Statement of Guidance

Processor Self-Assessment Guidance

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is explanatory guidance issued by the Guernsey Office of the Data Protection Authority (ODPA) to help processors complete the processors' self-assessment questionnaire under the Data Protection (Bailiwick of Guernsey) Law, 2017. It does not itself impose new obligations but clarifies key concepts referenced in the questionnaire, such as special category data, Data Protection Officer (DPO) requirements, data transfers, and lists of EU/EEA and adequate jurisdictions.

  • EU countries: Lists the EU member states relevant to determining cross-border data flows.
  • Special category data: Explains how 'special category data' under the Law replaces the former concept of 'sensitive personal data', listing corresponding categories such as racial/ethnic origin, health data, genetic and biometric data, and criminal data.
  • Data Protection Officers: Describes which organisations must appoint a DPO: public authorities, and controllers/processors whose core activities involve large-scale regular and systematic monitoring or large-scale processing of special category or criminal data.
  • Transfer: Clarifies the meaning of 'transfer' of personal data as distinct from mere 'transit', including examples such as electronic transmission, paper records sent overseas, or data accessible via a website in other countries.
  • EEA and adequate jurisdictions: Lists EEA member states and jurisdictions currently recognised as having 'adequate' data protection status for transfers, noting that adequacy assessments may change under the GDPR.

The guidance notes that the United Kingdom is treated as an authorised jurisdiction for data transfers under the Law only until 31 December 2020, after which its status may need reassessment. Readers should treat the lists of countries and adequacy determinations as subject to change and consult current ODPA guidance for updates.

Key obligations

  • Organisations that are public authorities, or controllers/processors whose core activities involve large-scale regular and systematic monitoring of data subjects or large-scale processing of special category or criminal data, must appoint a Data Protection Officer.

Applies to

processors, controllers, public authorities

Deadlines

  • 31 December 2020: The United Kingdom is deemed an authorised jurisdiction for data transfers under the Law only until this date.

Topics

Version history

2026-07-30

source file (current)