Statement of Guidance

Guidance on International Data Transfers

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is ODPA guidance explaining how controllers and processors in the Bailiwick of Guernsey should approach transfers of personal data outside the Bailiwick under Part X of the Data Protection (Bailiwick of Guernsey) Law, 2017. It sets out a seven step framework for deciding whether a proposed transfer is a 'restricted transfer' and, if so, what safeguard or exception can lawfully support it.

  • Step 1: Identify whether the Law applies and whether you are making a 'restricted transfer' to a legally distinct recipient outside the Bailiwick.
  • Step 2: Consider whether the purpose can be achieved without transferring personal data, eg by anonymising it.
  • Step 3: Check whether the recipient jurisdiction is the EU/EEA or subject to a European Commission adequacy finding (list includes UK, Jersey, Isle of Man, Japan private sector, Canada PIPEDA-covered data, EU-US Data Privacy Framework participants, and others).
  • Step 4: If not adequate, put in place an available safeguard: an instrument between public authorities, Binding Corporate Rules, Standard Data Protection Clauses (SCCs), an approved code of conduct, an approved certification mechanism, an Authority-authorised bespoke contract, or an administrative arrangement between public authorities.
  • Step 5: Carry out a Transfer Impact Assessment to check the safeguard gives essentially equivalent protection, adding supplementary measures if needed.
  • Step 6 and 7: Confirm equivalence of protection or, failing that, check whether one of eight specific statutory exceptions applies (eg court orders, explicit consent, vital interests, public register, one-off compelling legitimate interests, regulations in the public interest) before proceeding.

The guidance also flags a now-passed deadline requiring businesses still using the old EU Standard Contractual Clauses to migrate to the new post-Schrems II EU SCCs, and notes that no approved codes of conduct or certification mechanisms currently exist in the Bailiwick.

Key obligations

  • Before transferring personal data outside the Bailiwick, controllers and processors must first establish whether a 'restricted transfer' is occurring and document the parameters, destination jurisdiction and nature of the recipient.
  • Where the destination is not an adequate jurisdiction, the exporter must put in place one of the available safeguards listed in the Law (eg SCCs, BCRs, approved code, approved certification, Authority-authorised contract, or administrative arrangement between public authorities).
  • When relying on an available safeguard, the exporter must carry out a Transfer Impact Assessment to verify the level of protection is essentially equivalent to that under the Law, adding supplementary measures if it is not.
  • Any Bailiwick business still using the old EU Standard Contractual Clauses must migrate new transfers to the new EU SCCs.
  • Binding Corporate Rules must be approved by a competent supervisory authority (the ODPA or an EEA data protection authority) before being relied upon.
  • Any bespoke contract or administrative arrangement relied upon for a restricted transfer must be individually authorised by the Authority before it takes effect.
  • Where relying on the 'compelling legitimate interests' one-off transfer scenario, the exporter must document the balancing exercise and safeguards, inform the Authority of the transfer, and inform the affected individual and the compelling legitimate interest relied upon.

Applies to

controllers, processors, data controllers and processors established in the Bailiwick of Guernsey

Deadlines

  • 27 December 2022: Deadline for Bailiwick businesses still using the previous version of the EU Standard Contractual Clauses to transfer to the new EU SCCs for restricted data transfers.

Topics

Version history

2026-07-30

source file (current)