Statement of Guidance
Controller Self-Assessment Guidance
Status not confirmedView on ODPA's website Source document
Summary
This is explanatory guidance issued by the Office of the Data Protection Authority (Guernsey) to accompany the controllers' self-assessment questionnaire under the Data Protection (Bailiwick of Guernsey) Law, 2017. It clarifies key concepts controllers need to understand when assessing their own compliance, rather than creating new legal duties itself.
- Personal data: Explains that personal data covers facts and opinions about identifiable living individuals, in electronic form or in structured manual filing systems.
- Special category data: Lists the categories that replaced 'sensitive personal data', including racial or ethnic origin, health data, genetic and biometric data (where used to uniquely identify a person), and criminal data.
- Data collection notices: Sets out the full list of information that must be given to individuals at the point personal data is collected, including controller identity, purposes, legal basis, recipients, transfer details, retention, and data subject rights.
- Consent: Describes the redefined consent standard: consent must be freely given, specific, informed, unambiguous, evidenced by the controller, and capable of being withdrawn at any time.
- Data Protection Officers: Identifies which organisations must appoint a DPO: public authorities, and controllers or processors whose core activities involve large scale regular monitoring or large scale processing of special category or criminal data.
- Transfers and adequacy: Explains what constitutes a data transfer (as opposed to transit), lists EEA countries, and lists jurisdictions treated as having 'adequate' protection, noting the UK was treated as an authorised jurisdiction for transfers until 31 December 2020.
The guidance is purely explanatory and intended to help controllers correctly answer the self-assessment questionnaire; it does not itself impose new filing or notification requirements beyond those already set out in the Law.
Key obligations
- Controllers must provide individuals, at the time personal data is collected, with the full set of prescribed information (controller identity, purposes, legal basis, recipients, transfer details, retention period, data subject rights, complaint rights, and automated decision-making logic where relevant).
- Controllers relying on consent must be able to demonstrate that consent was freely given, specific, informed and unambiguous, and must allow withdrawal of consent at any time.
- Public authorities and controllers or processors engaged in large scale monitoring or large scale processing of special category or criminal data must appoint a Data Protection Officer.
Applies to
data controllers, public authorities, data processors
Deadlines
- 31 December 2020: The United Kingdom was deemed an authorised jurisdiction for data transfers under the Law only until this date.
Topics
Version history
2026-07-30