Skip to content
Clarium
Back to blog
JerseyDPJL 2018JOICdata protectionGDPRframework

The Data Protection (Jersey) Law 2018: The Framework

18 August 2026Will Wilson

The Data Protection (Jersey) Law 2018 (DPJL 2018) is Jersey's data protection regime. It mirrors the GDPR architecture closely and is supervised by the Jersey Office of the Information Commissioner (JOIC). Jersey holds EU adequacy — reaffirmed by the European Commission on 15 January 2024 — so personal data can flow from the EEA to Jersey without additional safeguards.

This is the framework page for the Jersey DPJL regime — the single reference that the blog links to when discussing data protection in Jersey.

The DPJL mirrors the GDPR framework

The whole framework layer runs in Jersey under the DPJL 2018: the record of processing activities obligation, the DPIA duty before high-risk processing, and the data subject access right — all on the same architecture as the GDPR.

The standards are deliberately aligned. Keeping records to the Article 30 standard is part of what Jersey's adequacy alignment rests on, and a Jersey organisation serving EU clients should treat the GDPR field list as its working template.

Where Jersey diverges from the GDPR

Three differences matter in practice.

The clock runs in weeks. A DSAR under the DPJL must be answered within four weeks, extendable by up to eight further weeks for complex or numerous requests — not the GDPR's one month. A pan-jurisdictional template that hard-codes "one month" and "complain to the ICO" is wrong on both counts for Jersey data subjects.

The supervisory authority is the JOIC, not the ICO. Refusal notices and complaints must point the requester to the Jersey Office of the Information Commissioner. Channel Islands firms serving EU clients frequently owe the same document to both regulators.

Jersey kept a registration requirement. Jersey businesses must register with the JOIC, a step that UK and EU firms do not take.

When Jersey firms answer to both regulators

A Jersey trust company or fund administrator serving EU clients owes compliance under both the DPJL 2018 and the GDPR. Because the regimes are aligned, one well-kept framework serves both: a register maintained to the Article 30 standard, DPIAs before high-risk processing, and a DSAR process that handles both the four-week and one-month clocks.

For the full regime walkthrough, including the registration requirement, see our guide to data protection in Jersey under the DPJL 2018.

Ready to simplify your GDPR compliance?

Try Clarium free — no credit card required.

Start Free Trial