EXJW WorldKnowledge Base

Knowledge Base › Legal

Your personal data with Jehovah’s Witnesses

What information is recorded about you, passed on, and how do you request access or deletion? Including a template letter

Recognizable questions I was never asked whether Jehovah’s Witnesses were allowed to keep data about me. Is that actually permitted? What do elders know about me? Are conversations about my personal life recorded somewhere? What information is passed on when I move to another congregation? Can information about something that happened years ago still play a role later on? Can I see what is being kept about me? And if I have become inactive or have left Jehovah’s Witnesses: can I ask for my data to be deleted? Many people may hardly think about it as long as they are actively participating in the congregation. You become a publisher, a Publisher Record is kept, elders provide pastoral care, and when you move, certain information goes with you to your new congregation. But what data are we actually talking about? And perhaps even more fundamentally: Did you ever give your consent for that? I was never asked whether I agreed to this. Is that allowed? Perhaps you cannot remember anyone ever asking you: “Do you consent to personal data about your faith, spiritual status, field service, and congregation situation being recorded and processed?” Even so, the absence of such explicit consent does not automatically mean that processing your personal data is unlawful. Under the GDPR, consent is not the only possible legal basis for processing personal data. This is especially important for a religious organization. Information revealing your religious beliefs counts under the GDPR as a special category of personal data . Stricter rules apply to that. At the same time, the GDPR contains a specific possibility for non-profit organizations with a religious aim to process such data under certain conditions as part of their legitimate activities. Among other things, this must involve members, former members, or people who have regular contact with the organization, and appropriate safeguards must be in place. Jehovah’s Witnesses explain in their own Dutch privacy statement which legal basis they use. It states that they generally do not process personal data on the basis of consent , because they can usually rely on another legal basis. For publishers, they cite as a basis, among other things, their legitimate interest in maintaining and managing the religion and religious activities of Jehovah’s Witnesses. So the absence of a signature does not automatically mean the data processing is prohibited. But the opposite is also important: The fact that you are a Jehovah’s Witness or a publisher does not automatically mean that every possible recording, retention period, or disclosure of personal information is justified. Data processing must comply with the GDPR rules. The relevant question is therefore not only: “Did I ever give consent for this?” but also: “What data is being processed about me, why is it needed, on what legal basis does this happen, how long is it kept, and who gets to see it?” Jehovah’s Witnesses: by becoming a Witness you have agreed There is an interesting formulation in Jehovah’s Witnesses’ global data protection policy. In the section on the exchange of personal data between branch offices, it says this only takes place when it is necessary for religious and charitable purposes. The organization then states that all Jehovah’s Witnesses have agreed to this by their voluntary decision to become Jehovah’s Witnesses and to identify themselves as such. That can raise an interesting question: Is choosing to become a Jehovah’s Witness the same as separately giving consent for every processing of your personal data? Legally, those are not necessarily the same thing. This is also clear from Jehovah’s Witnesses’ own Dutch privacy statement. It explains that the organization generally does not process personal data on the basis of consent , but usually relies on another legal basis. It is therefore important to distinguish between what an organization itself describes as agreement to its way of operating and “consent” as a specific legal basis under the GDPR . What data do Jehovah’s Witnesses keep about you? Jehovah’s Witnesses’ Dutch privacy statement mentions several types of data. Basic details For example: name, date of birth, gender. Contact details For example: address, email address, phone number, emergency contact details. Spiritual data Jehovah’s Witnesses mention among other things: date of baptism, “anointed” or “other sheep,” roles and duties within the congregation or organization, field service activity, spiritual status, dates associated with that status, similar information about someone’s spiritual well-being. The organization also states that personal data may come directly from you, but also from publicly available sources or from others . That last part is interesting. So information about you can be processed that you did not provide directly yourself. Pastoral care and introduction letters For pastoral care by elders, the Dutch privacy notice mentions basic details, contact details, spiritual data, and religious beliefs. With regard to retention periods, introduction letters are also explicitly mentioned. According to the Dutch notice, these are kept in line with the local retention policy. Other data for pastoral care is kept as long as it is needed for the purposes. The public privacy notice does not say exactly what personal information is included in each individual introduction letter. We therefore cannot say that every old transgression, every family problem, or every conversation with elders automatically ends up in such a letter. But you can ask what has been recorded about you personally . What happens when you move to another congregation? When you move, you do not necessarily start all over again administratively. Jehovah’s Witnesses themselves write that when a publisher chooses to move to another congregation, their basic details, contact details, and spiritual data are passed on to the new congregation . In some cases, the branch office also processes personal data in order to continue participation in religious activities and church administration. The notice also states that under certain circumstances data may be transferred outside the EU/EEA, with the safeguards mentioned there. That raises an interesting question: What does a new congregation already know about you before it has truly gotten to know you? Why is information shared? There are understandable reasons why a religious organization keeps and transfers information. When someone moves to another congregation, it can be useful, for example, to know that someone is baptized, what assignments they have, and what their current congregation situation is. Continuity of pastoral care can also be a reason. From the organization’s perspective, administration can therefore help responsibilities and support continue. But the same transfer of data can also have another side. How long does your past travel with you? For one person, there can be a big difference between administratively recording a current status and retaining or sharing very personal events from the past for a long time. Think, for example, of possible information about: a past pastoral or disciplinary matter; relationship or marital problems; family conflicts; past restrictions or responsibilities within the congregation; earlier conversations with elders; someone’s spiritual situation. This does not mean that all of this information is routinely stored about every publisher or included in every introduction letter. The public privacy notice is not specific enough for that. But if such information is in fact processed about you, you may wonder: Why is this still being kept? Is it still necessary for the original purpose? Who can read it? Has it been passed to another congregation? How long will it be kept? And where did information come from that I never provided myself? You do not need to guess. You can request access. A practical example: personal information moves with you An experience within a family shows why these questions can matter. A sister who had had no contact with her mother for years moved to another congregation. In her new congregation, it was known that she had cut off contact with her Witness mother. According to her family, this information had been passed along from the previous congregation. Later, she and her husband were confronted about this by elders. According to those involved, the situation also played a role in the question of what privileges her husband could receive within the congregation, including giving talks. Not having contact with her mother was seen as unchristian. In the end, she resumed contact with her mother. According to her family, this was also partly because she wanted her husband to be eligible for privileges again. This is a personal experience. It does not mean that every congregation acts the same way or that every introduction letter contains such information. But the example does raise an important privacy question: Which personal information is necessary for pastoral care, and when does information from someone’s past become more than is needed for that purpose? How long are data kept? There is no single retention period for all data. For the Publisher’s Record , the Dutch privacy notice states, for example: active publishers: current and previous service year; inactive publishers: last active service year; people who are no longer Jehovah’s Witnesses: these specific data are not retained. Different retention periods apply to other personal data. For pastoral care, for example, it states that introduction letters are kept according to local retention policy and other relevant data for as long as necessary for the purposes. So you cannot simply say: “As soon as you leave Jehovah’s Witnesses, your entire file is destroyed.” That does not follow from the public privacy notice. If you want to know what still exists in your specific situation, you can request it. What rights do you have under the GDPR? You have various rights regarding your personal data. Right of access You can ask which personal data about you are being processed and request information about, among other things, the purpose, recipients, and retention periods. Right to rectification If personal data are incorrect, you can ask for them to be corrected under certain conditions. Right to erasure Under certain circumstances, you can ask for personal data to be deleted. This right is not absolute. Right to restriction of processing In certain situations, you can ask for processing to be temporarily or partially restricted. Right to object Jehovah’s Witnesses themselves state that when they process personal data on the basis of legitimate interests, you have the right, under certain circumstances, to object to that processing. Ask for access first or have it deleted right away? When you do not know what is being kept about you, asking for access first can be a logical step. That way, you may find out, for example: which personal data actually exist; what data your congregation keeps; whether personal data from an introduction or transfer letter are being processed; which data were passed on to another congregation; where data came from that you did not provide yourself; what retention period is being used. After that, you can decide more specifically whether you want something corrected, want to object, or want to request deletion. And if you are inactive or have left Jehovah’s Witnesses? Being inactive and no longer being a Jehovah’s Witness are not the same thing in terms of data administration. That is clear, for example, from the different retention periods mentioned in the Dutch privacy notice for the Publisher’s Record. Even if you are no longer a Jehovah’s Witness, you can still use the privacy rights that apply to your situation. But do not automatically assume that everything has been deleted or that everything is still being kept. Ask. A simple but important question is: What personal data do you currently still process about me, for what purpose, on what legal basis, and how long are these data retained? Fill-in letter - access to and deletion of personal data You can adapt this letter to your own situation. Subject: GDPR request concerning my personal data Dear Sir/Madam, Under the General Data Protection Regulation, I request access to the personal data you process about me. My details Name: ............................................................................. Date of birth: ................................................................. Current or former congregation: ......................................... Previous congregation(s): ........................................................ Address: .............................................................................. Email address: ..................................................................... Telephone number: ................................................................ I request that you provide me with as complete an overview as possible of the personal data processed about me. I would also like to receive information about: the personal data you currently process about me; the purposes for which these data are processed; the legal basis for the processing; the categories of personal data; the source of personal data not provided directly by me; the recipients or categories of recipients to whom my personal data have been or are being disclosed; the retention period or the criteria used to determine that period. I specifically request access to personal data that, if available, relates to: my baptism and congregation status; my current or former assignments or privileges; my field service activity; my spiritual status; pastoral conversations or pastoral care; personal or family circumstances; previous measures or restrictions within the congregation; any disciplinary matters; correspondence or notes containing personal data about me; introductory, recommendation, or transfer letters drawn up about me or received concerning me. Transfer to other congregations If I have changed congregation during my time as a publisher, I also request information about: which personal data about me were passed on to another congregation; to which congregation or other entity these were provided; for what purpose; to the extent available, when this transfer took place. If an introduction letter, transfer letter, or similar document about me exists or has existed, I request access to the personal data about me contained in it, insofar as Article 15 GDPR entitles me to this. Data I did not provide myself To the extent that personal data about me were not collected directly from me, I would like to receive the information about their source to which I am entitled under the GDPR. Erasure For personal data that meet the conditions of Article 17 GDPR for erasure, I request deletion. If you are of the opinion that certain personal data must or may be retained despite my request, I would like to receive, by category, information about: which data are being retained; why they are still necessary; on what legal basis the further processing rests; how long these data will be retained. Objection To the extent that Article 21 GDPR applies to a processing activity, I object on the basis of my personal situation to the further processing of my personal data. I ask you to assess this objection and inform me of the outcome. Further transfer I request that you do not further transfer my personal data to another congregation or other entity where there is no valid legal basis for doing so. If you are of the opinion that further transfer is lawful and necessary, I would like to receive information about the personal data concerned, the purpose, the recipient or category of recipients, and the legal basis. I would like to receive a response to my request within the statutory period. If my request is rejected in whole or in part, I would like to receive a written explanation and information about my options to file a complaint with the Dutch Data Protection Authority or to use other legal remedies. Yours faithfully, Name: ............................................................................. Place: ............................................................................ Date: ............................................................................. Signature: ................................................................... Tip: keep the request you sent and the reply you receive. If you later want legal advice or contact the Dutch Data Protection Authority, this will give you an overview of what you asked for and how it was handled. In closing The fact that personal data are kept within a religious organization without you having signed a separate consent form does not automatically mean that the processing is unlawful . But it also does not mean that you may not ask questions about what is being kept about you. So perhaps the question is not only: “Did I ever give consent for this?” but especially: “What do they know about me, why is that being kept, who has received it, and how long will it remain?” The GDPR gives you rights that can help you get more clarity about that. You do not have to guess what has been recorded about you. You can ask. Sources JW.org - Use of personal data - Netherlands - updated March 21, 2025 JW.org - Worldwide personal data protection policy of Jehovah’s Witnesses European Union - General Data Protection Regulation - especially articles 6, 9, 15, 16, 17, 18 and 21 Dutch Data Protection Authority - Privacy rights under the GDPR