Advisory
Key findings from a Virtual Compliance Audit 2024-2025 (2025-03-21)
Issued 2025-03-21View on JOIC's website Source document
Summary
This advisory publishes the key findings from JOIC's virtual compliance audit of health service sector controllers who process significant volumes of special category personal data. It does not name the audited organisations but sets out sector-wide good practice and areas for improvement identified against seven risk areas under the Data Protection (Jersey) Law 2018 (DPJL 2018).
- Audit scope: Seven focus areas assessed: data protection governance, training and awareness, records management, security of personal data, data subject requests, data sharing, and risk assessment/DPIAs.
- Good practice found: Correct use of lawful bases (including appropriate reliance on consent), confident storage limitation and retention practices, and good information security and data management systems.
- Areas for improvement: Generic (non-role-specific) staff training, policies referencing outdated or wrong law (GDPR, UK regulations, or the 2005 Law instead of DPJL 2018), missing privacy policies, breach logs and retention schedules, and confusion or lack of awareness around data sharing protocols and agreements.
- Recommended best practice: Tailor training to specific roles, provide it before system access and at least annually thereafter (covering local law, special category data, sharing, retention/destruction, and confidentiality), maintain proportionate policies and procedures that are communicated and checked for adherence, and review office layout/confidentiality controls.
Some audited entities were required to respond directly to JOIC confirming that remedial action had been taken, and JOIC states it continues to work with one entity. The document is framed as general guidance for the wider sector rather than a formal enforcement notice against named parties.
Key obligations
- Entities found lacking appropriate data protection policies and procedures (e.g. privacy policy, breach log, retention schedule) were tasked with completing these to a satisfactory standard
- Some audited entities were required to respond directly to JOIC to confirm that remedial action had taken place
- Organisations should ensure privacy and retention policies reference the correct current law (DPJL 2018) rather than GDPR, UK regulations or the 2005 Law
- Data sharing agreements must be reviewed to avoid risk of damage or distress to individuals, regulatory action and reputational damage
- Training should be tailored to specific roles, provided before new employees are given system access, and repeated at least annually, covering local legislation, special category data handling, data sharing, and retention/destruction
Applies to
health service sector controllers, data controllers processing special category personal data
Deadlines
- at least annually: Recommended frequency for refresher data protection training after initial training for new employees