File folders in a filing cabinet

Some States committees think Guernsey’s data protection rules are costing deputies and civil servants too much time.

That’s according to the Bailiwick’s Data Protection Commissioner, Brent Homan, who recently revealed that concerns had been raised by some deputies.

So Express asked a straightforward question: who raised those concerns, and what changes are they looking for?

The response shed more light on the civil service’s view of the problem than who was actually complaining.

According to States Head of Data Protection Kyle Merrien, the law itself isn’t the issue.

Burden of requests

Mr Merrien was responding to comments in local media from Mr Homan – who heads up the Office of the Data Protection Authority (ODPA).

Mr Homan revealed that some committees had raised concerns about how much time they were spending following data protection rules, especially Subject Access Requests (SARs) – which allow people to ask to see their own data.

Asked who had raised those concerns, Mr Merrien stopped short of naming any committees.

Instead, he said the law had “been in place for eight years now and over that time the requirements have not changed”.

Instead, he pointed to a sharp increase in information rights requests across the States and argued that the challenge stems from the growing volume of data being collected and retained.

“What has changed is the amount of data that businesses, including the States of Guernsey, collect and process.”

Not discussing changes

Rather than legislative change, he suggested the answer lies in better internal data management, including collecting less information, deleting information that is no longer needed and improving how records are organised.

Mr Merrien also said some committee areas receive significantly more requests than others, creating greater pressure on staff and resources.

A man in a grey suit and white shirt.
Pictured: Data Protection Commissioner Brent Homan.

However, despite Mr Homan’s reference to discussions around possible amendments, Mr Merrien said those concerns were not currently being discussed with the ODPA.

“I am aware that some committee areas receive more requests than others and this places greater resource demands on them, but this is not something we are currently discussing with the ODPA,” he said.

The response leaves open the question of which committees prompted the concerns referred to by Mr Homan, and whether any are seeking changes to the law itself or simply a more practical way of managing requests within existing rules.

Wider scrutiny of data

Mr Merrien’s comments come against the backdrop of wider debates over how the States handles information.

Earlier this month, Express revealed that at least one Deputy had deleted emails from voters without reading them, prompting the ODPA to clarify the rules on how deputies handle sensitive data.

Policy and Resources (P&R) also faced criticism for refusing to share its GST modelling with deputies or the public, citing privacy concerns.

Rather than arguing for weaker information rights or changes to the law, Mr Merrien suggested public bodies should focus on collecting only the data they genuinely need and ensuring information is not retained indefinitely.

“The key to addressing this should be focussed on internal practices and procedures, ensuring that data is not collected if not required and not kept for longer than is necessary,” he said.

Mr Merrien’s argument appears to be that the answer is not fewer rights for islanders, but keeping less unnecessary data in the system in the first place.