Act
Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text)
In forceConsolidated text incorporating amendments up to the Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018.
View on GFSC's website Source document
Summary
This is the consolidated text of the Data Protection (Bailiwick of Guernsey) Law, 2017, Guernsey's principal data protection statute, broadly equivalent to the GDPR and the EU Law Enforcement Directive. It sets out data protection principles, data subject rights, duties of controllers and processors, security and breach notification requirements, rules on international data transfers, and the powers of the Data Protection Authority (formerly the Office of the Data Protection Authority/Commissioner) to investigate, sanction and fine breaches.
- Core principles: Controllers must process personal data lawfully, fairly and transparently, for specified purposes, with data minimisation, accuracy, storage limitation, integrity/confidentiality and accountability (section 6).
- Data subject rights: Individuals have rights to information, access, portability, rectification, erasure, restriction, objection to marketing or other processing, and not to be subject to solely automated decisions (Part III).
- Controller/processor duties: Controllers and processors must keep records, make returns, cooperate with the Authority, appoint Bailiwick representatives where required, and register with the Authority and pay prescribed levies (Part IV and V, sections 37 to 40).
- Security and breach notification: Controllers must take reasonable steps to secure personal data, notify and keep records of personal data breaches, and notify affected data subjects where there is high risk to their significant interests (Part VI).
- Impact assessments and DPOs: High-risk processing requires data protection impact assessments and, in some cases, prior consultation with the Authority; certain controllers/processors must designate a data protection officer (Parts VII and VIII).
- International transfers: Transfers of personal data to unauthorised jurisdictions are prohibited unless made under approved safeguards, binding corporate rules, or specific authorisation from the Authority (Part X).
- Enforcement and fines: The Authority can investigate complaints, conduct inquiries, make breach determinations, issue enforcement orders, and impose administrative fines subject to statutory limits (Part XII).
- Offences and civil liability: The Law creates criminal offences (e.g. unlawful obtaining/disclosure of personal data, obstruction, impersonation) and allows civil actions and appeals related to breaches of statutory duty (Parts XIII to XV).
The Law applies to any processing of personal data by automated means or held in a filing system, where the controller or processor is established in the Bailiwick, or where the processing concerns a Bailiwick resident in connection with offering goods/services or monitoring behaviour in the Bailiwick. It has extra-territorial effect and does not apply to purely personal, family or household processing.
Key obligations
- Controllers must ensure processing complies with the data protection principles of lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation and integrity/confidentiality, and must be able to demonstrate compliance (section 6).
- Controllers must facilitate exercise of data subject rights including access, portability, rectification, erasure, restriction and objection, and respond to requests subject to identity verification and limited exceptions (Part III).
- Controllers and processors must keep records, make returns and cooperate with the Authority (section 37).
- Controllers must designate a Bailiwick representative in certain cases (section 38).
- Controllers and processors must register with the Authority and pay prescribed levies (sections 39 and 40).
- Controllers must take reasonable steps to ensure security of personal data and apply data protection by design and default (sections 32 and 41).
- Controllers must notify the Authority of personal data breaches and keep records, and notify affected data subjects where there is high risk to their significant interests (sections 42 and 43).
- Controllers must carry out data protection impact assessments for high-risk processing and consult the Authority in advance where required (sections 44 to 46).
- Certain controllers and processors must designate a data protection officer with defined functions (sections 47 to 51).
- Transfers of personal data to unauthorised jurisdictions are prohibited unless made under approved safeguards, binding corporate rules, or Authority authorisation (sections 55 to 59).
Applies to
controllers, processors, joint controllers, data protection officers, Bailiwick representatives, monitoring bodies under codes of conduct
Deadlines
- 25th May, 2018: Effective date from which the Law (and related transitional/savings provisions and amendments made by the 2018 Commencement Ordinance) took effect.
Related documents
- Data Protection (Commencement, Amendment and Transitional) (Bailiwick of Guernsey) Ordinance, 2018 commences this document
- Data Protection (Commencement, Amendment and Transitional) (Bailiwick of Guernsey) Ordinance, 2018 is made under this document
- Data Protection (Commencement, Amendment and Transitional) (Bailiwick of Guernsey) Ordinance, 2018 amends this document
- Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018 is made under this document
- Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018 amends this document
- Data Protection (General Provisions) (Bailiwick of Guernsey) (Amendment) Regulations, 2024 is made under this document
- Data Protection (Law Enforcement and Related Matters) (Bailiwick of Guernsey) Ordinance, 2018 is made under this document
- Data Protection (International Cooperation and Assistance) (Bailiwick of Guernsey) Regulations, 2018 is made under this document