Statement of Guidance
Protect against phishing
Status not confirmedView on ODPA's website Source document
Summary
This is general awareness guidance published by the Office of the Data Protection Authority (Guernsey) explaining what phishing is and how individuals and organisations can reduce the risk of falling victim to phishing attacks. It does not impose new legal or regulatory requirements, but offers practical advice relevant to data protection and cybersecurity practices.
- Zero trust: Treat emails, attachments, and login pages with caution since they can be forged or compromised.
- Red flags: Watch for urgent calls to action, suspicious links, phone numbers, attachments, personal data requests, and inconsistencies in sender or domain details.
- Think before you click: Pause to question whether the sender and request are genuine and consistent with normal contact methods before acting.
- Verify authenticity: Confirm suspicious messages via a trusted second channel, a colleague, IT or cybersecurity contact, or by logging in directly through official channels rather than links in the message.
The guidance closes with practical dos and don'ts, such as never clicking unverified links or opening unexpected attachments, and not engaging with suspected scammers, recommending referral to the UK National Cyber Security Centre for further information.
Topics
Version history
2026-07-30