Statement of Guidance
Information to be Given (Privacy Notice Guidance)
Status not confirmedView on ODPA's website Source document
Summary
This guidance from the Guernsey Office of the Data Protection Authority explains the 'right to information' obligations under the Data Protection (Bailiwick of Guernsey) Law, 2017. It sets out what fair processing information (commonly given via a privacy notice) controllers must supply to individuals, and when it must be provided, depending on whether the personal data was obtained directly from the data subject or from another source.
- Form of information: Privacy information must be concise, transparent, intelligible, easily accessible, written in clear and plain language (especially for children), and provided free of charge.
- Core content (both sources): Identity and contact details of the controller and, where applicable, its representative and data protection officer; whether data is special category; purpose and legal basis for processing; legitimate interests relied on; recipients or categories of recipients; details of transfers outside the EU to authorised or unauthorised jurisdictions and safeguards; retention period or criteria; existence of data subject rights, the right to withdraw consent, the right to complain to a supervisory authority, and details of automated decision making or profiling.
- Additional content for data not obtained directly: The source the data originated from and whether it came from publicly available sources.
- Additional content for data obtained directly: Whether providing the personal data is part of a statutory or contractual requirement and the possible consequences of not providing it.
- Timing when data is obtained directly: Privacy information must be given at the time the data is obtained.
- Timing when data is obtained from another source: Privacy information must be given within a reasonable period and no later than one month of obtaining the data, or if used to communicate with the individual at the latest at first communication, or if disclosed to a third party at the latest when disclosed.
- Exemptions: No need to repeat information the individual already has; and for data obtained from other sources, exemptions apply where provision is impossible, disproportionately effortful, would prejudice the processing purpose, must be kept confidential under a legal duty, or where obtaining or disclosing the data is itself required by law.
Controllers relying on any exemption from providing privacy information must be able to justify that reliance, as it may be scrutinised by the supervisory authority if a data subject complains.
Key obligations
- Provide individuals with fair processing (privacy notice) information that is concise, transparent, intelligible, easily accessible, in clear and plain language, and free of charge
- Where data is obtained directly from the data subject, provide the required privacy information at the time the data is obtained
- Where data is obtained from a source other than the data subject, provide the required privacy information within a reasonable period and no later than one month of obtaining the data, or at first communication with the individual if earlier, or at the time of disclosure to a third party if that occurs first
- Include in privacy information the source of the data and whether it came from publicly available sources when data was not obtained directly from the data subject
- Include in privacy information whether provision of personal data is a statutory or contractual requirement and the consequences of not providing it, when data is obtained directly from the data subject
- Actively make privacy information available to individuals (for example via a website, with individuals made aware of and able to easily access it), rather than merely making it available passively
- Be able to justify and document reliance on any exemption from providing privacy information if challenged by the supervisory authority or a data subject complaint
Applies to
data controllers, data processors
Deadlines
- no later than one month: When personal data is not obtained directly from the data subject, privacy information must be provided within a reasonable period and no later than one month of obtaining the data (or sooner if used to communicate with the individual or disclosed to a third party)
Topics
Version history
2026-07-30
source file (current)
2026-07-30