Form

Checklist: Accountability & Governance

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a self-assessment checklist published by JOIC to help organisations acting as data controllers evidence accountability and governance under the Data Protection (Jersey) Law 2018 and the Data Protection Authority (Jersey) Law 2018. It does not itself create new legal duties but provides a structured tool for organisations to record compliance status, gaps and evidence against existing data protection requirements.

  • Governance and leadership: Senior management endorsement of data protection strategy, an up to date privacy policy, and accurate privacy notices.
  • Roles and responsibilities: Appointment of a DPO or equivalent with independence and resources, and clearly documented roles.
  • Data mapping and risk: Maintaining a Record of Processing Activities, data flow diagrams, DPIAs for high risk processing, and a risk register.
  • Policies and technical measures: Policies on retention, deletion, access, breach and data subject rights; processor contracts with required clauses; security and privacy by design controls.
  • Training and monitoring: Regular staff training, internal audits, and reporting of metrics such as DSARs and breaches to senior management.
  • Breach and third party governance: A tested incident response plan, breach log, vendor oversight, and safeguards for international transfers (e.g. SCCs plus Jersey Addendum or adequacy).
  • Rights and continuous improvement: Mechanisms to respond to data subject rights requests within statutory deadlines, periodic review of privacy notices, and annual review of the privacy framework with documented evidence available to JOIC.

The checklist is intended as a practical governance and audit aid rather than a binding instrument, and organisations use it to self-assess and document their ongoing compliance posture for potential review by JOIC.

Applies to

data controllers, organisations processing personal data

Topics

Version history

2026-07-30

source file (current)