Statement of Guidance

Ten-step Practical AI Guidance

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is practical guidance from the Guernsey ODPA setting out ten steps organisations should follow when using Artificial Intelligence, including generative and agentic AI, to ensure personal data is handled in compliance with data protection law. It is aimed at any organisation deploying or building AI systems that involve personal data, and explains how existing data protection concepts, lawful basis, DPIAs, transparency, data minimisation, individual rights, security, record keeping and oversight, apply specifically to AI use.

  • Check for personal data: Determine whether your AI system processes personal data, in training or in live use.
  • Role and lawful basis: Establish whether you are a controller or processor and identify and record your lawful processing condition, noting stricter conditions apply to special category data.
  • DPIA: Carry out a data protection impact assessment where AI could significantly affect individuals, such as automated decisions, profiling or large scale processing.
  • Transparency and fairness: Tell people how AI is used, test for bias, and be able to explain AI driven decisions.
  • Training data: Use reliable, lawfully obtained data, avoid unlawfully scraped data, anonymise where possible, and apply data minimisation.
  • Individual rights: Respect access, correction, erasure, objection and human review rights in relation to AI processing.
  • Risk management: Take a risk based approach, mitigate risks identified in the DPIA, and consult the ODPA if high risk remains after mitigation.
  • Security: Apply security measures such as encryption and access controls, set retention limits, and have a data breach policy.
  • Record keeping: Keep records justifying role, lawful basis, DPIA results, risk mitigations, testing and information given to individuals, and add AI use to the Record of Processing Activities.
  • Ongoing oversight: Regularly review risks, monitor for model drift, update DPIAs for significant changes, and train staff.

The guidance ends with a quick checklist summarising these steps. It is explanatory guidance rather than binding rules, but it reflects how the ODPA expects existing data protection law obligations to be applied to AI use.

Key obligations

  • Identify and record the lawful processing condition relied upon for any AI processing of personal data, applying stricter conditions where special category data is involved
  • Carry out a data protection impact assessment where AI processing is likely to significantly affect individuals, such as automated decisions, large scale or special category processing, or profiling
  • Provide clear privacy notices explaining what data is collected, why AI is used, and how it affects individuals
  • Test AI systems regularly for bias or discriminatory outcomes and be able to explain AI driven decisions if challenged
  • Avoid using unlawfully obtained or scraped personal data for training AI without a valid legal basis, and anonymise or minimise training data where possible
  • Respect individuals' rights of access, correction, erasure, objection and human review in relation to AI processing
  • Consult the ODPA if a high risk to individuals remains after mitigation efforts following a DPIA
  • Apply security measures such as encryption and access controls, set data retention limits, and maintain a data breach management policy for AI systems
  • Keep records justifying the organisation's role, lawful basis, DPIA results, risk mitigations, testing and information given to individuals, and add AI use to the Record of Processing Activities
  • Regularly review AI related risks, monitor for model drift, update DPIAs for significant changes, and train staff on responsible AI use

Applies to

organisations using or deploying AI systems that process personal data, controllers, processors

Topics

Version history

2026-07-30

source file (current)