Form
Template Letter to Data Subjects affected by the Data Breach
Status not confirmedView on JOIC's website Source document
Summary
This is a template letter published by the Jersey Office of the Information Commissioner (JOIC) for organisations to adapt when notifying individuals whose personal data has been affected by a data breach. It is guidance only, not a binding rule, and must be tailored to the specific facts of each incident before use.
- What happened: Space to describe the date the breach was discovered and a plain explanation of what occurred and its cause
- Data involved: A list of the categories of personal data (and any special category data) affected
- Risks: Explanation of potential risks to the individual, such as identity theft or phishing
- Remedial steps taken: Description of containment and investigation measures, including that the breach has been reported to the Jersey Data Protection Authority/JOIC
- Advice to the individual: Recommended precautions the data subject should take
- Contact and rights: Contact details for the organisation's Data Protection Officer and a statement of the individual's rights under the Data Protection (Jersey) Law 2018, including the right to complain to the JOIC
The template does not itself create new legal duties; it is a drafting aid reflecting the notification content organisations are expected to include when informing affected individuals of a personal data breach under Jersey data protection law.
Applies to
data controllers, organisations handling personal data in Jersey
Topics
Version history
2026-07-30