Quick answer
Software can help a church apply an agreed records-retention approach with fields, access controls, review reminders, exports, archives and deletion steps. It cannot decide what the church must keep, why a record is needed, how long to retain it or whether a historic record has archival value. Start with the rules and guidance that apply to the church’s legal body, denomination, nation and record type. Then map each system’s records to a retention decision with a named owner and review date. A supplier’s default deletion setting is not a records policy.
This guide is not legal, data-protection, safeguarding, employment, tax or archival advice. Some records, particularly safeguarding, clergy, financial, HR or formal registers, need specialist or denominational advice. Never delete a live concern, a record subject to a legal hold, or material whose retention status has not been decided through the appropriate process.
Set policy before changing software settings
Begin with record types and purposes, not platforms. A church-management profile, inbox, finance package, booking system and cloud drive can all contain records with different retention requirements. The relevant questions are: what is this record; why was it created; who needs it; what rule or guidance applies; when does the retention period start; where will it be held; and what happens at review?
The ICO’s storage-limitation guidance says personal data must not be kept in identifiable form longer than necessary for the purpose, but it does not give universal retention periods.1 A church therefore needs an applicable schedule or documented decision rather than a generic “delete after seven years” rule.
For Church of England bodies, the current Records and Information Management resource points to a retention schedule updated in May 2026 and a practical record-keeping review guide; it says the schedule covers what to keep, for how long and what can be disposed of or archived.2 Other churches should use guidance and advice applicable to their own governance and record types. Do not present a Church of England schedule as a universal rule for every UK church.
Build a retention map that people can use
Make a small map linking record types to real systems and owners. Do not put sensitive record detail into the map. The point is to make lifecycle decisions visible.
| Record type/purpose | System or location | Owner | Applicable policy or advice | Review and action |
|---|---|---|---|---|
| Current contact record | Church database | Office/data owner | Church privacy and records approach | Review inactive records and fields |
| Finance or Gift Aid evidence | Finance system/files | Treasurer | Applicable financial/tax rules | Retain and review with finance records |
| Safeguarding material | Controlled approved process | Safeguarding lead | Current safeguarding and records guidance | Separate specialist review only |
| Event registrations | Event platform/database | Event owner | Event purpose and privacy information | Close, minimise or archive after event |
| Published media | Hosting/platform files | Communications owner | Permission, archive and removal approach | Scheduled editorial review |
Record the start event for a period: end of financial year, closure of a case, end of employment, last contact or completion of an event. Without it, a retention label cannot be applied consistently. Include a clear exception process for a complaint, investigation, legal requirement or archival decision.
Configure systems to support, not replace, the map
Once policy decisions exist, configure the software around them. Useful controls can include required record type, status, review date, archive location, restricted roles, locked deletion, audit history, export, and a controlled deletion queue. Keep configurations explainable to the people responsible for records. An elaborate automation that deletes material without an owner is a risk, not a compliance feature.
Test whether a system distinguishes archive from deletion. An archived record may still contain personal data and need access control, review and retention justification. A deleted record may remain in backups for a period. The ICO says processor contracts must provide for deletion or return of personal data at contract end, while recognising that backup deletion can occur on a secure later cycle when safeguards are in place.3
Do not use a broad “notes” field to avoid classification. If the church cannot identify the type, purpose and access boundary of information, it cannot reliably apply a review or retention decision to it.
Run a review and deletion rehearsal
Use fictional or low-risk test records. Run a rehearsal before enabling any automatic setting.
- Create one test record for each mapped type with a clear purpose and owner.
- Apply the relevant access role, review date and archive/deletion action.
- Check that an ordinary user cannot override a sensitive decision.
- Export a test record and confirm it remains intelligible and access-controlled.
- Move one item to archive and confirm its future review responsibility.
- Delete a disposable test item and check user-visible deletion, audit evidence and backup explanation.
- Simulate supplier exit: obtain the current export, return/deletion route and contract evidence.
The rehearsal should not use a real safeguarding, pastoral or HR record. For those areas, test the workflow with the appropriate lead and use the approved policy, not a generic test case.
Implement a regular records review
Retention is a recurring operating practice. Set an annual or proportionate review date for the map, and a more frequent review where systems or processes change. Train owners to identify a new record type, apply a status and raise an exception. Keep evidence of decisions, but not a new duplicate store of all records.
The ICO recommends clear retention and erasure policies as good storage-limitation practice.1 The National Archives’ charity-sector framework also treats retention, transfer and disposal as part of a records lifecycle rather than a one-off deletion exercise.4 Use those principles to make reviews consistent, but get specialist advice where a record has legal, safeguarding or historic significance.
When replacing a supplier, agree what is returned, archived, transferred or securely deleted before the contract is switched off. The account closure process belongs in the implementation plan, not in a final email from the supplier. Keep the church’s records map updated with the new system and any new processor.
Software listings to explore
No software listing can determine your retention policy. These profiles are relevant only after the church has mapped its own records decisions.
- ChurchSuite, iKnow Church and ChurchTools are broad database profiles to examine for access, export and record-management controls.
- iKnow Safeguarding and Parish Safeguarding Dashboard require a separate safeguarding evaluation and approved records approach.
- ExpensePlus is a finance-focused profile where financial-record requirements must be considered separately.
- ChurchBase and ShepherdCare are general record environments requiring ownership, access and lifecycle decisions.
Start with the church-management category only if a records review identifies a genuine system gap rather than a missing policy decision.
Sources and research limits
This guide was researched and checked on 28 July 2026. It provides a system-implementation framework, not retention periods or legal advice. Confirm current denomination-specific, charity, tax, safeguarding, employment and data-protection requirements before changing live records.
Footnotes
-
Information Commissioner’s Office: Storage limitation (accessed 28 July 2026). ↩ ↩2
-
Church of England: Records and Information Management (accessed 28 July 2026). ↩
-
Information Commissioner’s Office: What needs to be included in the contract? (accessed 28 July 2026). ↩
-
The National Archives: Retention and transfer management framework (accessed 28 July 2026). ↩
Keep moving
Continue your decision
These next guides follow the same decision journey. They are not a ranking or a complete set of related products.
GDPR questions for church software suppliers
Ask UK church software suppliers practical, evidence-based questions about contracts, personal data, security and leaving the service.
How to migrate church management software
Move church-management systems with a careful plan for export, mapping, testing, cut-over, checking results and closing the old system.
How to choose church safeguarding software
Choose safeguarding administration software by testing records, access, reporting routes, retention and handover without mistaking software for safeguarding judgement.
Safeguarding administration, Children’s ministry and check-in