Notice

Reprimand issued to Beauvoir Limited regarding steps to protect outgoing mail (2025-01-20)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Issued 2025-01-20

Current version last checked: 2026-07-30

Summary

This is a public statement issued by the Guernsey Office of the Data Protection Authority (ODPA) reprimanding Beauvoir Limited for failing to take reasonable steps to secure sensitive personal data sent by ordinary post. The documents, which included notarised identification and financial information, went missing in transit, and Beauvoir had no tracking or recorded delivery in place and delayed notifying the individual for a month without reporting a breach to the Authority.

  • Breach found: Beauvoir breached section 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017 by failing to take reasonable steps to ensure security appropriate to the sensitive personal data being sent.
  • Sanction: The Authority issued a reprimand to Beauvoir under section 73 of the Law; no other sanction was applied given Beauvoir's remedial action.
  • Remedial action: Beauvoir has since introduced an outgoing mail policy requiring client data and due diligence documents to be sent by recorded delivery or courier.
  • Broader guidance: The Authority reiterates that controllers must implement security measures proportionate to the sensitivity of data, and must be able to quickly identify and report breaches to limit harm to data subjects.

This is a case-specific enforcement notice rather than a rule of general application, but it signals the Authority's expectations for how controllers in Guernsey should handle sensitive personal data sent by post, including breach identification and reporting timeliness.

Key obligations

  • Controllers and processors must take reasonable steps to ensure a level of security appropriate to personal data, considering the nature, scope, context and purpose of processing, the likelihood and severity of risk to data subjects, best practices, and the cost of implementing measures (section 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017).
  • Controllers should use tracking or recorded delivery (rather than ordinary mail) when sending sensitive personal or financial documentation by post.
  • Controllers must be able to promptly identify when a data breach has occurred and notify affected data subjects in a timely manner to limit potential harm.
  • A controller wishing to appeal an Authority determination must lodge the appeal with the Court within 28 days of receiving the determination (section 84 of the Law).

Applies to

controllers, processors, data controllers handling sensitive personal data

Deadlines

  • 28 days from the date the controller receives the Authority's determination: Deadline for a controller to appeal an Authority determination to the Court under section 84 of the Law.

Topics

Version history

2026-07-30

source file (current)