The Church of England’s recent data breaches serve as a stark reminder that even organisations handling the most sensitive personal information can fall victim to preventable security failures. In August 2025, two separate incidents exposed fundamental weaknesses in data protection protocols, affecting some of society’s most vulnerable individuals: abuse survivors and those undergoing safeguarding checks.
These breaches offer critical lessons for any organisation handling sensitive personal data, particularly those serving vulnerable populations. The technical and procedural failures reveal gaps that exist across the Church of England and its engagement of third-parties, making this case study essential reading for data protection professionals.