Jersey

data protection

87 Jersey regulatory document(s) tagged data protection.

Practice-note overview · reflects instruments as at 2026-07-30. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

The Data Protection (Jersey) Law 2018 establishes a GDPR-equivalent regime for the processing of personal data of natural persons in Jersey. It applies broadly across public and private sector bodies that determine or carry out the processing of personal data in or connected with Jersey, and the companion Data Protection Authority (Jersey) Law 2018 provides the institutional and registration machinery that supports it.

  • Controllers and processors: The regime applies to controllers (who determine the purposes and means of processing), joint controllers, and processors, together with data protection officers where appointed.
  • Public and private sector: It reaches public authorities, government departments, companies, sole traders, charities, schools, and unincorporated structures such as trusts (where trustees are normally the controller), foundations (the foundation itself), and funds or limited partnerships (typically the general or managing partner).
  • Establishment in Jersey: Any controller or processor established in Jersey that processes personal data must register with the JOIC; guidance treats administered structures such as companies, trusts, foundations, private trust companies, JPUTs, cell companies and SPVs as within scope where they are established in Jersey.
  • Activity-based reach: Guidance confirms the Law applies to specific activities including CCTV and other surveillance (where identifiable individuals are captured), use of AI systems processing personal data, and transfers of personal data outside Jersey.
  • Cross-border transfers: The transfer rules in Part 8 apply to any transfer of personal data from Jersey to a legally distinct receiver in a country outside Jersey and the EEA, including allowing remote access to Jersey-held data.
  • Home users: The Law applies to home CCTV or doorbell camera users only where the camera captures images beyond the user's own property boundary, such as neighbours' land, communal areas or public space.

Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · What to think about before using Artificial Intelligence · Your Duties and Responsibilities as a Data Controller · Definitions, the Data Protection Principles and Lawful Bases · Transferring Personal Data Outside Jersey · Registration · Administered Registrations · CCTV and Surveillance at Work and at Home


Key duties

Substantive data handling obligations sit in the Data Protection (Jersey) Law 2018, while registration, charges and enforcement machinery sit in the Data Protection Authority (Jersey) Law 2018 and the Registration and Charges Regulations. The recurring, deadline-bearing duties are registration and annual charging, notification of changes, breach notification, and responding to data subject requests.

Registration and charges

  • Register before processing: Controllers and processors established in Jersey must register with the Authority under Article 17 before processing personal data, including at or before incorporation for new entities; processing without registration is a criminal offence.
  • Annual charge: Every registered controller and processor must pay an annual charge for each calendar year or part year of registration. The base amount ranges from 70 pounds to 500 pounds depending on full-time equivalent employee numbers, with additional amounts for high revenue, financial services registration, or processing of special category data.
  • Charge deadlines: The annual charge falls due on 1 January and must be paid by the last day of the following month; where registration occurs during the year, the charge falls due one month after registration. Guidance describes an annual renewal cycle expiring on 31 December, with renewal due by the last day of February.
  • Reduced administered charge: An entity administered by a trust company business or fund services business may pay a flat annual charge of 50 pounds instead of the standard calculation, but cannot also claim the Regulation 6(4) exemption.
  • Notify changes: Registered controllers and processors must notify the Authority of any change to registration particulars as soon as practicable and in any event within 28 days of the change; failure to keep the entry current is a criminal offence.

Core processing obligations

  • Principles and lawful basis: Controllers must comply with the six data protection principles, demonstrate accountability, and establish and document a lawful basis from Schedule 2 Part 1 (and a Part 2 condition for special category data) before processing begins.
  • Transparency: Controllers must provide data subjects with prescribed information, generally at the point of collection or, where data is obtained indirectly, within about four weeks.
  • Records of processing: Controllers must keep records of processing activities as required by the Law.
  • By design and default: Controllers must implement data protection by design and by default under Article 15, ensuring only necessary personal data is processed by default.
  • Security: Controllers and processors must implement and regularly review appropriate technical and organisational measures to secure personal data.
  • Processor contracts: Controllers must only appoint processors under a written contract meeting the Law's requirements, covering instructions, confidentiality, security, assistance with rights and breach requests, sub-processor approval, and data return or deletion.
  • Data protection officer: Specified controllers and processors (for example, public authorities, or those carrying out large-scale monitoring or large-scale special category processing) must appoint a data protection officer with defined functions and independence, and register the DPO or responsible person's contact details.

Impact assessments and consultation

  • DPIA: Controllers must carry out a data protection impact assessment before processing likely to result in high risk to individuals (for example large-scale profiling, surveillance, special category data, CCTV or facial recognition, and automated decision-making).
  • Prior consultation: Where a DPIA identifies high risk that cannot be reduced or removed, the controller must consult the Authority in writing under Article 17 and must not begin processing until the review is complete. JOIC must give its opinion within eight weeks, extendable by a further six weeks in complex cases.

Breach notification

  • Notify JOIC: Controllers must notify JOIC of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it under Article 20, in phases if full details are not yet available.
  • Notify individuals: Where a breach poses a high risk of harm, controllers must inform affected individuals without undue delay, unless protective measures such as encryption remove that high risk.
  • Breach log: Controllers must maintain a detailed log of all breaches, reportable or not, which JOIC may inspect during audits.
  • Processor duty: A processor that suffers a breach must notify the controller without undue delay; the controller remains responsible for notifying JOIC.

Individual rights and transfers

  • Rights requests: Controllers must give effect to data subject rights, including access, rectification, erasure, restriction, portability, and objection (including to direct marketing and automated decision-making). Guidance describes a standard four-week response period, extendable for complex requests with prior notice.
  • Cross-border transfers: Personal data may only be transferred outside Jersey and the EEA where an adequacy decision applies, appropriate safeguards under Article 67(2) are in place (such as Standard Contractual Clauses plus the Bailiwick of Jersey Addendum), or a Schedule 3 exception applies; a Transfer Impact Assessment should be documented where there is no adequacy decision.

Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Data Breaches - What they are and how to deal with them · Your Duties and Responsibilities as a Data Controller · Data Protection by Design and Default, and Data Protection Impact Assessments · Definitions, the Data Protection Principles and Lawful Bases · Individual Rights – what they are, how to exercise them and how to manage them · Transferring Personal Data Outside Jersey · Registration · Administered Registrations


Exemptions and carve-outs

The instruments provide two broad categories of relief: exemptions from the registration charge, and exemptions or modifications from certain data protection principles and individual rights. The guidance stresses that the substantive exemptions are not automatic or blanket.

Registration and charge relief

  • Charge exemptions: Certain processing is exempt from the annual charge, including processing by public authorities, election candidates, provided schools, businesses solely retaining records after ceasing to trade, and qualifying non-profit associations, subject to conditions in the Schedule.
  • Household processing: Guidance indicates purely personal or domestic processing (and non-personal data or national security processing) falls outside the registration duty; the Law also recognises personal and household exemptions in its material scope.
  • Transitional re-registration: Under the Authority Law, controllers already registered under the 2005 Law, and all processors, were exempt from re-registering until the end of a defined registration period, with processors previously unregistered required to register within a 26-week transitional period.

Exemptions from principles and rights

Part 7 (Articles 41 to 62) of the Data Protection (Jersey) Law 2018 sets out numerous exemptions and modifications from transparency and subject rights obligations. These must be assessed case by case, applied to the minimum extent necessary, and documented.

  • Listed purposes: Exemptions include national security (evidenced by a ministerial certificate), crime and taxation, corporate finance, trusts, legal privilege, and other listed categories.
  • Further statutory cases: Articles 51 to 62 cover matters such as information already public by law, confidential references, exam scripts, Crown and judicial appointments, armed forces, self-incrimination, States Assembly privilege, and health, education and social work records.

On transfers, adequacy, appropriate safeguards and the specific Schedule 3 exceptions (and the residual compelling legitimate interests derogation) operate as the routes permitting transfers that would otherwise be restricted; public authorities cannot rely on the residual derogation.

Sources: Data Protection (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Exemptions - Arts.41-62 Data Protection (Jersey) Law 2018 · Transferring Personal Data Outside Jersey · Registration


Enforcement and penalties

Enforcement is exercised by the Data Protection Authority (JOIC), which can use investigations, inquiries and audits, and a graduated range of sanctions. Reprimands, warnings and orders can be issued against controllers and processors, escalating to administrative fines, public statements and criminal referral.

Enforcement powers

  • Investigation tools: The Authority may issue information notices, enter and search premises subject to safeguards and warrant requirements, and conduct or require data protection audits, with the audited controller or processor bearing the cost of a required audit.
  • Information notices: A person served with an information notice must respond within 28 days (or a shorter period, generally not less than 7 days, in urgent cases); a materially false response may be a criminal offence.
  • Orders and reprimands: The Authority can issue reprimands and orders requiring remedial action such as correcting or deleting data, stopping unlawful processing, notifying breaches, or responding properly to access requests.
  • Public statements: The Authority may publish a summary of findings and orders, naming the controller or processor, where seriousness and public interest justify it.

Administrative fines

  • Statutory caps: The enforcement policy states administrative fines are subject to statutory caps of up to 5,000,000 pounds, 10,000,000 pounds, or 300,000 pounds or 10 percent of global turnover depending on the contravention, and 10,000 pounds for not-for-profit public-interest processing. Other guidance refers to fines up to 5,000,000 pounds and up to 10,000,000 pounds in different contexts.
  • Public authority exception: Multiple enforcement statements confirm the Authority cannot currently impose administrative fines on public authorities; in those cases reprimands and orders are used instead.
  • Fines in practice: Published fines to date include 500 pounds against JRSY Laser Limited and 4,000 pounds against a sole trader trading as Star-Delta Electrical Services, both involving unlawful sharing of personal data during fee disputes.
  • Non-payment: Failure to pay an administrative fine can lead to civil debt recovery through the Petty Debts or Royal Court, including wage arrest or distraint of goods.

Criminal and civil

  • Criminal offences: Offences include failing to comply with an Authority order, unauthorised taking or sharing of personal data, forced subject access requests, providing false information, and obstructing investigators, prosecutable in the Royal Court and punishable by fines and/or up to two years' imprisonment. Processing without registration and failing to keep an entry current are also criminal offences.
  • Compensation: Individuals suffering loss, damage or distress from non-compliant processing may seek compensation from the Royal Court; the Authority itself cannot award compensation, and the Court may also grant injunctions and declarations.
  • Appeals: Both individuals and organisations may appeal Authority decisions to the Royal Court of Jersey within 28 days, on the ground that the decision was unreasonable, unfair in law, or beyond the Authority's powers.

Sources: Data Protection Authority (Jersey) Law 2018 · Data Breaches - What they are and how to deal with them · What does Enforcement look like? Procedures, Powers and Penalties, Criminal and Civil · How We Deal with Complaints · Public Statement - Jersey Financial Services Commission (2025-10-25) · Public Statement - Star Delta Electrical Services Fine (2025-03-25) · Public Statement - JRSY Laser Limited Fine (2025-03-18) · Public Statement - Government of Jersey Customer & Local Services (2023-10-14) · Public Statement - Children's Services (2022-02-22) · Public Statement - Children's Services (2021-10-21) · Public Statement - Planning & Building Control (2020-10-19) · Regulatory Action and Enforcement Policy

Documents

CitationRegulatorType
2020 MoU between the Jersey Data Protection Authority and the Guernsey Office of the Data Protection AuthorityJOICAgreement
2021 MoU between the Jersey Data Protection Authority and the Channel Islands Financial OmbudsmanJOICAgreement
2022 MoU between the Jersey Data Protection Authority/Information Commissioner and the States of Jersey PoliceJOICAgreement
2023 MoU between the Jersey Data Protection Authority/Information Commissioner and the Office of the Children's Commissioner for JerseyJOICAgreement
2024 MoU between JDPA/Jersey Information Commissioner and the UK Information CommissionerJOICAgreement
2024 MoU between the JDPA and the Comptroller and Auditor GeneralJOICAgreement
2024 MoU between the Jersey Data Protection Authority and The Gibraltar Regulatory AuthorityJOICAgreement
2024 MoU with The ADGM Office of Data ProtectionJOICAgreement
2024 MoU with The Isle of Man Information CommissionerJOICAgreement
2025 MoU between JDPA/Information Commissioner and Jersey Cyber Security CentreJOICAgreement
Administered RegistrationsJOICStatement of Guidance
Bailiwick of Jersey Addendum to the EU Standard Contractual ClausesJOICForm
Breach Log TemplateJOICForm
CCTV and Surveillance at Work and at HomeJOICStatement of Guidance
Case Studies - Learning from ExperienceJOICStatement of Guidance
Checklist - Legitimate Interests Assessment (LIA)JOICForm
Checklist Am I a Controller Joint Controller or ProcessorJOICForm
Checklist Appointing a Data ProcessorJOICForm
Checklist Breach Response PlanJOICForm
Checklist Data SharingJOICForm
Checklist Home Surveillance and CCTVJOICForm
Checklist Surveillance System Deployment Businesses OrganisationsJOICForm
Checklist Training SelectionJOICForm
Checklist: Accountability & GovernanceJOICForm
Checklist: Drafting a Data Protection Statement/Privacy NoticeJOICForm
Crown Dependency Data Protection Advisory - Generative AI Image Creation (2026-02-23)JOICAdvisory
DPIA ChecklistJOICForm
DPIA templateJOICForm
Data Breaches - What they are and how to deal with themJOICStatement of Guidance
Data Protection (International Co-operation) (Jersey) Regulations 2005JOICRegulation
Data Protection (Jersey) Law 2018JOICAct
Data Protection (Registration and Charges) (Jersey) Regulations 2018JOICRegulation
Data Protection Authority (Jersey) Law 2018JOICAct
Data Protection Statement TemplateJOICForm
Data Protection by Design and Default, and Data Protection Impact AssessmentsJOICStatement of Guidance
Definitions, the Data Protection Principles and Lawful BasesJOICStatement of Guidance
Exemptions - Arts.41-62 Data Protection (Jersey) Law 2018JOICStatement of Guidance
General AI ChecklistJOICForm
Guidance on applications to make information unavailable on the public registerJFSCStatement of Guidance
Guidance on the use of AI in Jersey's financial services sectorJFSCStatement of Guidance
HR AI ChecklistJOICForm
How We Deal with ComplaintsJOICStatement of Guidance
Individual Rights – what they are, how to exercise them and how to manage themJOICStatement of Guidance
JDPA Revised Fee Model Consultation Paper 2025-2026JOICConsultation Paper
Joint Statement on AI-Generated Imagery and the Protection of Privacy (2026-02-23)JOICAdvisory
Key Findings from a Full Compliance Audit 2023/4 (2024-08-12)JOICAdvisory
Key findings from a Virtual Compliance Audit 2023/4 (2024-12-01)JOICAdvisory
Key findings from a Virtual Compliance Audit 2024-2025 (2025-03-21)JOICAdvisory
Public Statement - Brenwal Limited (2023-11-13)JOICNotice
Public Statement - CSS Limited (2020-01-28)JOICNotice
Public Statement - Children's Services (2021-10-21)JOICNotice
Public Statement - Children's Services (2022-02-22)JOICNotice
Public Statement - Department for Children, Young People, Education and Skills (CYPES) (2025-09-25)JOICNotice
Public Statement - Government of Jersey Customer & Local Services (2023-10-14)JOICNotice
Public Statement - JRSY Laser Limited (2023-12-05)JOICNotice
Public Statement - JRSY Laser Limited Fine (2025-03-18)JOICNotice
Public Statement - Jersey Financial Services Commission (2025-10-25)JOICNotice
Public Statement - Parish of Grouville (2025-10-14)JOICNotice
Public Statement - Planning & Building Control (2020-10-19)JOICNotice
Public Statement - Star Delta Electrical Services Fine (2025-03-25)JOICNotice
Public Statement - The Office of the Financial Services Ombudsman (2025-10-28)JOICNotice
RegistrationJOICStatement of Guidance
Registry system statement (2024-03-07)JFSCNotice
Regulatory Action and Enforcement PolicyJOICRegulatory Policy
Statement following Credit Reference Agencies Announcement (2026-07-03)JOICNotice
Template - Data Protection Impact Assessment (DPIA)JOICForm
Template CCTV Surveillance SignageJOICForm
Template Data Protection Impact AssessmentJOICForm
Template Data Protection StatementJOICForm
Template Legitimate Interests Assessment (LIA)JOICForm
Template Letter Erasure RequestJOICForm
Template Letter Request for PortabilityJOICForm
Template Letter for Individual Raising a ComplaintJOICForm
Template Letter for Rectification RequestJOICForm
Template Letter for Right of Access RequestJOICForm
Template Letter to Data Subjects affected by the Data BreachJOICForm
Template Letter to Neighbour Notifying of Installation of CCTVJOICForm
Template Letter to Neighbour asking about CCTV already InstalledJOICForm
Template Letter to Raise an Objection for Automated ProcessingJOICForm
Template Letter to Raise an Objection to ProcessingJOICForm
Template Letter to Restrict ProcessingJOICForm
Template Record of Processing ActivityJOICForm
Transfer Impact Assessment ChecklistJOICForm
Transferring Personal Data Outside JerseyJOICStatement of Guidance
What does Enforcement look like? Procedures, Powers and Penalties, Criminal and CivilJOICStatement of Guidance
What to think about before using Artificial IntelligenceJOICStatement of Guidance
Your Duties and Responsibilities as a Data ControllerJOICStatement of Guidance