Statement of Guidance

Engaging processors

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from the Guernsey Office of the Data Protection Authority (ODPA) explaining what organisations must do when they engage third parties, known as processors, to carry out tasks involving personal data on their behalf. It applies whenever a controller outsources functions such as payroll, IT, marketing, or work to a group entity, and sets out the two core legal requirements for such arrangements under the Data Protection Law.

  • Sufficient guarantees: The controller must obtain sufficient guarantees that the processor will implement reasonable technical and organisational measures to ensure processing meets the requirements of the Law and safeguards data subject rights.
  • Legally binding contract: A legally binding contract complying with the Law must be put in place between the controller and the processor.
  • Examples of processor relationships: Outsourcing payroll and HR, day-to-day IT functions, business development and marketing operations, or work to a group entity.
  • Further resources: Links to related guidance on controller versus processor roles, processor assessments, contracts between controllers and processors, cloud-based services, an overview of appointing a processor, and a case study on appointing a Bailiwick-based processor.

The page is a signpost to a suite of more detailed guidance documents rather than a standalone set of binding rules, but it confirms the underlying legal obligations that apply whenever a controller uses a processor.

Key obligations

  • Controllers must obtain sufficient guarantees that a processor will implement reasonable technical and organisational measures so that processing meets the requirements of the Law and safeguards data subject rights.
  • Controllers must put in place a legally binding contract with any processor, compliant with the Law, before engaging them to process personal data on their behalf.

Applies to

controllers, processors, joint controllers, secondary processors

Topics

Version history

2026-07-30

source file (current)