Form

Checklist Am I a Controller Joint Controller or Processor

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a self-assessment checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations work out whether they are acting as a controller, joint controller, or processor under the Data Protection (Jersey) Law 2018. It is explicitly for illustrative and general guidance only and is not legal advice or a definitive statement of an organisation's obligations.

  • Questions 1 to 8: Ask whether the organisation decides the purpose or means of processing, what data and data subjects are involved, who data is shared with, privacy notice content, retention/erasure criteria, and the lawful basis for processing. Mostly Yes answers indicate the organisation is likely a controller.
  • Questions 9 and 10: Ask whether the organisation only processes personal data on another entity's documented instructions with no meaningful say over purpose or means. Yes answers here (and No to most of 1-8) indicate the organisation is likely a processor.
  • Mixed answers: A mix of controller-type and processor-type answers may indicate joint-controller status, or that the organisation is both a controller and a processor depending on context.

The checklist directs organisations that remain unsure of their status or responsibilities to consult JOIC's fuller guidance note or contact the office directly for advice.

Applies to

data controllers, joint controllers, data processors, organisations processing personal data under the Data Protection (Jersey) Law 2018

Topics

Version history

2026-07-30

source file (current)