Statement of Guidance

Contracts between Controllers and Processors

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is ODPA guidance explaining what Guernsey's Data Protection Law requires when a controller engages a processor to handle personal data. It sets out the mandatory content of controller processor contracts and summarises the ongoing duties both parties owe under the Law, including the specific obligations imposed on processors by sections 35 and 36.

  • Mandatory contract content: Contracts must state the subject matter, duration, nature, scope, context and purpose of processing, the categories of personal data and data subjects, the controller's duties and rights, and the processor duties required by sections 35 and 36 of the Law.
  • Parties to the contract: Both the controller and processor must be party to the contract; in secondary processing arrangements the processor and secondary processor must contract directly.
  • Standard clauses: The EU's Standard Contractual Clauses (EU 2021/3071) may be used as a simple route to compliant contract wording.
  • Controller duties: Controllers must not permit processing without a processor guarantee of adequate technical and organisational measures and a compliant written contract, and must keep records, respond to ODPA information requests and inspections, cooperate with the Authority, and maintain annual registration if processing personal data.
  • Processor duties (sections 35 and 36): Processors must process only on documented controller instructions, bind staff to confidentiality, delete or return data at end of contract, implement reasonable technical and organisational measures, assist with DPIAs and security/breach notification, submit to audits and inspections, and only engage sub-processors with authorisation and equivalent contractual protections.

The guidance is explanatory rather than a standalone legal instrument, but it restates binding requirements from the underlying Law that controllers and processors must implement in their contracts and operational practices.

Key obligations

  • Controllers must put in place a legally binding written contract with each processor covering subject matter, duration, nature/scope/context/purpose of processing, categories of personal data and data subjects, controller duties and rights, and processor duties under sections 35 and 36.
  • Controllers must not allow a processor to process personal data unless the processor guarantees reasonable technical and organisational measures and a compliant contract is in place.
  • Joint controllers must agree and document their respective roles and responsibilities and inform data subjects of them.
  • Controllers and processors must keep required records for specified periods and produce them for inspection or on request by the Data Protection Authority.
  • Controllers must provide information returns as required by the Data Protection Authority and cooperate with its functions, including information notices and audits.
  • Entities processing personal data about identifiable living individuals must maintain an annual registration.
  • Processors must process personal data only on the controller's documented instructions, informing the controller if legally required to act otherwise (unless prohibited by law).
  • Processors must bind their staff and any sub-processors to a duty of confidentiality.
  • At the end of the contract, processors must delete or return all personal data (and delete existing copies), except where retention is required by law.
  • Processors must assist controllers with data subject rights, DPIAs, security obligations and breach notification to the controller as soon as practicable.
  • Processors must facilitate lawful audits and inspections and provide information demonstrating compliance with sections 34 to 36 of the Law.
  • Processors may only engage a secondary processor with specific or general controller authorisation (with opportunity to object) and must impose equivalent contractual protections on that secondary processor.

Applies to

controllers, processors, joint controllers, secondary processors

Topics

Version history

2026-07-30

source file (current)