The Data Protection (Jersey) Law 2018 is an information privacy law in the Crown Dependency of the Bailiwick of Jersey, one of the Channel Islands. The latest version is 2018, updating the previous law from 2005 to mirror the General Data Protection Regulation (GDPR). It was adopted on 25 May 2018. [1]
Eight Principles Data must be...
- fairly and lawfully processed
- processed for one or more specified and lawful purposes
- adequate, relevant and not excessive
- accurate and up to date
- not kept longer than necessary
- processed in accordance with the individual’s rights
- kept safe and secure
- not transferred to countries outside European Economic area unless country has adequate protection for the individual.
Rights of Individuals
- Rights of access
- Rights to prevent processing
- Rights to prevent processing for direct marketing
- Rights in relation to automated decision-taking
- Right to seek compensation
- Rights to have inaccurate information corrected
- Right to complain to the Commissioner
The law implements the European Data Protection Directive of 24 October 1995, which concerns the "protection of individuals with regard to the processing of personal data and on the free movement of such data". These include restrictions on the gathering, collection, and use of personal data, as well as forcing data collectors to let individuals know how their data has been used. [1] [3] Gatherers of data are called "data controllers" and must register with the Data Protection Commissioner and pay a yearly fee. [4] [2] The law also contains numerous exemptions for journalism, crime investigation, &c. [5] Other Crown dependencies like Guernsey and the Isle of Man have similar laws. [1] The 2005 law was modelled from the UK's Data Protection Act 1998. [4] [1] These laws can all trace lineage back to the European Directive on Data Protection, 95/EC/46 of 1995 and the Council of Europe's European Convention 108, passed in 1981. [6] [7]
The 2005 overhaul of the Data Protection laws was prompted by the aforementioned Data Protection Directive. It restricted the transmission of protected data to countries outside of the European Economic Area unless they had been certified as having 'adequacy' in their own data protection laws. [4] [8] Jersey is considered outside of the European Economic Area, and its 1987 Data Protection law was not adequate, so the restrictions could have harmed Jersey's financial services industry. [4] (Jersey is a major international offshore financial centre [9] and tax haven [10] ) In 2008, Jersey achieved 'adequacy status' under the EU rules. [11] [12]
Jersey's law is modified to suit this finance industry. [1] One such modification exempts trusts from the law so that they can use the personal information of beneficiaries of the trust without having to disclose certain details of the usage to the beneficiary. This modification was accomplished through a revision called the "Subject Access Exemptions" in 2005. [1] [13]
The main office of the law is the Data Protection Commissioner [5] [14] (before 2005, called the Data Protection Registrar). [5] The commissioner for the first several years of the law was Emma Martins [4] [15] There is also a Data Protection Tribunal. [5] In 2011 an attempt was made to unify the Commission of Guernsey with that of Jersey so that one Commissioner office would serve both Channel Islands. [15]
In 2007 charity groups had to change the way they operated the Jersey Christmas Appeal because they kept a list of the families who were nominated to receive vouchers for food, toys, fuel, and other needs during the holidays. The beneficiaries had to send in signed forms agreeing to be on the list. [16]
The law has been used at least two times against Jersey politicians.
In 2009, Jersey Senator Stuart Syvret was arrested on charges of violating the law after he blogged an old 1999 police report on a suspected serial killer and rapist Nurse that included the suspect's name. The police investigation had been abandoned for lack of evidence and Syvret had at first accepted this. However over the years Syvret came to believe the government of Jersey was incompetent and corrupt, especially after his experiences as Health Minister during the Jersey child abuse investigation 2008. He came to believe that the "Nurse M" [17] (or "Nurse X" in court documents) investigation had been incomplete, that the suspect was still dangerous. This was his alleged motivation for blogging the suspects name in 2009. [18] At trial he argued that his actions fell under the exemptions of the Law, but the Magistrate rejected this. In November 2010 he was convicted of violating Articles 17, 21, and 55 of the Data Protection Law and sentenced to 10 weeks imprisonment and a fine. Assistant Magistrate Bridget Shaw gave the analysis and opinion: [18] [19]
"he must have caused distress to X and his family and risked provoking violence either by or against X. The defendant also risked causing great distress to relatives of the deceased. In my opinion this was done to create a totally unfounded scandal to undermine public confidence in the administration of justice." [18]
In 2011, Saint Brélade Deputy and Housing Minister Sean Power was forced to resign after he forwarded an email he pulled off a printer in the States Building. The email discussed Syvret. [20]
Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, contextual information norms, and the legal and political issues surrounding them. It is also known as data privacy or data protection.
The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, was a European Union directive which regulated the processing of personal data within the European Union (EU) and the free movement of such data. The Data Protection Directive was an important component of EU privacy and human rights law.
The Data Protection Act 1998 (DPA) was an act of Parliament of the United Kingdom designed to protect personal data stored on computers or in an organised paper filing system. It enacted provisions from the European Union (EU) Data Protection Directive 1995 on the protection, processing, and movement of data.
The Information Commissioner's Office (ICO) is a non-departmental public body which reports directly to the Parliament of the United Kingdom and is sponsored by the Department for Science, Innovation and Technology. It is the independent regulatory office dealing with the Data Protection Act 2018 and the General Data Protection Regulation, the Privacy and Electronic Communications Regulations 2003 across the UK; and the Freedom of Information Act 2000 and the Environmental Information Regulations 2004 in England, Wales and Northern Ireland and, to a limited extent, in Scotland. When they audit an organisation they use Symbiant's audit software.
The Personal Information Protection and Electronic Documents Act is a Canadian law relating to data privacy. It governs how private sector organizations collect, use and disclose personal information in the course of commercial business. In addition, the Act contains various provisions to facilitate the use of electronic documents. PIPEDA became law on 13 April 2000 to promote consumer trust in electronic commerce. The act was also intended to reassure the European Union that the Canadian privacy law was adequate to protect the personal information of European citizens. In accordance with section 29 of PIPEDA, Part I of the Act must be reviewed by Parliament every five years. The first Parliamentary review occurred in 2007.
Personal data, also known as personal information or personally identifiable information (PII), is any information related to an identifiable person.
Information privacy, data privacy or data protection laws provide a legal framework on how to obtain, use and store data of natural persons. The various laws around the world describe the rights of natural persons to control who is using their data. This includes usually the right to get details on which data is stored, for what purpose and to request the deletion in case the purpose is not given anymore.
The International Safe Harbor Privacy Principles or Safe Harbour Privacy Principles were principles developed between 1998 and 2000 in order to prevent private organizations within the European Union or United States which store customer data from accidentally disclosing or losing personal information. They were overturned on October 6, 2015, by the European Court of Justice (ECJ), which enabled some US companies to comply with privacy laws protecting European Union and Swiss citizens. US companies storing customer data could self-certify that they adhered to 7 principles, to comply with the EU Data Protection Directive and with Swiss requirements. The US Department of Commerce developed privacy frameworks in conjunction with both the European Union and the Federal Data Protection and Information Commissioner of Switzerland.
Privacy law is a set of regulations that govern the collection, storage, and utilization of personal information from healthcare, governments, companies, public or private entities, or individuals.
Stuart Syvret is a former Jersey politician. He held elected office as a member of the States Assembly from 1990 to 2010. From 1999 to 2007, Svyret had executive responsibilities first as president of the Health and Social Services Committee and, after the 2005 constitutional reforms, as Minister for Health and Social Services in the Council of Ministers. He was dismissed from ministerial office in September 2007 and returned to the backbenches until he was disqualified from membership of the States in April 2010 due to his absence from the island. He has been involved in a series of legal proceedings, as a defendant in a criminal prosecution in Jersey and as a claimant in judicial review and civil claims in Jersey and London.
The United States Commission's fair information practice principles (FIPPs) are guidelines that represent widely accepted concepts concerning fair information practice in an electronic marketplace.
The German Bundesdatenschutzgesetz (BDSG) is a federal data protection act, that together with the data protection acts of the German federated states and other area-specific regulations, governs the exposure of personal data, which are manually processed or stored in IT systems.
Frederick John Hill, known as Bob Hill, is a Jersey politician and human rights campaigner. For 18 years he was Deputy for the parish of St Martin in the States of Jersey.
The General Data Protection Regulation, abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and human rights law, in particular Article 8(1) of the Charter of Fundamental Rights of the European Union. It also governs the transfer of personal data outside the EU and EEA. The GDPR's goals are to enhance individuals' control and rights over their personal information and to simplify the regulations for international business. It supersedes the Data Protection Directive 95/46/EC and, among other things, simplifies the terminology.
The Office of the Privacy Commissioner administers the Privacy Act 2020. The Privacy Commissioner is entrusted to protect personal information of New Zealanders in accordance with the Privacy Act. Current Privacy Commissioner, Michael Webster, began his role in July 2022.
There are several national data protection authorities across the world, tasked with protecting information privacy. In the European Union and the EFTA member countries, their status was formalized by the Data Protection Directive and they were involved in the Madrid Resolution.
Maximilian Schrems is an Austrian activist, lawyer, and author who became known for campaigns against Facebook for its privacy violations, including violations of European privacy laws and the alleged transfer of personal data to the US National Security Agency (NSA) as part of the NSA's PRISM program. Schrems is the founder of NOYB – European Center for Digital Rights.
The Data Protection Act 2018 is a United Kingdom act of Parliament (UK) which updates data protection laws in the UK. It is a national law which complements the European Union's General Data Protection Regulation (GDPR) and replaces the Data Protection Act 1998.
The right of access, also referred to as right to access and (data) subject access, is one of the most fundamental rights in data protection laws around the world. For instance, the United States, Singapore, Brazil, and countries in Europe have all developed laws that regulate access to personal data as privacy protection. The European Union states that: "The right of access occupies a central role in EU data protection law's arsenal of data subject empowerment measures." This right is often implemented as a Subject Access Request (SAR) or Data Subject Access Request (DSAR).