Statement of Guidance
Data Protection by Design and Default, and Data Protection Impact Assessments
Status not confirmedView on JOIC's website Source document
Summary
This is JOIC guidance explaining the data protection by design and default requirements under the Data Protection (Jersey) Law 2018 (DPJL 2018), and when and how organisations must carry out Data Protection Impact Assessments (DPIAs). It is aimed at data controllers and processors and combines a plain-English explanation with a technical guide referencing specific DPJL 2018 articles.
- By design and default: Under Arts.15(1) to 15(4) DPJL 2018, controllers must implement appropriate technical and organisational measures both when determining the means of processing and during processing itself, ensure only necessary personal data is processed by default, and prevent personal data becoming accessible to an indefinite number of people without lawful basis.
- DPIAs for high risk processing: A DPIA is legally required for processing likely to result in high risk to individuals (e.g. large scale profiling, surveillance, special category data, CCTV/facial recognition, automated decision-making). A pre-screener checklist can help decide if a full DPIA is needed, and the decision should be recorded even if a full DPIA is not carried out.
- Consulting the Authority: Under Art.17 DPJL 2018, if a DPIA shows high risk that cannot be reduced or removed, the controller must consult the Authority in writing before processing starts, providing responsibilities of controllers/processors, a copy of the DPIA, DPO contact details, and any other information requested.
- DPO involvement: Where a Data Protection Officer is appointed, Art.26(1)(g) requires their involvement in advising on whether to carry out a DPIA, its methodology, whether to outsource it, appropriate safeguards, and whether the DPIA has been carried out correctly.
- Data subject views: Art.16(8) creates an expectation that controllers will, where appropriate, seek the views of data subjects or their representatives on intended processing.
- JOIC response times: On receiving a DPIA consultation submission, JOIC must give written notice of its opinion within eight weeks, extendable by a further six weeks (up to fourteen weeks total) in complex cases; the clock pauses if JOIC requests further information.
The guidance is informational and explanatory but restates binding legal obligations already found in the DPJL 2018 (particularly Arts.15, 16, 17 and 26), rather than creating new ones itself. Related DPIA templates and checklists are referenced as downloadable tools.
Key obligations
- Controllers must implement appropriate technical and organisational measures for data protection by design both when determining the means of processing and during the processing itself (Art.15(1) to (2) DPJL 2018)
- Controllers must ensure that, by default, only personal data necessary for each specific purpose is processed and that data is not made accessible to an indefinite number of people without consent or other lawful authority (Art.15(3) to (4) DPJL 2018)
- Controllers must carry out a DPIA before starting processing that is likely to result in high risk to individuals' rights and freedoms
- Where a DPIA identifies high risk that cannot be reduced or removed, the controller must consult the Authority in writing before starting processing, providing the information specified in Art.17(2) (responsibilities of parties, a copy of the DPIA, DPO contact details, and any other information requested)
- Controllers must not begin the processing in question until the JOIC has completed its review where consultation is required
- Where a DPO is appointed, their advice must be sought on whether to carry out a DPIA, its methodology, whether to outsource it, appropriate safeguards, and whether it has been carried out correctly (Art.26(1)(g))
- Controllers should, where appropriate, seek the views of data subjects or their representatives on intended high risk processing (Art.16(8))
- Controllers should keep a record of the decision on whether a full DPIA is needed, even where the conclusion is that one is not required
- DPIAs must be kept under review and reassessed if there are significant changes to the processing or its wider context
Applies to
data controllers, data processors, Data Protection Officers, organisations processing personal data in Jersey
Deadlines
- eight (8) weeks: JOIC will give written notice of its opinion on a submitted DPIA consultation within eight weeks of receiving the submission
- a further six (6) weeks: JOIC may extend its response period by six weeks in complex cases (up to fourteen weeks total), excluding time paused while awaiting further information from the controller