Statement of Guidance

Exemptions

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This guidance from the ODPA explains the exemptions and exceptions available to controllers and processors under the Data Protection (Bailiwick of Guernsey) Law, 2017, which can be used to limit or withhold information otherwise owed to individuals in response to subject access requests or other rights requests. It sets out how these exemptions, found in Schedule 8 of the Law, should be applied in practice.

  • Narrow application: Exemptions must be applied narrowly to specific personal data in specific circumstances, with no blanket application; each case must be assessed individually considering the type of data, purpose of processing, and impact on the data subject.
  • Mandatory exemptions: Very few exemptions are mandatory once the described circumstances apply (paragraph 16A on disclosures prohibited or restricted by enactments, and 16D on serious harm to data subjects or others); otherwise controllers may choose not to rely on an exemption even if it could apply.
  • Justification and documentation: Any decision to rely on an exemption should be carefully considered, fully justified, and documented, consistent with the Law's accountability requirements; controllers should be prepared to share this documentation with the Authority if asked.
  • Law enforcement processing: Exemptions under the Law Enforcement Ordinance differ from those under the Law; for law enforcement purposes, controllers should consult section 19 and Schedule 3 of the Ordinance instead.

This is informational guidance rather than a binding instrument, but it reflects the Authority's expectations for how exemptions should be assessed and evidenced by controllers and processors handling data subject rights requests.

Key obligations

  • Apply exemptions from Schedule 8 of the Data Protection (Bailiwick of Guernsey) Law, 2017 narrowly and only to specific personal data in specific circumstances, avoiding blanket application.
  • Assess reliance on an exemption on a case-by-case basis, considering the type of personal data, the purpose of processing, and any adverse impact on the data subject.
  • Document any decision to rely on an exemption and be prepared to produce that documentation to the Authority upon request.
  • Apply the mandatory exemptions under paragraph 16A (disclosures prohibited or restricted by enactments) and 16D (serious harm to data subjects or other individuals) in the circumstances they describe.
  • When processing personal data for a law enforcement purpose, refer to section 19 and Schedule 3 of the Law Enforcement Ordinance rather than the Law's exemptions.

Applies to

controllers, processors

Topics

Version history

2026-07-30

source file (current)