Notice
Public Statement - Jersey Financial Services Commission (2025-10-25)
Issued 2025-10-25View on JOIC's website Source document
Summary
This is a public statement issued by the Jersey Office of the Information Commissioner (Jersey Data Protection Authority) following an Inquiry into a personal data breach suffered by the Jersey Financial Services Commission (JFSC) via its Companies Registry portal. A software vulnerability allowed unauthorised access to the names and addresses of 66,806 individuals. The Authority found the JFSC in breach of its data security and data-protection-by-design obligations under the Data Protection (Jersey) Law 2018 and issued a formal reprimand.
- Findings: JFSC contravened Art.8(1)(f) DPJL 2018 (failure to ensure appropriate security/integrity and confidentiality of personal data) and Arts.15(1)(a) and (b) DPJL 2018 (failure to implement data protection by design and default, including inadequate testing and monitoring).
- Cause: A programming/configuration flaw in third-party software implemented in 2021 allowed unregistered users to access personal data that should not have been publicly available; the flaw went undetected until early 2024.
- Sanction: A formal reprimand was issued under Art.25(3) of the Data Protection Authority (Jersey) Law 2018; no formal remedial orders were imposed given the JFSC's proactive remediation, and no administrative fine was considered because public authorities are not currently subject to such fines.
- Mitigating factors: Full cooperation with the Inquiry, frank admissions of shortcomings, proactive introduction of mitigations (including regular Registry portal reporting) without direction from the Authority, and no evidence of detriment to affected individuals.
- Lessons for organisations: The Authority reiterates that organisations must build data protection by design and default into all systems, processes and third-party arrangements, and highlights use of Data Protection Impact Assessments (DPIAs) as a living, ongoing risk management tool.
This document is a case-specific enforcement notice about the JFSC's own contravention; it does not itself impose new generic rules on other organisations, but its 'Lessons Learned' section restates existing data-by-design and DPIA obligations that apply broadly to controllers under the DPJL 2018.
Key obligations
- Controllers must ensure processing of personal data uses appropriate technical and organisational measures to guarantee security, integrity and confidentiality (Art.8(1)(f) DPJL 2018).
- Controllers must implement data protection by design and by default at both the design and processing stages of any system or activity (Arts.15(1)(a) and (b) DPJL 2018).
- Controllers remain responsible for ensuring third-party products, software and outsourced service providers comply with data protection requirements.
- Organisations should use Data Protection Impact Assessments (DPIAs) as an ongoing, regularly reviewed process for new projects and processing activities.
- Controllers must notify affected individuals where a personal data breach is likely to result in a high risk to their rights and freedoms (Art.20(6) DPJL 2018).
Applies to
Jersey Financial Services Commission (public authority/data controller), organisations acting as data controllers generally (as addressed in the Lessons Learned section)