Statement of Guidance
Individual Rights – what they are, how to exercise them and how to manage them
Status not confirmedView on JOIC's website Source document
Summary
This is JOIC guidance explaining the individual rights set out in Part 6 of the Data Protection (Jersey) Law 2018, aimed both at members of the public (in easy-read form) and at data controllers/processors who must action these rights. It summarises what each right covers, how individuals can exercise it, and what organisations must do in response, including standard response timeframes and grounds for refusal.
- Right to be informed (Art.12): Controllers must proactively give individuals clear information about data collection and use, generally at the point of collection or within about 4 weeks if data is obtained from another source.
- Right of subject access (Art.28): Individuals can request a DSAR; controllers must respond within 4 weeks (extendable if complex, with notice given before the deadline), providing personal data and required contextual information while protecting third-party data.
- Right to rectification (Art.31): Controllers must correct inaccurate or incomplete data or explain refusal, record disputes, and notify recipients of corrections where feasible, within the 4-week response period.
- Right to erasure (Art.32): Controllers must erase data on specified grounds unless a listed exemption applies (legal obligation, public interest, legal claims, etc.), notifying other holders of the data where feasible, within 4 weeks.
- Right to restriction of processing (Art.33): Individuals can request restriction of processing in certain circumstances, handled under the same response timeframe.
- Right to data portability (Art.34): Controllers must provide certain consent- or contract-based automated data in a structured, machine-readable format, or transfer it to another organisation, within 4 weeks.
- Rights to object (Arts.35-37): Individuals can object to processing for public functions/legitimate interests, direct marketing, or historical/scientific purposes.
- Automated decision-making and profiling (Art.38): Solely automated decisions with legal or similarly significant effects are restricted; where used, controllers must conduct a DPIA, give meaningful information about the logic and consequences, allow human intervention, and enable individuals to challenge decisions.
The guidance also provides practical tools (template letters and checklists) for individuals to exercise rights and for controllers to manage requests, and confirms that unresolved disputes can be escalated to the JOIC.
Key obligations
- Controllers must provide required information to individuals at the point of collection, or within about 4 weeks if data is obtained indirectly, unless an exemption applies.
- Controllers must respond to subject access requests (DSARs) within 4 weeks, extending only for complex requests and notifying the individual of the delay before the initial deadline expires.
- Controllers must correct or complete inaccurate/incomplete personal data on request, or explain refusal and record the dispute, within 4 weeks.
- Controllers must notify other recipients of corrected or erased data where feasible, unless this is impossible or requires disproportionate effort.
- Controllers must erase personal data on request where a valid ground applies and no exemption (legal obligation, public interest, legal claims, etc.) applies, responding within 4 weeks.
- Controllers must provide portable, machine-readable copies of qualifying personal data, or transfer it to another organisation on request, within 4 weeks.
- Controllers must respond to objections to processing (public functions/legitimate interests, direct marketing, historical/scientific purposes) and to automated decision-making objections.
- Controllers using solely automated decision-making or profiling with legal or similarly significant effects must conduct a DPIA, provide meaningful information about the logic and consequences, enable human intervention, and allow individuals to express their views and challenge decisions.
- Controllers must respond to initial concerns raised by individuals within 4 weeks before the individual escalates to the JOIC.
Applies to
data controllers, data processors, organisations processing personal data (including Government, companies, sole traders, charities)
Deadlines
- within 4 weeks: Standard timeframe for controllers to respond to right to be informed queries, DSARs, rectification, erasure, restriction and portability requests, and to concerns raised directly with them, extendable for complex requests if the individual is notified before the deadline.