Statement of Guidance

Data Subject Access Requests

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is an ODPA guidance page introducing data subject access requests (DSARs) under the Data Protection (Bailiwick of Guernsey) Law, 2017. It explains what a DSAR is and directs controllers and individuals to further resources for handling and making such requests.

  • For controllers: Points to detailed guidance on how to handle DSARs to meet the Law's requirements, a webinar on responding to DSARs, a step by step guide to applying Section 16 where requests involve information about other people, and a DSAR Manager tool to help DPOs and organisations track and complete their obligations.
  • For individuals: Points to separate guidance explaining how to make a DSAR, what should be received in response, and what to do if unsatisfied with the response.
  • Law Enforcement processing: Notes that the information required to be provided in response to an access request under the Law Enforcement Ordinance differs from that required under the Law, and directs readers to section 13 of the Ordinance for that context.

The page itself is a signpost to substantive guidance and tools rather than a standalone set of rules; the underlying legal obligations to respond to access requests derive from the Law (and, where relevant, the Law Enforcement Ordinance) rather than from this page.

Key obligations

  • Controllers holding information about identifiable individuals must be able to handle DSARs in accordance with the requirements of the Data Protection (Bailiwick of Guernsey) Law, 2017
  • When a DSAR involves information about other people, controllers must apply Section 16 of the Law in responding
  • When responding to access requests made under the Law Enforcement Ordinance, controllers must consult and apply section 13 of that Ordinance rather than the Law's general requirements

Applies to

data controllers, data protection officers (DPOs), organisations processing personal data, individuals (data subjects)

Topics

Version history

2026-07-30

source file (current)