Platform Blog Pricing Log in Subscribe now Start for free

GDPR, LGPD and religious data: what every church needs to know

If your church records who attends, who's part of a small group, or even who asked for prayer over a personal matter, you're processing religious belief data. That puts your church under the strictest rules of GDPR and LGPD, even as a non-profit organization. Here's what that means in practice, without the legal jargon.

Why religious data is a special category

GDPR (Europe) and LGPD (Brazil) treat data about religious belief as a "special category" or "sensitive data", in the same group as health or political opinion data. The reasoning is simple: improper exposure of this kind of information can cause real harm to a person, in contexts where religion is grounds for discrimination. This applies even if your church never intended any harm at all, the law protects based on the type of data, not the intent of whoever holds it.

In practice, this means the simple fact that someone appears on your membership list already reveals that person's religious belief. Every export, every list shared, every uncontrolled access, is an exposure of that sensitive data.

What this changes in day-to-day church life

  • A clear legal basis. For every type of data it holds, the church needs to know what legal basis justifies it: explicit consent, legitimate interest, or fulfilling an existing relationship with the person.
  • Controlled access, not blanket access. Not everyone in leadership needs to see everything. A sensitive pastoral note shouldn't be visible to someone who just needs to confirm a phone number.
  • Right to erasure. When a former member asks to be removed from records, the church needs a real process for that, not just goodwill.
  • Portability. A person has the right to request their own data in a form they can take with them, if they decide to leave.

The most common mistake: assuming this only applies to businesses

Both GDPR and LGPD apply to any organization that processes personal data in a structured way, including churches, associations and non-profit religious organizations. Organization size doesn't exempt anyone from responsibility, though how you comply can be proportional to a small church's reality.

Compliance without a legal department

A church doesn't need a full-time lawyer to meet these rules. It needs three concrete things: a system that separates administrative data from sensitive pastoral notes, a defined process for erasure or export requests, and the discipline of not exporting full lists to share by email or WhatsApp without real need.

What this means in practice

Legal compliance isn't extra bureaucracy, it's about protecting the people who trust your church with information that, in many contexts around the world, can still be costly to expose. That's why Ekklesias's security architecture was built with per-church isolation, granular access control, and native compliance with GDPR, LGPD and Angola's Law 22/11 from the start. You can see how the full platform works.

← Back to blog

Try Ekklesias with your own data.

No credit card. No commitment.