Practical guide
GDPR questions for church software suppliers
A starting set of evidence-focused questions for UK churches assessing personal-data handling, contracts, security and data exit arrangements.
Published · Updated
This guide is a starting point for supplier conversations, not legal advice. A church remains responsible for understanding its own processing and obtaining appropriate professional advice where needed.
Roles and contract
- Which organisation supplies the service and signs the contract?
- For each workflow, who acts as controller and processor?
- Is a data processing agreement available before purchase?
- Which sub-processors are used, for what purpose and in which countries?
Security and access
- How are administrator accounts protected?
- Are multi-factor authentication and role-based permissions available?
- What audit records can the church review?
- How are incidents communicated, and within what timeframe?
Location and transfers
- Where is each type of data stored and backed up?
- What international transfer mechanism is relied upon?
- Can the supplier provide current documentation rather than a general assurance?
Retention, correction and exit
- Can authorised church staff correct and delete records?
- How are backups handled after deletion?
- What can be exported, in which formats and at what cost?
- What happens to data and accounts after cancellation?
Assess the answer, not the badge
A reference to “GDPR compliant” does not by itself answer these questions. Record the evidence supplied, unresolved points and the date checked.
Software listings to explore
These listings are relevant because their profiles record supplier-published information about data protection, hosting or processing arrangements. They are not a compliance assessment, a ranking or an endorsement. Use them to identify questions to test against the current contract and documentation for the plan you would buy.
- ChurchSuite publishes UK GDPR and Data Protection Act 2018 terms, privacy material and configurable access-control information. Confirm the current hosting and sub-processor position for your church.
- ChurchLinker publishes GDPR, sub-processor and data-processing agreement links, and states that data is held in UK/EU data centres. Request the current documents rather than relying on a summary.
- ChurchDesk publishes data-security, privacy and data-processing-agreement material, including hosting in Germany. Check the current contractual hosting, sub-processors and transfer position.
- ChMeetings publishes security, terms and data-processing-addendum material, while its profile records supplier-published United States hosting information. Confirm the selected region and transfer safeguards that would apply to your account.