Brent Homan was speaking following concerns raised by States committees about the obligations being made on them through the law, particularly in relation to data subject access requests, where someone asks to know what information an organisation might hold on them.
Mr Homan said his office had already contributed to discussions around potential legislative amendments and practical improvements to the current law, which is nearly 10 years old. He believed that light touch approaches could secure significant benefits.
‘There is always scope to improve, clarify and refine laws in light of operational experience, technological developments and feedback from organisations and the public,’ he said.
‘Ultimately, however, decisions on legislative change, timing and implementation rest with the States of Guernsey.’
He said it was also important to remember that the effectiveness of a regulatory regime was determined not only by the law itself, but by how it is applied.
‘The ODPA’s strategic approach places significant emphasis on helping organisations get things right in the first place through guidance, outreach and informal engagement. Enforcement remains important, but it is a last resort rather than a first response.’
Mr Homan said that the current law was flexible and risk-based, rather than prescriptive, and allowed organisation to adopt safeguards which are appropriate to the volume, sensitivity and nature of the personal information they process.
‘A small community charity holding limited contact information faces very different risks compared with a large financial services business processing substantial volumes of sensitive personal data,’ he said.
‘The challenge is finding the right balance. Individuals expect their personal information to be handled responsibly regardless of whether they are dealing with a multinational organisation, a small business or a charity.
‘Any conversation about reducing burdens therefore needs to be balanced against the reality that data protection failures can have significant impacts on individuals, regardless of the size of the organisation involved.’
Former Policy & Resources vice-president Heidi Soulsby has criticised the legislation, saying there is no proportionality in it and it takes no account of cost relative to risk, and is concerned about the burden of subject access requests.
Both Health & Social Care and Home Affairs have recently admitted that they were being overwhelmed with data access requests, and HSC has been sanctioned by the ODPA for its poor response to individual islanders.
Mrs Soulsby said that she first raised concerns when the law was being approved in 2017. Her bid to initiate change in the previous political term was blocked by the need to prioritise preparations for the Moneyval inspection.
The EU is also looking at ways to reduce the burden on smaller organisations.
‘I do think Guernsey should lead on this, rather than follow, given the impact it is having. Certainly, I don’t think we should wait until the EU makes changes,’ she said.
Mr Homan said that maintaining Guernsey’s adequacy status was also important for international trade, investment and business operations and any jurisdiction considering changes to its data protection framework must therefore think carefully about the implications.
‘Good data protection is not about choosing between people and prosperity. It is about protecting people, applying the law proportionately, and giving businesses and the international community confidence that Guernsey is a trusted place to share and use data,’ he said.