Statement of Guidance
Case Studies - Learning from Experience
Status not confirmedView on JOIC's website Source document
Summary
This is a guidance note from the Jersey Office of the Information Commissioner (JOIC) that compiles anonymised case studies illustrating how the Data Protection (Jersey) Law 2018 (DPJL 2018) applies in practice. It is informational rather than regulatory, intended to help organisations learn from real complaints, breach reports and audit findings handled by JOIC since 2018.
- Topics covered: Case studies are organised by topic including transparency, data subject access requests (DSARs), accuracy and rectification requests, erasure, security and data breaches, CCTV (household), and workplace privacy and monitoring.
- Structure of each case study: Each case study sets out Background, Investigation and Findings, Outcome, and Lessons Learned, with links to further guidance where relevant.
- Related material: More serious or high public interest matters are published separately as named Public Statements in JOIC's Action Taken section on its website.
- Audience versions: The guidance also references an easy read version for general readers and individuals, and a technical guide for data controllers, processors and practitioners.
The document does not impose new legal duties itself; it encourages organisations to share it with staff, data protection officers and management as part of training and compliance activities, and to use the lessons learned to review their own practices under the DPJL 2018.
Applies to
data controllers, data processors, organisations processing personal data in Jersey, data protection officers