Form

Template Letter to Data Subjects affected by the Data Breach

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a template letter published by the Jersey Office of the Information Commissioner (JOIC) for organisations to adapt when notifying individuals whose personal data has been affected by a data breach. It is guidance only, not a binding rule, and must be tailored to the specific facts of each incident before use.

  • What happened: Space to describe the date the breach was discovered and a plain explanation of what occurred and its cause
  • Data involved: A list of the categories of personal data (and any special category data) affected
  • Risks: Explanation of potential risks to the individual, such as identity theft or phishing
  • Remedial steps taken: Description of containment and investigation measures, including that the breach has been reported to the Jersey Data Protection Authority/JOIC
  • Advice to the individual: Recommended precautions the data subject should take
  • Contact and rights: Contact details for the organisation's Data Protection Officer and a statement of the individual's rights under the Data Protection (Jersey) Law 2018, including the right to complain to the JOIC

The template does not itself create new legal duties; it is a drafting aid reflecting the notification content organisations are expected to include when informing affected individuals of a personal data breach under Jersey data protection law.

Applies to

data controllers, organisations handling personal data in Jersey

Topics

Version history

2026-07-30

source file (current)