The Data Protection (Jersey) Law 2018 and Data Protection Authority (Jersey) Law 2018 come into force today, on the same day as the EU GDPR, giving Jersey a modern regime designed to maintain its adequacy status.
Key points
- Creates a GDPR-equivalent regime for Jersey.
- Regulated by the Jersey Office of the Information Commissioner.
- Breaches must be notified to the regulator within 72 hours.
- Controllers and processors must register and pay an annual charge.
UK organisations using Jersey-based providers, trusts or funds should ensure their contracts and incident procedures reflect the local requirements, including the 72-hour notification deadline.
Source: Data Protection (Jersey) Law 2018 (Jersey Legal Information Board)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.