← Back to the registration form
Parish Church of St Mary the Virgin, Lewisham
Privacy notice
How we look after the information you give us. Last updated 22 August 2026.
Draft for review
Written to describe what the parish system actually does, following the framework of the Diocese of Southwark’s privacy notice. It has not yet been checked by anyone legally qualified and should be approved by the PCC before it is relied on.
Who is responsible for your information
The Parochial Church Council (PCC) of the Parish Church of St Mary the Virgin, Lewisham is the data controller for the information described here. The PCC decides how and why it is used, and is answerable for it.
The Diocese of Southwark — formally the South London Church Fund and Southwark Diocesan Board of Finance — is a separate controller for the information it holds. Where we pass something to the diocese, such as a safeguarding referral, they become responsible for their own copy and their privacy notice applies to it.
Contact us at [email protected] or write to the parish office at the church.
We handle your information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — for emails and messages — the Privacy and Electronic Communications Regulations (PECR).
Why most of this counts as sensitive information
Worth saying plainly, because it is not obvious. We are a church, so the fact that we hold your details at all may suggest something about your religious beliefs. That makes almost everything here special category data under Article 9 of the UK GDPR, which carries stronger protections than ordinary personal information.
We rely on the condition in Article 9(2)(d), which allows a religious body to process information about its own members and people in regular contact with it, provided it is not disclosed outside the body without consent. That is why we treat this material carefully even where it looks mundane.
What we collect
- Who you are and how to reach you — name, address, email, telephone numbers, date of birth.
- Your household — so a family registering together enters an address once, and so we know who belongs with whom.
- An emergency contact — a name, relationship and telephone number for somebody we can ring if something happens.
- Health information, if you choose to give it— allergies, conditions, medication, and your doctor’s details, for children and adults taking part in activities where we may need it. You do not have to provide any of it.
- What you have agreed to — photography, emails, the WhatsApp list. We record refusals as well as agreements, so we know not to keep asking.
- Your involvement — groups you belong to, attendance, any role you hold, and the training or DBS check that role requires.
- Baptisms, weddings and funerals — where you have asked us to take one, or you are the family of somebody we have. See below.
- Safeguarding concerns, where one is raised about or by you.
- CCTV footage, if you come to the church. See below.
- A record of doors you unlock, if you are a keyholder. See below.
Baptisms, weddings and funerals
When we baptise, marry or bury somebody we keep a record of it, and of the family we dealt with. We use it to stay in touch: to write on an anniversary, to invite you to a memorial service, or simply so that the next person in this post knows what happened and who you are.
This is not the register. Baptisms and burials are entered in the parish registers, and marriages are registered with the General Register Office. Those are the legal record, they are governed by their own law, and nothing here replaces or alters them. What is described on this page is a pastoral record kept alongside them.
Our basis is legitimate interests, Article 6(1)(f), together with the religious body condition in Article 9(2)(d): caring for people who have come to us at a birth, a marriage or a death is the ordinary work of a parish. If you would rather we did not contact you, tell us and we will stop — and we will record that so nobody asks again.
Only the parish office and the Incumbent can see these records. Where somebody has died, the law does not treat their own details as personal information any longer, but their family’s details are yours and are protected exactly as anything else on this page.
Why we use it, and on what basis
- To run the parish — contacting you, organising groups, keeping registers. Our basis is legitimate interests, Article 6(1)(f): a church cannot function without knowing who belongs to it.
- To keep people safe — safeguarding records, DBS checks and training. Our basis is our legal obligations and the safeguarding of children and adults at risk. This is one of the few things we do that can override an objection from you.
- Health information — held only with your explicit consent, and used only to keep you or your child safe at an activity. Withdraw it whenever you like.
- Emails and WhatsApp messages — sent only where you have positively opted in, as PECR requires. Every email carries a link that removes you immediately. No account, no explanation, nobody to ask.
Who can see what
Not everybody in the parish can see everything. The system enforces this rather than relying on people to be careful:
- Group leaderssee the members of their own groups, and — in an emergency — allergies, conditions and who to telephone. They do not see NHS numbers or doctors’ details.
- The parish office sees contact details and group membership.
- Safeguarding records can be read only by the Incumbent and the Parish Safeguarding Officer, and every occasion on which they are opened is recorded.
- DBS records are visible only to the DBS Administrator and the Incumbent, deliberately separate from ordinary training records, which a different person administers.
Who else sees it
We do not sell your information, and we do not share it for anybody else’s marketing. We share it only where we must:
- the Diocese of Southwark, for safeguarding referrals and the returns every parish is required to make;
- our DBS checking provider, where you are applying for a check;
- Microsoft, who host this system and our email under contract and process your information only on our instructions;
- Backblaze, who store our encrypted backups. The files are encrypted before they leave us, so they hold data they cannot read;
- the police or social services, where somebody may be at risk of harm;
- HMRC, for Gift Aid, and other regulators where the law requires it.
We require everyone we share with to protect your information, to use it only for the purpose we specify, and never for their own.
Where it is kept
In the United Kingdom— on Microsoft Azure in Cardiff, and in the parish’s Microsoft 365 account. It is encrypted in transit, encrypted where it is stored, and reaching it requires a parish account with two-step sign-in.
Our daily backups are held by Backblaze, in the Netherlands. They are encrypted before they leave us and Backblaze has no key, so what is stored there cannot be read by them. The Netherlands is covered by the United Kingdom’s adequacy regulations, which means your information has the same protection there as it has here.
We keep that copy outside the United Kingdom deliberately. A backup held by the same company, in the same place, as the thing it is backing up is not much of a backup.
How long we keep it
We follow the Church of England’s Records Retention Schedule, which sets out how long a parish should hold each kind of record. In outline:
- Contact and membership details — while you are connected with the parish, and a reasonable period afterwards.
- Safeguarding records — for a long time, and sometimes permanently. This is deliberate, and required of us: these records exist to protect people, including years later.
- Training and DBS records — while you hold the role, and afterwards as evidence the parish met its obligations.
- Consents — kept even after you withdraw one, so we can show what you agreed to and when you changed your mind.
- CCTV footage — thirty days, then overwritten. Anything needed for an incident is kept until that is finished with.
- Records of doors unlocked — thirty days.
- Gift Aid declarations — kept while they stand, and for at least six years after the last claim made under one, because HM Revenue and Customs may ask us to produce it. Cancelling a declaration stops us claiming; it does not delete the record of what you declared, which is what makes past claims defensible.
- The parish accounts — at least six years. A charity must be able to produce its accounting records for six years, so where your name appears on an invoice or a payment it stays in them. The accounts are kept in Xero, and each night we take an encrypted copy and store it separately, so the records survive if that account is ever lost. Your giving is not itemised there. Gifts reach the accounts as daily totals, so the books show what the parish received and not who gave it — who gave what stays here, in the Hub. The one exception is a bank transfer or standing order: your bank puts your name on the statement, and the statement feeds into Xero.
Where we no longer need something, we delete it. Some records we are legally required to keep permanently.
Deleted information can survive for a time in our backup copies. If you ask us to erase something, we remove it from the live system straight away and see that it leaves the backups too.
The accounts are an exception. Our nightly copies of them are locked against deletion for six years, because that is how long a charity must be able to produce its accounting records, and we do not delete them automatically once that period ends. So where you appear in the accounts — a donation, an invoice, a payment — that entry remains there, and in the backup copies, for at least six years after we have removed you from everything else. It is used only for keeping and examining the accounts.
CCTV
There are cameras at the church, and they record. If you come to a service, a concert, a wedding or a meeting, you will be recorded, and that recording is personal information about you.
We have them to protect the building and the people in it. A church is open, often empty, and holds things that are hard to replace; and where something happens to somebody, footage may be the only account of it. We rely on legitimate interestsfor this — ours in looking after the building, and everybody’s in being safe in it — having weighed that against the fact that most people recorded have done nothing but come to church.
Recordings are seen only when there is a reason to look: a break-in, an accident, a safeguarding concern. They are not watched routinely and nobody is monitored by them. We may hand footage to the police, or to the diocese as part of a safeguarding referral, and we would normally do so only on request.
You can ask for a copy of footage of yourself. Tell us roughly when and where and we will look. If other people appear in it we may have to obscure them, which is not obstruction — they have the same right to privacy that you are exercising.
Where the cameras are. At the entrance doors, and one covering the nave. The door cameras are mostly doorbell cameras and point outwards, so they see whoever is at the door and some of the ground in front of it. The nave camera covers the body of the church.
The door cameras record sound as well as pictures. That is worth saying on its own, because it is easy to assume a camera only watches. If you speak at the door of this church, you may be recorded saying it.
We know that matters more here than in most places. People come to a church door in trouble, and say things there they would not say anywhere else. Sound recording at a church door is not a neutral thing, and the PCC should satisfy itself that each camera which records it needs to.
How long we keep it. Thirty days, after which recordings are overwritten. The exception is where something in a recording is needed — an incident, a claim, a safeguarding concern — in which case that part is kept until the matter is finished with, and no longer.
If you hold a key
Keyholders unlock doors with a fob or a code rather than a key, and the system records which door was opened, by whom, and when. It is kept for thirty days. That is a record of your comings and goings from a building, which is more personal than it first sounds — over months it shows when you are usually there and when you are not.
We keep it for two reasons and no others. The first is security: if something is damaged or goes missing, knowing who was in the building is often the only way to understand what happened. The second is safety — in a fire, who is likely to be inside. Again this rests on legitimate interests.
It is not used to check up on anybody. Nobody reviews it to see how long a volunteer stayed, when a member of staff arrived, or how often somebody comes in. It is looked at when there is an incident, and otherwise not at all. If that ever changed it would be a decision for the PCC, and this page would say so first.
You can ask for your own record at any time, and you will be told who has looked at it.
Cookies
This system sets four cookies, and none of them tracks you. There is no analytics, no advertising, and nothing is shared with anybody else. Each one exists so that a thing you asked to do keeps working from one page to the next.
- Signing in — remembers that it is you, for as long as you are signed in. Set only if you sign in with a parish account.
- Gift Aid — holds your place while you complete a declaration. One hour.
- Giving — the same, for setting up a standing order. Ninety minutes.
- Check-in— keeps the children’s check-in screen open on the morning it is being used. Four hours.
All four are deleted when you close your browser, whichever comes first, and none can be read by anything running in the page — a precaution that matters most on a shared computer in the parish office.
We do not ask you to accept cookies, and that is deliberate rather than an oversight. The rules require consent for cookies that are useful to us; they specifically do not require it for ones that are strictly necessary to provide something you have asked for, which is all we set. A banner asking permission we do not need would only teach people to click past the ones that matter.
If that ever changes — if the parish website comes to embed a map or a video from another company, or to use anything that identifies you — we will ask first, and this page will say so before it happens.
Counting visits to the website
The public website counts how many people visit it. We use Cloudflare Web Analytics, and we chose it over the usual alternatives for one reason: it does not identify anybody.
It records, for each page that is opened:
- which page it was, and roughly how long it was open;
- which site you came from, if any — so we can tell an arrival from a Google search from somebody following a link in a newsletter;
- the country, the kind of device, and the browser.
It sets no cookies, stores nothing on your device, and does not follow you to any other website. There is no identifier for you, so two visits by you cannot be joined together, and nothing here can be traced back to a person — not by Cloudflare, and not by us. There is consequently nothing about you for us to hold, show you, or delete, which is why this is not in the list of things you can ask for above.
This is why we still do not ask you to accept anything. Consent is required for tracking that is useful to us and identifies you; this only tells us that forty people read about baptisms last month, which is the sort of thing a parish needs in order to decide what to write next.
The Church Hub — the part you sign in to — is not counted at all. There we know exactly who you are, so recording which pages you read would be a record of one named person’s browsing. We decided against it, and if that is ever revisited it will be said here first and put to the PCC.
Your rights
You can ask us to:
- show you what we hold about you;
- correct anything that is wrong;
- delete information we no longer have a reason to keep;
- stop using it in a particular way;
- provide a copy in a portable form;
- withdraw a consent you have given, at any time.
Deleting something does not remove it from our backup copies the same day — see How long we keep it.
These rights are not absolute. We cannot delete a safeguarding record on request, for instance, because we are required to keep it. If we refuse any request we will tell you why, in writing, and you can challenge that. Write to [email protected] and we will reply within one month. We may need to check who you are first.
If we want to use it for something new
If we ever want to use your information for a purpose not described here, we will tell you before we start, explain the reason and the basis, and ask your consent where that is required.
If you are unhappy
Please tell us first — most things are quicker to put right directly. You also have the right to complain to the Information Commissioner’s Office:
- ico.org.uk
- 0303 123 1113
- Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF