Form

Checklist Data Sharing

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a self-assessment checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations review whether their routine sharing of personal data with third parties complies with the Data Protection (Jersey) Law 2018. It is a practical tool, not a binding rule, structured as a series of yes/no/partial questions with space for evidence and notes.

  • Policy and procedure: Checks for up to date internal policies on when and how personal data may be shared, staff guidance on responding to sharing requests, and links to the DPIA process for high-risk sharing.
  • Accountability: Checks that responsibility for data-sharing decisions is assigned to a senior staff member who is suitably trained.
  • Staff training and awareness: Checks that staff involved in data sharing receive regular training and awareness materials.
  • Records and agreements: Checks for logs of sharing decisions and formal data-sharing agreements covering purpose, recipients, data categories, minimisation, accuracy, security, retention, individual rights, review or termination, and sanctions for non-compliance.
  • Monitoring and review: Checks that sharing processes and agreements are periodically reviewed and that training, audit and decision records are kept.
  • Security and privacy information: Checks for appropriate technical and organisational security measures for shared data and clear privacy notices explaining data use and sharing.

The checklist itself does not create new legal duties; it is a self-audit aid referencing existing obligations under the DPJL 2018 for organisations that act as data controllers.

Applies to

data controllers, organisations sharing personal data with third parties

Topics

Version history

2026-07-30

source file (current)