Statement of Guidance
How to link a DPIA to the data protection principles
Status not confirmedView on ODPA's website Source document
Summary
This is ODPA guidance offering a practical checklist of questions to help organisations link a Data Protection Impact Assessment (DPIA) to the seven data protection principles under Guernsey's data protection law. It does not create new legal obligations but helps controllers identify where a project risks non-compliance with existing principles during the DPIA process.
- Lawfulness, fairness and transparency: Identify the purpose of processing, how individuals will be informed, whether notices need updating, and how consent is obtained/withdrawn.
- Purpose limitation: Check the project plan covers all processing purposes and that new purposes or future changes are reviewed.
- Minimisation: Assess whether data quality is sufficient and which data could be excluded without harming the project.
- Accuracy: Consider whether systems allow correction of data, how accuracy is verified, and who handles accuracy queries.
- Storage limitation: Define retention periods and confirm systems can delete or anonymise data accordingly.
- Integrity and confidentiality: Review security measures, system protections, and staff training for secure operation.
- Accountability: Document processing and compliance, review it regularly, and ensure records are accessible to relevant staff and management.
The document is a self-assessment tool rather than a binding requirement, intended to support controllers already conducting DPIAs in demonstrating compliance with the seven principles.
Applies to
data controllers, organisations conducting DPIAs
Topics
Version history
2026-07-30