Statement of Guidance

Overview: Appointment of Processors

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a short guidance note from the Guernsey Office of the Data Protection Authority (ODPA) providing a simple visual checklist of the steps an organisation should take when appointing a data processor. It is one part of a larger suite of guidance on engaging processors, and cross-references other numbered guidance notes for more detail on each step.

  • Establish role: Determine whether your organisation is acting as a controller or a processor (see Guidance 1).
  • Weigh risk and benefit: Consider the risk versus the benefit of appointing a processor (see Guidance 2).
  • Check sub processors: Understand what sub processors may be appointed by the processor (see Guidance 2).
  • Check data location: Understand where the data will be stored and accessed by the processor (see Guidance 2).
  • Assess safeguards: Obtain reasonable assurance of the processor's technological and organisational controls to protect personal data (see Guidance 2).
  • Put contract in place: Put in place a legally binding, written contract between the processor and the controller (see Guidance 3).

The document is purely explanatory and directs readers to the fuller guidance notes referenced for detailed requirements; it does not itself set out new legal obligations beyond summarising the process.

Key obligations

  • Before appointing a processor, determine whether the organisation is a controller or a processor
  • Put in place a legally binding, written contract between the controller and the processor
  • Obtain reasonable assurance of the processor's technological and organisational controls protecting personal data
  • Understand and account for where data will be stored and accessed by the processor
  • Understand what sub processors the processor may appoint before proceeding

Applies to

controllers, processors, organisations using third parties to process personal data

Topics

Version history

2026-07-30

source file (current)