GDPR and the Autonomy of Churches and Religious Associations
As of May 25, 2018, churches and religious associations are required – just like other data controllers – to comply with the provisions of the General Data Protection Regulation (GDPR). However, based on Article 91(1) of the GDPR, churches and religious associations have been granted the right to apply autonomous, specific regulations and principles of data protection, provided that such regulations were in place prior to the GDPR's entry into force, and subject to their alignment with its provisions.
Receive a package of free GDPR guides and micro-trainings
GDPR in the Catholic Church
The most commonly cited example of specific principles of personal data protection is the “General Decree on the Protection of Natural Persons in Relation to the Processing of Personal Data in the Catholic Church.” It not only provides for the oversight of an independent supervisory authority, which may be separate from the President of the Polish DPA (in this case, it is the Church Data Protection Officer appointed by the Catholic Church), but also regulates in detail the standards for processing personal data, the permissibility of data processing, and the necessity of fulfilling the information obligation. Importantly, different regulations have also been adopted – in compliance with the provisions of the GDPR – regarding the rights of the individuals whose data are processed.
GDPR and Other Religious Communities
In the absence of the notification of autonomous rules regarding the application of personal data protection regulations, any entity that independently determines the purposes and means of processing personal data is obliged to comply with the provisions of the GDPR. Therefore, if a particular church or religious association has not opted to apply autonomous principles, it is required to process personal data of individuals in accordance with the provisions directly resulting from the GDPR. An example of such a religious community is the Jehovah's Witnesses. Since it has not submitted its detailed personal data protection principles to the President of the Polish DPA, it is obliged to apply the provisions of the GDPR directly.
Ease of Joining – Our Consent
By joining a church or religious association, we do so voluntarily and consciously. The legal basis for processing personal data will therefore be a voluntary, specific, informed, and unambiguous statement of will, which is simply consent. Such a legal basis for processing personal data for entities that have not opted for autonomous solutions is provided both in the aforementioned general decree of the Catholic Church (Article 7(1)(1)) and in the provisions of the GDPR (Article 6(1)(a)). Organizations such as the Jehovah's Witnesses are therefore required to obtain prior consent for the processing of personal data if, during a conversation, they take notes regarding the name and surname of the interlocutor, their family situation, or financial status. Furthermore, they are obliged to comply with the remaining provisions of the GDPR, including those concerning the sharing, entrusting, or authorizing the processing of personal data if they share this knowledge among themselves, for example, in preparation for subsequent visits.
Therefore, if we do not want a particular religious community to process our personal data and, for example, visit us, it is sufficient that we do not give consent for the processing of personal data.
The above premise for processing personal data, however, does not apply to the processing of personal data within the framework of so-called parish registers if we have already joined a given church or religious association. The legal basis for processing personal data within parish registers is Article 9(1)(d) of the GDPR. The broad scope of this legal basis for processing concerns both the personal data of members and former members of a given church or religious association.
How to Permanently Delete Personal Data?
The situation becomes somewhat complicated (though perhaps only seemingly) when one is a member of a religious organization but wishes to leave or withdraw from it. Does the community have the right to continue processing the personal data of its former member? The answer to this question is found in the provisions of the GDPR. First and foremost, it is necessary to point out the right to withdraw consent given (Article 7(3) GDPR). If we effectively withdraw our consent, the religious organization will no longer have a legal basis for further processing of personal data. After withdrawing the consent, one should submit a request to the data controller, which is that organization, for the permanent deletion of our personal data (Article 17 GDPR). Templates for such requests may be helpful in this case and are available on the Knowledge is Safety Foundation website (accessed: August 20, 2019).
Free knowledge about GDPR.
Use it freely!
Every church or religious association is obliged to comply with the provisions on personal data protection, and thus to respect both the right to join such an organization or to leave it, as well as the right to the permanent deletion of personal data. And although some may look at us askance or try to persuade us to change our decision regarding leaving the religious community, each such organization will be required to respect this decision and to permanently delete the personal data it processed based on the consent we provided, if we withdraw it. However, our personal data will remain in the records, where our departure from the given religious organization will be noted, and it may not be used by the data controller without the consent of the local ordinary or the higher superior of the institute of consecrated life.


