Statement of Guidance
Data Breaches - What they are and how to deal with them
Status not confirmedView on JOIC's website Source document
Summary
This is JOIC guidance explaining what personal data breaches are under the Data Protection (Jersey) Law 2018 (DPJL 2018) and setting out the practical steps data controllers (and processors) must follow to assess, contain, log, report and communicate about breaches. It is explanatory rather than a standalone legal instrument, but it restates binding obligations from the DPJL 2018 and describes JOIC's enforcement approach, including potential administrative fines.
- Notify JOIC: Data controllers must notify JOIC without undue delay and, where feasible, within 72 hours of becoming aware of a breach that could risk individuals' rights and freedoms; if full details are unavailable, notification can be made in phases.
- Notify affected individuals: Where a breach poses a high risk of harm, controllers must inform affected individuals without undue delay, using clear plain language, unless proportionate protective measures (e.g. encryption) were applied or subsequent measures removed the high risk.
- Maintain a breach log: Controllers must keep a detailed log of all breaches, reportable or not, recording facts, circumstances, impact assessments and remedial actions; JOIC may inspect these logs during audits.
- Technical and organisational measures: Controllers must implement and regularly review appropriate technical and organisational measures to secure personal data and to plan for identifying and responding to breaches.
- Processor notification: Where a processor suffers a breach, it must notify the controller without undue delay; the controller remains responsible for notifying JOIC.
- Content of notifications: Notifications to JOIC and to individuals must include specified details (nature of breach, data involved, contact of DPO, likely consequences, mitigation measures, etc.), with further details permitted in a follow up notification if not initially available.
Failure to notify JOIC when required can result in an administrative fine of up to 5,000,000 pounds, and JOIC may commence a formal Inquiry under Art.21 of the Data Protection Authority (Jersey) Law 2018, potentially leading to findings of contravention, orders, fines or public statements. JOIC cannot order compensation to affected individuals.
Key obligations
- Data controllers must notify JOIC without undue delay, and where feasible within 72 hours of becoming aware of a breach, if it could risk individuals' rights and freedoms.
- Where full details are not yet available, controllers must still notify within 72 hours with basic facts and provide further information in phases without undue further delay.
- Where a breach poses a high risk of harm, controllers must inform affected individuals without undue delay, including required content (what happened, data involved, potential impact, protective steps, DPO contact details).
- Controllers must maintain a detailed breach log for every breach (reportable or not), recording facts, circumstances, impact assessments and remedial actions, and make it available for JOIC inspection.
- Controllers must implement and regularly review appropriate technical and organisational measures to secure personal data and to detect and respond to breaches.
- Processors must notify the controller without undue delay upon becoming aware of a breach affecting the controller's data.
- Notifications to JOIC must include specified information (data controller name, DPO contact, nature of breach, dates, data affected, measures taken) and supporting documents such as an extract from the breach log and breach reporting policy.
Applies to
data controllers, data processors
Deadlines
- within 72 hours of becoming aware of the breach: Deadline for data controllers to notify JOIC of a Data Breach that could risk individuals' rights and freedoms.
- without undue delay: Timeframe for notifying affected individuals where there is a high risk of harm, and for processors to notify the controller of a breach.
- without undue further delay: Timeframe for providing additional phased information to JOIC once available, following an initial notification.