Statement of Guidance

Processor Assessments

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is ODPA guidance explaining how controllers should assess the suitability of processors before and during engagement, as part of a wider suite of guidance on engaging processors under Guernsey's data protection Law.

It sets out the legal basis for requiring appropriate technical and organisational measures, describes what controllers should consider when evaluating a processor's sufficiency of guarantees, and provides an appendix of assessment questions covering data collection, governance, storage, security, destruction, secondary processors, secondary data uses, transfers and training.

  • Assessment focus areas: Controllers should evaluate a processor's industry standard compliance, technical expertise, documentation (privacy, record management and security policies), adherence to codes of conduct or certification schemes, use of secondary processors, risk of secondary data use, and any processing or storage outside an authorised jurisdiction.
  • Ongoing monitoring: Controllers must monitor processor compliance on an ongoing basis, and processors must allow for and contribute to audits and inspections by the controller or an appointed third party.
  • Contracts: A legally binding contract must be in place between controller and processor formalising respective obligations, with further detail in companion contract guidance.
  • Appendix tool: A non-exhaustive questionnaire (Appendix 1) is provided for processors to complete to assist controllers in assessing suitability.

This is informational guidance rather than binding rules in itself, but it reflects and explains existing statutory obligations under the Law regarding security measures, contracts, and accountability when using processors.

Key obligations

  • Controllers and processors must put in place appropriate technological and organisational measures to ensure the security of personal data they process.
  • Controllers must carry out a formal assessment of a processor's technical and organisational measures before appointment, taking into account the nature of processing and risks to data subjects, to ensure sufficient guarantees are provided.
  • A legally binding contract must be put in place between controller and processor formalising their respective obligations under the Law.
  • Controllers must ensure a processor's compliance on an ongoing basis to satisfy the Law's accountability principle and demonstrate due diligence.
  • Processors must allow for and contribute to audits and inspections carried out by the controller or a third party appointed by the controller.

Applies to

controllers, processors, secondary processors

Topics

Version history

2026-07-30

source file (current)