Form
Checklist Breach Response Plan
Status not confirmedView on JOIC's website Source document
Summary
This is a one-page checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations work through the practical steps of responding to a personal data breach. It is a self-assessment tool rather than a binding legal instrument, framed as a series of yes/no questions to prompt action once a breach has been identified.
- Preparedness: Whether a breach response plan exists and whether staff know their roles under it.
- Containment and remediation: Whether systems have been secured and vulnerabilities fixed (e.g. changing credentials, applying patches).
- Investigation: Whether the organisation understands how the breach occurred, who was involved, and the likely risk to affected individuals' rights and freedoms.
- External input: Whether external experts (cyber security specialists, legal counsel, police) need to be involved.
- Notification: Whether the JOIC or another supervisory authority, the Jersey Cyber Security Centre, the States of Jersey Police or other law enforcement, affected data subjects, or other parties (e.g. insurers or contractually-obliged third parties) need to be notified.
- Record keeping: Whether the organisation's breach log has been completed.
The checklist does not itself set out statutory deadlines or thresholds for notification; it is a prompt list intended to be used alongside JOIC's substantive breach guidance and the applicable Jersey data protection law requirements.
Applies to
data controllers, data processors, organisations handling personal data in Jersey
Topics
Version history
2026-07-30