If your church has a website with a contact form, a newsletter signup, or even just a “prayer request” box, you’re already collecting personal data — and UK GDPR applies to you just as much as it applies to any business. Many churches assume data protection law is something only large organisations need to worry about. In reality, the size of your congregation has nothing to do with whether the law applies; what matters is that you’re collecting and storing people’s information.

The good news is that compliance doesn’t have to be complicated, and it’s a natural extension of good church website design practice rather than a separate technical burden. Here’s what actually matters for a church website.

What counts as personal data on a church site

It’s more than names and email addresses. Personal data collected through a typical church website can include:

  • Contact form submissions (name, email, phone number)
  • Newsletter or mailing list signups
  • Prayer requests, which often contain sensitive personal circumstances
  • Event or Sunday school bookings, sometimes involving children’s details
  • Donation records, including payment information
  • Photos of congregation members published in galleries or on social media

Some of this — prayer requests in particular — can count as “special category data” under GDPR, since it may reveal health information, family circumstances, or other sensitive details. This data needs extra care, both in how it’s collected and how securely it’s stored.

The basics every church website needs

A privacy policy. This should explain what data you collect, why, how long you keep it, and who it might be shared with (for example, a mailing list provider like Mailchimp). It doesn’t need to be written by a lawyer, but it does need to be accurate and easy to find — usually linked in the footer of every page.

Clear consent for forms. Any form that collects data should make clear what happens to that information. A checkbox that says “I’d like to receive the newsletter” is far safer than pre-ticked boxes or vague wording buried in terms and conditions.

Cookie consent, if you use analytics or tracking. If your site runs Google Analytics or embeds YouTube videos, it’s likely setting cookies. A simple cookie banner giving visitors the choice to accept or decline covers this.

A photo policy. Publishing photos from services or events is common, but it’s worth having a simple process for opting out — particularly for photos involving children, where extra caution and often parental consent is expected.

Third-party plugins and hosting

Many church websites run on WordPress with a handful of plugins for forms, event bookings, or donations — the same kind of setup covered in our guide to SEO for church websites. Each of these plugins is a potential data processor, meaning you’re responsible for knowing where that data goes and how it’s protected. It’s worth checking:

  • Whether your form plugin stores submissions on your own server or sends them to a third party
  • Whether your hosting is based in the UK/EU, or if data may be transferred elsewhere
  • Whether old form submissions and inactive user accounts are ever deleted, rather than kept indefinitely
  • Whether your site is built with a mobile-first design, since mobile forms often use different plugins or embeds than the desktop version — each one worth checking separately

What to do if something goes wrong

Even with good practices in place, mistakes happen — an email sent to the wrong list, a plugin vulnerability, a lost device with member data on it. Under UK GDPR, if a breach is likely to risk people’s rights or freedoms, it must be reported to the Information Commissioner’s Office (ICO) within 72 hours. Having a simple, agreed process for who does this and how — decided in advance, not scrambled together during a crisis — makes a real difference.

A practical starting point

You don’t need to overhaul your entire website overnight. A sensible first step is:

  1. List everywhere on the site that collects personal data
  2. Check each one has clear, honest consent wording
  3. Make sure your privacy policy actually reflects what you do
  4. Confirm sensitive data (like prayer requests) is stored securely and only accessible to those who need it

If you’re planning a wider rebuild or migrating your church website, it’s the ideal time to review data handling too — new forms, new plugins, and new hosting all reset the checklist above.

Getting this right isn’t just about avoiding fines — it’s about maintaining the trust your congregation and visitors place in you when they share personal, sometimes deeply personal, information through your website.