Data protection is an important part of parish life. Parishes handle personal information about the congregation, volunteers, employees and others, and must do so responsibly and with care.
This page offers some guidance on parish responsibilities under UK data protection law, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and the Data Use and Access Act 2025.
New guidance is being developed by the Information Governance Team and will be made available by the end of March 2026.
Explore these pages for more:
- The Eight Rights of Individuals under GDPR
- The Six Lawful Bases under GDPR
- GDPR terms and what they mean
- GDPR FAQs
GDPR Training
Parish Buying has negotiated discounted rates on GDPR training with provider Me Training. Each course costs just £10 and there are five levels, ranging from Basic to Advanced. You can book through Parish Buying by following this link. (Free registration is needed.)
Templates
You might find these templates useful for your parish GDPR admin:
- Privacy Notice
- Retention Policy
- Audit Form
- Consent Form
- Churches’ CCTV Policy template and the accompanying Guidance for churches which have a camera surveillance system installed
Last Updated
Jan 2026 – removed and replaced introductory paragraphs to reflect change in legislation
Mar 2024 – updated Churches’ CCTV Policy Template V.2.0