Form

Checklist: Drafting a Data Protection Statement/Privacy Notice

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a JOIC checklist tool to help organisations in Jersey prepare or review a privacy notice (data protection statement) so that it satisfies the transparency requirements of Article 12 of the Data Protection (Jersey) Law 2018. It sets out the categories of information that should be included, rather than imposing new legal duties itself.

  • Identity and contact: Name of the controller, trading names, general contact details, DPO contact (if applicable), and confirmation of controller status.
  • Data collected: Categories of personal data collected directly and from third parties, special category data, and children's data.
  • Purposes and legal basis: Specific purposes for processing and the lawful basis relied on for each, including consent, legitimate interests, or special category conditions.
  • Source and sharing: Where the data comes from and the categories of recipients, processors, and joint controllers it is shared with.
  • International transfers: Whether data leaves Jersey, recipient locations, and safeguards used.
  • Retention: Retention periods or the criteria used to determine them.
  • Individual rights: Access, rectification, erasure, restriction, objection, portability, and rights around automated decision-making, plus how to exercise them.
  • Complaints: Internal complaints process and the right to complain directly to JOIC, with JOIC contact details.
  • Automated decision-making: Explanation of any automated decisions, the logic involved, consequences, and the right to request human intervention.
  • Security, changes and accessibility: High-level statement on security measures, how changes to the notice are communicated, a last-updated date, and accessible, plain-language formatting.

The checklist is a practical drafting aid rather than a standalone legal instrument; the underlying statutory obligation to provide this information to individuals arises from Article 12 of the DPJL 2018, and organisations should use this document to test their existing or draft privacy notices against that requirement.

Key obligations

  • Provide individuals with a privacy notice containing the identity and contact details of the data controller (and DPO where applicable)
  • Specify the categories of personal data collected, including special category and children's data
  • Clearly state the specific purposes for processing personal data and the lawful basis relied on for each purpose
  • Explain where personal data originates, including from individuals, third parties, or internally generated sources
  • Identify categories of recipients with whom personal data is shared, including processors and joint controllers
  • Disclose any international transfers of personal data, the locations involved, and safeguards applied
  • State retention periods for each category of data or the criteria used to determine them
  • Inform individuals of their rights under the DPJL 2018 and how to exercise them
  • Explain the internal complaints process and inform individuals of their right to complain directly to JOIC, including JOIC's contact details
  • Disclose the use of automated decision-making or profiling, the logic involved, consequences, and the right to request human intervention
  • Provide a high-level statement on security measures in place
  • Notify individuals of changes to the privacy notice and include a last-updated date
  • Ensure the privacy notice is in clear, plain language, easy to find, and available in accessible formats

Applies to

organisations in Jersey acting as data controllers, data controllers, data protection officers

Topics

Version history

2026-07-30

source file (current)