Form
Breach Log Template
Status not confirmedView on JOIC's website Source document
Summary
This is a template form published by the Jersey Office of the Information Commissioner (JOIC) for organisations to record details of personal data breaches. It is not itself a binding rule, but it restates the underlying legal requirement and provides a structured log for internal breach management.
- Legal basis: Refers to the Data Protection (Jersey) Law 2018, under which data controllers must notify the JOIC of any personal data breach within 72 hours of detection, using the secure form on the JOIC website.
- Purpose of template: Provides a structured log for organisations to record breach details, consequences, and remedial measures for internal record keeping.
- Fields to complete: Organisation name, date, reference number, date of breach, number of people affected, nature and description of breach, how the breach was discovered, description of data involved, whether individuals were informed, remedial action taken, whether other regulators were informed, and when the JOIC was first notified.
Organisations should also consult the JOIC's separate guidance note on notification of personal data breaches for further detail on the reporting process.
Key obligations
- Data controllers must notify the JOIC of any personal data breach within 72 hours of detection, using the secure form on the JOIC website.
Applies to
data controllers, organisations
Deadlines
- within 72 hours of detection: Data controllers must notify the JOIC of any personal data breach within 72 hours of detection.
Topics
Version history
2026-07-30