Form

Breach Log Template

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a template form published by the Jersey Office of the Information Commissioner (JOIC) for organisations to record details of personal data breaches. It is not itself a binding rule, but it restates the underlying legal requirement and provides a structured log for internal breach management.

  • Legal basis: Refers to the Data Protection (Jersey) Law 2018, under which data controllers must notify the JOIC of any personal data breach within 72 hours of detection, using the secure form on the JOIC website.
  • Purpose of template: Provides a structured log for organisations to record breach details, consequences, and remedial measures for internal record keeping.
  • Fields to complete: Organisation name, date, reference number, date of breach, number of people affected, nature and description of breach, how the breach was discovered, description of data involved, whether individuals were informed, remedial action taken, whether other regulators were informed, and when the JOIC was first notified.

Organisations should also consult the JOIC's separate guidance note on notification of personal data breaches for further detail on the reporting process.

Key obligations

  • Data controllers must notify the JOIC of any personal data breach within 72 hours of detection, using the secure form on the JOIC website.

Applies to

data controllers, organisations

Deadlines

  • within 72 hours of detection: Data controllers must notify the JOIC of any personal data breach within 72 hours of detection.

Topics

Version history

2026-07-30

source file (current)