Jersey

data protection

84 Jersey regulatory document(s) tagged data protection.

Practice-note overview · reflects instruments as at 2026-09-07. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

Jersey's data protection regime rests on two principal statutes. The Data Protection (Jersey) Law 2018 sets the substantive rules for handling personal data and implements GDPR-equivalent standards, while the Data Protection Authority (Jersey) Law 2018 creates the Jersey Office of the Information Commissioner (JOIC, the Authority) and provides the registration, fee and enforcement machinery. Both apply broadly across the public and private sectors to anyone processing personal data.

  • Controllers and processors: Any controller or processor that determines or carries out the processing of personal data is caught, whether a company, sole trader, charity, public authority or government department.
  • Establishment in Jersey: JOIC guidance treats controllers and processors established in Jersey as required to register before processing personal data, including newly formed entities at or before incorporation.
  • Administered structures: Trusts, foundations, funds, private trust companies, family offices, JPUTs, cell companies and SPVs administered by trust company or fund services businesses fall within scope; trustees, the foundation itself, or the general/managing partner are typically the controller.
  • Public authorities: Public authorities and scheduled public authorities are within scope, subject to specific modifications and to schedules on law enforcement processing.
  • Surveillance and AI users: Organisations using CCTV, ANPR, facial recognition, drones, workplace monitoring or AI systems that process identifiable individuals' data are within scope; home CCTV users come within scope where cameras capture beyond their own property boundary.

The regime also reaches cross-border activity: transfers of personal data outside Jersey engage Part 8 of the Data Protection (Jersey) Law 2018, and the Data Protection (International Co-operation) (Jersey) Regulations 2005 impose duties on the Authority itself when co-operating with foreign data protection authorities under Convention 108.

Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Data Protection (International Co-operation) (Jersey) Regulations 2005 · What to think about before using Artificial Intelligence · Your Duties and Responsibilities as a Data Controller · Transferring Personal Data Outside Jersey · Registration · Administered Registrations · CCTV and Surveillance at Work and at Home


Key duties

The continuing obligations divide into registration and charging duties owed to the Authority, and substantive processing obligations under the Data Protection (Jersey) Law 2018. The duties carrying fixed deadlines are registration, annual charge payment and notification of changes.

Registration and charges

  • Register with the Authority: Controllers and processors must register under Article 17 of the Data Protection Authority (Jersey) Law 2018 before processing personal data; processing without registration is a criminal offence.
  • Annual charge: Registered controllers and processors must pay an annual charge for each calendar year (or part) under the Data Protection (Registration and Charges) (Jersey) Regulations 2018. The base amount ranges from £70 to £500 by full-time equivalent staff numbers, with additions for high revenue, financial services registration or special category data processing; administered entities may instead pay a flat £50.
  • Payment deadlines: The charge falls due on 1 January and must be paid by the last day of the following month; where registration occurs during the year, it falls due one month after registration. Renewal must be completed by the last day of February each year or the registration expires.
  • Notify changes: Registered controllers and processors must notify JOIC of any change to their registration particulars as soon as practicable and in any event within 28 days.
  • Substantiate the charge: When paying, a payer must supply sufficient information to identify itself and substantiate the correct charge amount, and provide any further information the Authority requests.

Core processing obligations

  • Principles and lawful basis: Controllers must comply with the data protection principles (Article 8) and process lawfully, fairly and transparently, identifying a lawful basis from Schedule 2 Part 1 (and a condition from Schedule 2 Part 2 for special category data) before processing begins.
  • Transparency and records: Controllers must provide required information to data subjects (Articles 9-13) and keep records of processing activities, and comply with data protection by design and by default under Article 15.
  • DPIAs: A data protection impact assessment must be carried out before high-risk processing (Article 16); where high risk cannot be mitigated the controller must consult the Authority in writing under Article 17 before processing starts. JOIC must give its opinion within eight weeks, extendable by a further six weeks.
  • Processor contracts and security: Controllers must appoint processors under written contracts (Article 19), and both controllers and processors must implement appropriate technical and organisational security measures (Articles 21-23).
  • Data protection officers: Certain controllers and processors must appoint a DPO with defined independence and duties (Articles 24-26), for example public authorities and those undertaking large-scale monitoring or special category data processing.

Breaches, rights and transfers

  • Breach notification: Controllers must notify JOIC of a personal data breach without undue delay and, where feasible, within 72 hours (Article 20), and must inform affected individuals where the breach poses a high risk. Processors must notify the controller without undue delay, and controllers should maintain a breach log of all breaches.
  • Data subject rights: Controllers must handle rights requests under Part 6 (access, rectification, erasure, restriction, portability, objection, and automated decision-making) within statutory procedures. JOIC guidance sets the standard response period at four weeks, extendable for complex requests.
  • Cross-border transfers: Restricted transfers outside Jersey may only proceed on the adequacy route, under appropriate safeguards (Article 67(2), such as Standard Contractual Clauses plus the Bailiwick of Jersey Addendum), or under a Schedule 3 exception. Where no adequacy decision applies a documented Transfer Impact Assessment should be carried out, and the residual Schedule 8 paragraph 9 exception requires notification to JOIC and to the affected individuals.

Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Data Breaches - What they are and how to deal with them · Your Duties and Responsibilities as a Data Controller · Data Protection by Design and Default, and Data Protection Impact Assessments · Definitions, the Data Protection Principles and Lawful Bases · Individual Rights – what they are, how to exercise them and how to manage them · Transferring Personal Data Outside Jersey · Registration · Administered Registrations


Exemptions and carve-outs

Exemptions operate at two levels: substantive exemptions from principles and subject rights under Part 7 of the Data Protection (Jersey) Law 2018, and exemptions from the registration charge under the Registration and Charges Regulations.

Statutory exemptions (Part 7)

  • Listed purposes: Articles 41 to 62 disapply certain transparency or subject-rights provisions for national security (evidenced by a ministerial certificate), crime and taxation, journalism and other special purposes, legal privilege, health and social work, corporate finance, and other listed business, regulatory and negotiation purposes.
  • Not blanket: JOIC guidance stresses exemptions are not automatic: controllers must assess each case individually, apply the minimum departure necessary, document their decision, and remain accountable; data subjects retain the right to complain to JOIC.
  • Material scope carve-outs: JOIC guidance identifies purely personal or household processing as outside the Law, and confirms that data merely transiting a third country without being accessed there, and transfers within the same legal entity, are not Restricted Transfers.

Registration and charge exemptions

  • Charge exemptions: Certain processing is exempt from the annual charge, including processing by public authorities, election candidates, provided schools, businesses solely retaining records after ceasing to trade, and qualifying non-profit associations, subject to the Schedule conditions.
  • Administered reduction: A controller or processor administered by a trust company or fund services business may pay a flat £50 annual charge instead of the standard calculation, but cannot also claim the Regulation 6(4) exemption.
  • Transitional exemption: Under Schedule 2 of the Data Protection Authority (Jersey) Law 2018, controllers already registered under the 2005 Law, and all processors, were exempt from re-registering until the end of a defined registration period, with unregistered processors required to register within a 26 week transitional window.
  • Public authorities and fines: Public authorities are exempt from administrative fines; JOIC has repeatedly noted it could not fine public-sector controllers and issued reprimands and orders instead.

Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Exemptions - Arts.41-62 Data Protection (Jersey) Law 2018 · Transferring Personal Data Outside Jersey · Registration · Public Statement - Jersey Financial Services Commission (2025-10-25) · Public Statement - Government of Jersey Customer & Local Services (2023-10-14) · Public Statement - Children's Services (2022-02-22) · Public Statement - Children's Services (2021-10-21) · Public Statement - Planning & Building Control (2020-10-19)


Enforcement and penalties

Enforcement is administered by JOIC under the Data Protection Authority (Jersey) Law 2018, which provides for investigations, inquiries and audits, together with sanctions ranging from advice through reprimands, orders and public statements to administrative fines. Criminal offences and civil remedies sit alongside these powers.

Administrative sanctions and fines

  • Orders and reprimands: The Authority may issue words of advice, warnings, formal reprimands, and orders (for example under Article 25(3) of the Data Protection Authority (Jersey) Law 2018) requiring remedial action such as correcting or deleting data, stopping unlawful processing, notifying breaches, or improving processes and staff training.
  • Administrative fines: The Regulatory Action and Enforcement Policy states fines are subject to statutory caps of up to £5,000,000, £10,000,000, or £300,000 / 10% of global turnover depending on the contravention, and £10,000 for not-for-profit public-interest processing. Separate JOIC guidance describes an overall maximum of £10 million, and states that failing to notify a breach when required can attract a fine of up to £5,000,000.
  • Worked examples: Imposed fines in the indexed public statements have been modest: £500 against JRSY Laser Limited and £4,000 against Star-Delta Electrical Services, in each case with a reprimand and orders.
  • Public statements: The Authority may publish a summary of findings and orders (naming the controller or processor) under Article 14 of the Data Protection Authority (Jersey) Law 2018 where seriousness and public interest justify it.
  • Information and audit powers: Under Schedule 1 of the Data Protection Authority (Jersey) Law 2018, authorised officers may issue information notices (requiring a response within 28 days, or a shorter urgent period generally not less than 7 days), enter and search premises subject to safeguards, and require data protection audits at the audited party's cost.

Criminal offences and civil remedies

  • Criminal offences: JOIC guidance states that failing to comply with an Authority order, unauthorised taking or sharing of personal data, forced subject access requests, giving false information, and obstructing investigators are criminal offences, prosecutable in the Royal Court and punishable by fines and/or up to two years' imprisonment. Providing a materially false response to an information notice may also be an offence.
  • Compensation: Individuals who suffer harm from non-compliant processing may seek compensation from the Royal Court, which can also grant injunctions and declarations; the Authority itself cannot award compensation.
  • Non-payment of fines: Failure to pay an administrative fine can lead to civil debt recovery through the Petty Debts or Royal Court, including wage arrest or distraint of goods.
  • Appeals: Controllers, processors and complainants may appeal a rejection of complaint or final determination to the Royal Court of Jersey within 28 days, on grounds that the decision was unreasonable, unfair in law, or beyond the Authority's powers.
  • Public authorities: Public authorities are not currently subject to administrative fines; enforcement against them has proceeded by reprimand and orders.

Sources: Data Protection Authority (Jersey) Law 2018 · Data Breaches - What they are and how to deal with them · What does Enforcement look like? Procedures, Powers and Penalties, Criminal and Civil · How We Deal with Complaints · Public Statement - The Office of the Financial Services Ombudsman (2025-10-28) · Public Statement - Star Delta Electrical Services Fine (2025-03-25) · Public Statement - JRSY Laser Limited Fine (2025-03-18) · Public Statement - Children's Services (2021-10-21) · Regulatory Action and Enforcement Policy

Documents

CitationRegulatorType
2020 MoU between the Jersey Data Protection Authority and the Guernsey Office of the Data Protection AuthorityJOICAgreement
2021 MoU between the Jersey Data Protection Authority and the Channel Islands Financial OmbudsmanJOICAgreement
2022 MoU between the Jersey Data Protection Authority/Information Commissioner and the States of Jersey PoliceJOICAgreement
2023 MoU between the Jersey Data Protection Authority/Information Commissioner and the Office of the Children's Commissioner for JerseyJOICAgreement
2024 MoU between JDPA/Jersey Information Commissioner and the UK Information CommissionerJOICAgreement
2024 MoU between the JDPA and the Comptroller and Auditor GeneralJOICAgreement
2024 MoU between the Jersey Data Protection Authority and The Gibraltar Regulatory AuthorityJOICAgreement
2024 MoU with The ADGM Office of Data ProtectionJOICAgreement
2024 MoU with The Isle of Man Information CommissionerJOICAgreement
2025 MoU between JDPA/Information Commissioner and Jersey Cyber Security CentreJOICAgreement
Administered RegistrationsJOICStatement of Guidance
Bailiwick of Jersey Addendum to the EU Standard Contractual ClausesJOICForm
Breach Log TemplateJOICForm
CCTV and Surveillance at Work and at HomeJOICStatement of Guidance
Case Studies - Learning from ExperienceJOICStatement of Guidance
Checklist - Legitimate Interests Assessment (LIA)JOICForm
Checklist Am I a Controller Joint Controller or ProcessorJOICForm
Checklist Appointing a Data ProcessorJOICForm
Checklist Breach Response PlanJOICForm
Checklist Data SharingJOICForm
Checklist Home Surveillance and CCTVJOICForm
Checklist Surveillance System Deployment Businesses OrganisationsJOICForm
Checklist Training SelectionJOICForm
Checklist: Accountability & GovernanceJOICForm
Checklist: Drafting a Data Protection Statement/Privacy NoticeJOICForm
Crown Dependency Data Protection Advisory - Generative AI Image Creation (2026-02-23)JOICAdvisory
DPIA ChecklistJOICForm
Data Breaches - What they are and how to deal with themJOICStatement of Guidance
Data Protection (International Co-operation) (Jersey) Regulations 2005JOICRegulation
Data Protection (Jersey) Law 2018JOICAct
Data Protection (Registration and Charges) (Jersey) Regulations 2018JOICRegulation
Data Protection Authority (Jersey) Law 2018JOICAct
Data Protection Statement TemplateJOICForm
Data Protection by Design and Default, and Data Protection Impact AssessmentsJOICStatement of Guidance
Definitions, the Data Protection Principles and Lawful BasesJOICStatement of Guidance
Exemptions - Arts.41-62 Data Protection (Jersey) Law 2018JOICStatement of Guidance
General AI ChecklistJOICForm
Guidance on applications to make information unavailable on the public registerJFSCStatement of Guidance
Guidance on the use of AI in Jersey's financial services sectorJFSCStatement of Guidance
HR AI ChecklistJOICForm
How We Deal with ComplaintsJOICStatement of Guidance
Individual Rights – what they are, how to exercise them and how to manage themJOICStatement of Guidance
JDPA Revised Fee Model Consultation Paper 2025-2026JOICConsultation Paper
Joint Statement on AI-Generated Imagery and the Protection of Privacy (2026-02-23)JOICAdvisory
Key Findings from a Full Compliance Audit 2023/4 (2024-08-12)JOICAdvisory
Key findings from a Virtual Compliance Audit 2023/4 (2024-12-01)JOICAdvisory
Key findings from a Virtual Compliance Audit 2024-2025 (2025-03-21)JOICAdvisory
Public Statement - Brenwal Limited (2023-11-13)JOICNotice
Public Statement - CSS Limited (2020-01-28)JOICNotice
Public Statement - Children's Services (2021-10-21)JOICNotice
Public Statement - Children's Services (2022-02-22)JOICNotice
Public Statement - Department for Children, Young People, Education and Skills (CYPES) (2025-09-25)JOICNotice
Public Statement - Government of Jersey Customer & Local Services (2023-10-14)JOICNotice
Public Statement - JRSY Laser Limited (2023-12-05)JOICNotice
Public Statement - JRSY Laser Limited Fine (2025-03-18)JOICNotice
Public Statement - Jersey Financial Services Commission (2025-10-25)JOICNotice
Public Statement - Parish of Grouville (2025-10-14)JOICNotice
Public Statement - Planning & Building Control (2020-10-19)JOICNotice
Public Statement - Star Delta Electrical Services Fine (2025-03-25)JOICNotice
Public Statement - The Office of the Financial Services Ombudsman (2025-10-28)JOICNotice
RegistrationJOICStatement of Guidance
Registry system statement (2024-03-07)JFSCNotice
Regulatory Action and Enforcement PolicyJOICRegulatory Policy
Statement following Credit Reference Agencies Announcement (2026-07-03)JOICNotice
Template - Data Protection Impact Assessment (DPIA)JOICForm
Template CCTV Surveillance SignageJOICForm
Template Legitimate Interests Assessment (LIA)JOICForm
Template Letter Erasure RequestJOICForm
Template Letter Request for PortabilityJOICForm
Template Letter for Individual Raising a ComplaintJOICForm
Template Letter for Rectification RequestJOICForm
Template Letter for Right of Access RequestJOICForm
Template Letter to Data Subjects affected by the Data BreachJOICForm
Template Letter to Neighbour Notifying of Installation of CCTVJOICForm
Template Letter to Neighbour asking about CCTV already InstalledJOICForm
Template Letter to Raise an Objection for Automated ProcessingJOICForm
Template Letter to Raise an Objection to ProcessingJOICForm
Template Letter to Restrict ProcessingJOICForm
Template Record of Processing ActivityJOICForm
Transfer Impact Assessment ChecklistJOICForm
Transferring Personal Data Outside JerseyJOICStatement of Guidance
What does Enforcement look like? Procedures, Powers and Penalties, Criminal and CivilJOICStatement of Guidance
What to think about before using Artificial IntelligenceJOICStatement of Guidance
Your Duties and Responsibilities as a Data ControllerJOICStatement of Guidance