Notice
Public Statement - The Office of the Financial Services Ombudsman (2025-10-28)
Issued 2025-10-28View on JOIC's website Source document
Summary
This is a public statement issued by the Jersey Office of the Information Commissioner (the Authority) under Article 14 of the Data Protection Authority (Jersey) Law 2018, following an investigation into the Channel Islands Financial Ombudsman (CIFO, formally the Office of the Financial Services Ombudsman) as a data controller. The investigation, triggered by a complaint about CIFO's handling of three data subject access requests (DSARs), found multiple contraventions of the Data Protection (Jersey) Law 2018 and resulted in a formal reprimand and corrective orders.
- Contraventions found: CIFO breached Art.6(1)(d) (safeguards for rights of individuals), Art.8(1)(a) (lawful, fair and transparent processing), Arts.15(1)(a-b) (adequate resourcing), Art.27(1) (responding to DSARs within the legal period), Arts.28(1)(a-h) (assisting data subjects' understanding of information provided), Art.28(3)(a) (addressing all relevant data, including phone call data) and Art.28(4)(b) (reasonable application of redactions) of the DPJL 2018.
- DPO deficiency: CIFO's Data Protection Officer lacked sufficient knowledge of internal case handling processes to fulfil the DPO role adequately, raising concerns under Art.25(1)(b) of the DPJL 2018.
- Sanction: A formal reprimand was issued to CIFO on 30 May 2025, together with orders under Art.25(3) of the DPAJL 2018.
- Orders imposed: CIFO was ordered to review its DSAR process and procedures, ensure staff handling DSARs receive up-to-date training, and upskill its DPO to understand internal processes; CIFO has since completed these orders to a satisfactory standard.
- Publication rationale: The Authority determined that publishing this enforcement action was in the public interest given CIFO's role as an ombudsman responsible for protecting consumer and individual rights.
The statement also sets out broader lessons for all organisations regarding DSAR handling: appropriate organisational and technical measures must be in place, DPOs must have adequate training, skills, independence and support, and organisations must cooperate fully with Authority investigations and respond to information requests within legal timeframes, with non-cooperation potentially constituting a criminal offence.
Key obligations
- Data controllers must respond to data subject access requests within the legal period set out in the DPJL 2018
- Data controllers must ensure appropriate organisational and technical measures and adequate resourcing are in place to handle DSARs lawfully, fairly and transparently
- Responses to DSARs must include sufficient explanation to aid the data subject's understanding of the personal information provided, and must address all relevant data (including matters such as phone call data)
- Redactions and exemptions applied to DSAR responses must be reasonable and properly justified, particularly regarding third-party data
- Any individual performing the DPO function must have necessary training, skills and experience, be able to act independently without conflicting duties, and receive adequate organisational support
- Organisations must cooperate fully with the Authority's investigations and respond to information requests within legally prescribed periods; failure to do so may constitute a criminal offence
- CIFO specifically was ordered to review its DSAR process and procedures, provide up-to-date training to staff handling DSARs, and upskill its DPO
Applies to
data controllers, statutory bodies, the Office of the Financial Services Ombudsman (CIFO)