Guernsey

data protection

116 Guernsey regulatory document(s) tagged data protection.

Practice-note overview · reflects instruments as at 2026-07-30. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

The principal instrument is the Data Protection (Bailiwick of Guernsey) Law, 2017, which the summaries describe as broadly equivalent to the GDPR and the EU Law Enforcement Directive. It governs any processing of personal data by automated means or held in a filing system, and reaches beyond the islands through an extra-territorial effect.

  • Establishment trigger: The Law applies where the controller or processor is established in the Bailiwick of Guernsey (Guernsey, Alderney or Sark).
  • Targeting trigger: It also applies where processing concerns a Bailiwick resident in connection with offering goods or services to, or monitoring the behaviour of, people in the Bailiwick.
  • Persons caught: Controllers, processors, joint controllers, secondary processors, data protection officers, Bailiwick representatives and monitoring bodies under codes of conduct.
  • Household exclusion: The Law does not apply to purely personal, family or household processing.

Established in the Bailiwick

ODPA guidance explains that a person is established under section 111 if it is a Guernsey, Alderney or Sark person, maintains an office, branch, agency or regular practice in the Bailiwick, causes processing equipment in the Bailiwick to be used (other than for transit), or carries on effective and real processing through stable arrangements there. Occasional, non-stable contact does not trigger the registration duty.

Sector-specific regimes

  • Law enforcement: The Data Protection (Law Enforcement and Related Matters) Ordinance, 2018 sets out a separate, tailored regime for personal data processed by competent authorities for law enforcement purposes, applying specified provisions of the Law with modifications.
  • Electronic communications: The European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 applies to providers of public electronic communications networks and services, and sits alongside rather than replacing the Law.

Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · Data Protection (Law Enforcement and Related Matters) (Bailiwick of Guernsey) Ordinance, 2018 · European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 · Established in the Bailiwick


Key duties

The recurring obligations centre on registration and annual levies, record-keeping, breach notification and responding to data subject requests, layered on top of the core data protection principles. The following duties carry the clearest deadlines or recurrence.

Registration and levies

  • Register annually: Controllers and processors established in the Bailiwick that process personal data (outside purely personal or household affairs) must register with the ODPA unless an exemption applies, and renew annually during January to February each year.
  • Pay the levy: ODPA registration guidance states annual levies of GBP 2,488.80 for organisations with 50 or more full-time-equivalent staff and GBP 62.22 for other organisations, with registered charities and not-for-profits paying nothing but still registering. The 2024 amending Regulations separately changed the scheduled fees and levies from 1 January 2025 and introduced an automatic RPIX inflation uplift for 2026 to 2028 (with no decrease where the index does not rise).
  • Levy Collection Agents: Smaller entities may pay through a Levy Collection Agent (only organisations registered with or regulated by the GFSC may act as one); the agent must issue a certificate of exemption within one month of paying the levy and keep records for six years. Entities with 50+ FTEs, those required to appoint a DPO, LCAs themselves, and charities/not-for-profits/elected officials must register directly.
  • Returns and changes: Registered controllers and processors must notify the Authority of changes to their register particulars; levy collection agents must make annual returns.

Records, governance and DPOs

  • Records of processing: Controllers and processors must keep records of processing activities and retain them for the periods specified in the Regulations, and cooperate with the Authority's information requests, inspections and audits.
  • Accountability: Controllers must implement appropriate technical and organisational measures and be able to demonstrate compliance with the data protection principles, applying data protection by design and by default under section 32.
  • DPO appointment: A DPO must be appointed by public authorities (except courts acting judicially), and by controllers or processors whose core activities involve large-scale systematic monitoring or large-scale processing of special category or criminal data. The organisation must notify the ODPA of the DPO's name and contact details and publish them.
  • Processor contracts: Controllers must obtain sufficient guarantees of appropriate measures and put a compliant written contract in place before a processor processes personal data, covering the matters and processor duties in sections 35 and 36.

Breaches, DPIAs and requests

  • Breach notification: Controllers must take reasonable steps to secure personal data, notify the Authority of personal data breaches and keep records, and notify affected data subjects where there is high risk to their significant interests. The ODPA's AI guidance states breaches risking individuals' significant interests must be notified within 72 hours of becoming aware.
  • Impact assessments: A data protection impact assessment is required for high-risk processing, with prior consultation with the Authority where required.
  • Access requests: Controllers must respond to a data subject access request within one calendar month of receipt or identity verification, extendable where the request is complex, notifying the requestor of any extension and its reasons.
  • Collection notices: Controllers must give individuals the prescribed information at the point of collection through a clear privacy or data processing notice.
  • Lawful basis: Controllers must identify and document a lawful processing condition before processing begins, with a stricter list for special category data.

International transfers

Transfers of personal data to unauthorised jurisdictions are prohibited unless made under approved safeguards (such as standard contractual clauses), binding corporate rules, or specific authorisation from the Authority.

Electronic communications providers

Under the 2004 Privacy Directive Ordinance, providers of public electronic communications services face additional duties, including taking technical and organisational security measures and informing subscribers of significant residual risks, restricting use of traffic and location data, obtaining consent before storing or accessing information on terminal equipment, and complying with rules on line identification, directories and direct marketing.

Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018 · Data Protection (General Provisions) (Bailiwick of Guernsey) (Amendment) Regulations, 2024 · European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 · Artificial Intelligence Guidance · Data Sharing - A Simple Guide · Data protection by design and default · Data Protection Officers (DPOs) · Data Subject Access Request Guide for Controllers · Engaging processors · Contracts between Controllers and Processors · Everything You Need to Know About ODPA Registration and Levy · Established in the Bailiwick · Guidance for Administrators and Administered Entities · Controller Self-Assessment Guidance · DSAR Guidance Tool – User Guide (DPO to DPO)


Exemptions and carve-outs

The instruments provide both a broad structural carve-out and narrower operational exemptions from particular duties and rights.

  • Personal or household use: The Law does not apply to processing for purely personal, family or household purposes.
  • Registration - occasional processing: A controller or processor whose processing in the Bailiwick is only occasional (for example an out-of-jurisdiction consultant making occasional client visits) need not register, under regulation B1 introduced by the 2020 amendment. The general registration Regulations also exempt occasional, non-large-scale, non-high-risk processing and exempt small entities using a levy collection agent.
  • No-levy categories: Registered charities and not-for-profit organisations (and States of Guernsey Deputies) must still register but pay no levy.
  • Schedule 8 exemptions: Schedule 8 of the Law provides exemptions allowing controllers to limit or withhold information otherwise owed to individuals, grouped into exemptions based on the nature of the data, prejudice-based exemptions, and wider public-interest exemptions. They must be applied narrowly and case by case, never as a blanket policy, and documented; most are optional, but paragraph 16A (disclosures prohibited or restricted by enactments) and paragraph 16D (serious harm to data subjects or others) must be applied when their circumstances arise.
  • Exam marking data: For subject access requests about exam marking data received before results are published, an altered response timescale applies rather than full exemption.
  • Transitional relief: The 2018 Commencement Ordinance temporarily excused controllers and processors from certain notification, joint-controller, impact assessment and processor-related duties for continuing lawful processing, and delayed the right to data portability until the transition date, while breach reporting still applied.
  • Corporate subscribers - marketing: Under the direct marketing guidance, corporate subscribers are exempt from the electronic mail consent rules, though individual data within business marketing still engages the Law.

Exemptions under the Law Enforcement Ordinance differ from those under the Law; for law enforcement processing, controllers are directed to section 19 and Schedule 3 of that Ordinance. The general Regulations also add further exemptions to Schedule 8 and disapply certain provisions for specified education, health and social assistance disclosures, subject to a vital-interest safeguard.

Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · Data Protection (Commencement, Amendment and Transitional) (Bailiwick of Guernsey) Ordinance, 2018 · Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018 · Direct Marketing - A Guide for Organisations · Exemptions · Exemptions Outlined in Schedule 8 of the Data Protection (Bailiwick of Guernsey) Law, 2017 - Technical Guidance · Everything You Need to Know About ODPA Registration and Levy · Established in the Bailiwick


Enforcement and penalties

Enforcement and sanction powers sit primarily with the Data Protection Authority under the Law.

  • Authority powers: Under Part XII the Authority can investigate complaints, conduct inquiries, make breach determinations, issue enforcement orders and impose administrative fines subject to statutory limits.
  • Criminal offences: Parts XIII to XV create criminal offences (such as unlawful obtaining or disclosure of personal data, obstruction and impersonation) and allow civil actions and appeals related to breaches of statutory duty.
  • Registration failures: ODPA guidance states that failing to register when required is a criminal offence and that unpaid levies may be recovered as a civil debt.
  • Statutory audits: The Authority may conduct a data protection audit of a controller or processor under schedule 7, paragraph 9, generally following a formal investigation.
  • Electronic communications: Certain enforcement and compensation provisions of the Law are extended to breaches of the 2004 Privacy Directive Ordinance, including a route for persons to ask the Authority to exercise its enforcement functions and provisions for compensation claims.

The summaries confirm that administrative fines are subject to statutory limits but do not state specific maximum fine amounts, so those figures are not reproduced here.

Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 · Data Audits · Guidance for Administrators and Administered Entities

Documents

CitationRegulatorType
Accountability and GovernanceODPAStatement of Guidance
Appointing a Processor Operating Exclusively in the Bailiwick of GuernseyODPAStatement of Guidance
Artificial Intelligence GuidanceODPAStatement of Guidance
Bailiwick Data Protection Advisory (2025-03-03)ODPAAdvisory
Bailiwick Data Protection Advisory (2025-08-27)ODPAAdvisory
Bailiwick Data Protection Advisory - Data Scraping (2025-01-31)ODPAAdvisory
Bailiwick of Guernsey Addendum to the EU Standard Contractual ClausesODPAForm
CCTV GuidanceODPAStatement of Guidance
Cloud ComputingODPAStatement of Guidance
Committee for Health & Social Care Reprimanded (2025-05-08)ODPANotice
Committee for Health & Social Care sanctioned for systemic issues handling Data Subject Access Requests (2026-06-26)ODPANotice
Conditions for Lawful Processing (Data Protection (Bailiwick of Guernsey) Law, 2017)ODPAStatement of Guidance
ConsentODPAStatement of Guidance
Consent GuidanceODPAStatement of Guidance
Contracts between Controllers and ProcessorsODPAStatement of Guidance
Controller Self-Assessment GuidanceODPAStatement of Guidance
Controller Self-Assessment Questionnaire (Electronic)ODPAForm
Controller, Joint Controller, Processor or Secondary Processor?ODPAStatement of Guidance
Controllers' Self-Assessment Questionnaire (SA-1)ODPAForm
Crown Dependency Data Protection Advisory: generative AI image creation (2026-02-23)ODPAAdvisory
Cyber security checklistODPAStatement of Guidance
DPIAODPAStatement of Guidance
DPIA TemplateODPAForm
DSAR Guidance Tool – User Guide (DPO to DPO)ODPAStatement of Guidance
DSAR Manager (Tool)ODPAForm
Data AuditsODPAStatement of Guidance
Data Collection: a simple guideODPAStatement of Guidance
Data EthicsODPAStatement of Guidance
Data Inventory - Useful Header Suggestions (Template)ODPAForm
Data Processing or Privacy NoticesODPAStatement of Guidance
Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text)GFSCAct
Data Protection (Commencement, Amendment and Transitional) (Bailiwick of Guernsey) Ordinance, 2018ODPAAct
Data Protection (General Provisions) (Bailiwick of Guernsey) (Amendment) Regulations, 2024ODPARegulation
Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018ODPARegulation
Data Protection (International Cooperation and Assistance) (Bailiwick of Guernsey) Regulations, 2018ODPARegulation
Data Protection (Law Enforcement and Related Matters) (Bailiwick of Guernsey) Ordinance, 2018ODPAAct
Data Protection (Transfer in the Substantial Public Interest) Order, 2002 (Consolidated)GFSCRegulation
Data Protection Authority opens Inquiry into data breach at the Director of the Revenue Service (2024-04-29)ODPANotice
Data Protection Officers (DPOs)ODPAStatement of Guidance
Data Security - A Thematic Report on Practices within the Fiduciary Sector (2014-04)GFSCAdvisory
Data Sharing - A Simple GuideODPAStatement of Guidance
Data Subject Access Request Guide for ControllersODPAStatement of Guidance
Data Subject Access RequestsODPAStatement of Guidance
Data protection by design and defaultODPAStatement of Guidance
Data protection in employmentODPAStatement of Guidance
Data sharingODPAStatement of Guidance
Determination - Committee for Health & Social Care sanctioned for systemic issues handling Data Subject Access Requests (2026-06-26)ODPANotice
Determination - Enforcement Order issued to Watches of Switzerland Company Limited (2025-08-20)ODPANotice
Determination - Failure by the Committee for Home Affairs to comply with Data Subject Access Request deadline (2026-04-14)ODPANotice
Determination - Jacksons fined £65,000 for unlawfully changing customer marketing preferences (2025-09-25)ODPANotice
Determination - ODPA partially upholds complaint against States of Alderney by former Chief Executive (2025-11-26)ODPANotice
Determination - ODPA sanctions First Contact Health for phishing attack breach (2026-02-12)ODPANotice
Determination - ODPA sanctions Fresh Dental for phishing attack breach (2025-12-11)ODPANotice
Determination - The Medical Specialist Group fined £100,000 following cyber-attack breach (2025-10-20)ODPANotice
Direct MarketingODPAStatement of Guidance
Direct Marketing - A Guide for OrganisationsODPAStatement of Guidance
Enforcement Order issued to Guernsey Union D'Escrime LBG over failures in processing of personal data (2023-12-08)ODPANotice
Enforcement Order issued to The Committee for Health and Social Care over data protection training and governance (2023-02-23)ODPANotice
Enforcement Order issued to Watches of Switzerland Company Limited (2025-08-20)ODPANotice
Engaging processorsODPAStatement of Guidance
Established in the BailiwickODPAStatement of Guidance
European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004ODPAAct
Everything You Need to Know About ODPA Registration and LevyODPAStatement of Guidance
ExemptionsODPAStatement of Guidance
Exemptions Outlined in Schedule 8 of the Data Protection (Bailiwick of Guernsey) Law, 2017 - Technical GuidanceODPAStatement of Guidance
Failure by the Committee for Home Affairs to comply with Data Subject Access Request deadline (2026-04-14)ODPANotice
Following ODPA investigation into IT outage, SoG confirms completion of recommendations (2025-02-12)ODPANotice
Guidance for Administrators and Administered EntitiesODPAStatement of Guidance
Guidance for CCTV UsersODPAStatement of Guidance
Guidance on International Data TransfersODPAStatement of Guidance
Guidance on registrationODPAStatement of Guidance
HSC ordered to improve its access request response (2024-11-22)ODPANotice
HSC reprimanded for delayed breach notification (2024-07-04)ODPANotice
Handling Data BreachesODPAStatement of Guidance
How to link a DPIA to the data protection principlesODPAStatement of Guidance
Information Sharing in Health Emergencies at WorkODPAStatement of Guidance
Information sharing in health emergencies at workODPAStatement of Guidance
Information to be Given (Privacy Notice Guidance)ODPAStatement of Guidance
Investigation ProcessODPAProcedure
Investigation Report issued to family after ODPA serves Enforcement Order (2023-12-15)ODPANotice
Jacksons fined £65,000 for unlawfully changing customer marketing preferences (2025-09-25)ODPANotice
Joint Statement on Privacy Risks of AI-Generated Imagery (2026-02-23)ODPAAdvisory
LCA Certificate of Exemption (Template)ODPAForm
Law Enforcement OrdinanceODPAStatement of Guidance
Lawful processing conditions for personal dataODPAStatement of Guidance
Lawful processing conditions for special category dataODPAStatement of Guidance
Levy Collection Agents GuidanceODPAStatement of Guidance
Managing Personal Data BreachesODPAStatement of Guidance
Medical Specialist Group issued with an Enforcement Order for failings identified in processing agreement (2024-10-31)ODPANotice
ODPA launch inquiry into States IT outages (2023-10-06)ODPANotice
ODPA partially upholds complaint against States of Alderney by former Chief Executive (2025-11-26)ODPANotice
ODPA sanctions First Contact Health for phishing attack breach (2026-02-12)ODPANotice
ODPA sanctions Fresh Dental for phishing attack breach (2025-12-11)ODPANotice
ODPA successful in Petty Debts (2024-02-08)ODPANotice
Overview: Appointment of ProcessorsODPAStatement of Guidance
Policy & Resources ordered to release employment reference (2024-04-12)ODPANotice
Processor AssessmentsODPAStatement of Guidance
Processor Self-Assessment GuidanceODPAStatement of Guidance
Processor Self-Assessment Questionnaire (SA-2)ODPAForm
Processors' Self-Assessment Questionnaire (SA-2)ODPAForm
Protect against phishingODPAStatement of Guidance
Registration guidance for private landlordsODPAStatement of Guidance
Registration guidance for sole traders and small businessesODPAStatement of Guidance
Reprimand issued to Beauvoir Limited regarding steps to protect outgoing mail (2025-01-20)ODPANotice
Revenue Service reprimanded following breach of financial information (2024-12-16)ODPANotice
Section 16 (other individuals' data)ODPAStatement of Guidance
Section 16 GuidanceODPAStatement of Guidance
Statutory referrals to the ODPAODPAStatement of Guidance
Subject Access Request Guide for Data SubjectsODPAStatement of Guidance
TemplatesODPAStatement of Guidance
Ten-step Practical AI GuidanceODPAStatement of Guidance
The Ladies' College ordered to improve security measures following breach (2025-12-04)ODPANotice
The Medical Specialist Group fined £100,000 following cyber-attack breach (2025-10-20)ODPANotice
The Seven Data Protection PrinciplesODPAStatement of Guidance
Transfer Impact AssessmentsODPAStatement of Guidance
Transferring people's data outside the BailiwickODPAStatement of Guidance