Statement of Guidance
Artificial Intelligence Guidance
Status not confirmedView on ODPA's website Source document
Summary
This is general guidance from the Office of the Data Protection Authority (Guernsey) explaining how the Data Protection (Bailiwick of Guernsey) Law, 2017 applies to the use of personal data within artificial intelligence (AI) systems. It does not create new legal rules but sets out a ten step practical framework for applying existing data protection obligations to AI use cases, covering scope, lawful bases, the data protection principles, individual rights, data protection by design, security, breach reporting and international transfers.
- Scope: Applies to any AI system processing personal data within the Bailiwick of Guernsey, or where goods or services using AI are offered to Bailiwick residents; automated processing for law enforcement purposes should also be assessed against sections 17 and 33 of the Law Enforcement Ordinance.
- Lawful basis: Organisations using AI to process personal data must identify an appropriate lawful basis (e.g. consent, contract, legal obligation, public interest, legitimate interests) before processing.
- Data protection principles: AI systems must be designed and operated in line with the seven principles: lawfulness, fairness and transparency; purpose limitation; minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
- Individual rights: Mechanisms must be in place to let data subjects exercise their ten rights, including the right to have automated decision-making or profiling reviewed by a human being on request.
- Data protection by design and DPIAs: Proportionate technical and organisational measures must ensure only necessary data is processed by default; a Data Protection Impact Assessment should be considered, and may be legally required, for high-risk AI processing such as automated decision-making or profiling.
- Security and breach notification: Appropriate security measures and breach detection mechanisms are required; breaches likely to risk individuals' significant interests must be notified to the ODPA within 72 hours of becoming aware, and affected individuals informed where appropriate; lower-risk breaches should still be logged internally.
- International transfers: Personal data transferred outside the Bailiwick of Guernsey via AI systems must be protected by adequate safeguards, such as standard contractual clauses or other approved transfer mechanisms.
The guidance closes with links to external resources (ICO guidance, UNESCO AI ethics standards, ISO/IEC 42001, the EU AI Act, and others) for organisations wanting more detail, and notes the ODPA is open to discussing innovative AI-related practices with organisations directly.
Key obligations
- Identify an appropriate lawful basis before using AI to process personal data
- Design and operate AI systems in accordance with the seven data protection principles (lawfulness, fairness and transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality, accountability)
- Provide mechanisms enabling data subjects to exercise their rights, including the right to have automated decisions or profiling reviewed by a human on request
- Implement data protection by design and by default, ensuring only necessary personal data is processed by default
- Consider and, where legally required, carry out a Data Protection Impact Assessment for high-risk AI processing such as automated decision-making or profiling
- Implement appropriate technical and organisational security measures and mechanisms to detect, respond to and report data breaches involving AI systems
- Notify the ODPA within 72 hours of becoming aware of a personal data breach that risks individuals' significant interests, and notify affected individuals where appropriate
- Ensure cross-border personal data transfers via AI systems are protected by adequate safeguards such as standard contractual clauses
Applies to
Organisations and individuals using AI systems within the Bailiwick of Guernsey, Data controllers processing personal data via AI, Businesses offering AI-driven goods or services to Bailiwick residents
Deadlines
- within 72 hours of becoming aware of a breach: Personal data breaches that risk individuals' significant interests must be notified to the ODPA within this period