Statement of Guidance
Data Audits
Status not confirmedView on ODPA's website Source document
Summary
This ODPA guidance explains the concept of data protection audits under Guernsey's data protection law, distinguishing between statutory audits the ODPA itself may carry out and internal audits organisations are encouraged to conduct. It provides a practical, staged methodology for organisations wishing to review their own data processing activities and includes a downloadable data audit template.
- Statutory audits: The ODPA has legal power (schedule 7, para 9 of the Law) to conduct a data protection audit on a controller or processor, but only in limited circumstances, usually following a formal investigation.
- Internal audits: Organisations are encouraged (not legally compelled by this guidance) to conduct their own internal data audits regularly to document processing activities and build a proactive compliance programme.
- Suggested audit stages: Planning (identify sponsor and audit lead); identifying personal data and how it is processed; assessing processing and compliance against lawful bases and safeguards; and reporting, recommending and implementing changes.
- Related reminders: Review third-party controller/processor contracts (the Law requires certain specific elements in such agreements), review staff contracts and training materials, and retain audit documentation for use in any future ODPA enquiry.
The document is advisory in nature: it does not itself impose a mandatory internal audit requirement, but it flags an existing statutory obligation that controller/processor contracts must contain certain specific elements under the Law, and highlights that the ODPA can compel a statutory audit in limited circumstances.
Key obligations
- Controller/processor agreements must include certain specific elements required by the Law.
- Controllers and processors may be required to submit to a statutory data protection audit conducted by the ODPA following a formal investigation, as provided under schedule 7, para 9 of the Law.
Applies to
data controllers, data processors, organisations that handle personal data