Agreement

2025 MoU between JDPA/Information Commissioner and Jersey Cyber Security Centre

Jersey Office of the Information Commissioner (JOIC) · Jersey

In force

Published: 2025-12-02

Current version last checked: 2026-07-30

Summary

This is a Memorandum of Understanding (MoU) between the Jersey Data Protection Authority/Information Commissioner (JDPA/JOIC) and the Jersey Cyber Security Centre (JCSC), setting out how the two bodies will cooperate on data protection and cyber security matters. The MoU expressly states it is a statement of intent only and does not create legally binding obligations, nor does it modify any existing law or regulatory requirement.

  • Purpose: Establishes a framework for collaboration, liaison and information exchange between JDPA/JOIC and JCSC to support each body's respective statutory functions.
  • Liaison: The Information Commissioner and the Director of JCSC (and staff) will meet at least bi-annually to discuss matters of mutual interest, with more frequent contact permitted.
  • Cyber security standards: JDPA will encourage regulated organisations to follow good cyber security practice, potentially referencing JCSC's technical standards, while JCSC may provide advice and assistance to JDPA on request.
  • Information sharing: The parties may share information such as trends, research, enforcement techniques and significant issues, but only where permitted by law; specific complaint or individual/business details are excluded, and JCSC will not share incident-related organisation information without that organisation's consent.
  • Incident deconfliction: Sets out how JCSC and JDPA will coordinate and remind organisations of their respective reporting obligations where a cyber incident may also be a reportable data protection incident, without either body notifying or opining on the other's behalf.
  • Confidentiality and retention: Both parties must protect confidential information exchanged, assert exemptions against third-party disclosure requests where asked, and dispose of shared information securely once it is no longer needed.
  • Commencement and termination: The MoU took effect once both parties signed it (2 November 2025) and continues until either party gives 30 days' written notice of termination; confidentiality and retention provisions survive termination.

The MoU does not impose direct obligations on data controllers, processors, Operators of Essential Services or other third parties; it governs only the working relationship between JDPA/JOIC and JCSC, and either party may publicise the relationship subject to mutual agreement on wording.

Key obligations

  • The Information Commissioner and the Director of the JCSC must meet at least bi-annually to discuss matters of mutual interest.
  • Each party must protect the confidentiality of information received from the other and maintain controls to minimise inappropriate disclosure.
  • Information received under the MoU must not be retained longer than reasonably required and must be securely disposed of once no longer needed.
  • A party wishing to terminate the MoU must give the other party 30 days' advance written notice.
  • Neither party may publicise the relationship or use the other's name/trademark for promotional purposes without prior written consent.

Applies to

Jersey Data Protection Authority/Information Commissioner (JDPA/JOIC), Jersey Cyber Security Centre (JCSC)

Deadlines

  • 2 November 2025: Date both parties signed the MoU, triggering its commencement (MoU takes effect once both parties have signed it).
  • 30 days: Advance written notice required by either party to terminate the MoU.
  • at least bi-annually: Minimum frequency of liaison meetings between the Information Commissioner and the Director of the JCSC.

Topics

Version history

2026-07-30

source file (current)