Platform · Legal Compliance

Legal compliance, out of the box.

The day your church starts on ChurchPlan, the laws of the land are already built into the software — privacy statutes, charity and tax rules, and the protections around children, youth and families. The compliance work volunteers used to carry is done by the system.

Receipts, consents, retention and visibility — enforced by the software, not left to a policy binder.

CRA CanadaIRS United StatesATO AustraliaIRD New ZealandCH · CZ · PL · HR · IT also supportedUK · Gift Aid recordsPIPEDA · GDPR · CCPA · AU Privacy Act · NZ Privacy Act
Out of the box

The laws and standards, built in.

Every ChurchPlan account enforces the system side of these frameworks automatically — no configuration, no add-ons, no compliance module to buy.

Tax & charity laws

IRS — 501(c)(3) substantiation

Written acknowledgments that meet the IRS $250 substantiation rule, including the intangible religious benefits statement, issued before filing season opens.

CRA — Income Tax Act

Official donation receipts in the format the Canada Revenue Agency prescribes, with serial numbering, versioned reissues and seven-year retention.

ATO — Australian receipting

Receipts meeting Australian Taxation Office requirements for deductible gift recipients — your DGR name, ABN and gift statement on every one.

IRD — New Zealand receipting

Official donation receipts meeting Inland Revenue requirements — donee IRD number, authorised signature and unique numbering, issued automatically.

United Kingdom — Gift Aid records

UK relief is claimed by the charity through Gift Aid, not by the donor. ChurchPlan produces HMRC-ready contribution statements and data exports to support your claims.

Ireland — Charitable Donation Scheme

Relief is claimed by the approved body, not the donor. With 31% grossing up, a €1,000 donation becomes €1,449, so the body claims €449.

Germany — BMF donation confirmations

German donation confirmations use the BMF template made binding by § 50 EStDV. ChurchPlan provides the itemized giving records your treasurer needs to complete it.

France — Cerfa n° 11580

A reçu fiscal follows Form 2041-RD. ChurchPlan provides the itemized giving records, including the cumulative figure the Cerfa asks for.

Privacy & data protection

PIPEDA

Consent-based collection, use and retention of personal information for Canadian congregations, with every member able to see and correct their own record.

GDPR

Data-subject rights, lawful processing and deletion for members in the EU and UK, with consent recorded per member rather than assumed for the parish.

CCPA / CPRA

Disclosure and deletion rights for California-based donors and members, handled from the member’s own profile rather than by request to an administrator.

COPPA — children under 13

US children’s online-privacy rules honoured by design — guardian-managed profiles, verifiable parental consent, and minimal data collection for minors.

Privacy Act (APPs)

Australian Privacy Principles–aligned handling, retention and access for Australian parishes, applied to member and donor records alike.

Privacy Act 2020 (NZ)

New Zealand’s information privacy principles — consent, retention and access — respected by design across every module.

💳 PCI DSS Level 1

Card data never touches ChurchPlan — every payment is tokenized by Stripe, certified at PCI’s highest level.

ChurchPlan enforces the system side of these frameworks — formats, consents, retention, and access controls. Your church remains responsible for its own conduct and governance.

Four pillars

The rules are complex. Following them isn't.

🧾

Receipts that satisfy the regulator

Every donation is receipted automatically in the format the tax authority requires — CRA, IRS, ATO and New Zealand IRD, and in Switzerland, Czechia, Poland, Croatia and Italy. Everywhere else, including Germany, France, the UK and Ireland, churches receive a complete Giving Summary.

  • Charity Registration Number verified before donations activate
  • Receipts issued by the charity that receives the gift, in its name
  • Year-end summaries your treasurer doesn't have to assemble
🛡

Privacy regimes, built in

Consent-based handling, retention, and deletion mapped to the five regimes your congregation may live under.

  • PIPEDA, GDPR, CCPA/CPRA, AU Privacy Act and NZ Privacy Act 2020 aligned
  • Members control their own profile and consents
  • Two kinds of information, kept apart on purpose
🧒

Safeguarding by default

Child-safety isn't a setting an admin can forget — the system prevents the error before it happens.

  • Supervisor-only attendance for children's services
  • Locked unsubscribes and hidden capacity where it matters
  • Roles scoped to the ministry, not the whole database
🔑

Right roles, right eyes

Personal information is protected by strict roles and permissions — only the clergy and staff your church authorizes can view congregation details, and only where members have given consent.

  • Granular permissions per module and per ministry
  • Consent-based visibility of member information
  • Every admin action attributable — nothing anonymous
The difference

A binder hopes. A system enforces.

Most compliance failures aren't malice — they're a volunteer who didn't know the rule. ChurchPlan removes the opportunity for the mistake.

The policy binder

Rules live in a document. People have to remember them, every time, under Sunday-morning pressure. One forgotten step becomes the parish's problem.

The ChurchPlan way

Rules live in the software. The receipt is issued correctly because it can't be issued incorrectly. The roster is supervisor-only because the system won't show it to anyone else.

Let the system carry it.

Start free — the receipting rules, privacy regimes, and safeguarding defaults are already in place when you arrive.

Start free