Act

European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

In force

Status per Guernsey Legal Resources (guernseylegalresources.gg) (as at 2026-07-25)

Current version last checked: 2026-07-30

Summary

This Ordinance implements the EU Privacy Directive's rules on privacy in electronic communications for Guernsey, sitting alongside (not replacing) the Data Protection (Bailiwick of Guernsey) Law, 2017. It imposes specific technical and organisational obligations on providers of public electronic communications networks and services, and restricts certain uses of subscriber and traffic data, location data, and unsolicited marketing communications.

  • Security: Public electronic communications service providers must take appropriate technical and organisational measures to safeguard service security and, where a significant residual risk remains, inform subscribers of the risk, mitigation steps, and likely costs.
  • Confidentiality of terminal equipment: Storing or accessing information on a subscriber's or user's terminal equipment (e.g. cookies) requires giving clear information and an opportunity to refuse, subject to limited exceptions for transmission or requested information society services.
  • Traffic data: Traffic data must generally be erased or anonymised once no longer needed for transmission, with limited exceptions for billing, fraud prevention, marketing and value-added services, subject to consent and information requirements.
  • Itemised billing: Subscribers may request non-itemised bills; the regulator must balance itemised billing rights against calling/called party privacy.
  • Line and location identification: Providers must offer free, simple means to prevent or manage calling/connected line identification, and restrict processing of location data to anonymised data or consented value-added service use, with withdrawal rights.
  • Nuisance calls and emergencies: Providers may override line-identification blocking to trace malicious/nuisance calls, and must support emergency call functions (999/112), including caller location data for emergency services.
  • Directories and marketing: Rules govern inclusion of subscriber data in directories and restrict use of automated calling systems, fax, and electronic mail for direct marketing, generally requiring prior consent or an existing customer relationship, with mandatory sender identification.
  • Enforcement: Certain enforcement and compensation provisions of the Data Protection Law are extended to breaches of this Ordinance, including a route for persons to request the Data Protection Authority exercise its enforcement functions and provisions for compensation claims.

The Ordinance has been amended several times since 2004, most substantially by the 2018 Data Protection (Commencement, Amendment and Transitional) Ordinance, which updated cross-references to the Data Protection (Bailiwick of Guernsey) Law, 2017 and revised the schedule extending that Law's enforcement provisions.

Key obligations

  • Providers of public electronic communications services must take appropriate technical and organisational measures to safeguard service security, proportionate to risk, cost and technology.
  • Where a significant residual security risk remains, providers must inform affected subscribers of the risk, protective measures available, and likely costs, free of charge (beyond normal receipt costs).
  • A person must not store or access information on a subscriber's or user's terminal equipment unless the subscriber/user has been given clear information about the purpose and an opportunity to refuse, subject to limited technical exceptions.
  • Public communications providers must erase or anonymise traffic data once no longer needed for transmission, except where retained for billing/interconnection payment purposes or, with consent, for marketing or value added services.
  • Providers must obtain subscriber/user consent before processing traffic data for marketing or value-added services, and must allow withdrawal of that consent at any time.
  • At a subscriber's request, providers of public electronic communications services must supply non-itemised bills.
  • Providers must give users and subscribers a free, simple means to prevent presentation of calling line identification on outgoing calls, and called subscribers a free means to prevent presentation on incoming calls.
  • Providers must publish information to the public about the availability of calling/connected line identification facilities and related options.
  • Location data (other than traffic data) may only be processed if the individual cannot be identified, or with consent for value-added services, after providing information on data types, purposes, duration and third-party transmission; consent must be withdrawable at any time and free of charge.
  • Providers must ensure calling line identification presentation and caller location information are made available for emergency calls (999/112), notwithstanding any withholding request.
  • Automated calling systems, facsimile machines, and unsolicited electronic mail may only be used for direct marketing subject to prior consent or existing customer relationship rules set out in the Ordinance, and sender identity/address must not be concealed.

Applies to

providers of public electronic communications networks, providers of public electronic communications services, communications providers, subscribers, users, the Data Protection Authority

Related documents

Topics

Version history

2026-07-30

source file (current)