Statement of Guidance

Ten-step Practical AI Guidance

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-09-11

Summary

This is practical guidance from the Office of the Data Protection Authority (Guernsey) explaining how organisations should apply data protection law when developing or using Artificial Intelligence, including generative and agentic AI. It sets out ten steps organisations should follow to process personal data responsibly in AI systems, and ends with a quick compliance checklist. It is explanatory guidance rather than a binding instrument, but it reflects how the ODPA expects the existing data protection law to be applied to AI.

  • Step 1 to 2: Confirm whether personal data is involved, clarify whether you are a controller or processor, and identify a valid lawful processing condition (with stricter conditions for special category data).
  • Step 3: Carry out a Data Protection Impact Assessment (DPIA) where AI could significantly affect individuals, such as automated decisions, profiling, or large scale or special category data processing.
  • Step 4 to 6: Be transparent about AI use via privacy notices, test for bias, be able to explain AI driven decisions, handle training data responsibly (lawful sourcing, no unlawful scraping, anonymisation, data minimisation), and respect individual rights of access, correction, erasure, objection and human review.
  • Step 7 to 8: Take a risk based (not zero risk) approach, consulting the ODPA if high risk remains after mitigation, and secure AI systems with encryption, access controls, retention limits and breach management.
  • Step 9 to 10: Keep documented records (role, lawful basis, DPIA results, mitigations, testing, and information given to individuals) including in the Record of Processing Activities, and maintain ongoing oversight through regular risk review, drift monitoring, DPIA updates and staff training.

The guidance closes with a ten-item checklist summarising these steps for quick reference, and notes that compliance is about managing and explaining risk rather than eliminating it entirely.

Key obligations

  • Determine whether AI processing involves personal data and apply data protection obligations accordingly.
  • Identify and record whether the organisation is acting as controller or processor, and identify and record the lawful processing condition relied on for AI processing.
  • Carry out and document a Data Protection Impact Assessment (DPIA) where AI could significantly affect individuals' rights (e.g. automated decisions, special category or large-scale data, profiling).
  • Provide clear, plain-English information to individuals about how AI is used and how it affects them (privacy notices).
  • Regularly test AI systems for bias or unfair/discriminatory outcomes and be able to explain AI-driven decisions if challenged.
  • Ensure training data is lawfully sourced, avoid unlawfully scraped personal data absent a valid legal basis, anonymise data where possible, and apply data minimisation.
  • Respect individuals' rights of access, correction, erasure, objection, and (in the EU/UK) human review of significant automated decisions.
  • Consult the ODPA if a high risk remains following mitigation efforts identified in a DPIA.
  • Apply security measures (encryption, access controls, audits), set data retention limits, and maintain a data breach management policy.
  • Keep records justifying AI-related decisions (role, lawful basis, DPIA results, mitigations, testing/validation, information given to individuals) and add AI use to the Record of Processing Activities.
  • Review risks regularly, monitor AI models for drift, update DPIAs for significant changes, and train staff on responsible AI use.

Applies to

organisations using or deploying AI that process personal data, controllers, processors

Topics

Version history

2026-09-11

source file (current)

2026-07-30

source file