A N N U a L R E P O
Total Page:16
File Type:pdf, Size:1020Kb
2019 Fulfilling the obligations of the Authority under article 44 of the Data Protection Authority (Jersey) Law 2018 and the Information Commissioner ANNUAL REPORT under article 43 of the Freedom of Information (Jersey) Law 2011. R.49/2020 CONTENTS 03 2019 HIGHLIGHTS AND ACHIEVEMENTS 25 ANNUAL REPORT OF FREEDOM OF INFORMATION ACTIVITIES 05 THE JERSEY DATA PROTECTION AUTHORITY’S ROLE, Benefits of Effective Freedom of Information VISION, MISSION, PROMISE AND 2019 STRATEGIC AIMS The Freedom of Information (Jersey) Law 2011 2019 Operational Performance and Appeals Significant 2019 Decision Notices 07 INTRODUCTION View from the Chair View from the Commissioner 29 PUBLIC AWARENESS, ENGAGEMENT AND EDUCATION 11 ORGANISATION The JDPA and the States Assembly The JOIC Events About the Jersey Office of the Information Commissioner Education National/International Liaison 2019 13 GOVERNANCE, ACCOUNTABILITY AND TRANSPARENCY The Data Protection Authority 35 COMMUNICATIONS AND OPERATIONS Delegation of Powers Brand Development Authority Structure Relocation Authority Meetings Website and App Authority Members Remuneration Social Media Accountability Arrangements Media and the JOIC The JOIC Team Data Protection Week - January 2019 Awards and Recognition 17 THE NEW REGISTRATION AND FEES MODEL 43 ENVIRONMENTAL POLICY 19 SUMMARY OF 2019 DATA PROTECTION ACTIVITIES Corporate Social Responsibility Benefits of Effective Data Protection 2019 Operational Performance Enforcement 45 FINANCIAL INFORMATION Breach Reporting 1 • Jersey Office of the Information Commissioner • 2019 Annual Report Jersey Office of the Information Commissioner • 2019 Annual Report • 2 9 6 2 Successfully assessed & evaluated 13 256 Hosted data 40% data breaches Rise in complaints protection lunch 5 Shortlisted for the 2019 & learns from 5 and data breaches Global Privacy and Castle Street from 2018 to 2019 Data Protection Awards Highlights and 8 11 achievements 13 National & international Developed an privacy conferences attended Reached independent finance by Commissioners over & Managers 700 function Islanders from organisations 3 and the public during Data Protection Week 2019 12 1 Developed and 7 10 introduced a new 4 Jersey Tech Awards win – revenue model and ‘Technology Project registration process Reached of the Year’ Team members Communicated Launched a data 7 appointed our DP message to 1,721 protection App hundreds of Islanders Island secondary school Junior Case Worker, Finance students via our Young & new website Officer, Communications Officer, via our public talks HR Manager, Legal Support, programme Privacy Ambassador and 2 Authority Members programme 3 • Jersey Office of the Information Commissioner • 2019 Annual Report Jersey Office of the Information Commissioner • 2019 Annual Report • 4 OUR ROLE OUR VISION The Jersey Data The Jersey Data Protection Authority (JDPA) is an independent statutory authority and A prosperous close-knit Island community its mission is to promote respect for the private lives of individuals through ensuring that embraces a collaborative and innovative privacy of their personal information by: approach to data protection, providing a leading-edge model to other similar Æ Implementing and ensuring compliance with the Data Protection (Jersey) Law jurisdictions. Protection 2018 and the Data Protection Authority (Jersey) Law 2018, and influencing thinking on privacy and processing of personal information matters on a local and international basis. Æ In addition, the Authority is responsible for providing advice and guidance to OUR PROMISE Island businesses and individuals, and making recommendations to the States of Authority’s Role, To promote the information rights of Jersey in response to international data protection legislative changes. individuals through a practical and ethical Æ The Information Commissioner has the separate responsibility to: Encourage approach to business practice and regulation public authorities to follow good practice in their implementation of the Freedom that supports the delivery of public services, Vision, Mission, of Information (Jersey) Law 2011 and help to promote transparency by supplying and promotes the social and economic the public with information about the Law. interests of the Island. Promise and 2019 Strategic Aims OUR 2019 STRATEGIC OUTCOMES 1 The people of Jersey are 2 The Island’s approach to 3 Jersey is recognised as a provided with a high data protection clearly world leader, embracing level of data protection contributes to its reputation innovation to safely and expert service whilst as a well-regulated develop and implement resources are judiciously jurisdiction. digital technology. and responsibly managed. 5 • Jersey Office of the Information Commissioner • 2019 Annual Report Jersey Office of the Information Commissioner • 2019 Annual Report • 6 In explaining the reason he made that sacrifice, he said During 2019, we worked with the Government of Jersey (the Government) to develop I am pleased to report that we have established a strong working that to become king in Paris was worth having to submit a system of funding that would reduce the contribution of the Government from 85% relationship with the Guernsey Data Protection Authority. This is to Catholic religious practices: ‘Paris vaut bien une messe’. to 33% of total revenue and increase the contributions from registration fees. This particularly important as many organisations have a pan-Island presence. VIEW FROM Repeating these words would be a suitable response to provides us with a greater level of financial independence from the Government, Both authorities agree that we should ensure as much consistency as criticism about administrative burden of data protection: while retaining the principle that the Government should make a reasonable possible in our guidance and approach to enforcement. The people and businesses building the trust necessary to enjoy a functioning contribution in recognition that data protection is a human right. of the Channel Islands deserve the same high standards of data protection and democracy and prosperous economy ‘vaut bien une expect their regulators to take a coordinated approach. Our two commissioners THE CHAIR In developing a new model for the consideration of the States Assembly, the messe’! meet regularly. In addition, the Chair of The Guernsey Data Protection Authority fundamental principles were to deliver just enough funding to enable us to fulfil our Richard Thomas and Commissioner Emma Martins joined the members of the DATA PROTECTION: I am pleased to present the second Annual Report of The statutory responsibilities and strike an appropriate balance between the financial Jersey Data Protection Authority after our Authority meeting in December. Our two Jersey Data Protection Authority (JDPA). In the Annual obligations of the Government and industry. We also wanted to ensure that it would WHAT IS IT GOOD FOR? authorities have now signed a Memorandum of Understanding to provide a formal Report last year, I introduced the JDPA and explained distribute the cost burden fairly and proportionately based on data risk and ability framework for our cooperation. its roles and responsibilities. It was an interesting and to pay and be as simple as possible to understand and as easy as possible The viability of a society and the success of its economy challenging first year, as we implemented our new to register. I am also pleased to announce that two new non-executive members joined the relies in the end on trust. People must be able to trust governance model and began to exercise our new powers. Authority in 2019. Both are well-respected members of the Jersey community and We consulted with members of the business community in developing our initial that governments and their agents will act in the public bring vital expertise. interest. They must be able to trust industry to treat them The focus of our second year was on our transition to proposal. We then submitted the proposal to public consultation. We incorporated fairly and in accordance with the law. It is important to greater independence. Article 52 of the GDPR requires feedback from the consultation and provided a revised proposal to the States One of the new members is Helen Hatton, renowned as the prime architect of the remember all of this when struggling to comply with data that each supervisory authority must act with complete Assembly. The members passed a revised regulation to bring the model into effect modern Jersey financial regulatory regime. Helen’s professional background involves Jacob protection laws. The administrative requirements of these independence in performing its powers and exercising its for 2020. a wealth of ground breaking financial initiatives. Additionally, she speaks regularly tasks. An independent authority is crucial for a successful on regulatory compliance and publishes papers on regulatory matters. laws can sometimes seem onerous and time-consuming. Transparency and accountability are essential components of data protection. Kohnstamm data protection regime, because it is necessary to Nevertheless, they are indispensable tools for building It is important that we are also transparent and accountable in our operations. The second appointment is Paul Routier MBE. Paul was an elected member to the secure public trust. Members of the public entrust public trust with members of the public with respect to the Our accountability programme includes developing a strategic plan to guide all States of Jersey