Data Deletion Requests (GDPR Article 17)

Data Deletion Requests (GDPR Article 17)

Audience: This article is for church administrators.

TimelyChurch supports the Right to Erasure under GDPR Article 17 (also called "Right to be Forgotten"). When a member asks for their data to be deleted, TimelyChurch records the request, applies a 30-day grace period, and then anonymizes the person's record. This guide explains how the workflow operates today and what to do as an administrator.


Current Capability (May 2026)

The data deletion workflow applies a 30-day grace period. Status flow:

pendingapproved → (30 days) → completed

pendingrejected

approvedcancelled (during grace period)

Where requests can be created today

Source Available? Notes
Member self-service (a member submits "Delete My Data" from the portal) Not yet available Planned but not yet available to members. Roadmap.
Church admin (on behalf of a member) Not yet available Admin must contact TimelyChurch support to file the request. Roadmap.
Super Admin (TimelyChurch platform support) Yes TimelyChurch support files the request directly

Reflecting reality: Today, if a member asks to be forgotten, you (the church admin) should email TimelyChurch support with the person's name, ID, and the reason. Support will create the request on your behalf. A self-service UI for both members and church admins is on the roadmap.


Anonymization (What Happens After Approval)

Once approved and the grace period elapses, the person's record is anonymized rather than hard-deleted. This preserves:

  • Class enrollments, attendance, schedule history (so reports stay accurate)
  • Donation totals (for church accounting)

The following PII is removed/replaced:

  • Name → "Deleted Member"
  • Email, phone, address → null
  • Avatar, custom fields → cleared
  • Family link → severed

Status Reference

Status Meaning
pending Request received, awaiting admin review
approved Approved; the 30-day grace period is counting down
rejected Denied (e.g., legal hold, active investigation) — no data is changed
completed Grace period expired and record has been anonymized
cancelled Request was withdrawn during the grace period

Each state transition records who made the change and when.


Best Practices for Admins

  1. Verify the request is genuine. Before forwarding to support, confirm by phone or in-person that the member really wants their data deleted. Email requests can be spoofed.
  2. Document the reason. Note why the member is requesting deletion. TimelyChurch stores this with the request.
  3. Inform the member of the 30-day grace period. They can withdraw the request during that window.
  4. Don't delete people manually. Use the data deletion request workflow instead so the audit trail and grace period are honored.
  5. For team members (staff), revoke access first. Use the Team Management page to remove their team access before submitting the deletion request.

Roadmap

A self-serve UI is planned for both members ("Delete My Data" button on the member profile page) and church admins (a "Data Deletion Requests" page under Settings > Privacy). Until then, route requests through TimelyChurch support.


See Also

We use cookies to personalize your experience. By continuing to visit this website you agree to our use of cookies

More