No Content Set
Exception:
Website.Models.ViewModels.Components.General.Banners.BannerComponentVm

Site logo Site logo
  • Better Business Grant
  • Events
  • News
  • Team
  • About Us
  • Starting up

  • Operations

  • Finance

  • Growth

  • People

  • Starting up
    • First things first
      • Do you know that your business idea is viable?
    • Getting prepared
      • Developing a business plan
      • Preparing financial forecasts
    • Getting the formalities ready
      • Types of trading entity
      • Starting up as a sole trader or partnership in Jersey
      • Setting up a limited company in Jersey
        • Additional licence and registration requirements
      • Setting up in Jersey as a non-resident
      • Setting up a catering business
      • Starting a mobile catering business in Jersey
      • Social Security contributions and your new business
      • Setting up as a bookkeeper or accountant
    • Guides & checklists
      • Business Plan Template
      • Running a business from your home
      • Relocating your business to Jersey
  • Operations
    • Productivity Hub
      • SEE Enterprise Pathway Pilot
      • Productivity Support Scheme Grant
      • Business performance
        • Admin for your business
      • GVA Calculator (Gross Value Added)
    • Marketing
      • Types of marketing activities
    • Technology & data protection
      • Cyber security
      • Cyber essentials
      • Data protection definitions
      • Data Protection for SMEs
      • Data Protection – Frequently asked questions
      • Data Protection Registration
      • GDPR – A risk based approach to compliance
      • GDPR - What will it mean for your business?
      • Incoming Threats
      • Keep your business safe online
      • Systems that support your business
      • Systems and Hardware
      • Your online behaviour
    • Premises & insurance
      • Business Insurance
    • Local services providers
  • Finance
    • Managing finances
      • Financial Plan Development
      • Minimizing Waste & Energy Costs
    • Raising funds
      • Listing on the local stock exchange
    • Free business health check
      • Business Health Check Form
    • Funding opportunities to boost your productivity
      • Better Business Grant
        • Better Business Grant payment process
        • Better Business Grant Ts&Cs for grants under £5,000
        • Better Business Grant Ts&Cs for grants over £5,000
        • Better Business Grant Ts&Cs for apprenticeship grants
        • Better Business Grant FAQs
        • Better Business Grant application guidance
      • Agricultural Loans Fund
  • Growth
    • Importing & exporting
      • Exporting
        • Are you ready to export?
        • Getting started in export
        • Develop your export plan
        • Researching your export markets
        • Exporting from Jersey
        • Route to your export market
        • Logistics of exporting
        • Delivering great customer service overseas
        • International payments and contracts
        • Exporting to the USA
        • How to visit international markets
        • Doing business with India
        • Import/Export focus groups
      • Importing goods into Jersey
        • 10 steps to importing goods into Jersey
      • Marketing internationally
        • Writing an international marketing plan
        • Maximise the impact of your digital presence
    • Programmes
      • Business Improvement Programme
      • Leading Growth Programme
  • People
    • Wellbeing in the workplace
      • Stress
      • Time management
      • Resilience
      • Physical exercise
      • Healthy eating
    • Remote workers
    • Hiring
    • Employment disputes
  • Guides
  • Case Studies
  • Better Business Grant
    • Better Business Grant payment process
    • Better Business Grant Ts&Cs for grants under £5,000
    • Better Business Grant Ts&Cs for grants over £5,000
    • Better Business Grant Ts&Cs for apprenticeship grants
    • Better Business Grant FAQs
    • Better Business Grant application guidance
  • Events
  • News
  • Team
  • About Us
    • Corporate documents
    • Working with Jersey Business

Starting up

You're thinking of starting up your business in Jersey which is the first step in turning a good idea into a commercial opportunity. Find out more

View all Starting up guides View all Starting up case studies
First things first
Getting prepared
Getting the formalities ready
Guides & checklists
First things first Do you know that your business idea is viable?
Getting prepared Developing a business plan Preparing financial forecasts
Getting the formalities ready Types of trading entity Starting up as a sole trader or partnership in Jersey Setting up a limited company in Jersey Setting up in Jersey as a non-resident Setting up a catering business Starting a mobile catering business in Jersey Social Security contributions and your new business Setting up as a bookkeeper or accountant
Guides & checklists Business Plan Template Running a business from your home Relocating your business to Jersey

Operations

Running your business operations as smoothly as possible for maximum efficiency gives an instant boost to your bottom line. Find out more

View all Operations guides View all Operations case studies
Productivity Hub
Marketing
Technology & data protection
Premises & insurance
Local services providers
Productivity Hub SEE Enterprise Pathway Pilot Productivity Support Scheme Grant Business performance GVA Calculator (Gross Value Added)
Marketing Types of marketing activities
Technology & data protection Cyber security Cyber essentials Data protection definitions Data Protection for SMEs Data Protection – Frequently asked questions Data Protection Registration GDPR – A risk based approach to compliance GDPR - What will it mean for your business? Incoming Threats Keep your business safe online Systems that support your business Systems and Hardware Your online behaviour
Premises & insurance Business Insurance

Finance

A clear financial plan and understanding of your finances is key to the success or failure of a business. Find out more

View all Finance guides View all Finance case studies
Managing finances
Raising funds
Free business health check
Funding opportunities to boost your productivity
Managing finances Financial Plan Development Minimizing Waste & Energy Costs
Raising funds Listing on the local stock exchange
Free business health check Business Health Check Form
Funding opportunities to boost your productivity Better Business Grant Agricultural Loans Fund

Growth

Whether you're expanding, venturing into exports, or enhancing skills, businesses must move forward or risk falling behind. Find out more

View all Growth guides View all Growth case studies
Importing & exporting
Programmes
Importing & exporting Exporting Importing goods into Jersey Marketing internationally
Programmes Business Improvement Programme Leading Growth Programme

People

Your most valuable asset. Find out more

View all People guides View all People case studies
Wellbeing in the workplace
Remote workers Hiring Employment disputes
Wellbeing in the workplace Stress Time management Resilience Physical exercise Healthy eating

GDPR – A risk based approach to compliance

Home

Operations

Technology & data protection

GDPR – A risk based approach to compliance

LinkedIn Twitter Facebook WhatsApp Email
Download page

Your business must ensure that the data is handled legally, securely, efficiently and effectively in order to deliver the best possible care.

When your organisation collects, stores or uses (i.e. processes) personal data, the individuals whose data you are processing may be exposed to risks. It is important that organisations that process personal data take steps to ensure that the data is handled legally, securely, efficiently and effectively in order to deliver the best possible care.

Download
6 Essential Steps to GDPR Compliance Infographic

(414kb)

What risk does the information you hold pose to your customers?

The risk-profile of the personal data you hold should be determined according to:

  • the personal data processing operations carried out;
  • the complexity and scale of data processing;
  • the sensitivity of the data processed; and
  • the protection required for the data being processed.

For example, where a data processing activity is particularly complex, or where a large volume or sensitive data is involved (i.e. an internet, health, financial or insurance company), this would attract a higher risk rating than routine personal data that relates solely to employee or customer account details.

Think of the potential harm to your customers

It is useful to look at the tangible harms to individuals that your organisation needs to safeguard against. These may include processing that could lead to:

  • Physical, material or non-material damage;
  • Discrimination;
  • Identity theft or fraud;
  • Financial loss;
  • Reputational damage;
  • Loss of confidentiality protected by professional secrecy;
  • Unauthorised reversal of pseudonymisation;
  • Any other significant economic or social disadvantage.

TIP: Conduct a risk-assessment to improve awareness of the potential future data protection issues associated with a project. This will help to improve the design of your project and enhance your communication about data privacy risks with relevant stakeholders.

Data protection by design and by default

The DPJL and GDPR provide for two crucial concepts for future project planning: Data Protection By Design and Data Protection By Default. While long recommended as good practice, both of these principles are now enshrined in the DPJL (Article 15).

Data Protection by design means embedding data privacy features and data privacy enhancing technologies directly into the design of projects at an early stage. This will help to ensure better and more cost-effective protection for individual data privacy.

Data Protection by default means that the user service settings (e.g. no automatic opt-ins on customer account pages) must be automatically data protection friendly, and that only data which is necessary for each specific purpose of the processing should be gathered at all.

Data Protection Impact Assessment (DPIAs)

Under the DPJL, a Data Protection Impact Assessment (DPIA) is a mandatory pre-processing requirement where the envisaged project/initiative/service involves data processing which “is likely to effect in a high risk to the rights and freedoms of natural persons.” (Article 16 DPJL).

This is particularly relevant when a new data processing technology is being introduced in your organisation. In cases where it is not clear whether a DPIA is strictly mandatory, carrying out a DPIA is still best practice and a very useful tool to help data controllers demonstrate their compliance with data protection law. DPIAs are scalable and can take different forms, but the DPJL sets out the basic requirement of an effective DPIA.

Data protection risk register

Maintaining a data protection risk register can allow you to identify and mitigate against data protection risks, as well as demonstrate compliance in the event of a regulatory investigation or audit.

DPJL readiness checklist tools

In addition to the general checklist below, the following pages will take organisations through more detailed questions in the areas of:

  • Personal data
  • Data subject rights
  • Accuracy and retention
  • Transparency requirements
  • Other data controller obligations
  • Data security
  • Data breaches
  • International data transfers

The following tables will assist organisations in mapping the personal data that they currently hold and process, recording the lawful basis on which the data was collected, and specifying the retention period for each category of data. Carrying out this exercise will help identify where immediate remedial actions are required in order to be compliant with the DPJL (and, where appropriate, the GDPR).

Download
the DPJL Readiness Checklist

(40kb)

Relevant Links

Jersey’s Information Commissioner
Data Protection for SMEs
Data Protection Registration
Data Protection – Frequently asked questions
GDPR - What will it mean for your business?

Business Stories

Operations

HR Now – Driving Success and Continuous Improvement

Becky Hill, the founder of HR Now, shares her positive experience with Jersey Business's Leading Growth and Business Improvement programs, highlighting their impact on her business's success and continuous improvement.

Find out more

Operations

Business Improvement Programme – Puritas

Puritas undertook the Business Improvement Programme, it’s resulted in an estimated £100,000 of savings for the company.

Find out more

Growth

Working smarter, not harder: Catching up with Lee Madden of GR8 Recruitment

GR8, a successful recruitment agency in Jersey, has grown significantly since its inception five years ago. We caught up with founder, Lee Madden, to discover how GR8 navigated its way through the pandemic and beyond.

Find out more
Bellpums And Pollution

Finance

Bellpumps and Drains – Opportunity through innovation
Find out more

Ready to talk?

"We’re by your side as you start your entrepreneurial journey, empowering you to step confidently into the world of business."

Emma Veitch 3

Emma Veitch

Senior Business Advisor

Before you contact us
  • Why not download the Start up checklist.
  • Take a look at our Build Your Business videos to help you sketch out how your business will operate.
Can’t find an answer to your question?

Click on the button below and a member of our friendly team will be in touch shortly.

Contact

Related News

Brandly PR Website

Finance

Insights & News

Ai could help make Jersey £2.8bn annually

23/04/2025

Find out more
BBG Approved 1

Operations

Growth

Insights & News

First Better Business Grant approval for Les Ormes

03/04/2025

Find out more
Bb2025apr HC

Insights & News

Capital investment trends in Jersey: A small island with big potential

02/04/2025

Find out more
Image GIF

Growth

Insights & News

Matched funding worth £5.3 million now available

24/03/2025

Find out more

Keep up-to-date with business information, news and events
sign up for the Jersey Business newsletter.

Subscribe

Starting up

Operations

Finance

Growth

People

Events

News

About Us

Contact Us

Cookie Policy

Privacy Policy

Terms & Conditions

© Jersey Business. All rights reserved. 2025

No Content Set
Exception:
Website.Models.ViewModels.Blocks.SiteBlocks.CookiePolicySiteBlockVm

Site Logo

JB