Statement of Guidance

Cyber security checklist

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a practical checklist from the Office of the Data Protection Authority (Guernsey) offering recommended cyber security actions for organisations that hold personal data. It is non-binding guidance rather than a set of legal rules, but it links good cyber hygiene to an organisation's ability to demonstrate accountability under data protection law.

  • Software and devices: Keep all software, systems and connected devices (including routers, printers, smart TVs) patched and updated, ideally via automated processes.
  • Staff awareness and training: Train staff to identify and report phishing and security incidents, and keep training current and ongoing.
  • Antivirus and access control: Ensure antivirus software is active and up to date, and restrict data access to staff on a need-to-do-the-job basis, removing leavers' access promptly.
  • Authentication: Use strong passwords and multi-factor authentication, referencing NCSC guidance.
  • Incident and recovery planning: Maintain a tested incident response plan (including hard-copy versions for key staff) and ensure data backups can be recovered, tested regularly.
  • Service providers: Understand and check the security practices of third-party service providers such as IT or HR providers.
  • Accountability and records: Document and record cyber security measures taken to protect personal data, to be able to demonstrate accountability under data protection law.
  • Further resources: Points to National Cyber Security Centre training for small organisations and to GFSC Cyber Security Rules and Guidance for more detail.

The checklist does not impose specific deadlines or mandatory filing requirements; it functions as best-practice guidance to help organisations reduce cyber risk and support compliance with existing data protection accountability obligations.

Key obligations

  • Organisations responsible for personal data should document and record the cyber security measures they take, so as to be able to demonstrate accountability under data protection law.

Applies to

organisations that process personal data, small organisations and charities, data controllers

Topics

Version history

2026-07-30

source file (current)