Read the Full Report
Total Page:16
File Type:pdf, Size:1020Kb
sey Da ANNUAL Fulfilling the obligations of the Authority under Article 44 of the Data Protection Authority (Jersey) Law 2018 and the Information Commissioner 2020 REPORT under Article 43 of the Freedom of Information (Jersey) Law 2011. 2020 ANNUAL REPORT | 1 CONTENTS 04 THE JERSEY DATA PROTECTION AUTHORITY’S ROLE, 34 ANNUAL REPORT OF FREEDOM OF INFORMATION VISION, MISSION, PROMISE AND 2020 STRATEGIC OUTCOMES 2020 Operational Performance & Appeals Our Role Significant 2020 Decision Notices Our Vision Our Promise 38 COMMUNICATIONS Message From the Chair Annual Registrations Message From The Commissioner Data Protection Toolkits Pandemic Messaging 10 JERSEY DATA PROTECTION AUTHORITY Data Protection Week 2020 Independence #AskTheCommissioner Campaigns 2020 12 LOOKING FORWARD - PRIVACY & HORIZON SCANNING CCTV Data Protection Obligations 14 GOVERNANCE, ACCOUNTABILITY AND TRANSPARENCY Individual Rights The Data Protection Authority Blogs Delegation of Powers Education 2020 Authority Structure Privacy Courtroom Challenge Authority Meetings The JOIC Talks For Industry Board Members Remuneration Communications Summary Risk Management Public Engagements and Awareness Environmental & Social Policy National/International Liaison 2020 Social 19 MANAGING PERFORMANCE & REGULATORY DELIVERABLES 48 FINANCIAL INFORMATION Summary 20 ORGANISATION Grant The Structure Registration Fee Income The Team Expenditure Year Ahead 24 SUMMARY OF 2020 DATA PROTECTION ACTIVITIES 2020 Operational Performance 2020 Case Data Complaints Investigation Matrix 2020 Case Outcomes Breach Reporting www.jerseyoic.org Enforcement 2 | JERSEY OFFICE OF THE INFORMATION COMMISSIONER 2020 ANNUAL REPORT | 3 OUR ROLE The Jersey Data Protection Authority (the Authority) is an independent OUR 2020 statutory body. Its mission is to promote respect for the private lives of individuals through ensuring privacy of their personal information by: STRATEGIC OUTCOMES Æ Implementing and ensuring compliance with the Data Protection (Jersey) Law 2018 and the Data Protection Authority (Jersey) Law 2018. Æ Influencing attitudes and behaviours towards privacy and processing of personal information, both locally and internationally. 1 The people of Jersey are Æ Providing advice and guidance to Island businesses and individuals, provided with a high level of data and making recommendations to the Government of Jersey in response protection and expert service to changes in international data protection laws. whilst resources are judiciously and responsibly managed. OUR VISION 2 The Island’s approach to data The Jersey Data Protection A prosperous, close-knit island community that embraces a collaborative protection clearly contributes to and innovative approach to data protection, providing a leading-edge its reputation as a well-regulated Authority’s role, vision, model to other similar jurisdictions. jurisdiction. 3 Jersey is recognised as a world mission, promise and OUR PROMISE leader, embracing innovation to safely develop and implement To promote the information rights of individuals through a practical and ethical approach to business practice and regulation that supports digital technology. 2020 strategic outcomes the delivery of public services, and promotes the social and economic VIEW interests of the Island. 4 | JERSEY OFFICE OF THE INFORMATION COMMISSIONER 2020 ANNUAL REPORT | 5 It is my pleasure, on behalf of the conducting investigations, but that it should also guide Government to pay a fair share, rather than just top protecting the privacy of individuals to the greatest practices. Finally, it also holds the JDPA all of its operational and administrative functions. To up the fee revenue received from businesses. We are extent possible. Our office advised on several contact accountable by giving the public the Jersey Data Protection Authority that end, the JDPA recommended a registration model involved in continuing discussions with Government tracing initiatives. One example was a smartphone opportunity to view its regulation practices that would distribute the financial burden fairly. Larger to re-evaluate the current fee model, with a view to app that can alert individuals that they might in action. Good data protection regulation (JDPA) to present to the Minister organisations with greater resources should pay more an arrangement that is just and therefore fairer for have been in contact with an infected individual, must not only be done, but also be seen to than smaller organisations. Organisations that collect everyone. without identifying those individuals. As the result be done. Public statements, like this annual report, sensitive data that present a greater risk to the rights of our collective action with the Government and and the members of the States give members of the public information they need to and freedoms of data subjects should pay more than Like everyone else, we faced new challenges from other public sector agencies, approximately 50% Assembly our Annual Report for other organisations, owing to the greater level of data the pandemic. Because of government-imposed of the Jersey population downloaded this app, evaluate the effectiveness of the JDPA. protection required. The other issue was the balance restrictions, our employees spent a large portion which constituted the highest participation of any In closing, we are sad that this will be the final 2020. This fulfils our statutory between funding from Government and revenues of the year working from home. Fortunately, jurisdiction in the world. We also advised government through registration fees. As Government was exempt modern technology made it possible for us to and the hospitality sector on the best means and annual report with Dr Jay Fedorak as Information obligation under Article 44 of from paying the registration fees and any regulatory continue to provide service to the public and our good practices for contact tracing of customers. These Commissioner. We have enjoyed working with him and penalties, the JDPA believed that Government should stakeholders. We were able to use telephone and issues were common to jurisdictions around the have benefitted from his extensive experience and the Data Protection Authority provide a grant of at least a third of the total funding. video conferencing to conduct investigations, present world, and we worked with our international partners international expertise. I would like to speak further In common with most jurisdictions around the world, training sessions and conduct meetings both internal to identify best practices for our communities, about Jay’s invaluable contribution to the JDPA, but I (Jersey) Law 2018. Jersey is experiencing a significant increase in workload and external. Travel restrictions meant that some of including as an active member of the Global Privacy decided that this annual report is not the right time relating to investigating and monitoring data breaches our Authority members could not attend our meetings Assembly task force. We anticipate that this type of This report covers an extraordinary year. We had just to praise him, for two reasons. The first is that he will and other types of regulation involving the public sector. in person, but video conferencing was a suitable international cooperation will increase. begun to implement our new registration model when remain in office until the first of July, and it seems This work often involves extremely sensitive personal alternative. Even though the restrictions also reduced the Covid-19 pandemic presented a wide range of risky to commend him too early. The second is that I data. Reviewing data protection impact assessments, our travel and recruitment expenditure, they triggered We also implemented rigorous enforcement measures further challenges to us all. The Voting Members of the want to ‘keep my powder dry’ for a tribute when we draft laws and interagency agreements, along with new expenditure in information and communications in 2020 in the form of two public statements. JDPA are grateful to the employees of the Jersey Office have to bid him farewell in a few months. creating guidance and implementation tools, are other technology that were necessary for employees to I announced the first in my message last year, of the Information Commissioner (JOIC) for continuing Jacob examples of our activities that primarily involve the be able to serve the public, while working remotely. regarding a statement we issued in January 2020. That to deliver exemplary service to the people of Jersey, However, I am pleased to report that the JDPA has public sector. It would not be fair for businesses to be The only deficiency we experienced was in the social statement related to a series of breaches by a private despite a myriad of administrative and operational already selected his successor. In October 2020, we Kohnstamm subsidising the costs incurred from the JOIC providing benefits of our work that can only be realised when sector business. We issued a second statement challenges, as well as a further increase in workload. commenced a recruitment process with the assistance services to Government people are able to meet in person. Social interaction involving a government department in October 2020. and knowledge sharing, in the workplace and at the Public statements serve several functions: of the Jersey Appointments Commission (JAC). We Chair, the Jersey Data In my message in the Annual Report for 2019, I described As the JDPA approached the first year of implementing Board level, is important