Form

Checklist Breach Response Plan

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a one-page checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations work through the practical steps of responding to a personal data breach. It is a self-assessment tool rather than a binding legal instrument, framed as a series of yes/no questions to prompt action once a breach has been identified.

  • Preparedness: Whether a breach response plan exists and whether staff know their roles under it.
  • Containment and remediation: Whether systems have been secured and vulnerabilities fixed (e.g. changing credentials, applying patches).
  • Investigation: Whether the organisation understands how the breach occurred, who was involved, and the likely risk to affected individuals' rights and freedoms.
  • External input: Whether external experts (cyber security specialists, legal counsel, police) need to be involved.
  • Notification: Whether the JOIC or another supervisory authority, the Jersey Cyber Security Centre, the States of Jersey Police or other law enforcement, affected data subjects, or other parties (e.g. insurers or contractually-obliged third parties) need to be notified.
  • Record keeping: Whether the organisation's breach log has been completed.

The checklist does not itself set out statutory deadlines or thresholds for notification; it is a prompt list intended to be used alongside JOIC's substantive breach guidance and the applicable Jersey data protection law requirements.

Applies to

data controllers, data processors, organisations handling personal data in Jersey

Topics

Version history

2026-07-30

source file (current)