Agreement
2025 MoU between JDPA/Information Commissioner and Jersey Cyber Security Centre
In forceView on JOIC's website Source document
Summary
This is a Memorandum of Understanding (MoU) between the Jersey Data Protection Authority/Information Commissioner (JDPA/JOIC) and the Jersey Cyber Security Centre (JCSC), setting out how the two bodies will cooperate on data protection and cyber security matters. The MoU expressly states it is a statement of intent only and does not create legally binding obligations, nor does it modify any existing law or regulatory requirement.
- Purpose: Establishes a framework for collaboration, liaison and information exchange between JDPA/JOIC and JCSC to support each body's respective statutory functions.
- Liaison: The Information Commissioner and the Director of JCSC (and staff) will meet at least bi-annually to discuss matters of mutual interest, with more frequent contact permitted.
- Cyber security standards: JDPA will encourage regulated organisations to follow good cyber security practice, potentially referencing JCSC's technical standards, while JCSC may provide advice and assistance to JDPA on request.
- Information sharing: The parties may share information such as trends, research, enforcement techniques and significant issues, but only where permitted by law; specific complaint or individual/business details are excluded, and JCSC will not share incident-related organisation information without that organisation's consent.
- Incident deconfliction: Sets out how JCSC and JDPA will coordinate and remind organisations of their respective reporting obligations where a cyber incident may also be a reportable data protection incident, without either body notifying or opining on the other's behalf.
- Confidentiality and retention: Both parties must protect confidential information exchanged, assert exemptions against third-party disclosure requests where asked, and dispose of shared information securely once it is no longer needed.
- Commencement and termination: The MoU took effect once both parties signed it (2 November 2025) and continues until either party gives 30 days' written notice of termination; confidentiality and retention provisions survive termination.
The MoU does not impose direct obligations on data controllers, processors, Operators of Essential Services or other third parties; it governs only the working relationship between JDPA/JOIC and JCSC, and either party may publicise the relationship subject to mutual agreement on wording.
Key obligations
- The Information Commissioner and the Director of the JCSC must meet at least bi-annually to discuss matters of mutual interest.
- Each party must protect the confidentiality of information received from the other and maintain controls to minimise inappropriate disclosure.
- Information received under the MoU must not be retained longer than reasonably required and must be securely disposed of once no longer needed.
- A party wishing to terminate the MoU must give the other party 30 days' advance written notice.
- Neither party may publicise the relationship or use the other's name/trademark for promotional purposes without prior written consent.
Applies to
Jersey Data Protection Authority/Information Commissioner (JDPA/JOIC), Jersey Cyber Security Centre (JCSC)
Deadlines
- 2 November 2025: Date both parties signed the MoU, triggering its commencement (MoU takes effect once both parties have signed it).
- 30 days: Advance written notice required by either party to terminate the MoU.
- at least bi-annually: Minimum frequency of liaison meetings between the Information Commissioner and the Director of the JCSC.