Statement of Guidance
Law Enforcement Ordinance
Status not confirmedView on ODPA's website Source document
Summary
This ODPA guidance explains the relationship between the Data Protection (Bailiwick of Guernsey) Law, 2017 (the Law) and the Data Protection (Law Enforcement and Related Matters) (Bailiwick of Guernsey) Ordinance, 2018 (the LEO). It clarifies when the narrower LEO applies instead of the general Law, namely where a 'competent authority' is processing personal data for a 'law enforcement purpose'.
- Who is a competent authority: Bodies such as the States, public committees, holders of public office, statutory bodies, courts and tribunals, the police forces of Guernsey, Alderney and Sark, parish Douzaines, and comparable bodies in other countries, but only when exercising a function conferred by law or States Resolution for a law enforcement purpose; also any other person performing a public-nature function for a law enforcement purpose, or any other prescribed person.
- What counts as a law enforcement purpose: Preventing, investigating, detecting or prosecuting criminal offences; executing criminal penalties; safeguarding against threats to public or national security; and enabling action under criminal proceeds enactments.
- Adequacy status: In July 2023 the UK deemed the LEO 'adequate' for transfers of personal data for law enforcement purposes.
- Areas that differ from the Law: Principles, data subject rights, lawful bases, controller/processor agreements, international transfers, ODPA enforcement powers, DPIAs, Data Protection Officers, exemptions, automated processing, and personal data breaches all operate differently under the LEO and must be separately understood by competent authorities.
Competent authorities must determine, purpose by purpose, whether the Law or the LEO applies to a given processing activity, since the same data may be subject to different regimes depending on the purpose for which it is used. For all activities outside a law enforcement purpose, competent authorities must apply the Law rather than the LEO.
Key obligations
- Competent authorities must identify, for each specific processing purpose, whether the Law or the LEO applies, since the same personal data may be processed under different legal regimes depending on purpose.
- Competent authorities must apply the Law (not the LEO) for any processing that is not for a law enforcement purpose.
- Where the LEO applies, competent authorities must understand and comply with its distinct requirements on principles, data subject rights, lawful bases, controller/processor agreements, international transfers, ODPA enforcement powers, DPIAs, Data Protection Officers, exemptions, automated processing, and personal data breaches.
Applies to
competent authorities (as defined in section 50 of the LEO), public bodies exercising law enforcement functions, police forces (Guernsey, Alderney, Sark), statutory bodies, courts and tribunals of the Bailiwick, parish Douzaines