The new data protection rules: Don’t panic

Published: 2 May 2017
Type: Insight

The EU’s new General Data Protection Regulation (GDPR) comes into effect in May 2018, and is designed to give individuals back control of their own data. By introducing substantial new penalties for businesses, the GDPR undoubtedly raises the stakes, but for those already taking data protection seriously there should be little cause for alarm as long as they plan ahead.


The advent of the GDPR represents the biggest change in data protection law for more than 20 years and will be adopted wholesale in both Guernsey and Jersey, even though they sit outside the EU, in order to preserve their adequacy status – a necessity for the islands’ financial services businesses which are dependent on a free flow of information. Inevitably, much of the focus in the media over the GDPR has been on the increased fines of up to €20 million, or 4% of global annual turnover, and in companies where the management of data is not currently a priority there may be a rude awakening. However, for others the GDPR will feel more like a tightening of the rules, by bringing the legislation into line with what some would already consider best practice.

GDPR Compliance

The new law introduces a risk-based approach to governance, and evidence of the correct compliance procedures being in place will be essential. Another key component will be accountability, with some organisations being required to appoint a Data Protection Officer in much the same way as Money Laundering Reporting Officers already take responsibility for AML/CFT compliance. Other new elements include mandatory breach reporting for data loss, increased protection for children and new rules about transparency, requiring companies to be clearer about the data they are holding and how that data will be used. Individuals will also now have the right to have their data deleted when it is no longer required, with the introduction of a so-called ‘right to be forgotten’.

As such, the GDPR certainly creates new compliance obligations and must become a key element of every company’s risk management framework at board level. Most financial services businesses in the Channel Islands should already be live to the issues of handling personal data, and be aware of the risks involved. The Panama Papers debacle served as a stark reminder to the offshore industry, when law firm Mossack Fonseca received worldwide media attention after information about its clients’ financial dealings was published. The reputational risks associated with data breaches have therefore long provided the impetus for companies to do what the GDPR will now compel them to do by law, and for most, the issue is already a boardroom issue. Where this is already the case, the key decision is to identify the right person in place as the Data Protection Officer, who can drive implementation across the business over the next 12 months. The individual concerned needs a good understanding of both the existing and new law, and will likely need upskilling over the coming months to keep abreast of the implementation timetable.

Moving swiftly on the appointment of a Data Protection Officer will avoid expensive, eleventh-hour remedying in May next year, and will make the adoption of the GDPR run smoothly. We advise companies to focus on two things when identifying the right person: first, the individual chosen must have sufficient influence within the business to be taken seriously and listened to at all levels; and second, they must have a genuine interest in the subject matter. With the right person leading the charge, and with an ongoing commitment to data protection, the advent of the GDPR should not cause undue concern. Where the new regulatory powers will have the potential to shock is in businesses that are currently oblivious to their data protection responsibilities.

First published by Business Brief, April 2017

Share
More publications
Appleby-Website-Corporate-Practice
11 Dec 2025

Listing Private Equity Acquisition Debt on The International Stock Exchange (TISE)

an introduction to listing private equity acquisition debt on The International Stock Exchange (TISE) as well as a summary of Appleby’s listing agent services in the Channel Islands.

Appleby-Website-Employment-and-Immigration
12 Nov 2025

Jersey employment law developments summarised by Appleby’s top-ranked lawyers

Appleby remains the only offshore law firm operating across all three Crown Dependencies and, once again, its employment law teams in each of those jurisdictions has been ranked Tier 1 in legal directories including Legal 500. Find out more about our Employment Law advice.

Appleby-Website-Corporate-Practice
4 Nov 2025

Appleby and private capital in the UK

Appleby Jersey continues to be active in supporting UK focussed private capital transactions. Our expert explores a number of areas where we can assist, namely Private Equity, Mergers & Acquisitions, Financing, TISE Listings, Company Incorporations / Administration Services, Fund Raising and Safe Harbours. Read more

IWD Grid Capture
8 Mar 2025

International Women’s Day 2025 roundtable: Rights. Equality. Empowerment.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a vision – it’s a call to action.

Appleby-Website-Corporate-Practice
20 Jan 2025

A Golden New Year for natural resources in the Channel Islands

Our expert considers why Jersey and Guernsey are attractive jurisdictions for natural resource companies

Employment-and-Immigration
30 Apr 2024

Secondary Pensions in Guernsey: Are you ready for it?

After several years of planning (and delays), The Secondary Pensions (Guernsey and Alderney) Law (Law) is due to shortly come into force for all employers. The Law’s fundamental aim is tackling pensioner poverty on the island, by requiring all employers to set up a pension for all their eligible employees, enrol them into it, and begin mandatory contributions.

The Global Website header
9 Apr 2024

The Global – your offshore corporate law questions answered: April 2024

The Global is a quarterly collection of corporate expert insights and analysis across Appleby's global jurisdictions. Here are follow-up FAQs from the insights we shared in the 2023 Q4 Review edition.

Intellectual Property
19 Mar 2024

Guernsey retains its EU adequacy – as expected

The post-Brexit regulatory landscape continues to throw up challenges and jurisdictional arbitrage, but there are some areas where consistency and stability are welcome. The recent confirmation from the European Commission that 11 jurisdictions had retained their “adequacy” status from a data protection perspective has left many breathing a (long anticipated) sigh of relief. All three of the Crown Dependencies (Guernsey, Jersey and the Isle of Man) have retained the coveted status.

Employment-and-Immigration
18 Mar 2024

Parental Bereavement Leave: Jersey to implement further family leave rights

The UK introduced “Jack’s law” in 2020. Jersey is now following the UK’s example, and as of 18 March 2024, a draft amendment to its Employment Law 2003 will come into force introducing a right to parental bereavement leave on the island.

The Global Website header
10 Jan 2024

The Global – your offshore corporate law questions answered

The Global is Appleby’s quarterly collection of expert insights and analysis on the latest developments in offshore corporate law. Here are follow-up FAQs from the insights we shared in the Q3 Review edition.