Notice
Reprimand issued to Beauvoir Limited regarding steps to protect outgoing mail (2025-01-20)
Issued 2025-01-20View on ODPA's website Source document
Summary
This is a public statement issued by the Guernsey Office of the Data Protection Authority (ODPA) reprimanding Beauvoir Limited for failing to take reasonable steps to secure sensitive personal data sent by ordinary post. The documents, which included notarised identification and financial information, went missing in transit, and Beauvoir had no tracking or recorded delivery in place and delayed notifying the individual for a month without reporting a breach to the Authority.
- Breach found: Beauvoir breached section 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017 by failing to take reasonable steps to ensure security appropriate to the sensitive personal data being sent.
- Sanction: The Authority issued a reprimand to Beauvoir under section 73 of the Law; no other sanction was applied given Beauvoir's remedial action.
- Remedial action: Beauvoir has since introduced an outgoing mail policy requiring client data and due diligence documents to be sent by recorded delivery or courier.
- Broader guidance: The Authority reiterates that controllers must implement security measures proportionate to the sensitivity of data, and must be able to quickly identify and report breaches to limit harm to data subjects.
This is a case-specific enforcement notice rather than a rule of general application, but it signals the Authority's expectations for how controllers in Guernsey should handle sensitive personal data sent by post, including breach identification and reporting timeliness.
Key obligations
- Controllers and processors must take reasonable steps to ensure a level of security appropriate to personal data, considering the nature, scope, context and purpose of processing, the likelihood and severity of risk to data subjects, best practices, and the cost of implementing measures (section 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017).
- Controllers should use tracking or recorded delivery (rather than ordinary mail) when sending sensitive personal or financial documentation by post.
- Controllers must be able to promptly identify when a data breach has occurred and notify affected data subjects in a timely manner to limit potential harm.
- A controller wishing to appeal an Authority determination must lodge the appeal with the Court within 28 days of receiving the determination (section 84 of the Law).
Applies to
controllers, processors, data controllers handling sensitive personal data
Deadlines
- 28 days from the date the controller receives the Authority's determination: Deadline for a controller to appeal an Authority determination to the Court under section 84 of the Law.