Home Articles Get your free assessmentComing soon

How to Protect Member and Donor Information at Your Church

A church workroom with member mail pigeonholes, a locked records cupboard and an open directory on the counter

When someone fills out a visitor card, gives online, signs their child into the nursery, or sits down with a pastor for a difficult conversation, they are handing your organization something. Not just information — trust. They are assuming that what they shared stays where they put it.

That assumption is doing a lot of quiet work. It is why people give, why they volunteer, and why they tell you things they have not told anyone else. A breach does not just cost money. It spends down the one asset a church cannot replace.

The good news is that protecting this information is mostly about a handful of decisions, not about buying technology. Here is how to work through them.

Start by knowing what you actually hold

Almost no church can answer the question what personal information do we have, and where is it? Not because anyone is careless, but because the data accumulated over years, across systems, added by different people.

Spend an hour making a list. Not a formal data inventory — a list. Walk through it in categories.

Your church management system holds names, addresses, phone numbers, family relationships, attendance, and often giving history. Your accounting system holds giving records, and possibly bank account details for recurring givers and staff. Your online giving platform holds payment information, though ideally your organization never sees full card numbers. Email holds everything anyone has ever sent, which in practice is the most sensitive collection you own. Shared drives hold spreadsheets — and these are the ones that surprise people, because someone exported the full member list to a spreadsheet in 2023 for a mailing and it is still sitting in a folder. Children’s ministry check-in holds minors’ names, guardians, allergies, and photo permissions. Background check results and personnel files may be in a filing cabinet, an email attachment, or both. And pastoral care notes, if they exist in writing anywhere, are the most sensitive records in the organization.

Write down where each lives and who can get to it. This list is the foundation for everything else, and making it usually surfaces at least one thing that should not exist anymore.

Decide who should see what — then enforce it

The most common serious problem is not hackers. It is that far too many people inside the organization can see far more than their role requires.

This happens innocently. A volunteer needed admin rights for one project three years ago. A staff member changed roles but kept old permissions. The database was set up by someone who gave everyone full access because it was simpler.

Work through it role by role rather than person by person. Ask what a nursery volunteer genuinely needs: the children and guardians they are checking in that morning, and nothing else — certainly not giving history. A small group leader needs contact details for their group. The finance team needs giving records. The senior pastor may need broad access, but “may” is worth examining. Most administrative tasks do not require seeing what individual families give.

Then apply two principles that carry most of the weight. Give the least access that lets someone do their job, and give it for as long as they hold that role, not permanently. And treat giving records as a separate, tighter category than contact information — in most churches, far more people can see giving history than have any business seeing it, and members would be startled to learn who.

Put a recurring calendar reminder every quarter to review the user list in your church management system, your email admin console, and your accounting software. Ten minutes, four times a year.

Protect the accounts that open the doors

All the access control in the world does not help if someone simply logs in as your administrator.

Email is the master key, because it resets every other password — protect it first and hardest. Every staff member and every volunteer with access to member data should have multi-factor authentication enabled. This is the highest-value change available to you, it is free on both Microsoft 365 and Google Workspace, and it takes an afternoon.

Get rid of shared logins. One password to the database that six people know means you cannot revoke one person’s access, cannot tell who exported what, and cannot investigate anything. Give people individual accounts. Where a shared credential genuinely cannot be avoided, put it in a password manager with proper sharing so at least it can be rotated when someone leaves.

And close the door behind people who go. The most common way former volunteers retain access to member data is that nobody remembered to turn the account off. Add it to whatever departure process already exists.

Stop collecting what you do not need

Every piece of information you hold is a piece you have to protect. The cheapest security measure in existence is not having the data.

Look at your visitor card and your event registration forms. Are you asking for a date of birth you never use? A Social Security number you have no business collecting? A home address for an event that does not need one?

Then look backward. That 2019 mailing list export, the old volunteer applications, the spreadsheet of every attendee from a conference you hosted — if it has no current purpose, deleting it removes risk permanently. Write down a simple retention rule so this does not require judgment every time. Something as plain as contact records are kept while someone is connected to the church and for three years after; giving records are kept as long as tax rules require; visitor cards are entered into the database and then shredded is enough. Confirm the financial retention periods with your accountant, since those are set by tax and audit requirements rather than by preference.

Handle the most sensitive records differently

Some categories deserve stricter treatment than the general membership database, and it is worth being deliberate about them.

Counseling and pastoral care notes. If these exist in writing, they should be the most tightly held records you have — accessible to the minister involved and essentially nobody else, and never stored in a shared drive or general email folder. Confidentiality expectations here are both ethical and, in many states, legally significant. Talk to counsel about how privilege applies in your jurisdiction before deciding where these live.

Children’s ministry records. Minors’ information, guardian details, allergies, photo permissions, and check-in history. Access should be limited to current children’s ministry leadership, reviewed every term as volunteers rotate, and separated from the general directory.

Background checks. These frequently end up as email attachments, which is the worst possible place for them. They belong in a restricted personnel file with access limited to the one or two people responsible for screening.

Anything about giving. Members generally assume their giving is known to a very small number of people. Make that assumption true.

Make sure your vendors are holding up their end

Most of your member data is not on your premises. It is on servers belonging to your church management software company, your giving platform, your email provider, and your backup service. Their security is your security.

You are entitled to ask, and a good vendor will answer without evasion. Ask whether they support multi-factor authentication and role-based permissions, whether data is encrypted at rest and in transit, whether they have a current third-party security report such as a SOC 2, what their notification commitment is if they are breached, and how you would get a full export of your data if you left. That last question matters more than it sounds — your ability to leave is your leverage.

If a vendor cannot answer these questions, that is itself an answer.

Get backups right

Protecting information means protecting its availability, not just its confidentiality. A member database that has been encrypted by ransomware or deleted by accident is a data protection failure too.

Your church management system, financial records, and shared documents should be backed up automatically, retain several weeks of history, and keep at least one copy that someone with your password cannot reach or delete. Cloud platforms are resilient but they are not backups on their own — a deleted file syncs its deletion everywhere.

Then restore one file. Pick something from a month ago and bring it back. Untested backups fail at exactly the moment you need them.

Say what you do, and do what you say

If you publish a privacy statement — and you should — keep it short and truthful. Members appreciate knowing what you collect, what you use it for, that you do not sell or trade donor lists, who can see giving records, and how to ask for their information to be corrected or removed.

Do not copy an enterprise privacy policy off the internet. A promise you do not keep is worse than no promise, and a plain paragraph that is accurate does more for trust than three pages of legalese that is not.

Be aware, too, that data privacy law is expanding and several state laws now reach some nonprofits. This is worth a conversation with counsel rather than a guess, particularly if you operate across state lines or collect information from people outside the United States.

Train the people who touch the data

The most likely way member information leaves your organization is not a sophisticated intrusion. It is an email sent to the wrong address, a spreadsheet attached in error, a directory forwarded to someone who asked nicely, or a staff member who fell for an impersonation email.

Twice a year, spend fifteen minutes with everyone who touches member data on the specific things that go wrong. Check the recipient before sending anything with personal information attached. Never email a full member export — share a link with permissions instead. Verify by phone before acting on any request to change bank details or send money. And report mistakes immediately, because a misdirected email caught in ten minutes is a very different event than one caught in ten days.

That last point deserves emphasis. Build a culture where people report their own errors without fear. The organizations that get hurt badly are almost always the ones where somebody was too embarrassed to speak up.

A realistic place to begin

You will not do all of this in a week, and you do not need to.

Start with three things. Turn on multi-factor authentication for everyone with access to member data. Pull the user list from your church management system and remove anyone who should not be there. And find out who can currently see giving records, then decide whether that list is right.

Those three actions, done in a single afternoon, close the gaps most likely to hurt you.

When you want the full picture — including the parts of this that are easy to miss — MissionDefend’s free assessment will walk you through plain-English questions about how your organization stores member and donor information, who has access, how donations are processed, and how accounts are managed. You get a baseline score and a ranked list of what to fix first, with each fix explained in language you can hand to a volunteer or an outside IT helper.

It’s launching soon. Leave your email and we’ll tell you the moment it’s ready.

No spam and no sales calls — just one email when it’s live.


MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or a compliance certification. Consult qualified legal counsel regarding the privacy and records-retention laws that apply to your organization.

Found this useful? Pass it on.

Facebook X LinkedIn Email