Notice

Public Statement - Children's Services (2022-02-22)

Jersey Office of the Information Commissioner (JOIC) · Jersey

Issued 2022-02-22

Current version last checked: 2026-07-30

Summary

This is a public statement issued by the Jersey Office of the Information Commissioner (acting as the Data Protection Authority) against the Children's Service, Government of Jersey, following an inquiry into a self-reported personal data breach. The Authority found the Controller had contravened the Data Protection (Jersey) Law 2018 on three counts relating to two separate security incidents and a late breach notification.

  • Contravention 1: Sensitive child protection information was inadvertently disclosed to family members who remained connected to a Star Leaf video conference call when they should have been excluded, and the information was later shared with third parties and posted on social media.
  • Contravention 2: Details of a complaint about the same meeting were emailed to an unintended recipient.
  • Contravention 3: Both breaches were not reported to the Authority within the required 72-hour window under Article 20(1) of the DPJL 2018.
  • Outcome: The Authority imposed a formal reprimand and ordered updates to internal processes for using Star Leaf and staff training/education; no fine was imposed because administrative fines cannot be levied against public authorities.

The statement lists mitigating factors (cooperation, early admissions, and remedial steps already taken such as updated Star Leaf procedures, mandatory encryption of sensitive emails, restrictions on device use, and staff reminders about 72-hour breach reporting) and notes there were no aggravating factors. It confirms any affected party has a right of appeal to the Royal Court of Jersey within 28 days.

Key obligations

  • Controllers must ensure personal data is processed with appropriate technical and organisational security measures under Article 8(1)(f) of the DPJL 2018
  • Controllers must notify the Authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, under Article 20(1) of the DPJL 2018
  • The Children's Service is required to implement the ordered remedial measures, including updated processes for use of the Star Leaf platform and staff education/training

Applies to

public authority data controllers, Children's Services Department, Government of Jersey

Deadlines

  • 72 hours after becoming aware of a breach: Statutory deadline under Art.20(1) DPJL 2018 for notifying the Authority of a personal data breach
  • 28 days: Time limit for an affected party to appeal the Authority's determination to the Royal Court of Jersey under Art.32 of the Authority Law

Topics

Version history

2026-07-30

source file (current)