Act

Data Protection (Law Enforcement and Related Matters) (Bailiwick of Guernsey) Ordinance, 2018

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

In force

Status per Guernsey Legal Resources (guernseylegalresources.gg) (as at 2026-07-25)

Consolidated text incorporating amendments up to the Machinery of Government (Transfer of Functions) Ordinance, 2025.

Current version last checked: 2026-07-30

Summary

This Ordinance sets out a separate, tailored data protection regime for personal data processed by competent authorities for law enforcement purposes in the Bailiwick of Guernsey, applying specified provisions of the main Data Protection (Bailiwick of Guernsey) Law, 2017 with modifications rather than the full Law itself. It establishes principles of processing, data subject rights, security and breach notification duties, requirements for data protection officers, and rules on transferring personal data outside the Bailiwick.

  • Core principles: Controllers must ensure processing for a law enforcement purpose is lawful and fair, purpose-limited, data-minimised, accurate, subject to storage limitation, and kept secure (Part II).
  • Data subject rights: Controllers must give data subjects information about processing, and facilitate rights of access, rectification, restriction and erasure, subject to specified exceptions (Part III).
  • Controller and processor duties: Controllers must take steps to ensure compliance, build in data protection by design and default, and manage relationships with joint controllers and processors (Part IV).
  • Security and breach notification: Controllers must take reasonable steps to secure personal data, apply special measures for automated processing, and notify and keep records of personal data breaches, notifying data subjects where there is high risk to their significant interests (Part V).
  • Impact assessments and consultation: A data protection impact assessment is required for high-risk processing, and prior consultation with the Authority is required for certain high-risk processing or legislation (Part VI).
  • Data protection officers: Certain controllers must designate a data protection officer with defined functions and safeguards for their role (Part VII).
  • International transfers: Transfers of personal data to other jurisdictions are prohibited unless based on available safeguards or special circumstances, with conditions on subsequent transfers (Part VIII).

Schedules to the Ordinance set out modifications to the main Data Protection Law for competent authorities, the lawful conditions for processing special category data, and general exceptions and exemptions (including for educational and social assistance data). The Ordinance has been amended several times since 2018, including by a 2025 Machinery of Government Ordinance.

Key obligations

  • Controllers processing personal data for a law enforcement purpose must comply with, and be able to demonstrate compliance with, the data protection principles in sections 5 to 10
  • Controllers must publish or give data subjects specified information about processing (identity, purposes, rights, complaints information) within a reasonable period and no later than first communication or first disclosure to a recipient
  • Controllers must give data subjects further specified information (legal basis, retention period, recipient categories) as soon as practicable and in any case upon request
  • Competent authorities transmitting personal data subject to specific conditions must inform the recipient of those conditions and require compliance with them
  • Controllers must notify a recipient without delay if personal data transmitted is found to be incorrect or the transmission was unlawful
  • Controllers must facilitate data subjects' exercise of rights to access, rectification, restriction and erasure, subject to permitted exceptions
  • Controllers must take reasonable steps to ensure security of personal data and apply special security measures for automated processing
  • Personal data breaches must be notified and recorded, and data subjects notified where there is high risk to their significant interests
  • A data protection impact assessment must be carried out before high-risk processing begins
  • Prior consultation with the Authority is required before carrying out certain high-risk processing or introducing high-risk legislation
  • Controllers must designate a data protection officer where required and ensure that officer can perform the specified functions
  • Personal data must not be transferred to other jurisdictions except on the basis of available safeguards or specified special circumstances, and conditions must be imposed on subsequent transfers

Applies to

competent authorities, controllers, processors, data protection officers

Deadlines

  • without delay: Recipients of personal data must be notified without delay if it emerges the data was incorrect or the transmission was unlawful
  • as soon as practicable: Further information requested by a data subject to help exercise their rights must be given as soon as practicable, and in any case upon request
  • within a reasonable period, and no later than first communication with the data subject or first disclosure to a recipient: Controllers must publish or give data subjects the required information under section 12(2)

Related documents

Topics

Version history

2026-07-30

source file (current)