Leaving the Church may be a matter of faith, but getting your name off its books is a matter of EU law. A new opinion by an Advocate General at the EU Court of Justice says churches must comply with the bloc’s data protection rules, including the right to have personal data erased.

The case concerns a Belgian national who was baptised as a Catholic as a child but decided to leave the Church as an adult. He asked the Diocese of Ghent to remove all references to him from its physical and digital registers and archives. Instead, the Diocese simply struck through his name in the baptismal register, leaving it legible.

Dissatisfied with the Church’s approach, he lodged a complaint with the Belgian Data Protection Authority, which ordered the Diocese to erase his data properly. The Diocese challenged the decision, arguing that churches’ institutional autonomy and religious freedom entitled them to maintain their sacramental records. Thus, the case found its way in front of the Court of Justice of the EU (CJEU).

In her now published opinion, Advocate General Laila Medina found that baptismal registers contain a “‘structured’ set of personal data of the baptised individuals” and therefore qualify as filing systems under the General Data Protection Regulation (GDPR). The Church’s institutional autonomy does not exempt it from the regulation.

“Consequently, the data processing in question — its storage and, where appropriate, retrieval and use — must be in line with the GDPR,” Ms Medina wrote.

Balancing societal and personal interests

The GDPR does not give individuals an unconditional right to have all their personal data erased. However, following an objection to data processing, organisations must demonstrate “compelling legitimate grounds” to continue.

The Advocate General found that ensuring the correct administration of the sacraments could constitute such grounds. However, whether the Church’s interest takes precedence over the rights and freedoms of the person concerned is for the national courts to decide on a case-by-case basis.

The church could also seek to take advantage of a GDPR exemption for “archiving purposes in the public interest or historical research”. Again, Ms Medina said it was not clear that this would outweigh a person’s privacy rights. She also noted that under the GDPR, that exemption was mainly intended to address activities carried out by academic or research organisations that may ultimately benefit society as a whole.

The opinion further noted that if a person wishes to dissociate themselves from a religion, keeping their data may cause emotional distress and disrupt their right to self-determination.

The Church cannot simply cross out a name

Ultimately, according to Ms Medina, “merely striking through personal data in a baptismal register while leaving them legible, and adding an annotation concerning the person’s departure, does not constitute erasure under the GDPR”.

The data must be rendered illegible to the extent necessary to ensure that the person is no longer identified or easily identifiable. Information concerning the fact that a baptism took place at a given place and time may be retained.

This does not require the physical removal of pages from the register. Appropriate measures may be used to conceal the relevant data while leaving other information intact. In other words, the Church may have to reach for the Tipp-Ex.

The Advocate General’s opinion is not binding on the EU Court of Justice, which will issue the final judgment. However, the Court follows its Advocates General’s opinions in most cases.