Agreement
2023 MoU between the Jersey Data Protection Authority/Information Commissioner and the Office of the Children's Commissioner for Jersey
Status not confirmedView on JOIC's website Source document
Summary
This is a Memorandum of Understanding between the Jersey Data Protection Authority/Information Commissioner (JDPA/JOIC) and the Office of the Children's Commissioner for Jersey (CCJ), setting out a framework for cooperation and information sharing between the two bodies. It is expressly a non-binding statement of intent rather than a legally enforceable agreement, and does not impose obligations on regulated businesses or the public.
- Purpose: Establishes principles for the two regulators to alert each other to potential breaches or matters within the other's remit and to share relevant supporting information discovered while carrying out their respective statutory functions.
- Legal basis for sharing: Sets out the statutory gateways each party may rely on to share information (e.g. Schedule 2 Part 2 para 13 of the DPJL 2018 for CCJ disclosures to JDPA, and Article 8 of the DPAJL 2018 for JDPA disclosures to CCJ), while leaving each party responsible for assessing lawfulness of any specific disclosure.
- No compulsion to share: Neither party is required to disclose information where doing so would breach statutory responsibilities, and either party may decline or limit cooperation at its discretion.
- Confidentiality and breach handling: Shared information must be marked appropriately, protected with agreed security measures, and any wrongful disclosure or demand for disclosure must be notified to the sending party where practicable.
- Retention: Information shared under the MoU must not be retained longer than necessary and must be securely disposed of once no longer required.
- Governance: The MoU takes effect once both parties sign, can be terminated by 30 days' written notice, may only be amended by mutual agreement, and creates no enforceable rights.
Because this MoU governs inter-regulator cooperation rather than regulated entities' conduct, it does not create compliance duties for businesses or individuals; its provisions bind only the JDPA/JOIC and the Children's Commissioner in how they liaise and exchange information.
Key obligations
- JDPA and CCJ will alert each other, at their discretion, to potential breaches or matters within the other's remit discovered during regulatory duties
- Each party must ensure any disclosure of personal data under the MoU complies with the DPJL 2018 and relevant confidentiality laws
- Receiving party must mark and protect shared non-public information according to agreed security classifications
- Receiving party must notify the sending party of any legally enforceable demand for disclosure of shared information, where practicable
- Parties must dispose of information shared under the MoU securely once it is no longer required for its purpose
- Either party may terminate the MoU by giving 30 days' written notice to the other
Deadlines
- 30 days' written notice: Either party may terminate the MoU by giving 30 days' written notice to the other