

    Name two people. Access to screening results is limited to two named individuals — typically the safeguarding lead and one other. Not “the office.” Not “staff.” Two people, by name, written down. Everyone else sees the roster line, not the report.

    Pick one location. One folder, one cabinet, one portal. Multiple copies in multiple places is the actual failure mode, because you can clean up the one you remember and miss the three you don’t.

    Write the period down. Something like: background-check results are retained for [X] years after the volunteer’s service ends, then destroyed, with X confirmed by your attorney and insurer. The number matters less than the fact that a number exists.

    Put it on the calendar. A recurring annual reminder — “review screening files” — is what turns a policy into a practice. Without it, nothing is ever destroyed.

    Write down what you’ll keep forever. Usually just the roster: who was screened, when, and that they were cleared. That’s the record that protects the church years later, and it contains no Social Security numbers at all.

    Destroying them properly

    Destruction is where good intentions quietly fail, because “delete” means less than people think.

    On paper: cross-cut shred, or use a bonded destruction service that gives you a certificate. Do not put them in the recycling bin. Do not put them in the dumpster behind the fellowship hall.

    In email: deleting the message is not enough. Empty the trash or deleted-items folder too, and remember that most mail systems keep a further recoverable copy for a period after that. Check whether your provider offers a permanent-delete option, and if attachments were forwarded to anyone, delete them from those mailboxes as well.

    On a shared drive: delete the file, then empty the drive’s own trash, which usually runs on a separate timer from your email trash. Then check whether anyone downloaded a copy.

    In backups: this is the one everyone forgets. Your backup exists precisely to make deletion reversible. A file removed today may sit in backups for months. You usually can’t and shouldn’t surgically remove it, and that’s fine — but you should know the rotation period, and note that the file isn’t fully gone until that period has passed.

    On old hardware: a retiring laptop or copier can hold every report ever printed. Have drives wiped or destroyed before anything leaves the building.

    What to do this week

    Search your own mailbox for the name of your screening provider, and see how many reports come back. That number, whatever it is, is the honest starting point — and finding it takes about five minutes.

    Then do one thing: call the provider and ask whether they can stop emailing results and let you view them in their portal instead. That single change stops the pile from growing while you decide what to do about the files you already have.

    Sensitive records are one of several places churches carry more risk than they realise. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including where sensitive records like these actually live — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission and Equal Employment Opportunity Commission, Background Checks: What Employers Need to Know; Federal Trade Commission, Disposing of Consumer Report Information? Rule Tells How; Electronic Code of Federal Regulations, 16 CFR § 682.3 — Proper disposal of consumer information.

  • The Most Sensitive File in the Building

    The Most Sensitive File in the Building

    A pastor sits down after a Thursday afternoon conversation and writes half a page of notes. A marriage in trouble. A relapse. A name and a date and enough detail to remember what to follow up on next month.

    The notes go into a Word document on the office laptop, in a folder called Care. The laptop is the one the whole staff borrows when theirs is charging. The folder syncs to the shared drive, because everything on that laptop syncs to the shared drive — that’s how it was set up years ago, and it was set up that way so nothing would ever be lost.

    Every person on staff can open that folder. Not one of them ever has. That isn’t a security control; it’s good manners.

    Elsewhere in the same building: benevolence applications with bank details and eviction notices in a cabinet that doesn’t lock, a text thread on a personal phone that contains a full disclosure of abuse, and a notes field in the church management software where somebody typed “husband’s drinking again — do not mention to the Wilsons” three years ago, not realizing that eleven volunteers can see it.

    This is the most sensitive information any church holds, and it is almost always the least protected.

    Confidentiality and security are two different things

    This distinction is worth slowing down for, because the two are constantly confused.

    Clergy confidentiality — often discussed alongside the clergy-penitent privilege, a legal rule about what a minister can be compelled to testify to in court — is a legal and ethical concept. It’s about who may lawfully demand the information, and what a minister is obliged to do with it. Its scope varies significantly by state, and denominations layer their own ordination vows and disciplinary standards on top. Some states affirm the privilege broadly, some limit it to confessional communications, and the Children’s Bureau’s fifty-state summary notes that in some states it is denied altogether.

    Data security is about who can physically or technically reach the file. Passwords, permissions, locks, encryption.

    Here is the load-bearing sentence: a note that is privileged in principle is still readable by anyone with the password. Privilege governs a courtroom. It does nothing whatsoever against a compromised email account, a laptop left in a car, or a volunteer clicking into a folder they shouldn’t have been able to open.

    A related confusion is worth clearing up. Churches often assume health-privacy law covers them. Generally it does not — the federal rule applies to health plans, health care clearinghouses, and health care providers who transmit certain information electronically in connection with standard transactions. A congregation offering pastoral care isn’t ordinarily any of those. There may be exceptions if your ministry operates a counseling center, employs licensed clinicians, or bills insurance, and that’s a question for your attorney. But do not assume a federal law is protecting these records. Usually nothing is except your own practices.

    And one thing that overrides all of it: mandatory reporting obligations exist, they vary, and in defined circumstances they take precedence over confidentiality. According to the Children’s Bureau’s summary of state statutes, members of the clergy are named as mandated reporters in 29 states and Guam, and seven jurisdictions — New Hampshire, North Carolina, Oklahoma, Rhode Island, Texas, West Virginia, and Guam — disallow the clergy-penitent privilege as grounds for failing to report suspected child abuse or neglect. Four states — Indiana, New Jersey, North Carolina, and Wyoming — require all persons to report regardless of profession. That summary is current through May 2023 and these laws change. Know your own state’s rule cold, in writing, before you need it. Ask a lawyer. This article is not legal advice.

    Decide what gets written down at all

    The most effective control here isn’t technical. It’s editorial.

    Before you write anything, ask: what do I actually need to remember, and what would harm this person if it were read by someone else? Those two answers overlap far less than people assume.

    A workable standard for care notes in a congregational setting:

    Write enough to follow up. Date, who you met with, that a conversation happened, and what you committed to do. “Met with R. Follow up in two weeks. Referred to counseling resource list.”

    Leave out the detail that isn’t yours to hold. The specifics of a disclosure, third parties’ names, diagnoses, financial particulars, anything about someone’s spouse or children who were not in the room. If you don’t need it to be a good pastor next month, it doesn’t need to exist on paper.

    Never write speculation, judgment, or diagnosis. Not because someone might sue, though they might, but because you’re recording a guess about a human being that will outlive your memory of how uncertain you were.

    Assume it will be read. By a successor, by a board in a conflict, by a court under subpoena, by an attacker in a breach. Write the note that you would be content to have read aloud.

    This is not an argument for keeping no records. Continuity of care matters, and a pastor who remembers nothing serves people badly. It’s an argument for writing the minimum that does the job.

    Where these files should actually live

    Out of the general shared drive. This is the single highest-value change most churches can make in an afternoon. The default setup at a small organization is one shared drive, open to all staff, because that was simplest to configure. Care notes and benevolence files need to come out of it into a separate location with its own permissions.

    Access granted to named people, not to “staff.” There is a real difference between a folder shared with the staff group and a folder shared with Pastor Miller and Pastor Ruiz. The first automatically includes every future hire, every intern, and the office volunteer who was added to the group last spring. The second doesn’t. Name the individuals.

    Paper goes in a locking cabinet, and the key is controlled. Benevolence applications in particular — they routinely contain bank account numbers, Social Security numbers, pay stubs, and eviction notices, which is a more complete identity-theft package than most churches hold anywhere else.

    Set a retention limit and honor it. Decide how long care notes and benevolence files are kept, write it down, and destroy them on schedule. Records you no longer hold cannot be exposed, subpoenaed, or misread by a successor. What the right period is depends on your state, your denomination’s polity, your insurer, and whether any licensed counseling is involved — ask your attorney for the number, then follow it.

    Multi-factor authentication on the accounts that can reach any of this. MFA is the extra code or tap after the password. It’s free on Microsoft 365 and Google Workspace, and Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. If a folder is worth restricting, the account that can open it is worth protecting.

    Email, texting, and the notes field nobody thinks about

    Email is a filing cabinet you don’t control. A message about a member’s situation is copied into the sender’s sent folder, the recipient’s inbox, both mailboxes’ backups, and the provider’s servers. It stays there for years. If either account is ever compromised — the most common single security incident at any organization — the attacker gets not just the mailbox but the searchable history of everything the church knows about its people.

    If you must send something by email, keep the substance out of the subject line. Subject lines appear in notification previews on lock screens, on shared reception monitors, in mobile summaries, and in any forwarded thread. “Re: Thursday” is a fine subject line. “Re: Dana’s rehab intake” is a broadcast.

    Better: send “Can we talk about a pastoral matter today?” and have the conversation by voice.

    Texting is worse, and it’s what people actually use. A pastoral text thread sits on a personal phone with no organizational control at all. It appears in lock-screen previews. It’s visible to anyone who picks up the phone, including a spouse or a child. It backs up to a personal cloud account. And when that pastor leaves the church, the entire history leaves with them, on their device, permanently. Text to arrange a meeting. Don’t text the meeting.

    The church management software notes field is far more visible than people think. Almost every ChMS — church management software, the system that holds your directory, attendance, and giving — has a general notes or comments field on each person’s record. Staff type sensitive things into it because it’s convenient and it feels private.

    It usually isn’t. Depending on how your permissions are configured, that field may be visible to every staff member, every group leader, every volunteer with a login, and anyone who can run an export. Go look today: log in as a volunteer-level user, or ask one to show you their screen, and see exactly what a group leader can read on a member’s record. Most churches are surprised. Then either lock the field down properly or stop using it for anything but logistics.

    Two situations to plan for now

    When a staff member leaves. This is the moment the whole problem becomes visible. Their church account gets disabled — but the notes in their personal notebook go home in a box. The care history in their text messages leaves on their phone. The documents in their personal Dropbox stay in their personal Dropbox.

    Handle it at the front end rather than the back: make it clear from the first week of employment that ministry records belong to the ministry and live in ministry systems. Then, at departure, walk through it explicitly — accounts disabled, church files returned or transferred to the named successor, personal-device copies deleted, paper handed over. Have the conversation warmly and have it anyway, including when someone leaves on the best possible terms.

    When a device is lost. A laptop in a stolen car, a phone left in an airport. If care notes were on it, the question is whether anyone can read them.

    Two settings make the answer no, and both are free and already built in. Full-disk encryption — BitLocker on Windows, FileVault on Mac — scrambles everything on the drive so it’s unreadable without the login. On phones and tablets it’s on by default as long as you have a passcode. And remote wipe, which lets an administrator erase a device that’s gone. Turn both on across every device that touches ministry records, today, before you need them.

    If a device is lost, change the passwords for every account that was signed in on it, sign out all active sessions, and tell someone immediately. If information about people was exposed, notification requirements exist in every state and vary considerably — that’s a call to your attorney, promptly.

    What to do this week

    Open your shared drive and look at who can see the folder containing care notes, benevolence applications, or anything similar. If the answer is “everyone on staff,” move that folder somewhere with permissions granted to two or three named people. Fifteen minutes.

    Then log in to your church management software as a volunteer-level user and read what they can see on a member’s record. If the notes field is exposed, you’ve just found this week’s second job.

    MissionDefend’s free assessment asks straightforward questions about how your organization handles member data, accounts, email, and donations — no jargon — and returns a baseline score with the highest-value fixes ranked in order.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: U.S. Department of Health and Human Services, Children’s Bureau, Mandatory Reporting of Child Abuse and Neglect: State Statutes; U.S. Department of Health and Human Services, Covered Entities and Business Associates; Microsoft, mandatory multifactor authentication guidance; National Conference of State Legislatures, Security Breach Notification Laws.

  • What Do You Actually Have? A One-Afternoon Data Inventory

    What Do You Actually Have? A One-Afternoon Data Inventory

    Someone in the office asks a simple question: where do we keep the allergy list for the kids?

    Four answers come back. It’s in the check-in system. It’s also on a printed sheet in the nursery binder. Sarah keeps a copy on her phone because the tablet is slow on Sunday mornings. And there’s a spreadsheet somebody emailed around before the fall kickoff, which is still sitting in maybe nine inboxes.

    All four answers are true. That’s the problem.

    This isn’t a story about carelessness. It’s what happens when a small organization runs on goodwill and improvisation for a decade. Nobody decided to keep four copies of children’s medical information. It accumulated, the way things accumulate in a building that’s been used by a lot of people for a long time.

    You cannot protect what nobody has written down. Every other security decision you’ll make — who gets multi-factor authentication first, what to back up, what to shred, what to tell people if something goes wrong — depends on knowing what you’re holding and where it lives. That knowledge almost never exists in one place. Building it takes an afternoon.

    Why this is the first job, not the fifth

    Most security advice starts with a control: turn on this setting, buy this tool, write this policy. Those are all reasonable, and they’re all guesses until you know what you have.

    The Federal Trade Commission’s guide for businesses puts inventory first, before locks and disposal, in a single sentence: know what personal information you have in your files and on your computers. Not because it’s exciting, but because everything downstream is unanswerable without it.

    Consider what you can’t decide today. Is your backup adequate? Depends what needs backing up. Should the giving system have stricter access than the calendar? Obviously — but who has access to the giving system right now? If a laptop went missing tonight, what would be on it? If you had to notify people that their information was exposed, which people, and how would you reach them?

    Every one of those is a lookup against a list you don’t have yet.

    The four questions, and a table to hold them

    For each thing you find, you’re answering four questions. That’s the whole method.

    What is it? In plain words. Not “member records” — names, home addresses, phone numbers, birthdays, and marital status for about 340 households. Be specific enough that a stranger reading the line understands the sensitivity.

    Who can reach it? Not who should. Who actually can, today, if they tried. This includes anyone who knows a shared password, anyone whose account was never turned off, and the person who has a key to the cabinet.

    Where does the copy live? Plural, almost always. The system of record, plus the export somebody made, plus the printout, plus the backup, plus the attachment in the email thread.

    Do we still need it? The most useful question on the list, and the one that shrinks the problem fastest. Data you deleted cannot be stolen.

    Put the answers in a table — one row per thing. A single shared document, or a printed sheet on a clipboard. Either works.

    What it isWhere the copies liveWho can reach itSensitivityStill need it?
    Member directory — names, addresses, phones, birthdays, ~340 householdsChMS; export on office PC desktop; printed pictorial directory (2021)3 staff logins; 1 shared “office” login; anyone with the printed copyHighYes — but delete the desktop export
    Children’s check-in, allergies, emergency contactsCheck-in system; nursery binder; volunteer’s phone photo; emailed spreadsheet6 volunteers via shared tablet login; ~9 email recipientsVery highYes — one copy only
    Background check results, 2016–presentVendor portal; paper files, unlocked cabinetVendor login shared by 2 people; anyone in the officeVery highCheck retention rule with counsel
    Giving and pledge recordsGiving platform; QuickBooks; annual statement PDFs on shared driveTreasurer, bookkeeper, pastor; shared drive is open to all staffHighYes — restrict the drive folder
    Old laptop, closetUnknownAnyone who opens the closetUnknownNo — wipe and dispose properly

    The sensitivity column is a judgment call, and a coarse one is fine. High, medium, low. What you’re really flagging is: how bad would it be if this ended up somewhere public, or in the hands of someone who wanted to harm one of these people? A birthday list is not the same as a benevolence file.

    Now go find the rows.

    Walk the building

    Do this part physically. Take a legal pad and actually open the doors.

    The office. Filing cabinets — including the one nobody has a key for, which you should note as an open item rather than skip. Look for personnel files, background check results, old giving envelopes, offering count sheets, contribution statements, and applications from volunteers who came and went years ago.

    The children’s and youth area. Check-in records, allergy and medical information, emergency contacts, permission slips, incident reports. This is usually the most sensitive paper in the building and the least locked.

    The pastor’s study and the counseling room. Care notes, benevolence applications, correspondence. Handle this category with particular seriousness — it deserves its own conversation, and we’ll cover it separately.

    The closet, the storage room, the attic over the fellowship hall. Old computers. Old phones. A retired copier — the FTC’s guidance for businesses is blunt about this: the hard drive in a digital copier stores data about the documents it copies, prints, scans, faxes, or emails, and deleting or reformatting doesn’t actually remove it. Boxes of paper somebody meant to sort.

    The counters and desks. The sticky note with the Wi-Fi password is a minor issue. The sticky note with the login for the giving platform is not.

    Walk the accounts

    Now sit down and list the online services. This is harder, because there’s no door to open. Start from three places: the bank statement (what are you paying for?), the office computer’s saved passwords or bookmarks, and the memory of whoever has been around longest.

    Expect to find: the church management software, the giving or donation platform, the payroll provider, the accounting system, the email and file storage (Microsoft 365 or Google Workspace), the website and its hosting, the domain registrar, the email newsletter tool, the event registration tool, the background check vendor, the livestream and video accounts, the social media pages, and the survey tool somebody used once for a stewardship campaign.

    For each one, the question that matters most is the second one: who can reach it? Log in and look at the user list. Do not rely on memory.

    And then the category that catches everyone: the personal accounts holding church data. The volunteer who built the directory in her own Google Sheets. The worship leader whose personal Dropbox has every service recording. The former treasurer’s home computer, where the QuickBooks file lived. These are not violations of trust — they’re what happens when someone volunteers to help and uses the tools they already have. But that data is outside anything you control, and it walks out the door when they do.

    What you will find, because everyone finds it

    Three discoveries happen in nearly every inventory. Name them in advance so nobody feels caught out.

    The shared login. One username and password for the giving platform, or the check-in tablet, or the Facebook page, used by five people, three of whom no longer serve. It exists because it was easier, and because individual accounts sometimes cost money per seat. The cost of it is that you can never tell who did what, and you can never remove one person without disrupting everyone.

    The departed volunteer who still has access. The youth intern from two summers ago whose account was never disabled. The former board member still in the shared drive. Offboarding is the single most commonly skipped step in small organizations, because there’s rarely a formal offboarding at all — people just stop coming.

    The spreadsheet that was emailed around. Somebody exported the directory to help with a mailing, attached it to a message, and sent it to eleven people. Every one of those copies is now permanent, sitting in eleven mailboxes, four of which are personal accounts with no multi-factor authentication — MFA, the extra code or tap after the password. If any one of those accounts is ever compromised, your directory goes with it.

    None of these are failures of character. They’re the predictable result of a small staff doing a large job. Write them down without commentary, and fix them in order.

    Turning the list into decisions

    The inventory is only worth the afternoon if it changes something. Three immediate moves come almost free.

    Delete. Go down the “still need it” column and act on every no. Old exports, duplicate spreadsheets, applications from people who never served, printed directories from four years ago. Paper goes in a shredder, not a recycling bin. Devices need to be properly wiped, not just deleted from — get help with that if you’re unsure.

    Reduce copies. For anything marked very high, drive it toward a single authoritative copy with controlled access. The nursery binder and the phone photo and the emailed spreadsheet all go away; the check-in system stays.

    Fix the access list. For the three or four most sensitive systems, remove everyone who shouldn’t be there, and put individual logins in place of shared ones where you can.

    Two things to note but not solve today. Records retention — how long you’re required to keep giving records, personnel files, and background checks — has real legal and tax dimensions, and the answer differs by state and by what kind of organization you are. And if information about people is ever exposed, notification requirements exist in all fifty states, the District of Columbia, and several territories, and they vary considerably in who they cover and what they require. Both of those are questions for your attorney, with your inventory in hand. The inventory is what makes that a thirty-minute conversation instead of a three-hour one.

    What to do this week

    Block ninety minutes. Take a legal pad and walk the building — office, children’s area, closets, storage. Write down every place you find information about a person, and note who can reach it. Don’t fix anything yet; just list it.

    Then open the two systems that hold your most sensitive data — usually the check-in system and the giving platform — and look at the user list. Remove anyone who has left.

    That’s it for week one. You’ll have more of a security program than most organizations twice your size.

    Once you know what you hold, the next question is how well it is protected. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first. An inventory like this makes those answers much easier to give.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Protecting Personal Information: A Guide for Business; Federal Trade Commission, Digital Copier Data Security: A Guide for Businesses; National Conference of State Legislatures, Security Breach Notification Laws.

  • How to Protect Member and Donor Information at Your Church

    How to Protect Member and Donor Information at Your Church

    When someone fills out a visitor card, gives online, signs their child into the nursery, or sits down with a pastor for a difficult conversation, they are handing your organization something. Not just information — trust. They are assuming that what they shared stays where they put it.

    That assumption is doing a lot of quiet work. It is why people give, why they volunteer, and why they tell you things they have not told anyone else. A breach does not just cost money. It spends down the one asset a church cannot replace.

    The good news is that protecting this information is mostly about a handful of decisions, not about buying technology. Here is how to work through them.

    Start by knowing what you actually hold

    Almost no church can answer the question what personal information do we have, and where is it? Not because anyone is careless, but because the data accumulated over years, across systems, added by different people.

    Spend an hour making a list. Not a formal data inventory — a list. Walk through it in categories.

    Your church management system holds names, addresses, phone numbers, family relationships, attendance, and often giving history. Your accounting system holds giving records, and possibly bank account details for recurring givers and staff. Your online giving platform holds payment information, though ideally your organization never sees full card numbers. Email holds everything anyone has ever sent, which in practice is the most sensitive collection you own. Shared drives hold spreadsheets — and these are the ones that surprise people, because someone exported the full member list to a spreadsheet in 2023 for a mailing and it is still sitting in a folder. Children’s ministry check-in holds minors’ names, guardians, allergies, and photo permissions. Background check results and personnel files may be in a filing cabinet, an email attachment, or both. And pastoral care notes, if they exist in writing anywhere, are the most sensitive records in the organization.

    Write down where each lives and who can get to it. This list is the foundation for everything else, and making it usually surfaces at least one thing that should not exist anymore.

    Decide who should see what — then enforce it

    The most common serious problem is not hackers. It is that far too many people inside the organization can see far more than their role requires.

    This happens innocently. A volunteer needed admin rights for one project three years ago. A staff member changed roles but kept old permissions. The database was set up by someone who gave everyone full access because it was simpler.

    Work through it role by role rather than person by person. Ask what a nursery volunteer genuinely needs: the children and guardians they are checking in that morning, and nothing else — certainly not giving history. A small group leader needs contact details for their group. The finance team needs giving records. The senior pastor may need broad access, but “may” is worth examining. Most administrative tasks do not require seeing what individual families give.

    Then apply two principles that carry most of the weight. Give the least access that lets someone do their job, and give it for as long as they hold that role, not permanently. And treat giving records as a separate, tighter category than contact information — in most churches, far more people can see giving history than have any business seeing it, and members would be startled to learn who.

    Put a recurring calendar reminder every quarter to review the user list in your church management system, your email admin console, and your accounting software. Ten minutes, four times a year.

    Protect the accounts that open the doors

    All the access control in the world does not help if someone simply logs in as your administrator.

    Email is the master key, because it resets every other password — protect it first and hardest. Every staff member and every volunteer with access to member data should have multi-factor authentication enabled. This is the highest-value change available to you, it is free on both Microsoft 365 and Google Workspace, and it takes an afternoon.

    Get rid of shared logins. One password to the database that six people know means you cannot revoke one person’s access, cannot tell who exported what, and cannot investigate anything. Give people individual accounts. Where a shared credential genuinely cannot be avoided, put it in a password manager with proper sharing so at least it can be rotated when someone leaves.

    And close the door behind people who go. The most common way former volunteers retain access to member data is that nobody remembered to turn the account off. Add it to whatever departure process already exists.

    Stop collecting what you do not need

    Every piece of information you hold is a piece you have to protect. The cheapest security measure in existence is not having the data.

    Look at your visitor card and your event registration forms. Are you asking for a date of birth you never use? A Social Security number you have no business collecting? A home address for an event that does not need one?

    Then look backward. That 2019 mailing list export, the old volunteer applications, the spreadsheet of every attendee from a conference you hosted — if it has no current purpose, deleting it removes risk permanently. Write down a simple retention rule so this does not require judgment every time. Something as plain as contact records are kept while someone is connected to the church and for three years after; giving records are kept as long as tax rules require; visitor cards are entered into the database and then shredded is enough. Confirm the financial retention periods with your accountant, since those are set by tax and audit requirements rather than by preference.

    Handle the most sensitive records differently

    Some categories deserve stricter treatment than the general membership database, and it is worth being deliberate about them.

    Counseling and pastoral care notes. If these exist in writing, they should be the most tightly held records you have — accessible to the minister involved and essentially nobody else, and never stored in a shared drive or general email folder. Confidentiality expectations here are both ethical and, in many states, legally significant. Talk to counsel about how privilege applies in your jurisdiction before deciding where these live.

    Children’s ministry records. Minors’ information, guardian details, allergies, photo permissions, and check-in history. Access should be limited to current children’s ministry leadership, reviewed every term as volunteers rotate, and separated from the general directory.

    Background checks. These frequently end up as email attachments, which is the worst possible place for them. They belong in a restricted personnel file with access limited to the one or two people responsible for screening.

    Anything about giving. Members generally assume their giving is known to a very small number of people. Make that assumption true.

    Make sure your vendors are holding up their end

    Most of your member data is not on your premises. It is on servers belonging to your church management software company, your giving platform, your email provider, and your backup service. Their security is your security.

    You are entitled to ask, and a good vendor will answer without evasion. Ask whether they support multi-factor authentication and role-based permissions, whether data is encrypted at rest and in transit, whether they have a current third-party security report such as a SOC 2, what their notification commitment is if they are breached, and how you would get a full export of your data if you left. That last question matters more than it sounds — your ability to leave is your leverage.

    If a vendor cannot answer these questions, that is itself an answer.

    Get backups right

    Protecting information means protecting its availability, not just its confidentiality. A member database that has been encrypted by ransomware or deleted by accident is a data protection failure too.

    Your church management system, financial records, and shared documents should be backed up automatically, retain several weeks of history, and keep at least one copy that someone with your password cannot reach or delete. Cloud platforms are resilient but they are not backups on their own — a deleted file syncs its deletion everywhere.

    Then restore one file. Pick something from a month ago and bring it back. Untested backups fail at exactly the moment you need them.

    Say what you do, and do what you say

    If you publish a privacy statement — and you should — keep it short and truthful. Members appreciate knowing what you collect, what you use it for, that you do not sell or trade donor lists, who can see giving records, and how to ask for their information to be corrected or removed.

    Do not copy an enterprise privacy policy off the internet. A promise you do not keep is worse than no promise, and a plain paragraph that is accurate does more for trust than three pages of legalese that is not.

    Be aware, too, that data privacy law is expanding and several state laws now reach some nonprofits. This is worth a conversation with counsel rather than a guess, particularly if you operate across state lines or collect information from people outside the United States.

    Train the people who touch the data

    The most likely way member information leaves your organization is not a sophisticated intrusion. It is an email sent to the wrong address, a spreadsheet attached in error, a directory forwarded to someone who asked nicely, or a staff member who fell for an impersonation email.

    Twice a year, spend fifteen minutes with everyone who touches member data on the specific things that go wrong. Check the recipient before sending anything with personal information attached. Never email a full member export — share a link with permissions instead. Verify by phone before acting on any request to change bank details or send money. And report mistakes immediately, because a misdirected email caught in ten minutes is a very different event than one caught in ten days.

    That last point deserves emphasis. Build a culture where people report their own errors without fear. The organizations that get hurt badly are almost always the ones where somebody was too embarrassed to speak up.

    A realistic place to begin

    You will not do all of this in a week, and you do not need to.

    Start with three things. Turn on multi-factor authentication for everyone with access to member data. Pull the user list from your church management system and remove anyone who should not be there. And find out who can currently see giving records, then decide whether that list is right.

    Those three actions, done in a single afternoon, close the gaps most likely to hurt you.

    When you want the full picture — including the parts of this that are easy to miss — MissionDefend’s free assessment will walk you through plain-English questions about how your organization stores member and donor information, who has access, how donations are processed, and how accounts are managed. You get a baseline score and a ranked list of what to fix first, with each fix explained in language you can hand to a volunteer or an outside IT helper.

    It’s launching soon. Leave your email and we’ll tell you the moment it’s ready.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification. Consult qualified legal counsel regarding the privacy and records-retention laws that apply to your organization.