Form

Processor Self-Assessment Questionnaire (SA-2)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a self-assessment questionnaire (SA-2) published by the Guernsey ODPA to help organisations acting as data processors evaluate their own compliance with the Data Protection (Bailiwick of Guernsey) Law, 2017. It is an editable internal tool, not a filing submitted to the regulator, and is expressly stated to be guidance only, not legal advice.

The questionnaire walks a processor through key compliance areas and can double as a starting point for the record of processing activities that processors must keep under the Law. Alongside the questions, the document embeds explanatory notes that restate specific legal requirements applicable to processors.

  • Data collection: What personal and special category data is processed and for what purpose.
  • Governance: Whether a Data Protection Officer is appointed, written agreements with controllers, and maintenance of processing records.
  • Storage and archiving: Where and how personal data (including archived data) is stored, and identification of any sub-processors involved.
  • Security: Physical, administrative and technological security measures, access controls, and breach detection/reporting procedures.
  • Destruction and termination: Responsibility for and methods of data destruction at contract end.
  • Sub-processors: Authorisation arrangements, written agreements, and liability where sub-processors are engaged.
  • Transfers of personal data: Cross-departmental and third-party transfers, including transfers outside the EEA and safeguards used.
  • Training: Staff data protection training, refresher courses, and awareness among the Board, senior management, IT and other staff.

While the form itself is a voluntary self-assessment aid, it flags several binding requirements under the Law that processors should note: written processing agreements with controllers, maintenance of records of processing activities, obtaining controller authorisation before engaging sub-processors, and prompt communication of any data breach to the controller (who must in turn notify the Commissioner's Office within 72 hours of discovery).

Key obligations

  • Processors must ensure a written agreement is in place with the controller setting out how personal data is to be processed.
  • Processors must maintain a central record of processing activities in a format that can demonstrate compliance to the controller.
  • Processors must not engage a sub-processor without the controller's prior specific or general written authorisation, and must inform the controller of intended changes where general authorisation is used.
  • Processors must communicate any data breach or compromise to the controller as soon as possible so the controller can meet the 72-hour reporting requirement to the Commissioner's Office.
  • Processors engaging sub-processors must obtain sufficient guarantees of compliance from those sub-processors and remain liable for their actions.

Applies to

processors, sub-processors, organisations processing personal data on behalf of a controller

Deadlines

  • 72 hours of discovery: Data breaches must be reported by the controller to the Commissioner's Office within 72 hours of discovery; processors must notify the controller as soon as possible to enable this.

Topics

Version history

2026-07-30

source file (current)