A unified framework for protecting people, protecting information and strengthening accountability across the Diocese

The Anglican Diocese of Garissa has taken an important step towards strengthening good governance, accountability, safety and responsible stewardship through the adoption of three key Anglican Church of Kenya (ACK) policies: the Safeguarding Policy, the Ethics and Whistleblowing Policy, and the Data Protection Policy.

The policies were approved and adopted by the 2025 Diocesan Synod for application in the Diocese of Garissa. The Synod resolution specifically identifies the three policies as part of the Diocese’s governance framework.

The adoption reflects a commitment to ensure that the Church is not only a place of worship and ministry, but also a community where people are treated with dignity, resources are managed responsibly, concerns can be raised safely, and personal information is handled with care.

Together, the three policies provide a practical framework built around three important responsibilities:

Protecting people. Protecting information. Protecting the integrity of the Church.


A Commitment to a Safe, Accountable and Trustworthy Church

The Church’s ministry involves people, relationships, resources and information. Clergy, lay leaders, staff, volunteers, parishioners, children, young people, beneficiaries, visitors and partners all place a measure of trust in the Church.

That trust comes with responsibility.

The three policies therefore address different but closely connected areas of Church life.

Safeguarding focuses on preventing and responding to abuse, harm and exploitation and ensuring that children, vulnerable people and everyone who interacts with Church ministries can do so in safety.

Ethics and Whistleblowing establishes standards of integrity and accountability, including measures against fraud, bribery, corruption, money laundering and other unethical conduct, while providing channels through which concerns can be reported.

Data Protection provides guidance on how personal and sensitive information entrusted to the Church should be collected, used, stored, shared and protected.

The three areas cannot be separated. A Church that protects people must also protect their dignity and privacy. A Church that values integrity must provide safe ways for wrongdoing to be reported. And a Church entrusted with personal information must treat that information as a responsibility rather than simply as an administrative resource.


1. Safeguarding: That None May Suffer Harm

At the heart of the ACK Safeguarding Policy is a simple but profound commitment:

“That None May Suffer Harm.”

The policy establishes the Church’s commitment to preventing abuse, harm and exploitation and to creating an environment in which children, young people and adults are respected and protected. It describes safeguarding not simply as a legal or administrative requirement, but as an expression of the Church’s Christian calling.

The policy states that safeguarding is a shared responsibility. It applies across dioceses, parishes, institutions, ministries and community programmes and involves clergy, lay leaders, staff, volunteers and partners. It also recognizes the responsibility of everyone who encounters the Church’s activities, including congregants, beneficiaries, students, clients and visitors.

For the Diocese of Garissa, this means that safeguarding should become part of everyday ministry and administration.

It includes the way children and young people are cared for, how pastoral ministry is conducted, how volunteers and staff are recruited, how concerns are reported, how allegations are handled and how survivors are supported.

Prevention and safe recruitment

The Safeguarding Policy provides for measures including recruitment planning, vetting and background checks, appropriate contracts and agreements, orientation and training, supervision and performance management, volunteer management and record-keeping.

These measures are intended to reduce risks before harm occurs rather than waiting until a serious incident has taken place.

Reporting and responding to concerns

Safeguarding also requires the Church to have clear mechanisms for reporting concerns and responding appropriately.

The policy contains dedicated provisions on reporting mechanisms, response procedures, survivor support, confidentiality and privacy.

This is particularly important because safeguarding is not only about preventing harm; it is also about ensuring that when a concern arises, it is taken seriously and addressed through appropriate procedures.

The policy also emphasizes compliance with Kenyan law, including legal obligations relating to the protection of children and reporting of suspected abuse.

Safeguarding is everyone’s responsibility

The ACK Safeguarding Policy makes clear that safeguarding cannot be left to one office or one individual. It must become part of the culture of the Church.

For the Diocese of Garissa, this calls upon every parish, ministry, institution, clergy member, lay leader, employee and volunteer to understand their responsibilities and contribute to creating safe spaces for ministry.


2. Ethics and Whistleblowing: Integrity in the Stewardship of God’s Work

The second pillar is the ACK Ethics and Whistleblowing Policy.

The policy recognizes that the Church is entrusted with financial resources, property, information, authority and the confidence of its members and partners. These resources must therefore be managed with honesty, transparency and accountability.

The policy addresses a broad range of risks, including fraud, bribery, corruption, money laundering, terrorism financing, misuse or destruction of assets and other illegal or unethical conduct.

It also aligns the Church’s approach with relevant Kenyan legislation and international standards, including the Bribery Act, AML/CFT requirements, FATF recommendations, ISO 37001 and the United Nations Convention Against Corruption.

But the purpose of the policy goes beyond legal compliance.

It is rooted in the Christian understanding of stewardship.

The policy describes integrity and accountability as essential to the Church’s witness and calls clergy, staff, volunteers and partners to conduct themselves honestly and responsibly.

Speaking up when something is wrong

An important element of the policy is its whistleblowing framework.

People who become aware of suspected wrongdoing need a safe and appropriate way to raise their concerns.

The policy therefore establishes reporting mechanisms and procedures while providing safeguards for people who report concerns in good faith. It specifically addresses protection from retaliation, confidentiality, anonymous allegations, fair treatment of persons accused and support for whistleblowers.

This is important for building an institutional culture in which people do not feel that silence is the safest option.

The Diocese’s commitment is therefore not simply “do not engage in wrongdoing.” It is also:

If you see something that may be wrong, speak up through the appropriate channels.

At the same time, concerns must be handled fairly, confidentially and through proper procedures, protecting the rights of both those who raise concerns and those who may be accused.


3. Data Protection: Respecting the Dignity and Privacy of Every Person

The third pillar is the ACK Data Protection Policy.

In modern Church life, personal information is everywhere.

Parishes and institutions may hold names, telephone numbers, addresses, membership information, pastoral records, photographs, children’s information, staff records, financial information, health-related information and other sensitive personal data.

The Data Protection Policy recognizes that this information is not simply administrative material. It relates to real people and their dignity.

The policy therefore establishes a framework for responsible collection, use, storage, sharing and protection of personal information. It is grounded both in Christian values and in the legal requirements of Kenya’s Constitution and the Data Protection Act, 2019.

Privacy is part of Christian care

The policy connects data protection with justice, dignity and care for vulnerable people.

It calls for appropriate safeguards such as informed consent, limiting access to sensitive information and anonymising information where possible. Particular attention is given to children, older people, the sick, the poor and others whose information could place them at risk if mishandled.

This has important implications for everyday ministry.

Pastoral information, counselling records, prayer requests and other confidential information should be handled securely and only shared with authorized persons on a need-to-know basis.

Special care for children’s information

Children’s information requires particular protection.

The policy provides for parental or guardian consent in the processing of children’s personal data, subject to specified exceptions, and emphasizes that children’s information should be collected only where necessary and handled with heightened security and confidentiality.

The same principle applies to photographs and other media involving children. The Church should exercise particular care before publishing identifying information or images of children, especially where doing so could put them at risk.

In an increasingly digital Church, responsible data management is therefore part of responsible ministry.


Three Policies, One Commitment

Although the three policies address different areas, they are united by a common purpose.

They seek to build a Church that people can trust.

Safeguarding asks:

Are people safe in our Church and ministries?

Data Protection asks:

Are people’s personal information, privacy and dignity being respected?

Ethics and Whistleblowing asks:

Are the Church’s resources, authority and responsibilities being exercised with honesty and accountability?

Together, they create a stronger framework for responsible ministry.

PolicyPrimary FocusCore Commitment
Safeguarding PolicyProtection from abuse, harm and exploitationThat none may suffer harm
Ethics & Whistleblowing PolicyIntegrity, accountability and reporting wrongdoingThat the Church serves with honesty and transparency
Data Protection PolicyPrivacy and responsible information managementThat personal information is handled with dignity and care

This integrated approach is particularly important for the Diocese of Garissa, whose ministry extends across parishes, communities and institutions in a diverse and challenging regional context.

The policies provide common standards while allowing those standards to be applied within the realities of local ministry.


What This Means for Our Parishes, Institutions and Ministries

The adoption of these policies is not simply a matter of placing documents on a website.

They are intended to guide how the Diocese conducts its ministry and administration.

For clergy and lay leaders, this means understanding and modelling the standards expected by the Church.

For staff and volunteers, it means knowing their responsibilities and seeking guidance whenever they encounter a safeguarding, ethical or data protection concern.

For parish and institutional leadership, it means establishing appropriate practices, maintaining accountability and ensuring that people are adequately informed and trained.

For members of the Church and the wider community, it means knowing that concerns should be taken seriously and that there are established policies and procedures governing the Church’s response.

The Safeguarding Policy specifically calls for structures, training, reporting and accountability, while the Ethics Policy provides for compliance monitoring, audits, training, record-keeping and policy review.

The Data Protection Policy similarly provides for training, leadership engagement, compliance audits, documentation, complaints handling and continual improvement.


From Policy to Practice

A policy becomes meaningful only when it changes practice.

The Diocese of Garissa therefore recognizes that implementation will require continued awareness, training, responsible leadership and participation at every level of the Church.

Safeguarding must become part of the culture of ministry.

Ethical conduct must become part of the culture of leadership and stewardship.

Data protection must become part of the culture of administration and pastoral care.

The goal is not to create additional bureaucracy for its own sake. Rather, these policies provide a common framework to help the Church make sound decisions, prevent harm, respond appropriately when concerns arise and strengthen the trust placed in it.

The ACK Safeguarding Policy itself describes safeguarding as a “living document” that should be reviewed and refined as the Church learns from implementation and responds to changing circumstances.

This same spirit of continual improvement is reflected across the three policies.


A Church of Integrity, Safety and Trust

The Diocese of Garissa welcomes these policies as an important part of strengthening its ministry and governance.

As a Christian community, the Diocese is called not only to proclaim the Gospel but also to demonstrate its values through the way it treats people, manages resources, responds to wrongdoing and handles information entrusted to it.

A safe Church protects those entrusted to its care.

An ethical Church is transparent about its responsibilities and accountable for its actions.

A responsible Church respects the privacy and dignity of the people whose information it holds.

These are not separate expressions of Christian witness. They are interconnected.

To protect people is to honour their dignity.
To protect information is to honour their privacy.
To protect institutional integrity is to honour the trust placed in the Church.

The adoption of the three policies by the 2025 Diocesan Synod marks an important step in that direction. The Diocese now has a clearer framework through which safeguarding, ethical conduct, whistleblowing and data protection can become part of everyday ministry and administration.

As we move from policy to practice, the responsibility belongs to all of us.

Together, we can help build a Church where people are safe, information is respected, concerns can be heard, resources are stewarded faithfully, and the dignity of every person is upheld.


Access the Full Policies

For detailed guidance, procedures, responsibilities, reporting mechanisms and implementation requirements, members of the Church, staff, volunteers, partners and other stakeholders are encouraged to read the full policy documents.

📄 ACK Safeguarding Policy – 2025 Edition

“That None May Suffer Harm”

[READ / DOWNLOAD THE FULL SAFEGUARDING POLICY]

📄 ACK Ethics and Whistleblowing Policy

Integrity • Transparency • Accountability

[READ / DOWNLOAD THE FULL ETHICS & WHISTLEBLOWING POLICY]

📄 ACK Data Protection Policy – 2025 Edition

Privacy • Dignity • Responsible Data Stewardship

[READ / DOWNLOAD THE FULL DATA PROTECTION POLICY]