Regulatory Policy

Regulatory Action and Enforcement Policy

Jersey Office of the Information Commissioner (JOIC) · Jersey

In force

Published: 2025-08-19

Current version last checked: 2026-07-30

Summary

This is the Jersey Office of the Information Commissioner's (JOIC) published policy explaining how it will exercise its regulatory and enforcement powers under the Data Protection (Jersey) Law 2018 and the Data Protection Authority (Jersey) Law 2018. It sets out the principles, objectives and factors the JOIC uses to decide what action to take against controllers and processors, ranging from advice and warnings through to information notices, entry and search powers, audits, criminal referral and administrative fines. It does not create new legal duties beyond those in the underlying laws, but it does explain statutory timeframes and criteria that regulated organisations should be aware of.

  • Regulatory tools: The JOIC may use information notices, recommendations and determinations, orders, reprimands, warnings, public statements, administrative fines, powers of entry/search/seizure, and audits, and may support criminal investigations with the States of Jersey Police.
  • Information notices: A formal information notice requires a controller, processor or individual to respond within 28 days (a shorter period, generally no less than 7 days, may be set in urgent cases); providing a materially false response can be a criminal offence.
  • Choosing sanctions: The JOIC weighs factors such as severity, sensitivity of data, number of individuals affected, vulnerability, repeat or wilful conduct, cooperation, and aggravating/mitigating factors when deciding on action.
  • Administrative fines: Fine orders must specify a payment date (and may allow instalments), must be effective, proportionate and dissuasive, and are subject to statutory caps (up to £5,000,000, £10,000,000, or £300,000/10% of global turnover depending on the contravention, or £10,000 for not-for-profit public-interest processing).
  • Non-compliance with an information notice: If a notice is not fully complied with, the Commissioner may apply to a court for an order compelling a response, subject to discretionary factors.

The policy applies broadly to any controller, processor or individual subject to Jersey's data protection regime, and is intended to give regulated organisations, the public and JOIC staff clarity on the JOIC's proportionate, targeted, accountable, consistent and transparent approach to enforcement.

Key obligations

  • A person served with an information notice must respond within 28 days (or a shorter period, generally not less than 7 days, if the notice specifies an urgent shorter timeframe)
  • Providing a false or materially misleading response to an information notice may constitute a criminal offence
  • Where the Authority orders an administrative fine, the order must specify the date by which the fine is to be paid
  • Aggregate administrative fines for related contraventions of the same processing operations must not exceed the statutory cap applicable to the relevant provision

Applies to

controllers, processors, data protection officers, individuals subject to the Data Protection (Jersey) Law 2018

Deadlines

  • 28 days: Standard period for a controller, processor or individual to respond to a JOIC information notice
  • generally no shorter than 7 days: Minimum period the JOIC will generally allow for a response to an information notice in urgent cases

Topics

Version history

2026-07-30

source file (current)