COMPLAINTS to Jersey’s data watchdog surged by more than 50% last year – with public authorities accounting for around a third of all cases.
The Jersey Office of the Information Commissioner received 135 complaints and inquiries during 2025, compared with 86 the previous year – a rise of almost 57%.
And despite making up just 1% of organisations registered with the regulator, the public sector, appointed regulators and statutory bodies were responsible for 44 complaints – around one in three of the Islandwide total.
The Information Commissioner’s annual report said public authorities attracted the highest number of complaints, although it described this as “not unreasonable” given that they are large employers and users of personal data.
The figures come amid stark warnings from Information Commissioner Paul Vane about the growing threats posed by cyber attacks, artificial intelligence and online harms.
He warned that deepfakes and other AI-generated material have already been used in Jersey to “deceive, defraud, or harass”, adding that such material can damage reputations and wellbeing and even affect elections.
“In an island the size of Jersey, these harms are amplified significantly,” Mr Vane said.
“As a regulator, we recognise that these risks are not abstract. They are here, they are evolving, and they demand a proactive, collaborative response grounded in the law and in ethics.”
Half of complaints received last year involved Islanders trying to access their own personal information and either being refused it or receiving only part of what they had requested.
The watchdog said complaints investigated in this area often involved excessive redactions, organisations failing to respond or refusing to disclose information applicants expected to receive.
A further 21% concerned personal information being shared when complainants believed it should not have been. Examples included employers oversharing information, group emails being sent without using the blind-copy function and former employees using personal data without permission.
Of complaints closed during the year, 27% were investigated and resulted in a finding that data-protection rules had been breached, while 10% were investigated and resulted in no breach finding. The regulator issued sanctions including reprimands and orders.
Meanwhile, organisations themselves reported 209 data breaches to the watchdog during 2025, up from 184 the previous year.
Of these, 146 involved unauthorised disclosures, including emails or information being sent to the wrong person.
Another 54 involved issues including ransomware, phishing attacks and lost data. One ransomware incident was considered serious enough to trigger a joint investigation involving Jersey and three other jurisdictions.
Mr Vane warned that cyber and data breaches were becoming “more sophisticated and more frequent” and said cyber security could no longer be treated simply as an IT issue.
“It must be a board-level priority, a legal obligation, and should be central to organisational integrity,” he said.
The regulator has made cyber security, children’s privacy and artificial intelligence its three strategic priorities for 2026 to 2028.

