“Mass for John Smith, RIP.” “For Mary, recovering from surgery.” A Mass intention is a small thing to write in a book, but it says a lot. It shows that someone is Catholic, or close to someone who is. It can mention an illness or a death. Under UK data protection law, that makes it special category data: the kind that gets the most protection, along with health records and political opinions.
None of this means parishes can’t keep intentions. They’ve always kept them, and the law allows for it. But it’s worth knowing what’s expected, especially once requests come in online. This post is a plain-English summary, not legal advice.
Why parishes can hold this data
Ordinary personal data needs a lawful reason to be used. Special category data needs an extra condition too. For parishes, the usual one is in Article 9(2)(d) of the UK GDPR: a not-for-profit body with a religious aim may use this kind of data about its members and the people in regular contact with it, as part of its normal activities, as long as it isn’t shared outside without their consent.
A parishioner asking their own parish for a Mass fits that well. Where it doesn’t, for example someone from outside the parish, Pewbook’s request form relies on their explicit consent, which they give by sending the request.
Who is responsible
When a parishioner asks for a Mass through Pewbook, your parish is the controller. You decide what happens with the request. Pewbook is the processor: we run the system for you, under a data processing agreement, and we only use the data to provide the service. If a parishioner writes to us about their details, we pass the message to you.
For your staff accounts, it’s the other way round. Pewbook is the controller for the names and email addresses of the people who log in.
Collect only what you need
The request form asks for:
- who the Mass is for, and what it’s for;
- the Mass they’ve chosen;
- the requester’s name and email address, and a phone number only if they want to give one;
- whether the intention can be printed in the newsletter.
That’s all. There’s no date of birth, no address and no account. Their internet address is used briefly to stop floods of spam and isn’t stored.
Private by default on public pages
Your parish’s public page shows each Mass as Available or Taken, and nothing else. Nobody browsing it can see who has asked for what.
Publishing intentions in the newsletter is normal practice, and Pewbook supports it. But it’s the requester’s choice. Every request has an Include this intention in the parish newsletter box. If they untick it, their intention shows as “Private intention” on the office’s copy, and it never appears anywhere public. Intentions are never shown on your public page, even when you publish the newsletter there.
Kept for as long as it’s needed, and no longer
- A request nobody confirms by email is deleted after 24 hours.
- The requester’s email address and phone number are deleted 12 months after the Mass. If a request is declined or cancelled, their name and contact details are deleted 12 months later.
- The intention and the Mass stay in the register for as long as the parish needs them, because church law asks parishes to keep it. There’s more on that in Keeping the Mass intentions register right.
Parishioners can see this on the form itself, under How we use your details, before they send anything.
Held in the UK or EU
Your parish’s data is held in the UK or EU. The few outside services we use, for sending email for example, are listed by name as sub-processors in our data processing agreement, and we tell parishes before adding a new one. Our privacy policy sets out the rest.
No tracking on parishioners’ pages
Pages parishioners use carry no advertising, no tracking cookies and no third-party analytics. If we count visits to a page, we do it ourselves, without cookies and without identifying anyone. Even the QR code on your porch poster is made in your browser, without sending anything about your parish to another service.
“Remember me”, done carefully
Regular parishioners can tick Remember me on this phone or computer so they don’t have to click an email link every time. We don’t store their email address for this. We keep a random code on their device and a scrambled copy on ours, which stops working after the number of days your parish chooses. If a parishioner thinks someone else has used their device, an admin can forget every device linked to their email address in one step. Your parish can also turn the feature off.
People’s rights
Parishioners can ask to see their details, to have them corrected or to have them deleted. Because you’re the controller, those requests come to you. You can remove a requester’s contact details while keeping the register entry for the Mass, which church law asks you to keep. If someone is unhappy with how their details have been handled, they can complain to the Information Commissioner’s Office.
A short checklist for your office
- Make sure your parish privacy notice mentions Mass intentions and how long you keep them.
- Add your office’s contact details in Pewbook’s settings, so they’re shown in the form’s privacy notice and in emails.
- Think twice before printing health details in the newsletter. “For Mary, who is ill” says less than the name of her illness.
- Don’t let prayer lists, sick lists and intentions build up in email inboxes and spreadsheets. Keep them in one place, with one set of rules.