Form
Checklist Data Sharing
Status not confirmedView on JOIC's website Source document
Summary
This is a self-assessment checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations review whether their routine sharing of personal data with third parties complies with the Data Protection (Jersey) Law 2018. It is a practical tool, not a binding rule, structured as a series of yes/no/partial questions with space for evidence and notes.
- Policy and procedure: Checks for up to date internal policies on when and how personal data may be shared, staff guidance on responding to sharing requests, and links to the DPIA process for high-risk sharing.
- Accountability: Checks that responsibility for data-sharing decisions is assigned to a senior staff member who is suitably trained.
- Staff training and awareness: Checks that staff involved in data sharing receive regular training and awareness materials.
- Records and agreements: Checks for logs of sharing decisions and formal data-sharing agreements covering purpose, recipients, data categories, minimisation, accuracy, security, retention, individual rights, review or termination, and sanctions for non-compliance.
- Monitoring and review: Checks that sharing processes and agreements are periodically reviewed and that training, audit and decision records are kept.
- Security and privacy information: Checks for appropriate technical and organisational security measures for shared data and clear privacy notices explaining data use and sharing.
The checklist itself does not create new legal duties; it is a self-audit aid referencing existing obligations under the DPJL 2018 for organisations that act as data controllers.
Applies to
data controllers, organisations sharing personal data with third parties
Topics
Version history
2026-07-30