Notice
Determination - Failure by the Committee for Home Affairs to comply with Data Subject Access Request deadline (2026-04-14)
Issued 2026-04-14View on ODPA's website Source document
Summary
This is a published enforcement determination by the Guernsey Office of the Data Protection Authority (ODPA) against the Committee for Home Affairs, finding that it breached section 27 of the Data Protection (Bailiwick of Guernsey) Law, 2017 by failing to respond to a data subject access request (DSAR) within the statutory deadline. It sets out the facts of the case, the Authority's reasoning, and the sanction imposed.
- Background: A DSAR was submitted on 30 January 2025; Home Affairs extended the compliance period to 30 April 2025 but did not fully respond until 10 July 2025, with disclosures continuing well past the deadline.
- Breach found: Home Affairs breached section 27(1) of the Law by failing to comply with the request within the designated period (one month, extendable by up to two months for complexity), with the final disclosure made 71 days after the legal deadline.
- Authority's reasoning: The Authority did not accept staff shortages, personnel changes, or document volume as sufficient justification for the delay, though it noted these are relevant factors controllers must manage through business continuity measures.
- Remedial steps noted: Home Affairs has since introduced tailored data protection training on Subject Access Requests and developed a new Subject Access Request policy for the Family Proceedings Advisory Service.
- Sanction: The Authority issued a Reprimand to Home Affairs.
The determination serves as a reminder to public authorities and other data controllers under the Guernsey Data Protection Law that they must comply with DSARs within the one month designated period (or an extended period of up to two further months where properly notified), and that operational difficulties such as staffing issues do not excuse non-compliance.
Key obligations
- Controllers must comply with a data subject access request, and notify the requestor of action taken, as soon as practicable and in any event within the designated period of one month.
- Where an extension is applied due to complexity or volume of requests, the controller must notify the requestor within the designated period of the extension and the reasons for it, and the extension must not exceed a further two months.
- Controllers must put in place appropriate business continuity measures (e.g. covering staff shortages or personnel changes) to ensure ongoing compliance with data subject rights obligations.
Applies to
data controllers, public authorities (States of Guernsey Committees)
Deadlines
- one month following the relevant day: Statutory designated period within which a controller must comply with a data subject access request under section 27(1) of the Law.
- a further two months: Maximum extension a controller may apply to the designated period for a DSAR under section 27(4), with notification of the extension and reasons required within the original designated period.