Form
Checklist Appointing a Data Processor
Status not confirmedView on JOIC's website Source document
Summary
This is a practical checklist published by the Jersey Office of the Information Commissioner to help organisations that act as data controllers when they appoint a third-party data processor. It sets out steps to follow before appointment, what the processing contract must contain, and ongoing monitoring and risk-assessment duties. It is guidance rather than a standalone legal instrument, but it reflects obligations arising under Jersey data protection law.
- Before appointment: Confirm controller status, understand the processor's role, identify data categories and purposes, check the processor's security measures, ask about sub-processors, and assess ability to support data subject rights.
- Contract requirements: Put in place a written contract specifying subject-matter, duration, nature and purpose of processing, data types and subjects, and requiring the processor to act only on documented instructions, maintain confidentiality, implement security measures, control sub-processor use, return or delete data at the end of the service, and allow audits.
- Ongoing monitoring: Regularly verify the processor's compliance with instructions and security standards, support the controller's own obligations (data subject rights, breach notification, high-risk processing reviews), oversee any sub-processors, confirm data deletion/return at contract end, and keep records demonstrating compliance.
- Risk and compliance review: Assess whether processing is high risk and needs extra safeguards, confirm legal basis and transparency obligations are addressed, update the record of processing activities, and periodically review the contract as scope or technology changes.
Key obligations
- Confirm and document that the organisation remains the data controller before appointing a processor
- Enter into a written contract with the processor covering subject-matter, duration, nature and purpose of processing, data categories, and controller/processor obligations
- Ensure the contract requires the processor to act only on documented instructions, maintain confidentiality, implement appropriate technical and organisational security measures, and control any sub-processor use
- Ensure the contract requires the processor to return or delete personal data at the end of the service unless retention is legally required, and to allow audits/inspections
- Regularly monitor the processor's ongoing compliance with the contract and security requirements
- Maintain oversight of any sub-processors engaged by the processor and ensure equivalent obligations apply to them
- Keep records documenting appointment and monitoring of the processor to demonstrate compliance
- Update the register of processing activities to reflect the processor relationship and periodically review the contract as circumstances change
Applies to
data controllers, data processors, organisations using third-party suppliers to process personal data
Topics
Version history
2026-07-30