Act
Data Protection (Jersey) Law 2018
In forceChapter 15.240 of the Revised Edition
View on JOIC's website Source document
Summary
This is Jersey's principal data protection statute, establishing a GDPR equivalent regime for the processing of personal data of natural persons in Jersey. It sets out the core principles controllers and processors must follow, creates rights for data subjects, and establishes the enforcement and remedies framework overseen by the Jersey Office of the Information Commissioner and the Data Protection Authority.
- Controller duties: Controllers must comply with data protection principles, establish a lawful basis for processing, ensure fair and transparent processing, obtain valid consent where relied upon, and provide required information to data subjects.
- Records and design: Controllers must keep records of processing, build in data protection by design and by default, and carry out data protection impact assessments and prior consultation with the Authority for high risk processing.
- Processors and security: Controllers must only appoint processors under appropriate contractual terms; controllers and processors share duties to secure personal data and notify the Authority of personal data breaches.
- Data protection officers: Certain controllers and processors must appoint a data protection officer with defined duties and independence protections.
- Data subject rights: Controllers must handle requests for access, rectification, erasure, restriction, portability, and objection to processing, including objections to direct marketing and automated decision-making.
- Cross-border transfers: Personal data may only be transferred outside Jersey where adequacy, appropriate safeguards, or a specified exception applies.
- Exemptions: The Law sets out numerous exemptions from transparency and subject rights provisions, including for national security, crime and taxation, corporate finance, trusts, legal privilege, and other listed purposes.
- Enforcement: The Law creates civil remedies (including compensation), criminal offences (such as unlawful obtaining of personal data, obstruction and providing false information), and enforcement mechanisms including codes of conduct and certification schemes.
The Law applies broadly across public and private sector bodies that determine or carry out the processing of personal data in or connected with Jersey, and has been amended multiple times since 2018, with the version described here consolidated and in force as at 1 April 2026.
Key obligations
- Controllers must comply with the data protection principles and be able to demonstrate accountability for that compliance
- Controllers must establish and document a lawful basis for all processing of personal data
- Controllers must provide data subjects with prescribed information about the processing of their personal data
- Controllers must keep records of processing activities as required by the Law
- Controllers must carry out a data protection impact assessment before undertaking high risk processing, and consult the Authority in advance where required
- Controllers must ensure any processor is appointed under a contract meeting the Law's requirements
- Controllers and processors must implement appropriate technical and organizational security measures for personal data
- Controllers must notify the Authority of personal data breaches as required under Article 20
- Specified controllers and processors must appoint a data protection officer with the functions set out in the Law
- Controllers must respond to and give effect to data subject rights requests, including access, rectification, erasure, restriction, portability and objection requests
- Controllers must not transfer personal data outside Jersey unless adequacy, appropriate safeguards, or a permitted exception applies
Applies to
controllers, processors, data protection officers, public authorities, scheduled public authorities