Home Articles Get your free assessmentComing soon

Tag: records retention

  • Background Checks: Who Holds Them, For How Long, and How to Destroy Them

    Background Checks: Who Holds Them, For How Long, and How to Destroy Them

    There is a drawer in most church offices that nobody thinks about.

    It holds background-check results. Every volunteer who has ever worked with children, going back as far as the church has been screening people. Some of them are printouts stapled at the corner. Some are in a folder on the shared drive called Screening. Most of them, if we’re honest, are still sitting in the office administrator’s email as PDF attachments, because that’s how the screening company delivered them and nobody ever moved them anywhere else.

    You did the screening because you take child safety seriously. That was the right call, and your insurer and your denomination probably required it.

    But the screening created something new: a small, concentrated archive of the most sensitive personal information your organization will ever touch, held by an office that was never set up to hold it.

    This post is about what to do with that archive.

    What’s actually inside one of those reports

    A background check is not a yes-or-no answer. It’s a document, and the document is dense.

    Depending on the provider and the level of check, it typically contains the person’s full legal name and any former names, date of birth, current and previous home addresses, and often all or part of a Social Security number — because that number is how the provider matches records to the right human being. Then it contains the results: county and state criminal records, sex offender registry checks, sometimes driving records, sometimes credit information.

    That combination is unusual. Plenty of organizations hold names and addresses. Far fewer hold a name plus a date of birth plus a Social Security number plus a home address, all in one file, for dozens of people at once.

    That specific combination is everything someone needs to open credit in another person’s name. It is, in practical terms, the highest-value data a small church holds — more valuable to a thief than your giving records.

    And there’s a second harm on top of the financial one. These files may contain criminal history for volunteers your church screened, considered, and welcomed anyway. A leak doesn’t just expose an identity. It exposes something a person told you in confidence, about the hardest part of their life, in order to serve. Losing that is a pastoral failure as much as a technical one.

    Where these files actually end up

    None of the following is negligence. Every one of them is what happens when a small office handles a task it was given without being given a system.

    In an inbox, forever. The screening company emails a PDF — a PDF is just a document file, and one that keeps its formatting and can be opened by anyone, with no protection unless someone deliberately adds it. It arrives, gets read, gets acted on, and stays in the mailbox. Five years later it’s still searchable by typing a volunteer’s last name, and if that mailbox is ever compromised, so is every report in it.

    In a shared drive folder open to everyone. Cloud drives default to convenient, not restrictive. A folder created by one person is very often visible to every staff account, and sometimes to every volunteer who was ever added to the team drive.

    In a filing cabinet in an unlocked office. The cabinet may lock. The question is whether it is locked at 4pm on a Thursday when the building is open for choir practice and a dozen people are walking past the door.

    For people who left a decade ago. This is the most common one. Nobody ever decided to keep the file of a nursery volunteer who moved away in 2014. Nobody decided to delete it either. Absent a decision, records simply accumulate.

    On a former administrator’s laptop. Someone downloaded the reports to work from home during a busy screening season. That laptop left with them.

    The rule that fixes most of this

    Here it is, and it’s simpler than any policy document:

    Keep the decision. Don’t keep the report.

    Your organization needs to be able to prove that a volunteer was screened, when, by whom, and that they were approved. That’s a single line in a roster: Name — screened 14 March 2026 — provider — cleared — approved by [name].

    What your organization almost never needs is the underlying report sitting in your building. The screening company already has it. That’s their business, they’re built for it, and they carry insurance for it.

    So the default should be: the provider holds the report; you hold the record of the decision.

    Most screening platforms let you view results in their portal rather than emailing them out, and many will let you turn off attachment delivery entirely. Ask your provider two questions: Can results stay in your system instead of being emailed to us? and How long do you retain them, and can we retrieve them later if we need to?

    If the answer to the first is yes, you have just removed the entire problem from your building.

    Where you genuinely must keep something — because your insurer, your denomination, or your state’s volunteer rules require a copy — keep the smallest version that satisfies the requirement, and store it in one place, not four.

    What the law expects, in general terms

    Some real caution here: this is the shape of the rules, not advice about your situation. Requirements differ meaningfully by state, by whether you use a screening company, by the type of work the volunteer does, and by whether the person is an employee or a volunteer. Your attorney and your insurance carrier should confirm your policy before you adopt it.

    With that said, three things are worth knowing.

    Reports from a screening company are usually “consumer reports.” When you buy a background check from a third-party screening company, that report generally falls under the Fair Credit Reporting Act (FCRA) — the federal law governing how consumer reporting information is obtained, used, and disposed of. The FTC and EEOC’s joint guidance for employers walks through the obligations that come with it, including giving the person a clear written notice and getting written permission before you run the check, and giving them a copy of the report and a statement of their rights before you turn them down because of it.

    There is a federal rule specifically about throwing these away. The FTC’s Disposal Rule (16 CFR Part 682) requires anyone who maintains or possesses consumer information for a business purpose to dispose of it “by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.” The FTC’s own business guidance states plainly that “any business or individual who uses a consumer report for a business purpose is subject to the requirements of the Disposal Rule,” and names employers among them. Its examples of reasonable measures: “burn, pulverize, or shred papers,” and “destroy or erase electronic files or media” so the information “cannot be read or reconstructed.”

    Retention floors exist and they’re shorter than you’d guess. The FTC/EEOC guidance points to the EEOC’s requirement that personnel and employment records be “preserved for one year after the records were made, or after a personnel action was taken, whichever comes later.” That is an employment rule, and whether it reaches your organization at all depends on your size, on whether the person is an employee or a volunteer, and on how the exemptions for religious employers apply to you. Other floors may apply too — from your state, your denomination, or your insurer. Ask. But notice the direction of the surprise: the legal floor is often low, and the reason churches keep these files for fifteen years is habit, not law.

    Building a retention rule you’ll actually follow

    A retention policy that lives in a binder is not a control. Keep it to five sentences someone can act on.

    Name two people. Access to screening results is limited to two named individuals — typically the safeguarding lead and one other. Not “the office.” Not “staff.” Two people, by name, written down. Everyone else sees the roster line, not the report.

    Pick one location. One folder, one cabinet, one portal. Multiple copies in multiple places is the actual failure mode, because you can clean up the one you remember and miss the three you don’t.

    Write the period down. Something like: background-check results are retained for [X] years after the volunteer’s service ends, then destroyed, with X confirmed by your attorney and insurer. The number matters less than the fact that a number exists.

    Put it on the calendar. A recurring annual reminder — “review screening files” — is what turns a policy into a practice. Without it, nothing is ever destroyed.

    Write down what you’ll keep forever. Usually just the roster: who was screened, when, and that they were cleared. That’s the record that protects the church years later, and it contains no Social Security numbers at all.

    Destroying them properly

    Destruction is where good intentions quietly fail, because “delete” means less than people think.

    On paper: cross-cut shred, or use a bonded destruction service that gives you a certificate. Do not put them in the recycling bin. Do not put them in the dumpster behind the fellowship hall.

    In email: deleting the message is not enough. Empty the trash or deleted-items folder too, and remember that most mail systems keep a further recoverable copy for a period after that. Check whether your provider offers a permanent-delete option, and if attachments were forwarded to anyone, delete them from those mailboxes as well.

    On a shared drive: delete the file, then empty the drive’s own trash, which usually runs on a separate timer from your email trash. Then check whether anyone downloaded a copy.

    In backups: this is the one everyone forgets. Your backup exists precisely to make deletion reversible. A file removed today may sit in backups for months. You usually can’t and shouldn’t surgically remove it, and that’s fine — but you should know the rotation period, and note that the file isn’t fully gone until that period has passed.

    On old hardware: a retiring laptop or copier can hold every report ever printed. Have drives wiped or destroyed before anything leaves the building.

    What to do this week

    Search your own mailbox for the name of your screening provider, and see how many reports come back. That number, whatever it is, is the honest starting point — and finding it takes about five minutes.

    Then do one thing: call the provider and ask whether they can stop emailing results and let you view them in their portal instead. That single change stops the pile from growing while you decide what to do about the files you already have.

    Sensitive records are one of several places churches carry more risk than they realise. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including where sensitive records like these actually live — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission and Equal Employment Opportunity Commission, Background Checks: What Employers Need to Know; Federal Trade Commission, Disposing of Consumer Report Information? Rule Tells How; Electronic Code of Federal Regulations, 16 CFR § 682.3 — Proper disposal of consumer information.

  • The Most Sensitive File in the Building

    The Most Sensitive File in the Building

    A pastor sits down after a Thursday afternoon conversation and writes half a page of notes. A marriage in trouble. A relapse. A name and a date and enough detail to remember what to follow up on next month.

    The notes go into a Word document on the office laptop, in a folder called Care. The laptop is the one the whole staff borrows when theirs is charging. The folder syncs to the shared drive, because everything on that laptop syncs to the shared drive — that’s how it was set up years ago, and it was set up that way so nothing would ever be lost.

    Every person on staff can open that folder. Not one of them ever has. That isn’t a security control; it’s good manners.

    Elsewhere in the same building: benevolence applications with bank details and eviction notices in a cabinet that doesn’t lock, a text thread on a personal phone that contains a full disclosure of abuse, and a notes field in the church management software where somebody typed “husband’s drinking again — do not mention to the Wilsons” three years ago, not realizing that eleven volunteers can see it.

    This is the most sensitive information any church holds, and it is almost always the least protected.

    Confidentiality and security are two different things

    This distinction is worth slowing down for, because the two are constantly confused.

    Clergy confidentiality — often discussed alongside the clergy-penitent privilege, a legal rule about what a minister can be compelled to testify to in court — is a legal and ethical concept. It’s about who may lawfully demand the information, and what a minister is obliged to do with it. Its scope varies significantly by state, and denominations layer their own ordination vows and disciplinary standards on top. Some states affirm the privilege broadly, some limit it to confessional communications, and the Children’s Bureau’s fifty-state summary notes that in some states it is denied altogether.

    Data security is about who can physically or technically reach the file. Passwords, permissions, locks, encryption.

    Here is the load-bearing sentence: a note that is privileged in principle is still readable by anyone with the password. Privilege governs a courtroom. It does nothing whatsoever against a compromised email account, a laptop left in a car, or a volunteer clicking into a folder they shouldn’t have been able to open.

    A related confusion is worth clearing up. Churches often assume health-privacy law covers them. Generally it does not — the federal rule applies to health plans, health care clearinghouses, and health care providers who transmit certain information electronically in connection with standard transactions. A congregation offering pastoral care isn’t ordinarily any of those. There may be exceptions if your ministry operates a counseling center, employs licensed clinicians, or bills insurance, and that’s a question for your attorney. But do not assume a federal law is protecting these records. Usually nothing is except your own practices.

    And one thing that overrides all of it: mandatory reporting obligations exist, they vary, and in defined circumstances they take precedence over confidentiality. According to the Children’s Bureau’s summary of state statutes, members of the clergy are named as mandated reporters in 29 states and Guam, and seven jurisdictions — New Hampshire, North Carolina, Oklahoma, Rhode Island, Texas, West Virginia, and Guam — disallow the clergy-penitent privilege as grounds for failing to report suspected child abuse or neglect. Four states — Indiana, New Jersey, North Carolina, and Wyoming — require all persons to report regardless of profession. That summary is current through May 2023 and these laws change. Know your own state’s rule cold, in writing, before you need it. Ask a lawyer. This article is not legal advice.

    Decide what gets written down at all

    The most effective control here isn’t technical. It’s editorial.

    Before you write anything, ask: what do I actually need to remember, and what would harm this person if it were read by someone else? Those two answers overlap far less than people assume.

    A workable standard for care notes in a congregational setting:

    Write enough to follow up. Date, who you met with, that a conversation happened, and what you committed to do. “Met with R. Follow up in two weeks. Referred to counseling resource list.”

    Leave out the detail that isn’t yours to hold. The specifics of a disclosure, third parties’ names, diagnoses, financial particulars, anything about someone’s spouse or children who were not in the room. If you don’t need it to be a good pastor next month, it doesn’t need to exist on paper.

    Never write speculation, judgment, or diagnosis. Not because someone might sue, though they might, but because you’re recording a guess about a human being that will outlive your memory of how uncertain you were.

    Assume it will be read. By a successor, by a board in a conflict, by a court under subpoena, by an attacker in a breach. Write the note that you would be content to have read aloud.

    This is not an argument for keeping no records. Continuity of care matters, and a pastor who remembers nothing serves people badly. It’s an argument for writing the minimum that does the job.

    Where these files should actually live

    Out of the general shared drive. This is the single highest-value change most churches can make in an afternoon. The default setup at a small organization is one shared drive, open to all staff, because that was simplest to configure. Care notes and benevolence files need to come out of it into a separate location with its own permissions.

    Access granted to named people, not to “staff.” There is a real difference between a folder shared with the staff group and a folder shared with Pastor Miller and Pastor Ruiz. The first automatically includes every future hire, every intern, and the office volunteer who was added to the group last spring. The second doesn’t. Name the individuals.

    Paper goes in a locking cabinet, and the key is controlled. Benevolence applications in particular — they routinely contain bank account numbers, Social Security numbers, pay stubs, and eviction notices, which is a more complete identity-theft package than most churches hold anywhere else.

    Set a retention limit and honor it. Decide how long care notes and benevolence files are kept, write it down, and destroy them on schedule. Records you no longer hold cannot be exposed, subpoenaed, or misread by a successor. What the right period is depends on your state, your denomination’s polity, your insurer, and whether any licensed counseling is involved — ask your attorney for the number, then follow it.

    Multi-factor authentication on the accounts that can reach any of this. MFA is the extra code or tap after the password. It’s free on Microsoft 365 and Google Workspace, and Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. If a folder is worth restricting, the account that can open it is worth protecting.

    Email, texting, and the notes field nobody thinks about

    Email is a filing cabinet you don’t control. A message about a member’s situation is copied into the sender’s sent folder, the recipient’s inbox, both mailboxes’ backups, and the provider’s servers. It stays there for years. If either account is ever compromised — the most common single security incident at any organization — the attacker gets not just the mailbox but the searchable history of everything the church knows about its people.

    If you must send something by email, keep the substance out of the subject line. Subject lines appear in notification previews on lock screens, on shared reception monitors, in mobile summaries, and in any forwarded thread. “Re: Thursday” is a fine subject line. “Re: Dana’s rehab intake” is a broadcast.

    Better: send “Can we talk about a pastoral matter today?” and have the conversation by voice.

    Texting is worse, and it’s what people actually use. A pastoral text thread sits on a personal phone with no organizational control at all. It appears in lock-screen previews. It’s visible to anyone who picks up the phone, including a spouse or a child. It backs up to a personal cloud account. And when that pastor leaves the church, the entire history leaves with them, on their device, permanently. Text to arrange a meeting. Don’t text the meeting.

    The church management software notes field is far more visible than people think. Almost every ChMS — church management software, the system that holds your directory, attendance, and giving — has a general notes or comments field on each person’s record. Staff type sensitive things into it because it’s convenient and it feels private.

    It usually isn’t. Depending on how your permissions are configured, that field may be visible to every staff member, every group leader, every volunteer with a login, and anyone who can run an export. Go look today: log in as a volunteer-level user, or ask one to show you their screen, and see exactly what a group leader can read on a member’s record. Most churches are surprised. Then either lock the field down properly or stop using it for anything but logistics.

    Two situations to plan for now

    When a staff member leaves. This is the moment the whole problem becomes visible. Their church account gets disabled — but the notes in their personal notebook go home in a box. The care history in their text messages leaves on their phone. The documents in their personal Dropbox stay in their personal Dropbox.

    Handle it at the front end rather than the back: make it clear from the first week of employment that ministry records belong to the ministry and live in ministry systems. Then, at departure, walk through it explicitly — accounts disabled, church files returned or transferred to the named successor, personal-device copies deleted, paper handed over. Have the conversation warmly and have it anyway, including when someone leaves on the best possible terms.

    When a device is lost. A laptop in a stolen car, a phone left in an airport. If care notes were on it, the question is whether anyone can read them.

    Two settings make the answer no, and both are free and already built in. Full-disk encryption — BitLocker on Windows, FileVault on Mac — scrambles everything on the drive so it’s unreadable without the login. On phones and tablets it’s on by default as long as you have a passcode. And remote wipe, which lets an administrator erase a device that’s gone. Turn both on across every device that touches ministry records, today, before you need them.

    If a device is lost, change the passwords for every account that was signed in on it, sign out all active sessions, and tell someone immediately. If information about people was exposed, notification requirements exist in every state and vary considerably — that’s a call to your attorney, promptly.

    What to do this week

    Open your shared drive and look at who can see the folder containing care notes, benevolence applications, or anything similar. If the answer is “everyone on staff,” move that folder somewhere with permissions granted to two or three named people. Fifteen minutes.

    Then log in to your church management software as a volunteer-level user and read what they can see on a member’s record. If the notes field is exposed, you’ve just found this week’s second job.

    MissionDefend’s free assessment asks straightforward questions about how your organization handles member data, accounts, email, and donations — no jargon — and returns a baseline score with the highest-value fixes ranked in order.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: U.S. Department of Health and Human Services, Children’s Bureau, Mandatory Reporting of Child Abuse and Neglect: State Statutes; U.S. Department of Health and Human Services, Covered Entities and Business Associates; Microsoft, mandatory multifactor authentication guidance; National Conference of State Legislatures, Security Breach Notification Laws.

  • What Do You Actually Have? A One-Afternoon Data Inventory

    What Do You Actually Have? A One-Afternoon Data Inventory

    Someone in the office asks a simple question: where do we keep the allergy list for the kids?

    Four answers come back. It’s in the check-in system. It’s also on a printed sheet in the nursery binder. Sarah keeps a copy on her phone because the tablet is slow on Sunday mornings. And there’s a spreadsheet somebody emailed around before the fall kickoff, which is still sitting in maybe nine inboxes.

    All four answers are true. That’s the problem.

    This isn’t a story about carelessness. It’s what happens when a small organization runs on goodwill and improvisation for a decade. Nobody decided to keep four copies of children’s medical information. It accumulated, the way things accumulate in a building that’s been used by a lot of people for a long time.

    You cannot protect what nobody has written down. Every other security decision you’ll make — who gets multi-factor authentication first, what to back up, what to shred, what to tell people if something goes wrong — depends on knowing what you’re holding and where it lives. That knowledge almost never exists in one place. Building it takes an afternoon.

    Why this is the first job, not the fifth

    Most security advice starts with a control: turn on this setting, buy this tool, write this policy. Those are all reasonable, and they’re all guesses until you know what you have.

    The Federal Trade Commission’s guide for businesses puts inventory first, before locks and disposal, in a single sentence: know what personal information you have in your files and on your computers. Not because it’s exciting, but because everything downstream is unanswerable without it.

    Consider what you can’t decide today. Is your backup adequate? Depends what needs backing up. Should the giving system have stricter access than the calendar? Obviously — but who has access to the giving system right now? If a laptop went missing tonight, what would be on it? If you had to notify people that their information was exposed, which people, and how would you reach them?

    Every one of those is a lookup against a list you don’t have yet.

    The four questions, and a table to hold them

    For each thing you find, you’re answering four questions. That’s the whole method.

    What is it? In plain words. Not “member records” — names, home addresses, phone numbers, birthdays, and marital status for about 340 households. Be specific enough that a stranger reading the line understands the sensitivity.

    Who can reach it? Not who should. Who actually can, today, if they tried. This includes anyone who knows a shared password, anyone whose account was never turned off, and the person who has a key to the cabinet.

    Where does the copy live? Plural, almost always. The system of record, plus the export somebody made, plus the printout, plus the backup, plus the attachment in the email thread.

    Do we still need it? The most useful question on the list, and the one that shrinks the problem fastest. Data you deleted cannot be stolen.

    Put the answers in a table — one row per thing. A single shared document, or a printed sheet on a clipboard. Either works.

    What it isWhere the copies liveWho can reach itSensitivityStill need it?
    Member directory — names, addresses, phones, birthdays, ~340 householdsChMS; export on office PC desktop; printed pictorial directory (2021)3 staff logins; 1 shared “office” login; anyone with the printed copyHighYes — but delete the desktop export
    Children’s check-in, allergies, emergency contactsCheck-in system; nursery binder; volunteer’s phone photo; emailed spreadsheet6 volunteers via shared tablet login; ~9 email recipientsVery highYes — one copy only
    Background check results, 2016–presentVendor portal; paper files, unlocked cabinetVendor login shared by 2 people; anyone in the officeVery highCheck retention rule with counsel
    Giving and pledge recordsGiving platform; QuickBooks; annual statement PDFs on shared driveTreasurer, bookkeeper, pastor; shared drive is open to all staffHighYes — restrict the drive folder
    Old laptop, closetUnknownAnyone who opens the closetUnknownNo — wipe and dispose properly

    The sensitivity column is a judgment call, and a coarse one is fine. High, medium, low. What you’re really flagging is: how bad would it be if this ended up somewhere public, or in the hands of someone who wanted to harm one of these people? A birthday list is not the same as a benevolence file.

    Now go find the rows.

    Walk the building

    Do this part physically. Take a legal pad and actually open the doors.

    The office. Filing cabinets — including the one nobody has a key for, which you should note as an open item rather than skip. Look for personnel files, background check results, old giving envelopes, offering count sheets, contribution statements, and applications from volunteers who came and went years ago.

    The children’s and youth area. Check-in records, allergy and medical information, emergency contacts, permission slips, incident reports. This is usually the most sensitive paper in the building and the least locked.

    The pastor’s study and the counseling room. Care notes, benevolence applications, correspondence. Handle this category with particular seriousness — it deserves its own conversation, and we’ll cover it separately.

    The closet, the storage room, the attic over the fellowship hall. Old computers. Old phones. A retired copier — the FTC’s guidance for businesses is blunt about this: the hard drive in a digital copier stores data about the documents it copies, prints, scans, faxes, or emails, and deleting or reformatting doesn’t actually remove it. Boxes of paper somebody meant to sort.

    The counters and desks. The sticky note with the Wi-Fi password is a minor issue. The sticky note with the login for the giving platform is not.

    Walk the accounts

    Now sit down and list the online services. This is harder, because there’s no door to open. Start from three places: the bank statement (what are you paying for?), the office computer’s saved passwords or bookmarks, and the memory of whoever has been around longest.

    Expect to find: the church management software, the giving or donation platform, the payroll provider, the accounting system, the email and file storage (Microsoft 365 or Google Workspace), the website and its hosting, the domain registrar, the email newsletter tool, the event registration tool, the background check vendor, the livestream and video accounts, the social media pages, and the survey tool somebody used once for a stewardship campaign.

    For each one, the question that matters most is the second one: who can reach it? Log in and look at the user list. Do not rely on memory.

    And then the category that catches everyone: the personal accounts holding church data. The volunteer who built the directory in her own Google Sheets. The worship leader whose personal Dropbox has every service recording. The former treasurer’s home computer, where the QuickBooks file lived. These are not violations of trust — they’re what happens when someone volunteers to help and uses the tools they already have. But that data is outside anything you control, and it walks out the door when they do.

    What you will find, because everyone finds it

    Three discoveries happen in nearly every inventory. Name them in advance so nobody feels caught out.

    The shared login. One username and password for the giving platform, or the check-in tablet, or the Facebook page, used by five people, three of whom no longer serve. It exists because it was easier, and because individual accounts sometimes cost money per seat. The cost of it is that you can never tell who did what, and you can never remove one person without disrupting everyone.

    The departed volunteer who still has access. The youth intern from two summers ago whose account was never disabled. The former board member still in the shared drive. Offboarding is the single most commonly skipped step in small organizations, because there’s rarely a formal offboarding at all — people just stop coming.

    The spreadsheet that was emailed around. Somebody exported the directory to help with a mailing, attached it to a message, and sent it to eleven people. Every one of those copies is now permanent, sitting in eleven mailboxes, four of which are personal accounts with no multi-factor authentication — MFA, the extra code or tap after the password. If any one of those accounts is ever compromised, your directory goes with it.

    None of these are failures of character. They’re the predictable result of a small staff doing a large job. Write them down without commentary, and fix them in order.

    Turning the list into decisions

    The inventory is only worth the afternoon if it changes something. Three immediate moves come almost free.

    Delete. Go down the “still need it” column and act on every no. Old exports, duplicate spreadsheets, applications from people who never served, printed directories from four years ago. Paper goes in a shredder, not a recycling bin. Devices need to be properly wiped, not just deleted from — get help with that if you’re unsure.

    Reduce copies. For anything marked very high, drive it toward a single authoritative copy with controlled access. The nursery binder and the phone photo and the emailed spreadsheet all go away; the check-in system stays.

    Fix the access list. For the three or four most sensitive systems, remove everyone who shouldn’t be there, and put individual logins in place of shared ones where you can.

    Two things to note but not solve today. Records retention — how long you’re required to keep giving records, personnel files, and background checks — has real legal and tax dimensions, and the answer differs by state and by what kind of organization you are. And if information about people is ever exposed, notification requirements exist in all fifty states, the District of Columbia, and several territories, and they vary considerably in who they cover and what they require. Both of those are questions for your attorney, with your inventory in hand. The inventory is what makes that a thirty-minute conversation instead of a three-hour one.

    What to do this week

    Block ninety minutes. Take a legal pad and walk the building — office, children’s area, closets, storage. Write down every place you find information about a person, and note who can reach it. Don’t fix anything yet; just list it.

    Then open the two systems that hold your most sensitive data — usually the check-in system and the giving platform — and look at the user list. Remove anyone who has left.

    That’s it for week one. You’ll have more of a security program than most organizations twice your size.

    Once you know what you hold, the next question is how well it is protected. MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then returns a baseline score and a ranked list of what to fix first. An inventory like this makes those answers much easier to give.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, Protecting Personal Information: A Guide for Business; Federal Trade Commission, Digital Copier Data Security: A Guide for Businesses; National Conference of State Legislatures, Security Breach Notification Laws.