Notice
Public Statement - JRSY Laser Limited (2023-12-05)
Issued 2023-12-05View on JOIC's website Source document
Summary
This is a public statement issued by the Jersey Office of the Information Commissioner under Article 14 of the Data Protection Authority (Jersey) Law 2018, following an investigation into JRSY Laser Limited. It sets out findings that the company unlawfully disclosed a customer's special category (health) data to the customer's employer and a third party during a fee dispute, and identifies other compliance failures.
- Unlawful disclosure: A director (also the nominated DPO) threatened to, and did, disclose the data subject's health treatment details and the fee dispute to the data subject's employer and a receptionist, with no lawful basis, in contravention of Article 8(1)(a) and (b) of the DPJL 2018.
- Registration failures: JRSY Laser was not registered with the Authority and had not paid its registration fee, contravening Article 6(1)(b) and (c) of the DPJL 2018.
- No policies or training: The company had no processes or policies for handling customer personal data and failed to train staff, including the DPO, contravening Article 8(1)(f) of the DPJL 2018.
- Failure to respond to information notice: JRSY Laser failed to respond within the legal timeframe to a formal information notice issued under Article 22 of the DPAJL 2018, without good reason.
- Sanctions imposed: The Authority issued a formal reprimand and made orders under Article 25(3) of the DPAJL 2018 requiring completion of registration and review/updating of processes and staff training; these orders were completed within the required timeframe.
The statement is primarily a public enforcement notice recording completed corrective action rather than an ongoing set of requirements on other entities, but it serves as a warning that similar conduct (threatening disclosure of personal data, especially special category data, to coerce debt settlement) will be treated as an aggravating factor, with administrative fines explicitly flagged as likely in future similar cases. It also reiterates that DPOs must have adequate skills and independence, and that organisations must cooperate fully with Authority information requests within statutory timeframes.
Key obligations
- Data controllers must register with the Authority and pay the applicable registration fee as required by Article 6(1)(b) and (c) of the DPJL 2018
- Data controllers must have processes and policies in place for handling personal data and must provide appropriate data protection training to staff, including the DPO (Article 8(1)(f) DPJL 2018)
- Organisations must respond to formal information notices issued under Article 22 of the DPAJL 2018 within the legal timeframe
- Individuals performing the DPO function must have the necessary skills and experience and must be able to fulfil their duties independently, without conflict with other tasks
- Controllers must not use disclosure of personal data, particularly special category data, as leverage to force settlement of disputes such as fee disputes
Applies to
data controllers