Statement of Guidance

Data protection by design and default

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is ODPA guidance explaining the 'Data Protection by Design and Default' requirement under Section 32 of the Data Protection (Bailiwick of Guernsey) Law, 2017. It sets out what controllers must do to embed data protection compliance into projects and processing activities from the outset, rather than treating it as an add-on.

  • Design stage integration: Controllers must consider data protection at the very first stage of any project, process, IT system, policy, data sharing initiative or new data collection, and throughout its life cycle.
  • Default settings: By default, only personal data necessary for the purpose should be processed; privacy settings on products or services should default to the highest level of privacy.
  • Technical and organisational measures: Controllers must adopt appropriate and proportionate technical and organisational measures to comply with the seven data protection principles and safeguard individuals' rights.
  • Supplier and processor oversight: Controllers must ensure third party processors and suppliers have appropriate data protection standards, considered during procurement.
  • Impact assessments: Under Section 44 of the Law, controllers must carry out a Data Protection Impact Assessment where processing is high risk; a risk assessment is recommended even where a full DPIA is not required.
  • Documentation: Controllers should document the considerations and decisions behind their measures to evidence compliance to the ODPA.

The guidance also notes that the ODPA may in future recognise certification schemes or codes of conduct as evidence of compliance, but none are currently approved.

Key obligations

  • Data controllers must establish and carry out proportionate technical and organisational measures to comply with the seven data protection principles from the design stage of any project or process involving personal data.
  • Data controllers must ensure that, by default, only personal data necessary for the specified purpose is processed, and that privacy settings default to the highest level of protection.
  • Data controllers must integrate necessary safeguards into processing to protect individuals' rights and be able to evidence compliance from the outset.
  • Data controllers must carry out a Data Protection Impact Assessment under Section 44 of the Law where proposed processing is high risk.
  • Data controllers must ensure third party processors and suppliers have appropriate data protection standards in place, assessed during procurement.
  • Data controllers must limit, by default, the amount of personal data processed, the extent of processing, the storage period, and accessibility of the data.

Applies to

data controllers

Deadlines

  • 25 May 2018: Data Protection by Design and Default became a legal requirement under the GDPR and the Data Protection (Bailiwick of Guernsey) Law, 2017 from this date.

Topics

Version history

2026-07-30

source file (current)