Advisory
Key findings from a Virtual Compliance Audit 2023/4 (2024-12-01)
Issued 2024-12-01View on JOIC's website Source document
Summary
This is a JOIC advisory report summarising key findings from a virtual compliance audit of health sector controllers who process significant volumes of special category personal data. It is not a formal enforcement notice but sets out good practice, areas for improvement, and best-practice recommendations that the regulator expects controllers generally to apply under the Data Protection (Jersey) Law 2018 (DPJL 2018).
- Audit scope: Assessed compliance risk across seven areas: data protection governance, staff training and awareness, records management, security of personal data, data subject requests, data sharing, and risk assessment/DPIAs.
- Good practice found: All audited entities had privacy policies, retention schedules, acceptable use policies, breach logs, and SAR processes in place; induction training was provided and most gave refresher training every 6 to 12 months.
- Areas for improvement: Restricting access to sensitive data to those who need it; increasing training frequency where risk warrants; correcting policies that wrongly reference GDPR or UK law instead of DPJL 2018 or misidentify controllers/processors; and tightening use of social media communication channels.
- Best practice recommendations: Role-specific, tailored training before system access is granted and at least yearly thereafter, covering local law, special category data handling, data sharing, and retention/destruction; policies and procedures must be effectively communicated and their real-world adherence checked; confidentiality measures (office layout, privacy screens, reception/building access) should be reviewed.
Next steps involved direct feedback to each audited organisation, with only one entity required to formally confirm remedial action to the Authority. The report is intended to guide other controllers, particularly in the health sector, in strengthening their own data protection compliance.
Key obligations
- Organisations should provide role-specific data protection training to new employees before granting system access and at least yearly thereafter, covering local legislation, special category data, data sharing, and retention/destruction.
- Organisations should restrict access to sensitive personal data to only those staff who need it.
- Privacy policies and retention policies should correctly reference DPJL 2018 (not GDPR or UK regulations) and correctly identify the organisation, not individuals, as the data controller.
- Organisations should review and formalise policies governing which communication/social media channels may be used for staff and data subject communications.
- Organisations should evaluate confidentiality measures such as office layout, privacy screens, and building/reception access controls.
- Organisations should ensure staff are aware of data protection policies and procedures and verify these are actually followed in practice.
- The one entity specifically identified was required to respond directly to JOIC confirming remedial action had been taken.
Applies to
health service sector controllers processing special category personal data, data controllers generally under the Data Protection (Jersey) Law 2018
Deadlines
- at least yearly: Recommended minimum frequency for refresher data protection training for staff
- twice per annum: Increased training frequency advised for one specific audited entity given the risk of the data it processes