Form

Template Data Protection Impact Assessment

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a template Data Protection Impact Assessment (DPIA) form published by the Jersey Office of the Information Commissioner (JOIC) for controllers to use when assessing privacy risks of a new project or significant change involving personal data. It is explicitly a starting point that must be adapted to the organisation's own circumstances, and is not itself binding law, but it reflects and points to obligations under the Data Protection (Jersey) Law 2018 (DPJL 2018).

  • Initial screener: Helps a controller decide whether a full DPIA is needed, based on factors such as automated/AI processing, large-scale special category data processing, or systematic large-scale monitoring of public areas.
  • Full DPIA sections: Covers nature, scope, context and purposes of processing, necessity and proportionality, technical and organisational security measures, and risk identification, assessment and mitigation.
  • Consultation: Requires seeking DPO advice, consulting relevant stakeholders and, where appropriate, data subjects, and documenting reasons if such consultation is not undertaken.
  • JOIC consultation: Controllers must consult the JOIC (via its online process) where identified risks cannot be mitigated.
  • Sign-off: Includes fields for recording DPO advice (accepted or overruled), approval of risk mitigation options and residual risks, and final DPIA approval.

Because this is a template rather than a rule, it does not itself create new legal duties beyond those already in the DPJL 2018, but it operationalises the DPJL requirements to conduct a DPIA, obtain DPO input, consider data subject views, and escalate unmitigated risks to the JOIC.

Key obligations

  • Controllers must seek the advice of the Data Protection Officer (DPO) when completing a DPIA, as required by Art.16(4) of the DPJL 2018.
  • The DPO is required to monitor performance of the DPIA on an ongoing basis under Art.26(1)(c) of the DPJL 2018, and the DPIA must be updated accordingly.
  • Controllers must seek the views of data subjects or their representatives on the intended processing under Art.16(8) of the DPJL 2018, unless doing so would limit protection of commercial/public interests or processing security, in which case the decision not to consult must be documented.
  • If the final decision differs from data subjects' views, the controller must document the reason for the decision.
  • Controllers must consult with the JOIC (online) where identified risks from the processing cannot be mitigated, and must record the interaction and outcome.

Applies to

data controllers, organisations processing personal data in Jersey

Topics

Version history

2026-07-30

source file (current)