Statement of Guidance

Protect against phishing

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is general awareness guidance published by the Office of the Data Protection Authority (Guernsey) explaining what phishing is and how individuals and organisations can reduce the risk of falling victim to phishing attacks. It does not impose new legal or regulatory requirements, but offers practical advice relevant to data protection and cybersecurity practices.

  • Zero trust: Treat emails, attachments, and login pages with caution since they can be forged or compromised.
  • Red flags: Watch for urgent calls to action, suspicious links, phone numbers, attachments, personal data requests, and inconsistencies in sender or domain details.
  • Think before you click: Pause to question whether the sender and request are genuine and consistent with normal contact methods before acting.
  • Verify authenticity: Confirm suspicious messages via a trusted second channel, a colleague, IT or cybersecurity contact, or by logging in directly through official channels rather than links in the message.

The guidance closes with practical dos and don'ts, such as never clicking unverified links or opening unexpected attachments, and not engaging with suspected scammers, recommending referral to the UK National Cyber Security Centre for further information.

Topics

Version history

2026-07-30

source file (current)