Statement of Guidance

Accountability and Governance

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This ODPA guidance explains the accountability and governance provisions of the data protection Law, which sit alongside its transparency requirements. It clarifies that organisations must be able to demonstrate compliance with the data protection principles, not just comply with them, and that tools like data protection impact assessments (DPIAs) and privacy by design are now legally required in certain circumstances.

  • Accountability principle: Section 6(2)(g) requires organisations to demonstrate compliance with the data protection principles, and makes clear this is their own responsibility.
  • Demonstrating compliance: Organisations must implement appropriate technical and organisational measures, which may include internal data protection policies covering staff training, internal audits and HR policy reviews.
  • Documentation: Organisations must maintain relevant documentation on their processing activities.
  • DPO appointment: Where appropriate, organisations must appoint a data protection officer.
  • Privacy by design and default: Organisations must implement measures meeting these principles, such as data minimisation, pseudonymisation, transparency, allowing individuals to monitor processing, and ongoing security improvements.
  • DPIAs: Organisations must use data protection impact assessments where appropriate.

The guidance notes that in practice this is likely to mean more formal policies and procedures for organisations, although many will already have suitable governance measures in place.

Key obligations

  • Implement appropriate technical and organisational measures that ensure and demonstrate compliance with the data protection principles
  • Maintain relevant documentation on processing activities
  • Appoint a data protection officer where appropriate
  • Implement measures meeting the principles of data protection by design and by default (e.g. data minimisation, pseudonymisation, transparency, allowing individuals to monitor processing, ongoing security improvements)
  • Use data protection impact assessments (DPIAs) where appropriate

Applies to

organisations processing personal data, data controllers

Topics

Version history

2026-07-30

source file (current)