Statement of Guidance
What to think about before using Artificial Intelligence
Status not confirmedView on JOIC's website Source document
Summary
This is a JOIC guidance note explaining how the Data Protection (Jersey) Law 2018 (DPJL 2018) applies when an organisation designs, procures, deploys or uses Artificial Intelligence systems. It is structured in three parts: a general overview, an easy read section for individuals and less experienced organisations, and a technical section for controllers and processors. The guidance is non-binding but sets out how JOIC expects existing DPJL 2018 obligations to be applied to AI use, including embedded AI features that may already be switched on in everyday software.
- Scope of AI: Covers machine learning, generative AI (e.g. ChatGPT, Copilot, Gemini), agentic AI, embedded/built-in AI in everyday tools, and shadow AI used by staff without approval.
- Personal data does not disappear: Data fed into an AI system, and outputs it generates about an identifiable person (scores, rankings, predictions), remain personal data subject to full DPJL 2018 obligations.
- Pre-deployment checklist: Before using AI involving personal data, organisations should identify a lawful basis (Schedule 2 Part 1, or Part 2 for special category data), assess data hosting/cross-border transfer, review supplier contracts, consider children's data, and check whether the AI influences significant decisions (Art.38).
- Transparency and rights: Privacy notices must disclose AI use and explain logic and consequences of automated decisions; individuals can request access to and rectification of AI-generated outputs and can seek human intervention in automated decision-making (Art.38).
- DPIA and bias review: A DPIA is almost certainly required where AI makes decisions about individuals or uses sensitive data; bias audits should be carried out to test for discriminatory outcomes, with a documented methodology.
- Ongoing governance: Organisations must monitor AI performance and drift, reassess lawful basis and DPIAs when models are retrained or repurposed, and establish exit/decommissioning plans as part of continuing compliance.
- Breach reporting: Data breaches involving AI systems must be reported to the JOIC within 72 hours (Art.20 DPJL 2018).
The guidance stresses that using a third-party AI product does not transfer data protection responsibility away from the organisation, which remains the data controller. It applies equally to sole traders and small organisations as to large ones, with the effort required being proportionate to risk, and treats AI use generally as high-risk, evolving processing requiring proactive, documented compliance.
Key obligations
- Identify and document a lawful basis under Schedule 2 Part 1 (or Part 2 for special category data) of the DPJL 2018 before using personal data in an AI system
- Include information about AI use in privacy notices, in plain language, including the logic and consequences of AI-influenced decisions (Art.12 DPJL 2018)
- Carry out a Data Protection Impact Assessment where AI makes or influences significant decisions about individuals or processes sensitive data
- Enable individuals to request human intervention, access AI-generated outputs about themselves, and seek rectification of inaccurate AI outputs
- Provide a mechanism for individuals to object to AI-driven direct marketing and to understand automated decisions affecting them (Art.38 DPJL 2018)
- Report qualifying personal data breaches involving AI systems to the JOIC within 72 hours (Art.20 DPJL 2018)
- Conduct bias audits of AI outputs, at least at each retraining cycle and at least annually for systems with significant impact on individuals, and document findings and remedial action
- Establish an acceptable use policy addressing employee use of AI tools (shadow AI) and check what AI features are already active/switched on by default in existing software
- Assess cross-border transfer implications where AI platforms store or process personal data outside Jersey (Arts.66-67 DPJL 2018)
- Establish and periodically review exit and decommissioning plans for AI systems, and reassess lawful basis and DPIAs when models are retrained or repurposed
Applies to
data controllers, data processors, organisations using or deploying AI systems, sole traders and small organisations, HR and recruitment functions
Deadlines
- 72 hours: Data breaches involving AI systems must be reported to the JOIC within 72 hours (Art.20 DPJL 2018)
- at least annually: Bias audits should be conducted at least annually for AI systems that significantly impact individuals (e.g. recruitment, credit, benefits), even without retraining
- at each retraining cycle: Bias audits should be repeated at each model retraining cycle or whenever the system is applied to a new population or purpose