Guernsey
data protection
116 Guernsey regulatory document(s) tagged data protection.
Who is caught
The principal instrument is the Data Protection (Bailiwick of Guernsey) Law, 2017, which the summaries describe as broadly equivalent to the GDPR and the EU Law Enforcement Directive. It governs any processing of personal data by automated means or held in a filing system, and reaches beyond the islands through an extra-territorial effect.
- Establishment trigger: The Law applies where the controller or processor is established in the Bailiwick of Guernsey (Guernsey, Alderney or Sark).
- Targeting trigger: It also applies where processing concerns a Bailiwick resident in connection with offering goods or services to, or monitoring the behaviour of, people in the Bailiwick.
- Persons caught: Controllers, processors, joint controllers, secondary processors, data protection officers, Bailiwick representatives and monitoring bodies under codes of conduct.
- Household exclusion: The Law does not apply to purely personal, family or household processing.
Established in the Bailiwick
ODPA guidance explains that a person is established under section 111 if it is a Guernsey, Alderney or Sark person, maintains an office, branch, agency or regular practice in the Bailiwick, causes processing equipment in the Bailiwick to be used (other than for transit), or carries on effective and real processing through stable arrangements there. Occasional, non-stable contact does not trigger the registration duty.
Sector-specific regimes
- Law enforcement: The Data Protection (Law Enforcement and Related Matters) Ordinance, 2018 sets out a separate, tailored regime for personal data processed by competent authorities for law enforcement purposes, applying specified provisions of the Law with modifications.
- Electronic communications: The European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 applies to providers of public electronic communications networks and services, and sits alongside rather than replacing the Law.
Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · Data Protection (Law Enforcement and Related Matters) (Bailiwick of Guernsey) Ordinance, 2018 · European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 · Established in the Bailiwick
Key duties
The recurring obligations centre on registration and annual levies, record-keeping, breach notification and responding to data subject requests, layered on top of the core data protection principles. The following duties carry the clearest deadlines or recurrence.
Registration and levies
- Register annually: Controllers and processors established in the Bailiwick that process personal data (outside purely personal or household affairs) must register with the ODPA unless an exemption applies, and renew annually during January to February each year.
- Pay the levy: ODPA registration guidance states annual levies of GBP 2,488.80 for organisations with 50 or more full-time-equivalent staff and GBP 62.22 for other organisations, with registered charities and not-for-profits paying nothing but still registering. The 2024 amending Regulations separately changed the scheduled fees and levies from 1 January 2025 and introduced an automatic RPIX inflation uplift for 2026 to 2028 (with no decrease where the index does not rise).
- Levy Collection Agents: Smaller entities may pay through a Levy Collection Agent (only organisations registered with or regulated by the GFSC may act as one); the agent must issue a certificate of exemption within one month of paying the levy and keep records for six years. Entities with 50+ FTEs, those required to appoint a DPO, LCAs themselves, and charities/not-for-profits/elected officials must register directly.
- Returns and changes: Registered controllers and processors must notify the Authority of changes to their register particulars; levy collection agents must make annual returns.
Records, governance and DPOs
- Records of processing: Controllers and processors must keep records of processing activities and retain them for the periods specified in the Regulations, and cooperate with the Authority's information requests, inspections and audits.
- Accountability: Controllers must implement appropriate technical and organisational measures and be able to demonstrate compliance with the data protection principles, applying data protection by design and by default under section 32.
- DPO appointment: A DPO must be appointed by public authorities (except courts acting judicially), and by controllers or processors whose core activities involve large-scale systematic monitoring or large-scale processing of special category or criminal data. The organisation must notify the ODPA of the DPO's name and contact details and publish them.
- Processor contracts: Controllers must obtain sufficient guarantees of appropriate measures and put a compliant written contract in place before a processor processes personal data, covering the matters and processor duties in sections 35 and 36.
Breaches, DPIAs and requests
- Breach notification: Controllers must take reasonable steps to secure personal data, notify the Authority of personal data breaches and keep records, and notify affected data subjects where there is high risk to their significant interests. The ODPA's AI guidance states breaches risking individuals' significant interests must be notified within 72 hours of becoming aware.
- Impact assessments: A data protection impact assessment is required for high-risk processing, with prior consultation with the Authority where required.
- Access requests: Controllers must respond to a data subject access request within one calendar month of receipt or identity verification, extendable where the request is complex, notifying the requestor of any extension and its reasons.
- Collection notices: Controllers must give individuals the prescribed information at the point of collection through a clear privacy or data processing notice.
- Lawful basis: Controllers must identify and document a lawful processing condition before processing begins, with a stricter list for special category data.
International transfers
Transfers of personal data to unauthorised jurisdictions are prohibited unless made under approved safeguards (such as standard contractual clauses), binding corporate rules, or specific authorisation from the Authority.
Electronic communications providers
Under the 2004 Privacy Directive Ordinance, providers of public electronic communications services face additional duties, including taking technical and organisational security measures and informing subscribers of significant residual risks, restricting use of traffic and location data, obtaining consent before storing or accessing information on terminal equipment, and complying with rules on line identification, directories and direct marketing.
Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018 · Data Protection (General Provisions) (Bailiwick of Guernsey) (Amendment) Regulations, 2024 · European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 · Artificial Intelligence Guidance · Data Sharing - A Simple Guide · Data protection by design and default · Data Protection Officers (DPOs) · Data Subject Access Request Guide for Controllers · Engaging processors · Contracts between Controllers and Processors · Everything You Need to Know About ODPA Registration and Levy · Established in the Bailiwick · Guidance for Administrators and Administered Entities · Controller Self-Assessment Guidance · DSAR Guidance Tool – User Guide (DPO to DPO)
Exemptions and carve-outs
The instruments provide both a broad structural carve-out and narrower operational exemptions from particular duties and rights.
- Personal or household use: The Law does not apply to processing for purely personal, family or household purposes.
- Registration - occasional processing: A controller or processor whose processing in the Bailiwick is only occasional (for example an out-of-jurisdiction consultant making occasional client visits) need not register, under regulation B1 introduced by the 2020 amendment. The general registration Regulations also exempt occasional, non-large-scale, non-high-risk processing and exempt small entities using a levy collection agent.
- No-levy categories: Registered charities and not-for-profit organisations (and States of Guernsey Deputies) must still register but pay no levy.
- Schedule 8 exemptions: Schedule 8 of the Law provides exemptions allowing controllers to limit or withhold information otherwise owed to individuals, grouped into exemptions based on the nature of the data, prejudice-based exemptions, and wider public-interest exemptions. They must be applied narrowly and case by case, never as a blanket policy, and documented; most are optional, but paragraph 16A (disclosures prohibited or restricted by enactments) and paragraph 16D (serious harm to data subjects or others) must be applied when their circumstances arise.
- Exam marking data: For subject access requests about exam marking data received before results are published, an altered response timescale applies rather than full exemption.
- Transitional relief: The 2018 Commencement Ordinance temporarily excused controllers and processors from certain notification, joint-controller, impact assessment and processor-related duties for continuing lawful processing, and delayed the right to data portability until the transition date, while breach reporting still applied.
- Corporate subscribers - marketing: Under the direct marketing guidance, corporate subscribers are exempt from the electronic mail consent rules, though individual data within business marketing still engages the Law.
Exemptions under the Law Enforcement Ordinance differ from those under the Law; for law enforcement processing, controllers are directed to section 19 and Schedule 3 of that Ordinance. The general Regulations also add further exemptions to Schedule 8 and disapply certain provisions for specified education, health and social assistance disclosures, subject to a vital-interest safeguard.
Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · Data Protection (Commencement, Amendment and Transitional) (Bailiwick of Guernsey) Ordinance, 2018 · Data Protection (General Provisions) (Bailiwick of Guernsey) Regulations, 2018 · Direct Marketing - A Guide for Organisations · Exemptions · Exemptions Outlined in Schedule 8 of the Data Protection (Bailiwick of Guernsey) Law, 2017 - Technical Guidance · Everything You Need to Know About ODPA Registration and Levy · Established in the Bailiwick
Enforcement and penalties
Enforcement and sanction powers sit primarily with the Data Protection Authority under the Law.
- Authority powers: Under Part XII the Authority can investigate complaints, conduct inquiries, make breach determinations, issue enforcement orders and impose administrative fines subject to statutory limits.
- Criminal offences: Parts XIII to XV create criminal offences (such as unlawful obtaining or disclosure of personal data, obstruction and impersonation) and allow civil actions and appeals related to breaches of statutory duty.
- Registration failures: ODPA guidance states that failing to register when required is a criminal offence and that unpaid levies may be recovered as a civil debt.
- Statutory audits: The Authority may conduct a data protection audit of a controller or processor under schedule 7, paragraph 9, generally following a formal investigation.
- Electronic communications: Certain enforcement and compensation provisions of the Law are extended to breaches of the 2004 Privacy Directive Ordinance, including a route for persons to ask the Authority to exercise its enforcement functions and provisions for compensation claims.
The summaries confirm that administrative fines are subject to statutory limits but do not state specific maximum fine amounts, so those figures are not reproduced here.
Sources: Data Protection (Bailiwick of Guernsey) Law, 2017 (Consolidated text) · European Communities (Implementation of Privacy Directive) (Guernsey) Ordinance, 2004 · Data Audits · Guidance for Administrators and Administered Entities