On Air Now Soleil Radio Stressbusters 6:00pm - Midnight
Now Playing Vesta Williams Once Bitten Twice Shy

Call for Jersey businesses 'to take responsibility' on data protection

Jersey businesses are being urged to 'start taking some responsibility' when it comes to data protection.

It's after a survey found that:

  • 38% of larger organisations say 'lack of time and operational pressures' is the greatest barrier to offering staff data protection training
  • Almost half of organisations report that they do not currently use AI tools or systems
  • Two-thirds of organisations (67%) report that they have never conducted a Data Protection Impact Assessment (DPIA) or a DPIA-style assessment
  • Almost two-fifths (39%) say they have no cyber-security policies or procedures in place
  • 29% say they keep no breach records

Information Commissioner, Paul Vane, said:

"One of the headlines was that 38% of large organisations say they don't have the time, or they've got too many operational pressures, to deal with things like offering basic data protection training to their staff.

"That's ludicrous. You need to be making time for that training, providing it, and outsourcing it if necessary to a reputable provider.

"There's another one about those organisations that are required by law to have a data protection officer. 90% of organisations that have to have a DPO don't bother checking their qualifications to make sure they're good enough to do the job.

"Why would you do that? You wouldn't do that with any other member of staff you've employed, you would check to make sure they're fit, able and proper to do the job they're employed to do.

"There does seem to be an element of burying your head in the sand that needs to be addressed, and hence this more structured, what we're calling a Triple 'A' approach to hopefully make people take more notice."

That new approach has been set out in the JOIC's 2026-2028 strategy:

  • Advise - Define expectations, build capacity, and enable compliance
  • Assess - Evaluate compliance, performance, and risk
  • Act - Take targeted action to address non-compliance

Mr Vane added:

"We're still going to do the advising and the guidance and the educational bit that we've done for years, but it's going to be more directed at these are the steps you need to take, and this is what we expect you to do, so more instructive.

"When that's absorbed by an organisation, we're going to come back in, say, four to six months, and we're going to check.

"We're going to do that by assessing whether or not you've implemented the guidance that we've issued, and that might be sector-based, certain individual companies that we target, but it's certainly going to be a more targeted approach and a more topic-specific, rather than trying to cover everything, because we can't do everything.

"Then, based on the findings from that, that might lead to a whole range of enforcement activities that we then undertake - whether that be through words of advice, further education and guidance depending on the maturity of that business, or the more serious end, you could be in orders and reprimands and fining territory that we might need to explore.

"Certainly, there will be more overt use of our enforcement capability and greater quantity of it moving forward because we're past that honeymoon period, we're well past it in fact, and this is something that needs to be taken incredibly seriously by organisations moving forward."

The strategy sets out the importance of compliance, given the severe impact breaches can have on businesses, and Jersey as a whole.

Mr Vane concluded:

"Enforcement is one focus for us, but for me, it's also about the foreseeable consequences for individuals, the physical and mental harm and financial loss and discrimination that they could suffer, and distress they could suffer as a result."

Guidance for organisations is available on the JOICs’ website.

More from Jersey News from Channel 103

Comments

Add a comment

Log in to the club to add your comment.