Form
Transfer Impact Assessment Checklist
Status not confirmedView on JOIC's website Source document
Summary
This is a practical checklist published by the Jersey Office of the Information Commissioner to help organisations carry out a Transfer Impact Assessment (TIA) before making a restricted transfer of personal data outside Jersey under the Data Protection (Jersey) Law 2018 (DPJL 2018). It is a self-assessment tool rather than a binding rule, prompting the user through the questions a TIA should cover.
- Parties to the transfer: Identify the sender and receiver, the receiver's type, location, reputation, role (controller/processor/joint-controller/sub-processor), and whether onward transfers or sharing will occur.
- Details of the transfer: Assess the purpose of the transfer, what data (including any special category data) is involved, volume and frequency, whether it concerns children or vulnerable individuals, and the security measures and format used in transit.
- Lawful basis: Identify the lawful basis for the transfer under Schedule 2 Part 1 of the DPJL 2018, and, for special category data, the applicable condition under Schedule 2 Part 2.
- Legitimate interests check: If relying on legitimate interests as the lawful basis, confirm a legitimate interest assessment has been completed before the TIA.
- Legal environment in the third country: Evaluate whether the destination country has data protection law, an effective regulatory authority, enforceable contractual and judicial remedies, data subject rights broadly equivalent to the DPJL 2018, relevant surveillance regimes, and any human rights risks.
The checklist does not itself set new legal requirements or deadlines; it operationalises existing obligations under the DPJL 2018 relating to restricted (international) data transfers.
Key obligations
- Before completing a Transfer Impact Assessment, an organisation relying on legitimate interests as its lawful basis for transfer must first carry out a legitimate interest assessment.
- Organisations making restricted transfers of personal data outside Jersey should assess and document the lawful basis for transfer, the safeguards and security measures in place, and the legal environment of the receiving country before transferring the data.
Applies to
data controllers, data processors, organisations transferring personal data outside Jersey
Topics
Version history
2026-07-30