Jersey
data protection
84 Jersey regulatory document(s) tagged data protection.
Who is caught
Jersey's data protection regime rests on two principal statutes. The Data Protection (Jersey) Law 2018 sets the substantive rules for handling personal data and implements GDPR-equivalent standards, while the Data Protection Authority (Jersey) Law 2018 creates the Jersey Office of the Information Commissioner (JOIC, the Authority) and provides the registration, fee and enforcement machinery. Both apply broadly across the public and private sectors to anyone processing personal data.
- Controllers and processors: Any controller or processor that determines or carries out the processing of personal data is caught, whether a company, sole trader, charity, public authority or government department.
- Establishment in Jersey: JOIC guidance treats controllers and processors established in Jersey as required to register before processing personal data, including newly formed entities at or before incorporation.
- Administered structures: Trusts, foundations, funds, private trust companies, family offices, JPUTs, cell companies and SPVs administered by trust company or fund services businesses fall within scope; trustees, the foundation itself, or the general/managing partner are typically the controller.
- Public authorities: Public authorities and scheduled public authorities are within scope, subject to specific modifications and to schedules on law enforcement processing.
- Surveillance and AI users: Organisations using CCTV, ANPR, facial recognition, drones, workplace monitoring or AI systems that process identifiable individuals' data are within scope; home CCTV users come within scope where cameras capture beyond their own property boundary.
The regime also reaches cross-border activity: transfers of personal data outside Jersey engage Part 8 of the Data Protection (Jersey) Law 2018, and the Data Protection (International Co-operation) (Jersey) Regulations 2005 impose duties on the Authority itself when co-operating with foreign data protection authorities under Convention 108.
Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Data Protection (International Co-operation) (Jersey) Regulations 2005 · What to think about before using Artificial Intelligence · Your Duties and Responsibilities as a Data Controller · Transferring Personal Data Outside Jersey · Registration · Administered Registrations · CCTV and Surveillance at Work and at Home
Key duties
The continuing obligations divide into registration and charging duties owed to the Authority, and substantive processing obligations under the Data Protection (Jersey) Law 2018. The duties carrying fixed deadlines are registration, annual charge payment and notification of changes.
Registration and charges
- Register with the Authority: Controllers and processors must register under Article 17 of the Data Protection Authority (Jersey) Law 2018 before processing personal data; processing without registration is a criminal offence.
- Annual charge: Registered controllers and processors must pay an annual charge for each calendar year (or part) under the Data Protection (Registration and Charges) (Jersey) Regulations 2018. The base amount ranges from £70 to £500 by full-time equivalent staff numbers, with additions for high revenue, financial services registration or special category data processing; administered entities may instead pay a flat £50.
- Payment deadlines: The charge falls due on 1 January and must be paid by the last day of the following month; where registration occurs during the year, it falls due one month after registration. Renewal must be completed by the last day of February each year or the registration expires.
- Notify changes: Registered controllers and processors must notify JOIC of any change to their registration particulars as soon as practicable and in any event within 28 days.
- Substantiate the charge: When paying, a payer must supply sufficient information to identify itself and substantiate the correct charge amount, and provide any further information the Authority requests.
Core processing obligations
- Principles and lawful basis: Controllers must comply with the data protection principles (Article 8) and process lawfully, fairly and transparently, identifying a lawful basis from Schedule 2 Part 1 (and a condition from Schedule 2 Part 2 for special category data) before processing begins.
- Transparency and records: Controllers must provide required information to data subjects (Articles 9-13) and keep records of processing activities, and comply with data protection by design and by default under Article 15.
- DPIAs: A data protection impact assessment must be carried out before high-risk processing (Article 16); where high risk cannot be mitigated the controller must consult the Authority in writing under Article 17 before processing starts. JOIC must give its opinion within eight weeks, extendable by a further six weeks.
- Processor contracts and security: Controllers must appoint processors under written contracts (Article 19), and both controllers and processors must implement appropriate technical and organisational security measures (Articles 21-23).
- Data protection officers: Certain controllers and processors must appoint a DPO with defined independence and duties (Articles 24-26), for example public authorities and those undertaking large-scale monitoring or special category data processing.
Breaches, rights and transfers
- Breach notification: Controllers must notify JOIC of a personal data breach without undue delay and, where feasible, within 72 hours (Article 20), and must inform affected individuals where the breach poses a high risk. Processors must notify the controller without undue delay, and controllers should maintain a breach log of all breaches.
- Data subject rights: Controllers must handle rights requests under Part 6 (access, rectification, erasure, restriction, portability, objection, and automated decision-making) within statutory procedures. JOIC guidance sets the standard response period at four weeks, extendable for complex requests.
- Cross-border transfers: Restricted transfers outside Jersey may only proceed on the adequacy route, under appropriate safeguards (Article 67(2), such as Standard Contractual Clauses plus the Bailiwick of Jersey Addendum), or under a Schedule 3 exception. Where no adequacy decision applies a documented Transfer Impact Assessment should be carried out, and the residual Schedule 8 paragraph 9 exception requires notification to JOIC and to the affected individuals.
Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Data Breaches - What they are and how to deal with them · Your Duties and Responsibilities as a Data Controller · Data Protection by Design and Default, and Data Protection Impact Assessments · Definitions, the Data Protection Principles and Lawful Bases · Individual Rights – what they are, how to exercise them and how to manage them · Transferring Personal Data Outside Jersey · Registration · Administered Registrations
Exemptions and carve-outs
Exemptions operate at two levels: substantive exemptions from principles and subject rights under Part 7 of the Data Protection (Jersey) Law 2018, and exemptions from the registration charge under the Registration and Charges Regulations.
Statutory exemptions (Part 7)
- Listed purposes: Articles 41 to 62 disapply certain transparency or subject-rights provisions for national security (evidenced by a ministerial certificate), crime and taxation, journalism and other special purposes, legal privilege, health and social work, corporate finance, and other listed business, regulatory and negotiation purposes.
- Not blanket: JOIC guidance stresses exemptions are not automatic: controllers must assess each case individually, apply the minimum departure necessary, document their decision, and remain accountable; data subjects retain the right to complain to JOIC.
- Material scope carve-outs: JOIC guidance identifies purely personal or household processing as outside the Law, and confirms that data merely transiting a third country without being accessed there, and transfers within the same legal entity, are not Restricted Transfers.
Registration and charge exemptions
- Charge exemptions: Certain processing is exempt from the annual charge, including processing by public authorities, election candidates, provided schools, businesses solely retaining records after ceasing to trade, and qualifying non-profit associations, subject to the Schedule conditions.
- Administered reduction: A controller or processor administered by a trust company or fund services business may pay a flat £50 annual charge instead of the standard calculation, but cannot also claim the Regulation 6(4) exemption.
- Transitional exemption: Under Schedule 2 of the Data Protection Authority (Jersey) Law 2018, controllers already registered under the 2005 Law, and all processors, were exempt from re-registering until the end of a defined registration period, with unregistered processors required to register within a 26 week transitional window.
- Public authorities and fines: Public authorities are exempt from administrative fines; JOIC has repeatedly noted it could not fine public-sector controllers and issued reprimands and orders instead.
Sources: Data Protection (Jersey) Law 2018 · Data Protection Authority (Jersey) Law 2018 · Data Protection (Registration and Charges) (Jersey) Regulations 2018 · Exemptions - Arts.41-62 Data Protection (Jersey) Law 2018 · Transferring Personal Data Outside Jersey · Registration · Public Statement - Jersey Financial Services Commission (2025-10-25) · Public Statement - Government of Jersey Customer & Local Services (2023-10-14) · Public Statement - Children's Services (2022-02-22) · Public Statement - Children's Services (2021-10-21) · Public Statement - Planning & Building Control (2020-10-19)
Enforcement and penalties
Enforcement is administered by JOIC under the Data Protection Authority (Jersey) Law 2018, which provides for investigations, inquiries and audits, together with sanctions ranging from advice through reprimands, orders and public statements to administrative fines. Criminal offences and civil remedies sit alongside these powers.
Administrative sanctions and fines
- Orders and reprimands: The Authority may issue words of advice, warnings, formal reprimands, and orders (for example under Article 25(3) of the Data Protection Authority (Jersey) Law 2018) requiring remedial action such as correcting or deleting data, stopping unlawful processing, notifying breaches, or improving processes and staff training.
- Administrative fines: The Regulatory Action and Enforcement Policy states fines are subject to statutory caps of up to £5,000,000, £10,000,000, or £300,000 / 10% of global turnover depending on the contravention, and £10,000 for not-for-profit public-interest processing. Separate JOIC guidance describes an overall maximum of £10 million, and states that failing to notify a breach when required can attract a fine of up to £5,000,000.
- Worked examples: Imposed fines in the indexed public statements have been modest: £500 against JRSY Laser Limited and £4,000 against Star-Delta Electrical Services, in each case with a reprimand and orders.
- Public statements: The Authority may publish a summary of findings and orders (naming the controller or processor) under Article 14 of the Data Protection Authority (Jersey) Law 2018 where seriousness and public interest justify it.
- Information and audit powers: Under Schedule 1 of the Data Protection Authority (Jersey) Law 2018, authorised officers may issue information notices (requiring a response within 28 days, or a shorter urgent period generally not less than 7 days), enter and search premises subject to safeguards, and require data protection audits at the audited party's cost.
Criminal offences and civil remedies
- Criminal offences: JOIC guidance states that failing to comply with an Authority order, unauthorised taking or sharing of personal data, forced subject access requests, giving false information, and obstructing investigators are criminal offences, prosecutable in the Royal Court and punishable by fines and/or up to two years' imprisonment. Providing a materially false response to an information notice may also be an offence.
- Compensation: Individuals who suffer harm from non-compliant processing may seek compensation from the Royal Court, which can also grant injunctions and declarations; the Authority itself cannot award compensation.
- Non-payment of fines: Failure to pay an administrative fine can lead to civil debt recovery through the Petty Debts or Royal Court, including wage arrest or distraint of goods.
- Appeals: Controllers, processors and complainants may appeal a rejection of complaint or final determination to the Royal Court of Jersey within 28 days, on grounds that the decision was unreasonable, unfair in law, or beyond the Authority's powers.
- Public authorities: Public authorities are not currently subject to administrative fines; enforcement against them has proceeded by reprimand and orders.
Sources: Data Protection Authority (Jersey) Law 2018 · Data Breaches - What they are and how to deal with them · What does Enforcement look like? Procedures, Powers and Penalties, Criminal and Civil · How We Deal with Complaints · Public Statement - The Office of the Financial Services Ombudsman (2025-10-28) · Public Statement - Star Delta Electrical Services Fine (2025-03-25) · Public Statement - JRSY Laser Limited Fine (2025-03-18) · Public Statement - Children's Services (2021-10-21) · Regulatory Action and Enforcement Policy