Statement of Guidance
Data Protection Officers (DPOs)
Status not confirmedView on ODPA's website Source document
Summary
This is ODPA guidance explaining when organisations must appoint a Data Protection Officer (DPO) under section 47 of the Data Protection (Bailiwick of Guernsey) Law, and what duties apply to the DPO and to the organisation supporting them. It also notes that different DPO requirements apply under the Law Enforcement Ordinance (sections 39 to 42) for law enforcement processing.
- Mandatory appointment triggers: A DPO must be appointed if the organisation is a public authority (except courts in their judicial capacity), carries out large scale systematic monitoring of individuals as a core activity, or carries out large scale processing of special category data as a core activity.
- Voluntary appointment: Organisations not meeting these criteria may still choose to appoint a DPO voluntarily, but must in any case ensure sufficient staff and skills to meet their obligations under the Law.
- Who can be DPO: The role can be filled by a dedicated staff member, a staff member with other duties, or a contracted external party, provided there is no conflict with other duties; a single DPO may serve a group of companies or public authorities if accessible and given proportionate time for each entity.
- DPO's minimum tasks: Informing and advising on compliance obligations, monitoring compliance and advising on data protection impact assessments, training staff, conducting internal audits, acting as first point of contact for the ODPA, and cooperating with the ODPA.
- Notification and publication duties: The organisation must give written notice to the ODPA of the DPO's name and contact details and publish a notice confirming the DPO's designation and contact details so individuals can contact them directly.
- Support requirements: The DPO must report to the highest tier of management, operate independently without penalty for performing their tasks, receive adequate resources, have access to all relevant personal data and processing operations, and be free from conflicts of interest.
- Qualifications: No specific credentials are mandated, but the DPO must have professional experience and knowledge of data protection law proportionate to the organisation's processing activities.
The guidance points readers to additional resources, including European Data Protection Board guidance on DPOs and ODPA's own DPO Zone, which includes a DSAR manager tool.
Key obligations
- Organisations meeting the statutory triggers (public authority, large scale systematic monitoring, or large scale processing of special category data as a core activity) must appoint a DPO.
- Organisations must ensure sufficient staff and skills to discharge their obligations under the Law regardless of whether a DPO is legally required.
- The DPO must not undertake other duties that conflict with their DPO responsibilities.
- Where a single DPO serves a group of companies or public authorities, that DPO must be easily accessible from each entity and allocate proportionate time to each.
- The organisation must give written notice to the ODPA of the DPO's name and contact details.
- The organisation must publish a notice confirming the DPO's designation and contact details, allowing individuals to contact the officer directly.
- The organisation must involve the DPO in all issues relating to data protection affecting the organisation.
- The DPO must report to the highest tier of management within the organisation.
- The organisation must ensure the DPO operates independently and is not dismissed or penalised for performing their tasks.
- The organisation must provide adequate resources to enable the DPO to meet legal obligations and maintain knowledge.
- The DPO must be able to access all personal data and processing operations of the organisation.
- The organisation must ensure there is no conflict of interest in relation to the DPO's functions.
Applies to
public authorities, data controllers, data processors, organisations processing personal data, group of companies, GPs' practices (example of core activity processing)