Statement of Guidance
Transferring Personal Data Outside Jersey
Status not confirmedView on JOIC's website Source document
Summary
This is JOIC guidance explaining the rules in Part 8 of the Data Protection (Jersey) Law 2018 (DPJL 2018) that apply when personal data is sent from Jersey to a legally separate controller or processor in a country outside Jersey and the EEA (a 'Restricted Transfer'). It is aimed at controllers and processors of all sizes, from sole traders to financial services groups, and explains when a transfer is permitted and what steps must be documented beforehand.
- When the rules apply: Any transfer, however small or infrequent, of personal data from Jersey to a legally distinct receiver in a Third Country (any country outside Jersey/EU/EEA), including allowing remote access to Jersey-held data; transfers to employees, transfers within the same legal entity, and data merely transiting through a third country without being accessed there are not Restricted Transfers.
- Adequacy route: If the receiving Third Country has an EU Commission adequacy decision (including the UK), the transfer can proceed without further safeguards.
- Appropriate safeguards route: Where there is no adequacy decision, one of five appropriate safeguards under Art.67(2) must be used, most commonly Standard Contractual Clauses plus the Bailiwick of Jersey Addendum.
- Exceptions route: In the absence of adequacy or safeguards, a transfer may only proceed under one of the specific exceptions in Schedule 3 (e.g. explicit consent, contractual or legal necessity).
- Residual exception: A final, exceptional derogation (Schedule 8 paragraph 9) allows an occasional (non-repetitive) transfer involving a limited number of data subjects for compelling legitimate interests, but requires a documented balancing assessment, notification to the individuals concerned, and notification to JOIC as soon as practicable; public authorities cannot rely on it.
- Supporting tools: JOIC provides a Transfer Impact Assessment (TIA) checklist and template, and a Bailiwick of Jersey Addendum for use with SCCs.
The guidance stresses that transfers must be necessary and proportionate (data minimisation, considering anonymisation or Jersey-based alternatives), that senders remain responsible for compliance including for onward and sub-processor transfers, and that individuals must be told where their data is being sent as part of transparency obligations under Art.12.
Key obligations
- Before making any Restricted Transfer, assess and document why sending personal data outside Jersey is necessary and consider alternatives such as anonymisation or a Jersey-based supplier.
- Only transfer personal data to a Third Country if the country has an EU Commission adequacy decision, or appropriate safeguards under Art.67(2) DPJL 2018 (e.g. Standard Contractual Clauses plus the Bailiwick of Jersey Addendum) are in place, or a Schedule 3 exception applies.
- Where no adequacy decision applies, carry out and document a Transfer Impact Assessment (TIA) covering risks, safeguards and conclusions.
- Inform individuals where their personal data is being sent and processed, in line with transparency requirements under Art.12 DPJL 2018.
- Processors sending data to a sub-processor outside Jersey remain responsible for ensuring that transfer complies with the transfer rules.
- If relying on the residual 'compelling legitimate interests' exception (Schedule 8 paragraph 9), notify JOIC of the transfer as soon as practicable and provide full details of the necessity and balancing assessment, and inform the affected data subjects.
Applies to
controllers, processors, sole traders, trust companies, law firms, financial services companies, HR consultancies, public authorities
Deadlines
- as soon as practicable: Notify JOIC of a Restricted Transfer made under the residual Schedule 8 paragraph 9 exception (compelling legitimate interests).