Statement of Guidance

Handling Data Breaches

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is general guidance from the Guernsey ODPA explaining what counts as a personal data breach and what organisations must do if one occurs. It sets out common breach scenarios with practical advice on prevention, and describes the legal obligation to report certain breaches to the ODPA.

  • What is a breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
  • Reporting duty: Organisations are legally obliged to report a breach to the ODPA if it is likely to pose a significant risk to affected individuals.
  • Timing: Notification to the ODPA must be made within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in harm to the individuals concerned.
  • Notifying individuals: In some circumstances organisations may also need to notify the individuals whose data was breached.
  • Common scenarios covered: Unauthorised staff access/printing of data, misdirected emails, lost physical documents in the post, unsecured special category data, and phishing attacks compromising systems.
  • Law Enforcement Ordinance: Controllers processing personal data for a law enforcement purpose must additionally consult section 34 of the Law Enforcement Ordinance when a breach occurs.

The guidance recommends having a breach response plan and staff training in place before an incident occurs, and points readers to more detailed ODPA guidance on breach reporting procedures.

Key obligations

  • Report a personal data breach to the ODPA within 72 hours of becoming aware of it, unless the breach is unlikely to result in harm to affected individuals
  • Assess whether affected individuals also need to be notified of the breach
  • Have a breach response plan and staff training in place to prevent and manage breaches
  • Controllers processing personal data for law enforcement purposes must consult section 34 of the Law Enforcement Ordinance when handling a breach

Applies to

organisations, data controllers, controllers processing personal data for a law enforcement purpose

Deadlines

  • within 72 hours after becoming aware: Deadline to report a personal data breach to the ODPA, unless the breach is unlikely to result in harm to affected individuals

Topics

Version history

2026-07-30

source file (current)