Statement of Guidance
The Seven Data Protection Principles
Status not confirmedView on ODPA's website Source document
Summary
This is general guidance from the Office of the Data Protection Authority (Guernsey) explaining the seven core data protection principles set out in the Data Protection (Bailiwick of Guernsey) Law, 2017. It applies to all local organisations that process personal data and explains, in plain terms, the standards they must meet. The guidance notes that the Law is principles based rather than rule based, so organisations must interpret and document how they apply each principle to their own processing activities.
- Lawfulness, Fairness and Transparency: Have a valid legal reason for processing personal data, obtain it without deception, and be clear about how it will be used.
- Purpose Limitation: Only use personal data for the reason(s) disclosed to the individual.
- Minimisation: Only collect the minimum amount of personal data necessary.
- Accuracy: Ensure personal data held is accurate and, where necessary, kept up to date.
- Storage Limitation: Do not retain personal data for longer than needed.
- Integrity and Confidentiality: Keep personal data secure against accidental loss, alteration, or unauthorised access.
- Accountability: Be able to evidence how responsibility is taken for handling people's data, underpinning the other six principles.
The guidance also flags that organisations processing personal data for law enforcement purposes under the Law Enforcement Ordinance are subject to a different set of data protection principles, found in sections 5 to 10 of that Ordinance, rather than these seven.
Key obligations
- Organisations must have a valid legal reason for processing personal data and must not obtain it deceptively, making clear to individuals how their data will be used
- Organisations must only use personal data for the purpose(s) disclosed to the individual
- Organisations must only collect the minimum amount of personal data necessary for the stated purpose
- Organisations must keep personal data accurate and up to date where necessary
- Organisations must not retain personal data longer than necessary
- Organisations must implement measures to keep personal data secure from accidental loss, alteration, or unauthorised access
- Organisations must be able to evidence their accountability for how they handle personal data
- Organisations processing personal data for law enforcement purposes must consult sections 5 to 10 of the Law Enforcement Ordinance instead of these seven principles
Applies to
local organisations processing personal data in the Bailiwick of Guernsey