Statement of Guidance

Data Sharing - A Simple Guide

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is general guidance from the Guernsey ODPA explaining how to share personal data lawfully under the Data Protection (Bailiwick of Guernsey) Law, 2017. It is aimed at anyone acting as a controller or processor of personal data and sets out practical points to consider before and during data sharing, rather than creating new legal rules.

  • Before sharing: Have a valid legal basis, define the categories of data and roles of parties, share the minimum data necessary, use secure transfer methods, limit retention, document the sharing, and tell individuals where appropriate.
  • Processor arrangements: Where a third party processes data on your behalf as a processor, you must have a written, legally binding controller/processor agreement in place.
  • Seven data protection principles: All sharing must follow lawfulness/fairness/transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity/confidentiality, and accountability.
  • Recommended (not mandatory) practice: The ODPA recommends carrying out a Data Protection Impact Assessment (DPIA) to assess risks and recommends having a data sharing agreement in place.
  • Overseas transfers: Sharing data with a third party outside the Bailiwick is treated as a 'data transfer'; check whether the recipient is in an authorised jurisdiction, and if not, put an appropriate safeguard (e.g. Standard Contractual Clauses) in place.

The guidance also distinguishes joint controller, controller-to-controller, and controller-to-processor sharing, and notes that data may be shared in an emergency where necessary and proportionate (e.g. risk to life or national security).

Key obligations

  • Ensure any data sharing complies with the Data Protection (Bailiwick of Guernsey) Law, 2017, including having a valid legal basis for the sharing.
  • Where a third party acts as a processor, put in place a written, legally binding controller/processor agreement.
  • Apply the seven data protection principles (lawfulness/fairness/transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity/confidentiality, accountability) whenever sharing personal data.
  • Before transferring personal data outside the Bailiwick of Guernsey, check whether the recipient jurisdiction is an authorised jurisdiction; if not, put in place an appropriate safeguard such as Standard Contractual Clauses.
  • Give individuals appropriate information about data sharing arrangements and ensure they can easily exercise their individual rights.

Applies to

controllers, processors

Topics

Version history

2026-07-30

source file (current)