Statement of Guidance
Overview: Appointment of Processors
Status not confirmedView on ODPA's website Source document
Summary
This is a short guidance note from the Guernsey Office of the Data Protection Authority (ODPA) providing a simple visual checklist of the steps an organisation should take when appointing a data processor. It is one part of a larger suite of guidance on engaging processors, and cross-references other numbered guidance notes for more detail on each step.
- Establish role: Determine whether your organisation is acting as a controller or a processor (see Guidance 1).
- Weigh risk and benefit: Consider the risk versus the benefit of appointing a processor (see Guidance 2).
- Check sub processors: Understand what sub processors may be appointed by the processor (see Guidance 2).
- Check data location: Understand where the data will be stored and accessed by the processor (see Guidance 2).
- Assess safeguards: Obtain reasonable assurance of the processor's technological and organisational controls to protect personal data (see Guidance 2).
- Put contract in place: Put in place a legally binding, written contract between the processor and the controller (see Guidance 3).
The document is purely explanatory and directs readers to the fuller guidance notes referenced for detailed requirements; it does not itself set out new legal obligations beyond summarising the process.
Key obligations
- Before appointing a processor, determine whether the organisation is a controller or a processor
- Put in place a legally binding, written contract between the controller and the processor
- Obtain reasonable assurance of the processor's technological and organisational controls protecting personal data
- Understand and account for where data will be stored and accessed by the processor
- Understand what sub processors the processor may appoint before proceeding
Applies to
controllers, processors, organisations using third parties to process personal data
Topics
Version history
2026-07-30