Form
DPIA Checklist
In forceView on JOIC's website Source document
Summary
This is a practical checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations decide when a Data Protection Impact Assessment (DPIA) is required and to guide them through completing one in line with the Data Protection (Jersey) Law 2018 (DPJL 2018). It is a self-assessment tool rather than a standalone legal instrument, but it restates and operationalises statutory DPIA duties.
- When a DPIA is mandatory: A DPIA must be carried out where processing involves systematic and extensive automated evaluation of personal aspects leading to decisions with legal or similarly significant effects, large scale processing of special category data, or large scale systematic monitoring of a publicly accessible area.
- Screening and advice: Organisations should check whether processing is likely to result in high risk to individuals' rights and freedoms and seek advice from their DPO or the JOIC if unsure, recording the decision reached.
- DPIA content: The checklist covers describing the project's nature, scope, context and purposes, the personal data used, data subjects affected, data flows and third parties/processors involved, and the lawful basis relied upon under Schedule 2 DPJL 2018.
- Necessity, risk and mitigation: It prompts assessment of necessity and proportionality, data minimisation, retention periods, identification of risks and potential harms, and the security measures and individual rights processes put in place to reduce those risks.
- Sign-off and statutory content: Completed DPIAs should contain all information required by Article 16(6) DPJL 2018, be written in plain English, be reviewed and signed off by appropriately senior staff, and have a scheduled review date.
- Referral to JOIC: Where high residual risks remain after mitigation, the DPIA must be sent to the JOIC (via its online form or otherwise) containing the information required by Article 17(2) DPJL 2018.
The checklist itself creates no new legal duties beyond those already in the DPJL 2018, but non-compliance with the underlying statutory DPIA requirements it reflects (such as failing to consult the JOIC on high residual risk processing) remains a compliance risk for organisations.
Key obligations
- Carry out a DPIA where processing involves systematic and extensive automated evaluation producing legal or similarly significant effects on individuals
- Carry out a DPIA where special category data is processed on a large scale
- Carry out a DPIA where systematic monitoring of a publicly accessible area occurs on a large scale
- Seek advice from a DPO or the JOIC where it is unclear whether a DPIA is needed, and record the decision taken
- Ensure completed DPIAs contain all information required by Article 16(6) of the DPJL 2018
- Have DPIAs reviewed and signed off by staff with appropriate seniority and set a review date
- Submit the DPIA to the JOIC, containing the information required by Article 17(2) DPJL 2018, where high risks remain after mitigation
Applies to
data controllers, organisations processing personal data in Jersey