Clarium
Back to blog
DPJL 2018Jerseydata protectionJOICGDPRChannel Islands

Data Protection in Jersey: A Guide to the DPJL 2018

5 August 2026Will Wilson

Jersey runs its own data protection regime. The island sits outside the UK and outside the EU, so neither the UK GDPR nor the EU GDPR applies there. What applies is the Data Protection (Jersey) Law 2018, the DPJL 2018, supervised by the Jersey Office of the Information Commissioner (JOIC). If you process personal data in Jersey, or serve people who live there, this is the law your compliance programme has to name.

Practitioners who know the GDPR will find the DPJL familiar, and that is deliberate. The differences are few, but they are exactly where UK-drafted policies, notices and breach plans quietly fail.

A GDPR twin, written to keep the data flowing

The DPJL 2018 came into force on 25 May 2018, the same day as the GDPR, and the timing was the point. Jersey's economy runs on financial services: trust companies, fund administrators and banks moving personal data between the island, the UK and the EU every working day. That movement depends on the European Commission treating Jersey as a safe destination for European data. So the States Assembly wrote a law that tracks the GDPR in substance, article for article, and left the Commission no reason to doubt the island's standards.

Territorial scope works the way GDPR practitioners expect. The law binds controllers and processors established in Jersey, and it reaches organisations elsewhere that offer goods or services to people in Jersey or monitor their behaviour.

Adequate since 2008, reaffirmed in 2024

Jersey's EU adequacy is often misdated to 2021. That was the UK's year. Jersey's decision is much older: the Commission found Jersey adequate on 8 May 2008, under Commission Decision 2008/393/EC, when the governing instrument was still Directive 95/46/EC. When the Commission completed its first periodic review of the eleven pre-GDPR adequacy decisions, it reaffirmed Jersey's on 15 January 2024.

Adequacy means personal data flows from the EU to Jersey without standard contractual clauses, transfer risk assessments or any other safeguard. The UK grants Jersey the same status under its own framework. For a fund administrator servicing Irish and Luxembourg funds, one Commission decision removes an entire layer of transfer paperwork.

It also explains the DPJL's discipline. Adequacy is reviewed, and divergence from European standards is the one thing that could cost the island its status.

Two laws, one regulator, four acronyms

Jersey's framework confuses people because two laws commenced together on 25 May 2018 and their acronyms are near-anagrams. The DPJL 2018 is the substantive law: principles, lawful bases, data subject rights, controller and processor duties, breach notification. The Data Protection Authority (Jersey) Law 2018, the DPAJL 2018, is the machinery: it established the regulator and defines its powers, the registration scheme and the fining regime.

The regulator the DPAJL created is the Jersey Data Protection Authority (JDPA). In practice you deal with it through the JOIC, the Jersey Office of the Information Commissioner, which is the Authority's operational face and the address on every registration, breach report and enquiry.

The common miscitation is calling the law "the JDPA 2018". The JDPA is the regulator; the law is the DPJL. A privacy notice that gets this wrong tells the JOIC precisely how much local attention your documentation has received.

Registration never went away

The UK abolished general notification when the GDPR arrived. Jersey kept it. Under the DPAJL 2018, controllers and processors established in Jersey must register with the JOIC and pay an annual charge, tiered by the size and nature of the organisation, before processing personal data. The register is public, which makes non-registration the most visible compliance failure available: anyone, the regulator included, can check it in seconds.

This is the obligation that catches otherwise mature GDPR programmes, because nothing in a UK or EU framework prompts it.

Same obligations, renumbered articles

The DPJL's substance will be familiar. The citations will not, and the renumbering is where copied UK documentation gives itself away.

| Obligation | DPJL 2018 | GDPR | |---|---|---| | Records of processing activities | Article 14 | Article 30 | | Data protection impact assessment | Article 16 | Article 35 | | Prior consultation | Article 17 | Article 36 | | Breach notification to the regulator | Article 20 | Article 33 | | Breach communication to individuals | Article 21 | Article 34 |

Article 14 requires a written record of processing activities with the same content as GDPR Article 30: purposes, categories of data subjects and data, recipients, transfers, retention periods, security measures. The under-250-employee exemption carries across too, along with the exceptions that swallow it for most regulated firms.

Data subject rights carry across as well. A Jersey resident can make a subject access request exactly as a UK or EU resident can. The difference is the complaint route, which runs to the JOIC rather than the ICO.

High-risk processing means a DPIA first, the JOIC second

Article 16 requires a data protection impact assessment wherever processing is likely to result in a high risk to rights and freedoms: new technologies, large-scale special category processing, systematic monitoring. The triggers and the method are those of GDPR Article 35. Article 17 adds the same backstop as GDPR Article 36: if the assessment leaves a high residual risk you cannot mitigate, you consult the JOIC before processing begins, not after.

A DPIA is only as good as the processing record underneath it; for how the two interlock with subject access, see RoPA vs DPIA vs DSAR.

Breach notification runs to St Helier, not Wilmslow

Article 20 sets the familiar clock: notify the JOIC without undue delay and, where feasible, within 72 hours of becoming aware of a breach likely to risk individuals' rights, with reasons accompanying any late report. Article 21 requires telling affected individuals where that risk is high, unless the data was protected (encryption is the canonical example) or the risk has since been neutralised.

Pan-jurisdictional incident plans fail here in a small, embarrassing way: the playbook says ICO, the on-call lawyer phones Wilmslow, and Jersey's regulator learns about the breach from somewhere else.

Where Jersey genuinely diverges

Three differences deserve attention beyond renumbering.

Criminal data is special category data. The GDPR splits sensitive data between Article 9 and criminal offence data under Article 10. The DPJL folds criminal convictions and alleged criminal activity into its Article 1 definition of special category data, with the processing conditions in Schedule 2. For Jersey's trust and fund sector, which screens clients against sanctions and adverse-media databases daily, AML screening is therefore special category processing, with the DPIA exposure that follows.

The sanctions cap differs in both directions. GDPR fines reach EUR 20 million or 4% of global turnover. Jersey's cap under the DPAJL is the higher of £300,000 or 10% of total global annual turnover or gross income, dropping to £10,000 where the processing was in the public interest and not for profit. For a small firm, Jersey's ceiling is lower than the GDPR's. For a large group, 10% is more than double the GDPR's percentage. "The fines are smaller in Jersey" is at best half true.

Lawful bases live in Schedule 2, not Article 6. The six bases are the same; the citation is not, and it is another place a UK-copied privacy notice betrays itself.

The Channel Islands advantage is real, and conditional

For a Jersey-registered business the position is unusually good. Adequacy in both directions with the EU and the UK means a Jersey administrator can service a Luxembourg fund, a London family office and a St Helier client on one framework, with no transfer mechanism needed between any of them. Guernsey holds its own, older adequacy decision from 2003, so intra-Channel Islands flows are equally clean. Very few small jurisdictions can offer their finance industry that.

The advantage is conditional. The 2024 reaffirmation assumes continued convergence, and the Commission reviews adequacy on a rolling basis. Jersey's status stays valuable exactly as long as Jersey firms can demonstrate they operate the regime: registers current, records maintained, breaches reported to the right regulator under the right law.

Built in Jersey, for the DPJL

Most compliance platforms treat Jersey as a footnote: a GDPR template with the names swapped, when it appears at all. Clarium was built in Jersey, for Jersey businesses, and it is the only RoPA platform with the DPJL 2018 built in rather than bolted on. Processing records are structured around Article 14, AI extraction turns a plain-language description of an activity into structured record fields, and visual data-flow maps show where data leaves the island and on what basis. Jersey-registered charities get the Growth tier free for a year. See pricing.

Ready to simplify your GDPR compliance?

Try Clarium free — no credit card required.

Start Free Trial