Churches & Charities
Data Protection for Jamaican Churches & Charities
Practical Jamaica DPA guidance for churches, charities and non-profits handling member, donor, volunteer and beneficiary information.
What you will learn
- Why non-profits can hold particularly sensitive information
- Why religious belief is sensitive personal data
- The processing activities and risks specific to faith and community groups
- Why the DPO requirement deserves careful assessment
Churches and charities can hold particularly sensitive information: member information, religious affiliation, donor records, financial information, prayer requests, counselling information, health information, beneficiary records, volunteer information, photographs and children's information.
Religious beliefs are specifically within the Act's concept of sensitive personal data. That means a church may process sensitive personal data simply because of the nature of its membership and activities.
Typical processing activities
Membership, donations, pastoral care, counselling, volunteering, community assistance, events, children's ministries, communications, marketing and fundraising, CCTV and employment. Capturing these in a Personal Data Register is a strong first step.
Common risks
Informality can create privacy risk. Examples include membership spreadsheets shared widely, prayer requests circulated without appropriate consideration, beneficiary information sent through informal messaging groups, volunteer access not removed, photographs published without proper governance, and donor lists improperly disclosed. A short privacy risk assessment and volunteer and staff training address most of these.
DPO consideration
Because religious beliefs constitute sensitive personal data, organisations processing such information should carefully assess the Act's DPO requirements. The OIC states that controllers processing sensitive personal data are among those required to appoint a DPO.
Retention and notices
Set documented retention rules for member, donor and beneficiary records, and publish a clear Non-Profit Privacy Notice.
Put this into practice
A readiness check for the member, donor and beneficiary data you hold.
Assess Our Privacy ReadinessFrequently asked questions
Key takeaways
- Non-profit status does not make personal data low risk.
- Religious beliefs are sensitive personal data under the Act.
- Informal practices such as broad message groups create real privacy risk.
- Organisations processing sensitive data should assess the DPO requirement.
Continue learning
Getting Started
What is Sensitive Personal Data?
Data Management
How to Build a Personal Data Register for Your Business
Training & Awareness
Data Protection Responsibilities for Employees
Data Management
How Long Should You Keep Personal Data?
Risk & Accountability
Data Protection Risk Assessments for Small Businesses
