Notice

Failure by the Committee for Home Affairs to comply with Data Subject Access Request deadline (2026-04-14)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Issued 2026-04-14

Current version last checked: 2026-07-30

Summary

This is a public enforcement statement from the Guernsey Office of the Data Protection Authority (ODPA) detailing a reprimand issued to the Committee for Home Affairs (CfHA) for failing to respond to a Data Subject Access Request within the statutory deadline required by the Data Protection (Bailiwick of Guernsey) Law, 2017.

  • What happened: CfHA missed its (already extended) statutory deadline for responding to a Data Subject Access Request, with final disclosures made 71 days late, and additional overlooked personal data disclosed just over two months after the deadline.
  • Cause: CfHA cited workload, staff shortages and personnel changes; the Authority found its search and collation processes were not sufficiently robust.
  • Breach found: CfHA contravened section 27 of the Law (compliance with requests to exercise data subject rights) by missing the deadline and by failing to run comprehensive searches.
  • Outcome: The Authority issued CfHA with a reprimand; CfHA has since introduced tailored data protection training and a new Subject Access Request policy for its Family Proceedings Advisory Service.
  • Lesson for controllers: All controllers must respond to access requests fully and within the statutory timeframe, and maintain well documented, thorough search procedures covering all systems that may hold relevant personal data.

While this notice concerns a specific enforcement action against CfHA, it restates the general obligation on all controllers under section 27 of the Law to respond to subject access requests within the statutory timeframe using robust search processes.

Key obligations

  • Controllers must respond to Data Subject Access Requests within the statutory timeframe required by section 27 of the Data Protection (Bailiwick of Guernsey) Law, 2017, including any properly applied extension.
  • Controllers must ensure their internal search and collation processes are sufficiently comprehensive to identify all personal data within the scope of a request.
  • Controllers should maintain well documented procedures for searching for and disclosing personal data in response to access requests, covering all systems that may hold relevant information.

Applies to

data controllers, the Committee for Home Affairs

Topics

Version history

2026-07-30

source file (current)