Form
Template - Data Protection Impact Assessment (DPIA)
Status not confirmedView on JOIC's website Source document
Summary
This is a template Data Protection Impact Assessment (DPIA) form published by the Jersey Office of the Information Commissioner (JOIC) for use by data controllers under the Data Protection (Jersey) Law 2018 (DPJL 2018). It is a guidance tool, not a binding rule itself, intended to help organisations record the screening, assessment and risk-mitigation process for projects involving personal data, and to be adapted to the organisation's own circumstances.
- Initial screener: Helps determine whether a full DPIA is required, based on numbers and types of individuals affected, categories of personal data (including special category data), and whether the project involves automated/AI processing, large-scale special category processing, or large-scale systematic monitoring of public areas.
- Full DPIA sections: Where required, covers nature, scope, context and purposes of processing, necessity and proportionality, technical and organisational security measures, and identification, assessment and mitigation of risks to data subjects.
- Consultation: Requires seeking advice from the Data Protection Officer (DPO), consulting relevant internal and external stakeholders, and seeking the views of data subjects or documenting why this was not done.
- JOIC consultation trigger: Where risks identified in the DPIA cannot be mitigated, the controller must consult with the JOIC (which can be done online) and record the outcome.
- Sign-off and record-keeping: Requires documented approval of risk mitigation options, residual risk levels, and whether DPO advice was accepted or overruled, with reasons recorded.
The template itself creates no new legal duties beyond those already imposed by the DPJL 2018 (such as DPO consultation under Art.16(4), data subject consultation under Art.16(8), and DPO monitoring under Art.26(1)(c)), but operationalises those duties into a recordable process for controllers to follow.
Key obligations
- Controllers must seek the advice of the DPO (where one exists) when completing a DPIA, as required by Art.16(4) of the DPJL 2018
- Controllers must seek the views of data subjects or their representatives on the intended processing, unless doing so would limit protection of commercial/public interests or processing security, per Art.16(8) of the DPJL 2018
- If a controller decides not to seek data subject input, or reaches a decision different from data subjects' views, the controller must document the reasons
- Controllers must consult with the JOIC (online) where identified risks in a DPIA cannot be mitigated, and must record any interaction with the JOIC
- Controllers should begin completing the DPIA at the start of any major project involving personal data or a significant change to an existing process, and integrate the outcomes back into the project plan
Applies to
data controllers