Form
Controllers' Self-Assessment Questionnaire (SA-1)
Status not confirmedView on ODPA's website Source document
Summary
This is a self-assessment questionnaire (SA-1) published by the Office of the Data Protection Authority (Guernsey) to help organisations acting as data controllers evaluate their own compliance with the Data Protection (Bailiwick of Guernsey) Law, 2017. It is a guidance tool, not itself a binding legal instrument, and is intended for internal use only as a starting point for identifying compliance gaps and building a record of processing activities.
The questionnaire walks a controller through its data collection practices, governance, data quality, storage and archiving, security, destruction, use of processors, cross border transfers, third party disclosures, subject access rights, and staff training. Alongside the questions, it flags specific requirements under the Law that organisations should be checking against.
- Records of processing: Controllers are required under the Law to maintain a central record of processing activities, including the lawful processing conditions and fair processing measures relied upon.
- Consent standard: Consent obtained before the Law must meet the Law's new definition of consent; if it falls short, another lawful basis must be used or consent re obtained.
- Data collection notices: Privacy notices given at the point of data collection must provide fuller detail to individuals than previously required.
- Breach reporting: Personal data breaches must be reported to the ODPA within 72 hours of discovery, and affected individuals must be notified where there is high risk to their rights and freedoms.
- Processor agreements: Written agreements covering data breach requirements must be in place with any processors used, and sub processing requires prior written authorisation from the controller.
- International transfers and disclosures: Transfers of personal data outside the EEA and disclosures to third parties (regular or non routine) must be supported by an identifiable lawful processing condition and, where required, notice to individuals or a valid exemption.
- Automated decision making: Individuals' rights concerning automated decisions and profiling are strengthened, and organisations undertaking such processing should review it for compliance.
The form itself imposes no filing or submission deadline to the ODPA; it is a self-diagnostic checklist for organisations to complete and retain, with cross references to accompanying Controllers' Self-Assessment Notes for further explanation.
Key obligations
- Maintain a central record of processing activities showing the lawful processing conditions and fair processing measures relied upon
- Ensure any consent relied upon meets the Law's new consent standard, or use another lawful processing condition, or re obtain consent
- Provide expanded privacy/data collection notices to individuals at the point of collection
- Report personal data breaches to the ODPA within 72 hours of discovery and notify affected individuals where there is high risk to their rights and freedoms
- Put in place written agreements with processors covering the Law's data breach and processing requirements
- Obtain specific or general prior written authorisation before a processor sub contracts processing to another party
- Identify and be able to demonstrate the lawful processing condition relied upon for each instance of regular or non routine data sharing
- Review automated decision making and profiling processes for compliance with strengthened individual rights under the Law
Applies to
controllers, organisations processing personal data, data protection officers, processors (where using third party processors)
Deadlines
- within 72 hours of discovery: Personal data breaches must be reported to the ODPA within this period, as noted in the questionnaire's guidance on breach reporting.