Statement of Guidance
Transfer Impact Assessments
Status not confirmedView on ODPA's website Source document
Summary
This is ODPA (Guernsey) guidance setting out a self-assessment tool and methodology for carrying out a Transfer Impact Assessment (TIA) before transferring personal data outside the Bailiwick of Guernsey. It reflects the CJEU's Schrems II judgment and explains how controllers and processors should verify that data transferred to third countries continues to receive essentially equivalent protection to that under the Data Protection (Bailiwick of Guernsey) Law, 2017.
- Part 1 self-assessment tool: Seven questions to document before any international transfer: applicable law(s), transfer details, transfer tool used, laws/practices of the destination country, needed supplementary measures, formal steps to implement them, and timing for re-evaluation.
- Part 2 step-by-step process: Section 1 identify applicable law(s); Section 2 map and understand your transfers and confirm your and the recipient's roles; Section 3 verify the transfer tool relied on (adequacy decision, listed transfer tool, or exception); Section 4 assess third-country laws and practices against Article 23(1) GDPR grounds and using specified reliable, verifiable sources; Section 5 identify and adopt supplementary measures if gaps are found; Section 6 take any formal procedural steps required (e.g. Authority approval for binding corporate rules); Section 7 periodically re-evaluate the level of protection and monitor for relevant developments.
- When a transfer is problematic: If third-country legislation is not applied in practice, or incompatible practices exist without governing legislation, the transfer must be suspended or supplementary measures implemented; where the position is uncertain, the exporter may suspend, implement measures, or proceed only if it can demonstrate and document no reasonable belief that problematic legislation applies.
Throughout the process, the guidance stresses that exporters must document their assessment at each stage and that the Authority will take action to ensure controllers and processors comply with their ongoing obligations under Part X of the Law.
Key obligations
- Before transferring personal data outside the Bailiwick, controllers/processors must complete and document a Transfer Impact Assessment covering the seven prescribed questions.
- Exporters must verify which data protection law(s) they are subject to and confirm the capacity (controller, joint controller or processor) of both parties before transferring data.
- Exporters must verify and rely on a valid transfer tool (adequacy decision, a transfer tool listed under the Law, or a permitted exception) before transferring data.
- Exporters must assess the laws and practices of the destination country for compatibility with the transfer tool's safeguards, using relevant, objective, reliable, verifiable and preferably publicly available sources, engaging the data importer in the assessment.
- Where third-country laws or practices impinge on the effectiveness of the transfer tool, the exporter must identify and adopt supplementary measures, or suspend the transfer if no effective measures can be found.
- Where formal procedural steps are required for the chosen supplementary measure or transfer tool (e.g. binding corporate rules), the exporter must seek prior approval from the Bailiwick of Guernsey's Data Protection Authority under Section 58 of the Law.
- Exporters must periodically re-evaluate the level of protection afforded to transferred personal data and monitor for developments that could affect it.
- Exporters must document their assessment and conclusions at each stage of the Transfer Impact Assessment process.
Applies to
controllers, joint controllers, processors, data exporters transferring personal data outside the Bailiwick of Guernsey