Agreement
2020 MoU between the Jersey Data Protection Authority and the Guernsey Office of the Data Protection Authority
Status not confirmedView on JOIC's website Source document
Summary
This is a bilateral Memorandum of Understanding between the Jersey Data Protection Authority (JDPA/JOIC) and the Guernsey Office of the Data Protection Authority (GDPA), setting out a non-binding framework for cooperation, information sharing and cross-border investigation coordination between the two regulators. It does not create enforceable rights and does not impose direct obligations on businesses or individuals; it governs how the two Authorities work with each other.
- Liaison: Commissioners agree to meet at least bi-annually and rotate hosting between offices to discuss matters of mutual interest.
- Information sharing: Both Authorities intend to share information on public attitude research, enforcement trends, audits, policy issues, security problems and law reform developments, subject to confidentiality requirements.
- Cross-border investigations: The Authorities will consult before transferring complaints, may conduct parallel or joint investigations, and will keep each other updated on investigations of mutual interest.
- Requests for assistance: Each Authority will use best endeavours to respond to requests for assistance, which must include sufficient information and a stated purpose; assistance may be declined at the Receiving Authority's discretion.
- Confidentiality and data handling: Shared information must be appropriately classified, not disclosed to third parties without consultation, retained no longer than necessary, and securely disposed of once no longer needed.
- Enforcement announcements: Where either Authority takes enforcement action, it will endeavour to give the other at least 24 hours' notice before publishing a related press release or public statement.
- Termination and review: Either Authority may terminate the MoU on 30 days' written notice; confidentiality and retention/disposal obligations survive termination.
Because this is an inter-regulatory cooperation agreement rather than legislation or a rule, it creates no compliance obligations for data controllers, processors or other regulated entities in Jersey or Guernsey.
Key obligations
- The Authorities will notify each other without delay if information shared under the MoU is found to be inaccurate, incomplete or out of date.
- A party receiving confidential information must consult the originating Authority before passing it to a third party or using it in enforcement or court proceedings.
- Information provided under the MoU must not be retained longer than necessary and must be securely disposed of once no longer required.
- Either Authority intends to give the other at least 24 hours' notice before publishing press releases or public statements on enforcement matters affecting the other's interest.
- Either Authority may terminate the MoU by giving 30 days' advance written notice to the other.
Deadlines
- 30 days' advance written notice: Notice period required for either Authority to terminate the MoU.
- no later than 24 hours prior to publication: Notice the Authorities will endeavour to give each other before publishing enforcement-related press releases or public statements, unless overriding reasons prevent it.
- bi-annually: Initial frequency for meetings between the Commissioners.
- once both Authorities have signed it: The MoU takes effect upon signature by both Authorities (exact signature dates in the source are illegible).
Topics
Version history
2026-07-30