
This article was last reviewed in August 2026. Privacy law and child safe rules change. Check the current position with the Office of the Australian Information Commissioner, or your denomination's safe ministry body, before you act on what you read here.
A church directory is one of the most useful things a small church keeps, and one of the most personal. It gathers names, numbers, addresses, birthdays, sometimes children's details and photographs, all in one place. This article is about keeping a directory in a way that looks after the people listed in it. It is not the directory template itself, which is a separate resource, and it is not a full guide to privacy law.
Collect only what you need
Start with what the directory is actually for. For most churches it is a way to contact people and to keep pastoral care connected, which means a name and one reliable phone number does most of the work. Everything past that, a home address, a birthday, a spouse's name, children's details, is worth offering rather than assuming. Let each person tick what they are happy to include. Plenty of members glad to share a mobile number would rather their home address stayed off a list that goes around.
This is also what Australian privacy law points to. The standard is to collect only what is reasonably necessary for what you are genuinely doing. A directory does not need a full date of birth to prompt a birthday card; the day and month will do.
Keep the more sensitive details out of the circulated directory altogether. Health notes, dietary needs that point to a medical condition, and prayer requests that reveal something personal are sensitive information under the Privacy Act, and they belong in a separate, restricted record held by the people who need them. They do not belong in a list that travels around the congregation. When you gather the information, tell people plainly how the directory will be used and who will see it.
Photographs and children need their own consent
A photograph of someone you can recognise is personal information too, and people tend to feel far more strongly about an image than about a phone number. A printed pictorial directory that stays within the membership is one thing. Putting a member's face on the church website or a Facebook page is another, and it needs its own clear yes that names the channel, not a single blanket permission collected once and assumed forever.
Children need more care again. For a child under about fifteen, get a parent or guardian's consent before listing the child or publishing a photograph, and say where the image will appear. The National Principles for Child Safe Organisations treat the way you handle records and images of children as part of keeping them safe, not a side matter.
Consent can also be taken back. Someone may be happy to appear this year and not the next, and that is their right. Keep internal directory use separate from anything public, give people an easy way to change their mind, and when a member asks to come off a list or out of a photo, act on it without delay. The Office of the Australian Information Commissioner's guidance on posting photos and videos is a plain place to start.
Decide who can see it, and tidy up old copies
A directory is only as private as its loosest copy. Decide who actually needs the full list, usually the pastor and a small number of people in care or administrative roles, and keep it to them. When a volunteer or leader steps down, retrieve their printed copy and remove their access to any shared file.
Old editions are the quiet risk. When you issue a new directory, collect and shred the old printed ones, and delete the old digital file properly rather than leaving it in an archive folder or an email attachment. A list left on a seat after a meeting, or a spreadsheet still sitting in a former volunteer's inbox, is how directories go astray.
It helps to know where the law sits. Most small churches fall under the Privacy Act's small-business exemption, because their annual turnover is under three million dollars, so the formal privacy principles may not strictly bind them. But the statutory tort for serious invasions of privacy, in force since June 2025, applies whether or not a church is exempt. Being exempt from the principles is not the same as being beyond the law, and it is a long way from being trusted by your members.
None of this needs a policy document to begin. Take the directory you already have and ask three things of it. Is every field on it actually needed? Has everyone agreed to what is listed, and to any photo that has been published? And who can see it? The Office of the Australian Information Commissioner's small-business privacy guidance is a useful next step if you want more detail. For most churches the real move is simpler: treat the directory as what it is, a list of people who trusted you with their details.