Data Protection Authority (Jersey) Law 2018
Data Controller: Government of Jersey, Customer & Local Services
1. The Data Protection Authority for the Bailiwick of Jersey (the Authority) has determined that the Government of Jersey, Customer & Local Services (CLS) (the Controller) has contravened Art.8(1)(a), Art.14(1)(a), Art.14(1)(b), Art.27(1) and Art.28(3)(a) of the Data Protection (Jersey) Law 2018 (the DPJL 2018) in that it failed to respond appropriately to certain requests for access to information held by it.
2. Following a lengthy investigation commenced in October 2020 pursuant to Art.20 of the Data Protection Authority (Jersey) Law 2018 (DPAJL 2018), the Authority has determined that CLS was responsible for contraventions relating to failure to respond appropriately to two subject access requests (the First DSAR and Second DSAR) made by an individual (the Complainant):
a. In respect of the First DSAR:
i. A response ought to have been provided to the Complainant by 19/06/2020 at the latest, but a full response was not, in fact, provided until 09/06/2021. Accordingly, CLS failed to provide a response to the First DSAR in accordance with the legal timeframe, in contravention of Art.27(1) of the DPJL 2018;
ii. CLS failed to provide certain copies of the Complainant’s information to which he was entitled in response to the First DSAR, in contravention of Art.28(3)(a) of the DPJL 2018.
b. In respect of the Second DSAR:
i. A response ought to have been provided by 20/07/2020 but a full response was not, in fact, provided until 09/06/2021. Accordingly, CLS failed to provide a response to the Second DSAR in accordance with the legal timeframe, in contravention of Art.27(1) of the DPJL 2018;
ii. CLS failed to provide certain copies of the Complainant’s information to which he was entitled in response to the Second DSAR, in contravention of Art.28(3)(a) of the DPJL 2018.
c. CLS failed to process the Complainant’s data, lawfully, fairly and in a transparent manner, in contravention of the first data protection principle at Art.8(1)(a) of the DPJL 2018;
d. CLS failed to implement proportionate technical and organisational measures to ensure processing is performed in accordance with this Law, in contravention of Art.14(1)(a) of the DPJL 2018;
e. CLS failed to demonstrate that those measures are in place so that processing is indeed performed in accordance with this Law, in contravention of Art.14(1)(b) of the DPJL 2018;
3. Specifically, it was found that:
a. CLS’ records management function had significant failings in that it did not have appropriate resources or systems in place to be able to respond to the Complainant’s DSARs in an appropriate manner.
b. The initial searches undertaken in response to the First and Second DSARs were undertaken by a junior officer who lacked appropriate training and knowledge to properly respond to those subject access requests in terms of knowing where information is held within CLS systems and also which exemptions applied (if any) and how to properly redact documents.
c. Upon review of the relevant material by the Authority, it was clear that certain exemptions had been relied upon unlawfully by CLS and redactions inappropriately and/or inconsistently applied.
d. When the Complainant raised concerns about the quality of the DSAR responses (including raising concerns about apparently missing information and inappropriately applied redactions and with which the Authority ultimately agreed) such concerns were dismissed with little interrogation and the general interactions between CLS and the Complainant in respect of these issues were poor and not well-managed.
e. The Controller showed insufficient appreciation of the significance of some of the problems arising from the processing of personal data which were the subject of the investigation and tended to minimise the effect the processing had on the data subject.
4. Whilst the Controller maintained open and candid correspondence with the Authority during the course of its enquiries, made early admissions in terms of identified failings and took swift steps to rectify those matters, ultimately the Authority imposed a formal Reprimand and made a number of orders pursuant to Art.25(3) of the DPAJL 2018 regarding:
a. the updating of its processes relating to their DSAR response including reviewing the information that is provided to members of the public about how CLS actions such requests;
b. education for staff and improvements made to their technical and organisational measures to ensure responses to DSARs will be achieved fully and in a timely manner and that those involved in the process are of sufficient training and education to carry out such activities.
5. Those improvement measures were ordered to be carried out within a stipulated timeframe and confirmation of such provided to the Authority, which CLS has done.
6. Had this been a private sector entity, the Authority would have considered the imposition of a significant fine in a case of this gravity. However, the DPAJL 2018 sets out that the Authority cannot issue administrative fines against public authorities and so the only sanctions available for consideration are the issuing of a formal reprimand and/or the making of certain orders designed to bring processing in-line with the DPJL 2018 and to ensure appropriate supervisory oversight by the Authority.
7. This public statement should act as a reminder to all controllers of the need to have appropriate systems, policies and appropriately trained staff to properly respond to requests that are made to them.
8. This is a public statement made by the Authority pursuant to Art.14 of the DPAJL 2018 following an Investigation by the Authority and following receipt of a complaint regarding the Controller’s processing of certain personal data. Individuals can make a formal complaint under Art.19 of the DPAJL 2018 Law if they think that a controller has contravened the DPJL 2018 and it involves or affects their rights.
9. The Authority may investigate a complaint and once an investigation has been completed, Art.23 of the DPAJL 2018 requires the Authority to make a Proposed Determination as to whether a Controller has contravened the DPJL 2018.
10. If the Authority determines that there has been a contravention, it must then go on to consider what sanction should be imposed against the Controller, if any.
11. Art.25 of the DPAJL 2018 sets out the various sanctions that are available to the Authority following a Proposed Determination and, having considered all relevant facts (including representations made by the Controller), the Authority has considered that this matter is most appropriately disposed of by way of a formal reprimand and the imposition of orders. (Administrative fines may not be levied against public authorities and so this form of sanction was not available in this particular case.)
12. Art.32 of the Authority Law allows an affected party a right of appeal to the Royal Court of Jersey. Any such appeal must be made within 28 days.