Statement of Guidance

How to link a DPIA to the data protection principles

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is ODPA guidance offering a practical checklist of questions to help organisations link a Data Protection Impact Assessment (DPIA) to the seven data protection principles under Guernsey's data protection law. It does not create new legal obligations but helps controllers identify where a project risks non-compliance with existing principles during the DPIA process.

  • Lawfulness, fairness and transparency: Identify the purpose of processing, how individuals will be informed, whether notices need updating, and how consent is obtained/withdrawn.
  • Purpose limitation: Check the project plan covers all processing purposes and that new purposes or future changes are reviewed.
  • Minimisation: Assess whether data quality is sufficient and which data could be excluded without harming the project.
  • Accuracy: Consider whether systems allow correction of data, how accuracy is verified, and who handles accuracy queries.
  • Storage limitation: Define retention periods and confirm systems can delete or anonymise data accordingly.
  • Integrity and confidentiality: Review security measures, system protections, and staff training for secure operation.
  • Accountability: Document processing and compliance, review it regularly, and ensure records are accessible to relevant staff and management.

The document is a self-assessment tool rather than a binding requirement, intended to support controllers already conducting DPIAs in demonstrating compliance with the seven principles.

Applies to

data controllers, organisations conducting DPIAs

Topics

Version history

2026-07-30

source file (current)