{
  "node_id": "je-dp-law-2018",
  "title": "Jersey Data Protection (Jersey) Law 2018 - JOIC",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Jersey's Data Protection (Jersey) Law 2018, which came into force on 25 May 2018 (the same date as the EU General Data Protection Regulation), is Jersey's primary personal data protection legislation establishing a GDPR-equivalent rights-based framework for the protection of personal data. Jersey is a Crown Dependency of the United Kingdom and a self-governing jurisdiction that is not a member of the European Union or subject to the UK Data Protection Act 2018; however, Jersey has historically aligned its data protection framework with EU standards to maintain EU and UK adequacy recognition critical to Jersey's status as a leading international financial centre. Jersey received a European Commission adequacy decision recognising Jersey as providing adequate data protection for the purposes of international data transfers from the EU, and has been similarly recognised under the UK GDPR post-Brexit framework. The supervisory authority is the Jersey Office of the Information Commissioner (JOIC), an independent institution responsible for oversight, enforcement, and guidance on data protection and freedom of information in Jersey. Key features of Jersey's Data Protection (Jersey) Law 2018: (1) Scope - applies to personal data processing by controllers established in Jersey or processing personal data of data subjects in Jersey; (2) Data processing principles - processing must comply with: lawfulness; transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations conducting large-scale systematic processing or processing sensitive data at scale; (7) Breach notification - controllers must notify the JOIC within 72 hours of becoming aware of a qualifying personal data breach; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred outside Jersey where adequate protection or appropriate safeguards exist; and (10) Administrative fines - the JOIC may impose significant fines for violations. Jersey's GDPR-equivalent framework and EU adequacy recognition underpin its position as a leading international financial and trust services centre.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "uk-retained-gdpr",
    "coe-convention-108-plus",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}