Act

Data Protection (Jersey) Law 2018

Jersey Office of the Information Commissioner (JOIC) · Jersey

In force

Status per the Jersey Revised Edition (jerseylaw.je) (as at 2026-09-01)

Chapter 15.240 of the Revised Edition

Current version last checked: 2026-09-10

Summary

This is Jersey's principal data protection statute, replacing the 2005 law and implementing GDPR-equivalent standards for the Island. It sets out the core rules for how personal data may be collected, used, secured and transferred, the rights individuals (data subjects) have over their data, and the powers of the Jersey Office of the Information Commissioner (Authority) to enforce compliance.

  • Core duties of controllers: Controllers must comply with the data protection principles, process data lawfully, fairly and transparently, provide required information to data subjects, and keep records of processing activities.
  • High risk processing: Controllers must carry out data protection impact assessments and, where required, consult the Authority before undertaking high risk processing.
  • Processors and security: Controllers must appoint processors under written contracts; both controllers and processors have joint security duties and must notify the Authority (and in some cases data subjects) of personal data breaches.
  • Data protection officers: Certain controllers and processors must appoint a data protection officer with defined independence, position and duties.
  • Data subject rights: The Law grants rights of access, rectification, erasure, restriction, data portability, objection to processing (including direct marketing), and rights relating to automated decision-making, and requires controllers to handle such requests within statutory procedures.
  • Cross-border transfers: Transfers of personal data outside Jersey are only permitted where adequate protection or appropriate safeguards (such as binding corporate rules) exist, subject to listed exceptions.
  • Exemptions: Specific exemptions apply for national security, crime and taxation, journalism, legal privilege, health and social work, and other listed purposes, which disapply certain transparency or subject-rights provisions.
  • Enforcement and offences: The Law creates civil remedies (including compensation claims), and criminal offences for unlawful obtaining of personal data, obstruction, and providing false information, alongside the Authority's supervisory and enforcement powers.

The Law applies broadly across the public and private sectors in Jersey to any controller or processor handling personal data, including public authorities, and includes schedules on lawful processing conditions, adequacy exceptions, binding corporate rules, and modifications for law enforcement processing. It has been amended multiple times since 2018, with the version shown current from 1 September 2026.

Key obligations

  • Controllers must comply with the data protection principles and demonstrate accountability for processing (Article 6, 8)
  • Controllers must process personal data lawfully, fairly and transparently and provide required information to data subjects (Articles 9-13)
  • Controllers must keep records of processing and comply with data protection by design and by default requirements (Articles 14-15)
  • Controllers must carry out data protection impact assessments for high risk processing and consult the Authority where required (Articles 16-18)
  • Controllers must appoint processors under a written contract meeting statutory requirements (Article 19)
  • Controllers and processors must notify the Authority of personal data breaches (Article 20)
  • Controllers and processors must implement appropriate security measures for personal data and processors must meet general processing obligations (Articles 21-23)
  • Certain controllers and processors must appoint a data protection officer with defined independence and duties (Articles 24-26)
  • Controllers must handle and respond to data subject rights requests (access, rectification, erasure, restriction, portability, objection, automated decision-making) in accordance with statutory procedures (Articles 27-38)
  • Cross-border transfers of personal data may only occur where adequate protection or appropriate safeguards exist, or an exception applies (Articles 66-67)

Applies to

controllers, processors, data protection officers, public authorities, scheduled public authorities, data subjects, credit reference agencies

Topics

Version history

2026-09-03

source file (current)

2026-07-30

source file