Agreement

2024 MoU between the JDPA and the Comptroller and Auditor General

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Published: 2025-10-06

Current version last checked: 2026-07-30

Summary

This is a Memorandum of Understanding (MoU) between the Jersey Comptroller and Auditor General (C&AG) and the Jersey Data Protection Authority (JDPA), signed 12 August 2024. It establishes a framework for cooperation, information exchange and mutual support between the two bodies in discharging their respective statutory functions. The MoU expressly states it is not legally enforceable and does not create new legal duties, transfer statutory responsibilities, or override either body's existing powers.

  • Working relationship: Commits both bodies to proactive, open and transparent cooperation, including at least biannual meetings to discuss matters of mutual interest.
  • Data sharing: Sets out the legal bases and principles governing any sharing of information (including personal data) between the C&AG and JDPA, referencing the DPJL 2018 and DPAJL 2018.
  • Confidentiality and breach reporting: Requires appropriate security measures for shared information, consultation before onward disclosure, and immediate notification if confidential material is wrongfully disclosed.
  • Retention and disposal: Requires information shared under the MoU to be retained no longer than necessary and disposed of securely once no longer needed.
  • Review and termination: The MoU is reviewed annually and may be terminated by either party on 30 days' written notice, with confidentiality and retention obligations surviving termination.

Because the MoU governs the relationship between the two regulators rather than imposing requirements on external regulated entities, it has no direct compliance impact on businesses or individuals outside these two bodies.

Key obligations

  • The C&AG and JDPA will hold at least biannual meetings to exchange information on matters of mutual interest.
  • Where sharing personal or confidential data, the disclosing party must ensure a lawful basis exists and apply appropriate security measures.
  • A party receiving confidential information must consult the sending party before onward disclosure to a third party where permissible, and notify it of anticipated legally enforceable disclosure demands.
  • A party must promptly notify the sending party if confidential material it received is wrongfully disclosed.
  • Information shared under the MoU must not be retained longer than necessary and must be securely disposed of once no longer required.
  • The MoU must be reviewed on an annual basis.
  • Either party wishing to terminate the MoU must give the other 30 days' advance written notice.

Applies to

Jersey Data Protection Authority (JDPA), Office of the Comptroller and Auditor General (C&AG)

Deadlines

  • annually: The MoU will be reviewed on an annual basis.
  • 30 days' advance written notice: Required notice period for either party to terminate the MoU.
  • biannual meetings: The working relationship will involve at least biannual meetings to exchange information of mutual interest.

Topics

Version history

2026-07-30

source file (current)