Statement of Guidance
Managing Personal Data Breaches
Status not confirmedView on ODPA's website Source document
Summary
This guidance from the Office of the Data Protection Authority (ODPA) explains how controllers and processors under the Data Protection (Bailiwick of Guernsey) Law, 2017 should identify, manage and report personal data breaches. It sets out the definition of a personal data breach, the differing duties of controllers versus processors, record keeping requirements, and when notification to the ODPA and to affected data subjects is required.
- Processor duty: A processor that becomes aware of a breach must notify the relevant controller as soon as practicable, following up in writing if initial notice was oral; processors do not report directly to the ODPA.
- Controller duty: A controller must ensure an appropriate response to any breach, take mitigating action to reduce risk to affected data subjects, and conduct a post-breach review to identify and remedy compliance shortfalls.
- Record keeping: Controllers must keep a written record of every breach they become aware of, covering the facts, effects, remedial action taken, and steps taken to comply with Section 42 (including any ODPA notice), retained for six years.
- ODPA notification: Controllers must give the ODPA written notice of a breach unless it is unlikely to pose any risk to the significant interests of affected data subjects; if not notifying, the rationale must be recorded.
- Data subject notification: Where a breach is likely to pose a high risk to the significant interests of a data subject, the controller must notify the data subject as soon as practicable, unless data was rendered unintelligible, sufficient mitigation removed the risk, or notification would be disproportionate.
- Content of notices: Notices to data subjects must describe the nature of the breach, provide contact details of the data protection officer or other information source, describe likely consequences, and describe measures taken or proposed to address the breach.
The guidance also explains that ODPA reporting is primarily aimed at ensuring breaches are handled properly and risks mitigated, with regulatory action considered only where proportionate given the severity of the breach and the controller's response.
Key obligations
- Processors must notify the relevant controller of a personal data breach as soon as practicable, confirming any oral notice in writing at the first opportunity.
- Controllers must take appropriate mitigating action to reduce risk to affected data subjects and conduct a post-breach review of compliance shortfalls.
- Controllers must keep a written record of every personal data breach, including facts, effects, remedial action, and Section 42 compliance steps, retained for 6 years from becoming aware of the breach.
- Controllers must give the ODPA written notification of a personal data breach as soon as practicable and no later than 72 hours after becoming aware of it, unless the breach is unlikely to risk the significant interests of affected data subjects (in which case the rationale for not notifying must be recorded).
- If notification to the ODPA is given later than 72 hours, the controller must provide a rationale for the delay.
- Where a breach is likely to result in high risk to the significant interests of data subjects, the controller must give written notice to the affected data subject(s) as soon as practicable, unless an applicable exception (encryption, effective mitigation, or disproportionate effort) applies.
- Notices to data subjects must include a description of the breach's nature, contact details for further information, likely consequences, and measures taken or proposed to address the breach.
- Controllers must record their rationale where they assess that a breach does not pose a high risk to data subjects' significant interests, or does not require ODPA notification.
Applies to
controllers, processors
Deadlines
- 72 hours after the controller becomes aware of the breach: Deadline for controllers to give the ODPA written notification of a personal data breach, unless not practicable (in which case a rationale for delay must be provided).
- 6 years from becoming aware of the breach: Minimum retention period for the controller's written record of a personal data breach.
- as soon as practicable: Timeframe for a processor to notify the controller of a breach, and for a controller to notify affected data subjects where high risk to their significant interests is likely.