Form
Controller Self-Assessment Questionnaire (Electronic)
Status not confirmedView on ODPA's website Source document
Summary
This is a self-assessment questionnaire template published by the Guernsey ODPA to help organisations acting as data controllers evaluate their own compliance with the Data Protection (Bailiwick of Guernsey) Law, 2017. It is an internal guidance tool, not a filing or legally binding instrument, and is intended as a starting point for building a record of processing activities and identifying compliance gaps.
- Scope of questions: Covers data collection, lawful processing conditions and consent, governance and Data Protection Officer arrangements, data quality, storage and archiving, security and breach procedures, destruction, use of processors, cross border transfers, disclosures to third parties (routine and non-routine), subject access and data subject rights, and staff training.
- Purpose: Helps senior management and directors assess current compliance and highlight areas needing attention; also serves as a starting point for the mandatory record of processing activities.
- Embedded legal reminders: The questionnaire flags several substantive Law requirements while prompting self-assessment, including that data breaches must be reported to the ODPA within 72 hours of discovery, that processor agreements must address new breach and accountability requirements, and that consent and data collection notices must meet the Law's updated standards.
- Status: Explicitly stated to be for guidance only, not legal advice, and for the organisation's internal use only.
Because the document is a self-help template rather than a rule or notice, it does not itself create new compliance deadlines or filing duties; any obligations referenced (such as breach reporting timelines or processor agreement requirements) derive from the underlying Data Protection Law itself, which the questionnaire is designed to help controllers assess against.
Applies to
controllers, data controllers
Deadlines
- within 72 hours of discovery: Under the Data Protection (Bailiwick of Guernsey) Law, 2017, personal data breaches must be reported to the ODPA within 72 hours of discovery (referenced within the questionnaire as a compliance reminder).