Notice

Revenue Service reprimanded following breach of financial information (2024-12-16)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Issued 2024-12-16

Current version last checked: 2026-07-30

Summary

This is a public statement issued by the Guernsey Data Protection Authority (ODPA) under section 64 of the Data Protection (Bailiwick of Guernsey) Law, 2017. It records that the Authority investigated the Revenue Service following a personal data breach (an email containing financial information sent to the wrong recipient) and issued a reprimand after finding the Revenue Service failed to maintain appropriate security safeguards.

  • What went wrong: Revenue Service policy required emails with personal data to be sent via a specialised secure platform, and an enhanced version was meant to enforce this via a pop up prompt, but in this case neither the policy nor the enhanced version was applied.
  • Prior warning signs: A similar breach in 2022 had already revealed that some employee accounts lacked the enhanced platform configuration, and further internal breach logs between July 2022 and April 2024 showed ongoing non compliance with the policy.
  • Legal basis for breach finding: The Authority found breaches of section 6 (integrity and confidentiality principle) and section 41 (appropriate security safeguards) of the Law.
  • Sanction imposed: A reprimand was issued against the Revenue Service under section 73 of the Law; no fine is mentioned.
  • Remedial action taken: The Revenue Service has since implemented measures to automatically route all emails with attachments through the secure platform and ensured the enhanced version is installed on employee computers.

The statement is primarily informational, documenting the outcome of a completed inquiry, but it restates general statutory obligations on controllers and processors regarding data security, and notes the standard right of appeal against Authority determinations.

Key obligations

  • Controllers and processors must take reasonable steps to ensure a level of security appropriate to the personal data they process, per section 41 of the Law.
  • Controllers and processors must process personal data in a manner ensuring appropriate security, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage, per section 6 of the Law.
  • A controller or processor wishing to appeal an Authority determination must do so within 28 days of the issuance of the determination, per section 84 of the Law.
  • Organisations should ensure security policies are actively followed, monitored and updated, and supplement organisational policies with technical measures to reduce reliance on human compliance.

Applies to

controllers, processors, the Revenue Service, public bodies handling personal data

Deadlines

  • 28 days of the issuance of the determination: Deadline for a controller or processor to appeal an Authority determination to the Court under section 84 of the Law.

Topics

Version history

2026-07-30

source file (current)