Form
Data Protection Statement Template
Status not confirmedView on JOIC's website Source document
Summary
This is a template Data Protection Statement (privacy notice) published by the Jersey Office of the Information Commissioner for organisations to adapt and use on their own websites. It is guidance material, not a binding rule itself, but it models the content that the Data Protection (Jersey) Law 2018 (DPJL 2018) expects a privacy notice to cover.
- Identity and scope: Who the data controller is and what the notice covers (e.g. website use only, with separate notices for staff or customers).
- Data collected and how: What personal data is collected, and whether directly (forms) or indirectly (browsing activity, cookies).
- Purposes and lawful basis: Why data is used and the DPJL 2018 lawful basis relied on for each purpose (legitimate interests, contract, consent, legal obligation).
- Marketing: A statement on whether personal data is used for marketing.
- Sharing and recipients: Third parties data is shared with (e.g. hosting or IT providers), and why.
- Retention: How long personal data will be kept.
- International transfers: Where personal data is sent outside Jersey and how transfers are safeguarded.
- Cookies: A cookie table and explanation of tracking technologies used.
- Individual rights: Access, correction, erasure, restriction, portability, objection, automated-decision rights, and right to withdraw consent.
- Security and breach notification: Security measures and a commitment to notify individuals and regulators of breaches where legally required.
- Complaints: How to complain to the organisation and to the Jersey Office of the Information Commissioner.
- Contact and updates: Contact details and how changes to the statement will be communicated.
Organisations processing personal data under the DPJL 2018 should adapt this template to their own circumstances rather than use it verbatim; bracketed placeholders must be completed and any inapplicable sections removed or amended.
Key obligations
- Organisations using this template should tailor it to accurately describe their own personal data collection, use, sharing, retention and international transfer practices rather than adopting it unmodified
- Organisations should identify and disclose the lawful basis under the DPJL 2018 relied on for each processing purpose
- Organisations should notify individuals and any applicable regulator of a suspected personal data security breach where legally required to do so
- Organisations should inform website users of significant changes to the privacy statement
Applies to
data controllers, organisations operating websites that collect personal data
Topics
Version history
2026-07-30