Church HR, Staffing & Child Safety
Social Media Policy for Church Staff and Volunteers
Short answer: a church social media policy needs to cover four things: contact with minors, confidentiality of pastoral and congregational information, who is authorized to speak for the church, and who owns the church's accounts and credentials. Everything else is preference. Those four are where the real damage happens, and three of them are cheaper to prevent in writing than to sort out afterwards.
The trigger is usually small and specific. A youth volunteer has been messaging a fifteen-year-old privately about a hard week at home. Kindly, with no bad intent, and with no adult able to see any of it. Or a staff member posts a photo from a family's worst day. Or the person who ran the church's Instagram account for four years has resigned and nobody else has the password.
None of those are technology problems. They're policy problems that surfaced through a phone, which is why they belong in the employee handbook rather than in a group chat.
The rule about minors comes first
If your policy says one thing, make it this: adults do not communicate privately, one-to-one, with a minor on any platform. Not direct messages, not disappearing messages, not a private group of two, not a game chat.
Communication with minors is either in a group that includes another approved adult, or it's copied to a parent, or it doesn't happen. The same rule that governs a closed office door governs a private inbox, and for the same reason. Not because you distrust your volunteers, but because a rule that applies to everyone protects the good ones. An adult who is never alone with a child, physically or digitally, can't be accused of what happened in private.
Two supporting rules go with it:
- Parents can see everything. Any channel used with youth is one a parent could join or review on request.
- Screenshots aren't the same as a record. Set up group channels the church can access, rather than relying on individual phones that leave with the person.
This section belongs in your safeguarding policy as well as your handbook. It's the same rule stated in both places, on purpose, so that nobody can say they only read one document. The wider safeguarding material is covered in what a child safety policy must cover.
Confidentiality: what staff learn, they do not post
Churches hold information ordinary employers never see: diagnoses, marriages under strain, addiction, job losses, immigration status, financial help given quietly.
The policy has to state that anything learned through a staff or volunteer role stays inside it. That includes:
- Prayer requests. The most common breach, and almost always well-intentioned. A request shared in a small group isn't a request to be posted publicly.
- Benevolence and financial assistance. Never named, never implied, never photographed.
- Counseling and pastoral conversations. Not summarized, not alluded to, not turned into a sermon illustration with the details lightly changed.
- Hospital and medical information, including "please pray for the surgery tomorrow."
- Photographs of minors, which need parental consent recorded. Decide once whether your church operates on opt-in or opt-out consent, write it down, and hold the list where the person running the account can actually check it.
A useful line for the policy: if you'd need to ask permission before telling a stranger in the grocery store, you need permission before posting it.
Who speaks for the church
Draw the line between the church's voice and a staff member's own.
Church accounts are operated by named, authorized people. Posts on behalf of the church are the church speaking, and staff should know who approves what.
Personal accounts belong to the person. But a staff member is identifiable as a staff member, and what they post publicly will be read as reflecting on the church whether or not that's fair. The workable standard isn't to police opinions. It's to require that staff make clear they're speaking personally, and to hold public conduct to the same standard the church already expects offline.
Be careful about writing this section too broadly. A rule that appears to stop employees discussing their pay, hours or working conditions with one another can create legal problems in some jurisdictions, and a rule that bans all criticism of the church is both unenforceable and corrosive. A church is an employer as well as a congregation, with the obligations that come with it (IRS Publication 1828, Tax Guide for Churches). Keep the restriction narrow, aimed at confidentiality, safeguarding, harassment and impersonation of the church's voice, not at disagreement.
Where conduct standards are tied to your church's beliefs, that section deserves specific care and a review by a licensed attorney for your state and your roles. See faith-based conduct standards in a handbook for why that section is different from ordinary employment policy.
Who owns the accounts
The boring section that saves the most trouble.
State plainly that accounts created for the church, including pages, groups, handles, ad accounts, the mailing list, the domain and the design tools, belong to the church, regardless of who set them up or whose email address is attached. The name and logo on those handles carry protections of their own (USPTO, Trademark basics), and so does the material posted through them (U.S. Copyright Office, General FAQ).
Then do the four things that make the statement true:
- Keep credentials in a church-controlled password manager, not on one person's phone.
- Attach every account to a church email address, never a personal one.
- Ensure two people have administrator access to each account, one of whom is a staff member or officer who isn't the day-to-day operator.
- Recover access at separation. Removing account access belongs on your offboarding checklist next to keys and the building code.
Churches lose pages with years of history because a volunteer moved away and stopped answering emails. There's often no fast fix. Platforms aren't built to adjudicate ownership disputes.
How churches get this wrong
Assuming good people don't need rules. The rule about minors isn't a statement about your volunteers. It's what makes it possible to defend them.
Writing a policy for staff only, when volunteers do most of the youth communication.
Banning a platform. Conversation moves to whatever is next, and now it's happening somewhere your policy doesn't mention. Write rules about behavior, not brands.
No consent record for photographs, so the person posting is guessing which children can appear.
Handling a breach informally. A staff member posts something they shouldn't have. It's taken down, someone has a quiet word, nothing is recorded, so the second occurrence looks like a first.
Leaving crisis posting undecided. When something serious happens involving the church, the moment to decide who speaks isn't that afternoon. Name the person in advance, and instruct everyone else to say nothing publicly.
What to do about it
- Write the minors rule first and put it in both the safeguarding policy and the handbook.
- Inventory every account the church uses and record who has access to each.
- Move credentials into a church-controlled manager and set a second administrator on every account.
- Decide your photo consent method and build the list.
- Name the authorized voices for routine posting and for crisis communication.
- Train volunteers on it annually, in fifteen minutes, with real examples rather than the document read aloud.
- Add account recovery to offboarding.
- Get signed acknowledgements from staff and from every volunteer working with youth.
Common questions
Can we tell staff what to post on their personal accounts?
You can set expectations about conduct, confidentiality and not appearing to speak for the church, and where a role is ministerial the church's latitude is broader. That latitude has limits, and they're narrower than most boards assume (EEOC, Religious discrimination). You can't sensibly police everything, and trying to produces a policy nobody respects. Aim at the specific harms; leave opinions alone.
Should the youth pastor be friends with students online?
Following and public interaction is normally fine and is often how ministry happens. Private, one-to-one messaging is the line. Some churches also require a second approved adult in every youth group chat, which is a good default and costs nothing.
What if a volunteer posts something harmful?
Take it down or ask for it to be removed, record what happened and what was done, and address it directly with the person. If it involves a minor, safeguarding, or a possible crime, it stops being a social media issue immediately. Follow your reporting duty, and take advice before you investigate it yourselves. Handling complaints and grievances in a church covers where that line sits.
Do we need a separate policy or a handbook section?
A handbook section for staff, and a short standalone version for volunteers who never see the handbook. Same rules, two containers. More on the surrounding governance sits on the church operations hub.
The practical wrap
Most of what goes wrong here was never malicious. It was a kind volunteer in a private inbox, a prayer request shared too widely, a photo posted without asking, or a password on a phone that left the church.
Write the four rules, tell people why they exist, and revisit them once a year. Then the policy is protecting your volunteers rather than suspecting them, which is the only version anyone will actually follow.
---
Put it in the handbook. The Church Employee Handbook is the full 25-page fillable set, including technology, communications and conduct sections written for a church, with the safeguarding-aligned language already in place, ready to adopt at your next board meeting. $99, instant download.
*Faith Docs provides self-help document templates, not legal advice. We are not a law firm. For representation, consult a licensed attorney.*
The document for this, ready to fill in.
Faith Docs sells the fill-in-the-blank templates churches actually need — drafted by church attorneys, yours to download the moment you buy.
Browse all documents →