Statement of Guidance

Your Duties and Responsibilities as a Data Controller

Jersey Office of the Information Commissioner (JOIC) · Jersey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is JOIC guidance explaining who counts as a data controller (as opposed to a processor or joint controller) under the Data Protection (Jersey) Law 2018, and setting out the practical duties controllers must meet, including how to appoint and oversee processors, when a Data Protection Officer (DPO) is required, and how to demonstrate accountability. It covers general organisations as well as trusts, foundations, funds and unincorporated structures where identifying the controller is less obvious.

  • Core controller duties: Use personal data fairly, lawfully and transparently; collect only what is necessary; keep it accurate; secure it appropriately; delete or anonymise it when no longer needed; and be able to demonstrate compliance (the accountability principle).
  • Individual rights: Provide privacy notices and enable individuals to exercise rights such as access, correction and erasure.
  • Processor appointments: Only use processors that can guarantee compliance, and put in place a written contract covering instructions, confidentiality, security, assistance with rights/breach requests, sub-processor approval, and data deletion/return at the end of processing.
  • Joint controllers: Where purposes and means are decided jointly, have a transparent written arrangement and make key details available to individuals.
  • Routine data sharing: Document why, what, how often and how data is shared with other organisations, and ensure individuals are informed and data remains accurate and necessary.
  • DPO appointment: Appoint a DPO where required (e.g. public authorities, or large-scale monitoring or special category data processing); support the DPO with independence, resources, access and board-level reporting; publish the DPO's (or responsible person's) contact details and register them with JOIC.
  • Special structures: For trusts, trustees are normally the controller(s); for foundations, the foundation itself is the controller; for funds/limited partnerships, the general or managing partner is typically the controller.
  • Accountability framework: Maintain written policies, training, breach/rights-request processes, records of processing, audits and documented decisions to evidence compliance.

The guidance also warns that controllers cannot avoid responsibility by relying on processors, and that non-compliance can lead to JOIC investigations, formal inquiries, enforcement orders, administrative fines of up to £5 million, and civil claims from affected individuals.

Key obligations

  • Process personal data fairly, lawfully and transparently, and collect only what is necessary for a clear purpose
  • Keep personal data accurate, up to date, and secured with appropriate technical and organisational measures
  • Delete or anonymise personal data when it is no longer needed and be able to evidence compliance (accountability)
  • Provide individuals with privacy information and enable them to exercise rights of access, correction and erasure
  • Enter into a written contract with any data processor covering instructions, confidentiality, security measures, assistance with data-subject rights and breach reporting, sub-processor approval, and data return/deletion at end of processing
  • Ensure joint controllers have a transparent written arrangement setting out respective responsibilities and make key terms available to individuals
  • Establish written, documented arrangements for routine data sharing with other organisations, including purpose, scope, frequency, storage and security responsibility
  • Appoint a DPO where required (public authorities, large-scale monitoring, or large-scale special category data processing), or otherwise designate a person responsible for data protection matters
  • Publish the DPO's or responsible person's contact details and provide them to JOIC as part of registration
  • Ensure the DPO is involved in all data protection matters, reports to the highest level of management, operates independently, and is given adequate resources and access
  • Maintain a data-protection management framework including policies, training, breach/rights-request procedures, records of processing activities and periodic audits
  • Document reasons for not following DPO advice to demonstrate accountability

Applies to

data controllers, joint controllers, data processors, public authorities, businesses, employers, charities, schools, unincorporated associations, trustees, foundations, fund managers/general partners, other Jersey-based organisations processing personal data

Topics

Version history

2026-07-30

source file (current)