Statement of Guidance

DPIA

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is ODPA guidance explaining what a Data Protection Impact Assessment (DPIA) is, when one is legally required, and why it matters for compliance. It is aimed at any organisation that processes personal data and is planning new or changed processing activities.

  • Legal requirement: The Law requires a DPIA to be carried out where proposed processing poses a particularly high risk to the individuals whose data is involved.
  • Best practice: Organisations should assess the impact of any new or revised processing that involves personal data, even where not strictly required by law.
  • Screening questions: The guidance lists questions to help decide if a DPIA is needed, covering new data collection, compelled disclosure, new uses of data, new intrusive technology (e.g. biometrics, facial recognition, profiling), significant decisions about individuals, special category or sensitive data, and intrusive contact with individuals.
  • Design and default: The Law requires organisations to build data protection into their processes by design and default, and DPIAs support meeting this legal duty.
  • Law enforcement processing: Where personal data is processed for a Law Enforcement purpose under the Law Enforcement Ordinance, the DPIA content requirements differ, and organisations should consult sections 36 and 37 of the Ordinance.

The page also offers a modifiable DPIA template that organisations can adapt to their own processes and requirements.

Key obligations

  • Carry out a DPIA where proposed processing presents a particularly high risk to individuals, as required by the Law.
  • Assess the impact of new or revised processing involving personal data even outside strictly high-risk cases.
  • Build data protection into processing by design and default, using DPIAs to support this legal duty.
  • When processing personal data for a Law Enforcement purpose under the Law Enforcement Ordinance, consult sections 36 and 37 of that Ordinance for the applicable DPIA content requirements.

Applies to

organisations processing personal data, organisations processing personal data for Law Enforcement purposes under the Law Enforcement Ordinance

Topics

Version history

2026-07-30

source file (current)