The shared drive has a folder called Old Stuff. Inside it is a folder called Old Stuff 2.
Somewhere in there is a spreadsheet from 2011 with the name, home address, phone number, and date of birth of every child who came to vacation Bible school that summer. Those children are adults now. Most of their families moved away. Nobody has opened the file in fifteen years.
It’s still there because deleting it never felt like anyone’s job, and because deleting things feels vaguely irresponsible — like throwing away the church’s memory.
Here’s the thing nobody says out loud in security training, and it’s the whole point of this post:
Data you no longer hold cannot be stolen.
Not “is harder to steal.” Cannot be stolen. There is no attacker clever enough, no password weak enough, no misconfigured folder careless enough to expose a file that does not exist. Deletion is the only control with a perfect success rate, and it’s the one almost nobody applies.
Deletion is a security control, not housekeeping
Every other thing we recommend reduces the probability that something goes wrong. Multi-factor authentication makes an account much harder to break into. Backups make a ransomware attack survivable. Good habits around payment changes make fraud far less likely. All of them are worth doing, and none of them are perfect.
Deleting data changes something different. It reduces the consequences — the size of the loss if the other controls fail.
Think about what a breach costs a church. Almost all of it scales with how many people’s information was involved: the notification letters, the phone calls, the pastoral fallout, the trust. A compromised mailbox holding two years of correspondence is a bad afternoon. The same mailbox holding twenty years is a very different event.
The size of your worst day is decided years in advance, by what you chose to keep.
Why churches keep everything
Not carelessness. Four honest reasons.
Deleting feels like erasing people. A church’s records are its history — baptisms, marriages, funerals, membership rolls. That instinct is correct for the historical record and wrong for the operational one. Nobody is suggesting you throw away the baptismal register. We’re talking about the 2019 volunteer sign-up sheet with everyone’s cell numbers on it.
Storage got cheap. There’s no longer a filing cabinet filling up to force the decision. Cloud storage — meaning files kept on a provider’s servers rather than a computer in your office — just quietly expands.
Nobody owns it. Retention is nobody’s job description. It falls between the treasurer, the administrator, and the board, which means it falls on the floor.
Fear of needing it later. This is the real one. What if we’re audited? What if there’s a dispute? That fear is legitimate, and the answer is not “keep everything forever” — it’s “find out the actual requirement, write it down, and then be free of the question.”
A framework to start from
What follows is general information and a starting point for a conversation, not a legal answer. Tax, employment, denominational, and state requirements all set floors, they vary by state, and they change. Confirm every line below with your accountant and your attorney before you adopt it. Two anchors are worth knowing because they come from the IRS guidance written for exempt organizations rather than from general small-business advice. IRS Publication 4221-PC tells public charities they “must keep records for federal tax purposes for as long as they may be needed to document evidence of compliance with provisions of the IRC,” notes that “generally, the statute of limitations runs three years after the date the return is due or filed, whichever is later,” and adds that if an organization has employees, “it must keep employment tax records for at least four years after filing the fourth quarter for the year.”
Giving and donation records. Long retention. These support your tax filings and your donors’ deduction claims, and your accountant will have a firm view. Keep them — but keep them in your giving platform or accounting system, not as spreadsheets scattered across the drive.
Member and attendance contact data. Short. This is a live directory, not an archive. If someone left the congregation in 2018, ask whether their cell number and home address need to be in an active file in 2026.
Children’s and youth records. The most sensitive category and the one requiring the most care in both directions. Many organizations hold these far longer than the tax rules would suggest, because the window in which a claim relating to a minor can be brought is long and varies considerably from state to state — that is usually a decision driven by limitations periods and insurer expectations rather than by a statute telling you to retain the file. Do not guess here. Ask your attorney and your insurer specifically about this category.
HR and payroll. Governed by employment and tax rules with real floors. Your payroll provider or accountant can tell you what applies. Note that the floors typically cover the tax records, not every email about the hiring process.
Background-check results. Often among the shortest, and best held by the screening provider rather than by you. Reports from a screening company generally fall under federal consumer-reporting law, which sets its own rules for how they are used and disposed of, so this category deserves its own policy.
Counseling and pastoral care notes. Special handling. There are confidentiality and privilege considerations that vary by state and by whether the person providing care is licensed. This is a lawyer question before it is an IT question.
Email. The default here is genuinely wrong in most churches, which is “keep it all forever.” Ask a different question: what does your organization actually need from a mailbox that is five years old? For most staff, the honest answer is nothing.
Photos and video. Retain the ones you use. Delete the eleven hundred near-duplicates from the 2017 mission trip. Pay particular attention to images of children, and to whether you still hold current permission to use them.
Board minutes and governing documents. Keep permanently — the IRS guidance for public charities says to keep the application for recognition of exempt status, the determination letter, organizing documents such as articles of incorporation and bylaws, and board minutes indefinitely. These are your corporate memory and your legal backbone, and they contain almost no personal information. This is the category where “keep everything” is right.
Where deletion quietly fails
You delete a file. You feel better. The file is still there, in one to five other places.
Email archives. Many organizations have archiving or journaling turned on — a system that copies every message to separate long-term storage. Deleting from the mailbox does nothing to the archive.
Trash and recycle bins with their own timers. Deleted email goes to a trash folder. Deleted cloud files go to a drive trash. These are separate systems with separate retention periods, and most business platforms keep a further recoverable copy that only an administrator can see, for a period after that. Deleting once is rarely deleting.
Backups. Your backup exists specifically to defeat deletion — that’s its job. A file removed today may live in backups for months. You generally shouldn’t try to surgically extract it, and you don’t need to. You do need to know your backup rotation period, so you know the honest date when the data is actually gone.
The export on someone’s laptop. The volunteer who pulled the full membership list into a spreadsheet to do the Christmas mailing. The treasurer who downloaded giving data to work on the budget at home. These copies are invisible to every policy you write, which is why the policy has to name them: no exports to personal devices, and any working copy is deleted when the task is done.
Third-party platforms you no longer use. The event-registration site from 2019. The old church management system you migrated away from. The mass-texting service someone trialled. Cancelling a subscription does not necessarily delete the data — many services retain it, sometimes indefinitely, unless you specifically ask. When you stop using a platform, send a written request to delete your data and keep the reply.
And the “delete” that isn’t a delete at all. Moving a file into a folder called Archive is not deletion. It is deletion’s costume.
The file is still on the same drive, with the same permissions, visible to the same people, included in the same backups, and exposed to exactly the same attack. Nothing has changed except that you now feel finished.
The same is true of renaming a folder DO NOT USE, of moving old records to “that laptop in the closet,” and of unplugging a computer that still has a hard drive in it.
Real deletion means the data is gone from the live system, gone from the trash, and on a known countdown out of backups. Anything short of that is filing.
One hour, once a year
A retention policy that requires a committee will never run. Here is a version that runs.
Put one recurring reminder on the calendar. Same week every year. Call it records review. Give it sixty minutes.
Do one category per year. Year one: email. Year two: the shared drive. Year three: old platforms and subscriptions. Trying to do all of it at once is how the whole thing gets abandoned in year one.
Two people, not one. One person who knows where things are, one person who has authority to say delete. That pairing prevents both paralysis and mistakes.
Write down what you did. Three lines in a document: what you reviewed, what you deleted, what you decided to keep and why. If anyone ever asks whether your organization managed its records responsibly, that log is the answer.
Start with the easiest win. Old platforms you no longer use. Deleting an account you already stopped paying for is pure gain, and it usually takes ten minutes per service.
The one time you stop deleting immediately
There is an exception, and it is absolute.
If your organization is involved in litigation, or a claim, or a government or denominational investigation — or if any of those becomes reasonably foreseeable — routine deletion stops that day, for everything that might be relevant. This is commonly called a legal hold: an instruction to preserve records that would otherwise be destroyed on schedule.
The federal rule governing litigation in federal court is blunt. Rule 37(e) applies where “electronically stored information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it.” Note the words anticipation of. The duty can begin before anyone files anything — before you receive a letter, sometimes at the moment a serious allegation is made. State courts have their own rules, and they vary, which is another reason this is a question for your attorney rather than one to settle from a blog post.
Practically, that means two things. Deleting on a published schedule, before any of this arises, is ordinary responsible practice. Deleting after it arises is a separate and much more serious problem, and the appearance of it is nearly as damaging as the fact.
So: get your attorney’s guidance on when a hold starts, know how to pause your routine, and if there is any question at all about whether something is in dispute — stop, and ask before you delete.
What to do this week
Open the list of software your organization pays for, or used to. Pick one service you no longer use, log in, and delete your data — or email their support address asking them to delete it and save the reply.
Then put one recurring calendar reminder in place, once a year, sixty minutes, called records review. That reminder is the entire policy. Everything else is detail you can add later.
Twenty minutes, and you’ve turned “we should really deal with that someday” into something with a date on it.
MissionDefend’s free assessment works through the same ground in plain English — where your organization’s information actually lives, who can reach it, and what’s still being kept for no reason — and hands you a baseline score with a ranked list of what to fix first.
No spam and no sales calls — just one email when it’s live.
Related reading
- listing what you hold before deciding what goes
- how the size of a breach drives notification duties
- screening reports, and how to destroy them properly
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: Internal Revenue Service, Publication 4221-PC, Compliance Guide for 501(c)(3) Public Charities; Internal Revenue Service, Recordkeeping requirements for exempt organizations; Legal Information Institute, Cornell Law School, Federal Rule of Civil Procedure 37(e).

