Statement of Guidance

Appointing a Processor Operating Exclusively in the Bailiwick of Guernsey

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a case study guidance note from the Guernsey Office of the Data Protection Authority illustrating how a controller should appoint a data processor that operates wholly within the Bailiwick of Guernsey. It uses a fictional example, a small chemist outsourcing HR and payroll to a local HR services company, to walk through the practical steps needed to comply with the Data Protection (Bailiwick of Guernsey) Law when engaging such a processor.

  • Step 1: Put a compliant contract in place: The controller and processor must have a written contract covering the subject matter, duration, nature, scope, context and purpose of processing, the category of personal data, categories of data subjects, the duties and rights of the controller, and the duties imposed on the processor under sections 35 and 36 of the Law.
  • Step 2: Obtain sufficient security guarantees: The controller must be satisfied the processor has appropriate technical and organisational measures in place, evidenced by things such as compliance with industry standards, technical expertise to assist with obligations like breach notification and DPIAs, provision of relevant documentation (data processing notice, record management and information security policies), and adherence to an approved code of conduct or certification scheme.
  • Ongoing review: Once this information is received, the controller must review it and conclude whether it is comfortable that appropriate measures are in place before allowing processing to proceed.

The guidance is one of a suite of ODPA resources on engaging processors and cross-references separate guidance on contracts between controllers and processors and on processor assessments. It does not itself impose new legal requirements beyond restating existing obligations under sections 35 and 36 of the Law as applied to a simple, wholly Guernsey based processing arrangement.

Key obligations

  • Controllers must ensure a written contract compliant with the Law is in place with any processor, covering subject matter, duration, nature/scope/purpose of processing, categories of personal data and data subjects, controller duties and rights, and processor duties under sections 35 and 36
  • Controllers must obtain sufficient guarantees from the processor that appropriate technical and organisational security measures are in place before engaging them to process personal data
  • Controllers must review the guarantees/documentation provided by the processor and conclude whether they are satisfied appropriate measures are in place before proceeding

Applies to

data controllers, data processors

Topics

Version history

2026-07-30

source file (current)