Statement of Guidance
What does Enforcement look like? Procedures, Powers and Penalties, Criminal and Civil
Status not confirmedView on JOIC's website Source document
Summary
This JOIC guidance note explains how Jersey's Data Protection Authority (JDPA) enforces the Data Protection (Jersey) Law 2018 (DPJL) and the Data Protection Authority (Jersey) Law 2018 (DPAJL). It sets out the three types of enforcement activity (investigations, inquiries and audits), the sanctions the Authority can impose, when criminal offences arise, and the civil remedies available through the Royal Court.
- Enforcement tools: Reprimands, warnings, and orders (e.g. to correct or delete data, stop unlawful processing, notify breaches, or respond properly to access requests) can be issued against controllers and processors.
- Administrative fines: The Authority may impose fines up to a maximum of £10 million, taking into account factors such as the organisation's prior year turnover, number of people affected, harm caused, and speed of remediation.
- Public statements: The Authority may publish a summary of findings and orders (naming the controller/processor but not usually the complainant) where seriousness and public interest justify it, after required consultation/notice steps.
- Criminal offences: Failing to comply with an Authority order, unauthorised taking or sharing of personal data, forced subject access requests, giving false information, or obstructing investigators are criminal offences, prosecutable in the Royal Court and punishable by fines and/or up to two years' imprisonment.
- Civil remedies: Individuals suffering harm from non-compliant processing may seek compensation from the Royal Court (the Authority itself cannot award compensation); the Court can also grant injunctions and declarations.
- Appeals: Both individuals and organisations may appeal Authority decisions to the Royal Court, but only on grounds that the decision was unreasonable, unfair in law, or beyond the Authority's powers.
The guidance emphasises a proportionate, targeted approach: minor or resolved issues may be dealt with informally or not investigated at all (e.g. where a complaint is unfounded, frivolous, vexatious, unnecessarily repetitive, or otherwise excessive), while serious or repeated breaches can escalate to formal orders, fines, public statements, or criminal referral.
Key obligations
- Controllers and processors must comply with Authority orders (e.g. to correct or delete personal data, stop unlawful processing, notify data subjects of breaches, or respond properly to subject access requests) or risk criminal prosecution.
- Controllers and processors must not obstruct or block JOIC staff during an investigation and must not give false or misleading information to the Authority.
- Organisations must not compel or force an individual to make a subject access request for their own criminal record to obtain information the organisation cannot otherwise access (forced subject access request prohibition).
- Controllers must respond to individuals' subject access and other data subject rights requests within the statutory period.
- A controller or processor found liable for non-compliant processing that causes loss, damage or distress may be required to pay compensation as determined by the Royal Court, unless they prove they were not responsible for the event.
Applies to
data controllers, data processors, organisations processing personal data in Jersey