Form

DPIA template

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a template provided by the Jersey Office of the Information Commissioner (JOIC) to help data controllers record the process and outcome of a Data Protection Impact Assessment (DPIA). It is a guidance tool, not a binding regulatory instrument, and must be adapted to the individual project. It is intended to be started at the outset of any major project involving personal data or a significant change to an existing process.

  • Initial screener: Helps identify whether a full DPIA is required, based on factors such as automated/AI processing, large-scale special category data processing, or systematic large-scale monitoring of public areas.
  • Full DPIA sections: Cover the nature, scope, context and purposes of processing, necessity and proportionality, security measures, risk identification and mitigation, and residual risk assessment.
  • Consultation: Requires seeking the views of data subjects (or documenting why not appropriate), obtaining advice from the Data Protection Officer, and consulting the JOIC where identified risks cannot be mitigated.
  • Approvals: Includes sign-off fields for the screener decision, risk mitigation options, DPO advice (accepted or overruled with reasons), and final DPIA approval.

The template itself does not set new legal rules but reflects obligations under the Data Protection (Jersey) Law 2018, including the duty to consult the DPO and data subjects and to engage the JOIC when risk cannot be reduced to an acceptable level.

Key obligations

  • Controllers must seek the advice of the Data Protection Officer (where one exists) when completing a DPIA, per Art.16(4) of the DPJL 2018
  • Controllers must seek the views of data subjects or their representatives on the intended processing, or document the reason for not doing so, per Art.16(8) of the DPJL 2018
  • Controllers must consult the JOIC where identified risks from the processing cannot be mitigated
  • If the final decision differs from the views of data subjects, the controller must document the reason for the decision
  • If DPO advice is overruled, the controller must record the reasons for overruling it
  • The DPO is required to monitor performance of the DPIA on an ongoing basis and the DPIA must be updated to reflect this advice

Applies to

data controllers, data protection officers

Topics

Version history

2026-07-30

source file (current)