Statement of Guidance

Exemptions - Arts.41-62 Data Protection (Jersey) Law 2018

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is JOIC guidance explaining the exemptions and modifications set out in Part 7 (Arts.41-62) of the Data Protection (Jersey) Law 2018. It does not create new law but explains when and how data controllers may lawfully depart from certain data protection principles and individual rights, such as the right to be informed, the right of access, and other subject rights.

  • National security (Art.41): Exempts processing from most DPJL principles and subject rights where required to safeguard national security, evidenced by a ministerial certificate.
  • Criminal record certifications (Art.42): Allows requests for criminal record certificates under the UK Police Act 1997 as applied in Jersey.
  • Manual data held by public authorities (Art.43): Exempts unstructured manual records from most of the Law except certain subject rights.
  • Special purposes (Art.44): Protects academic, journalistic, literary and artistic processing done with a view to publication in the public interest.
  • Crime and taxation (Art.45): Exempts transparency and subject rights obligations where compliance would prejudice crime prevention, prosecution, or tax collection.
  • Corporate finance (Art.46): Exempts certain financial services processing where disclosure could affect market prices or Jersey's financial stability.
  • Trusts, financial loss/charities/health and safety/maladministration/fair trading, negotiations, management forecasts (Arts.47-50): Exempt specific business, regulatory and negotiation-related processing from transparency and access rights where disclosure would cause harm.
  • Other statutory exemptions (Arts.51-62): Cover information already public by law, disclosures prohibited by other laws, confidential references, exam scripts, Crown/judicial appointments, armed forces, legal privilege, self-incrimination, States Assembly privilege, exam mark timing, health/education/social work records, and credit reference agency requests.

The guidance stresses that exemptions are not automatic or blanket: controllers must assess each case individually, apply the minimum departure from the Law necessary, and remain accountable and able to justify their reliance on an exemption. Data subjects retain rights to complain to JOIC, challenge decisions, and be protected from unlawful processing even where an exemption applies.

Key obligations

  • Controllers must assess reliance on any exemption on a case-by-case basis and not apply exemptions routinely or in a blanket fashion.
  • Controllers must apply exemptions only to the minimum extent necessary to protect the relevant interest or function.
  • Controllers must document their decision-making process when relying on an exemption, including who decided, what was considered, and why it was necessary.
  • Controllers must be able to demonstrate and justify compliance with the data protection principles, including decisions to withhold information under an exemption, to JOIC or a court if challenged.
  • Controllers must still comply with all parts of the DPJL 2018 not covered by the specific exemption relied upon.
  • Controllers should explain to a data subject, where possible, why information was withheld under an exemption.
  • Credit reference agencies receiving a request must give the individual a statement of their other rights in respect of credit reference agencies.
  • Scheduled public authorities must confirm whether they hold unstructured personal data about an individual unless doing so would exceed the prescribed cost limit.

Applies to

data controllers, data processors, public authorities, scheduled public authorities, credit reference agencies, financial services firms providing corporate finance services, courts

Topics

Version history

2026-07-30

source file (current)