Keeping data forever seems safer than deleting it, but it actually creates unnecessary risk. Here is how to think about how long each type of data should really be kept.
Why keeping everything indefinitely isn't the safer option
Unnecessarily retained data increases the risk surface in case of a security breach, and often contradicts data minimization principles present in many data protection laws.
Data categories and typical timeframes to consider
- Financial records with tax implications. Often subject to specific legal deadlines, frequently several years, set by local tax law.
- Active member contact data. Kept as long as the membership relationship remains active, with no artificial deadline imposed.
- Former member data with no erasure request. A reasonable period, set by the church's internal policy, after which data is archived or removed if there's no reason to keep it.
- Records of spiritual milestones. Baptisms, weddings, often kept indefinitely for their historical and practical value, even after the person has left.
How to set a retention policy without being a legal expert
A simple table, data category by data category, with the retention period and the justification for it, covers most needs without requiring extensive legal consultation for every decision.
What to do when the retention period expires
Having a process, even a manual one initially, to periodically review data that's passed its defined deadline, keeps the policy from staying on paper without real enforcement.
How to balance retention with genuine historical value
Not everything should be deleted the moment a technical deadline expires. Records with genuine historical value to the church, without identifiable sensitive personal data, can legitimately justify longer retention.
What this means in practice
A clear retention policy protects both the church and its members, avoiding unnecessary risk accumulation. Ekklesias lets you configure retention rules by data category. You can see how the full platform works.
← Back to blog