Act

Personal Information Protection Act 2016

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

In force

Status per Bermuda Laws Online (bermudalaws.bm) (as at 2026-07-30)

Current version last checked: 2026-07-30

Summary

This is Bermuda's core data protection statute, establishing a comprehensive framework governing how organisations use personal information and creating the Office of the Privacy Commissioner to oversee compliance. It sets out general principles for lawful use of personal data, individual rights, exemptions, supervisory powers, and offences for non-compliance.

  • Scope: Applies to every organisation (individuals, entities or public authorities) that uses personal information in Bermuda by automated means or as part of a structured filing system, subject to listed exclusions (domestic use, journalistic/artistic use, business contact information for employees, very old personal data, judicial records, parliamentary privilege, etc).
  • General principles: Organisations must have a lawful basis (such as consent) for using personal information, limit use to sensitive personal information conditions, act fairly, provide privacy notices, limit use to stated purposes, keep information proportionate, accurate and not retained longer than necessary, and apply appropriate security safeguards.
  • Breach notification: Organisations must notify the Commissioner and then affected individuals without undue delay following a security breach likely to adversely affect an individual, describing the nature, consequences and remedial measures taken.
  • Overseas transfers: Additional obligations apply under section 15 when personal information is transferred to an overseas third party.
  • Individual rights: Individuals have rights to access personal information (including medical records), correction, blocking, erasure, destruction, and compensation for financial loss or distress, exercised through a defined request procedure.
  • Supervision and enforcement: Establishes the Privacy Commissioner with powers to investigate, inquire, issue codes of practice, order compliance, and handle reviews and complaints; non-compliance with orders, notices, or the sensitive information provisions is an offence.
  • Penalties: Individuals convicted summarily face fines up to $25,000 or imprisonment up to two years or both; organisations convicted on indictment face fines up to $250,000.

The Act binds the Crown, allows the Minister to make regulations and consequential amendments, and requires periodic review of the legislation. Commencement was staggered: core administrative sections took effect in 2016, with the substantive obligations of the Act only coming into operation on 1 January 2025.

Key obligations

  • Every organisation must adopt suitable measures and policies to give effect to its obligations and individuals' rights under the Act, and designate a privacy officer responsible for compliance and communication with the Commissioner.
  • Organisations may only use personal information where a specified lawful condition is met (e.g. informed consent, contractual necessity, legal authorisation, public interest, emergency, or employment relationship).
  • Organisations must not use sensitive personal information to discriminate unlawfully and may only use it under specified lawful authority conditions.
  • Organisations must provide individuals with a clear privacy notice describing use, purposes, disclosure recipients, organisation contact details, privacy officer contact details, and choices for limiting or correcting use of personal information.
  • Organisations must limit use of personal information to purposes stated in the privacy notice or related purposes, ensure proportionality, and keep information accurate, up to date, and not retained longer than necessary.
  • Organisations must implement security safeguards proportional to the risk, sensitivity and context of the personal information held, subject to periodic review.
  • On a security breach likely to adversely affect an individual, the organisation must, without undue delay, notify the Commissioner (describing the breach, consequences, and remedial measures) and then notify affected individuals.
  • Organisations transferring personal information to an overseas third party must additionally comply with the requirements of section 15.
  • Organisations must respond to individual requests for access, correction, blocking, erasure or destruction of personal information in accordance with the prescribed procedure.
  • Organisations must comply with orders and notices issued by the Commissioner during investigations, inquiries, reviews or complaints.
  • The Minister must carry out a comprehensive review of the Act within five years of its coming into operation and submit a report to the House of Assembly within 18 months of beginning that review.

Applies to

organisations (individuals, entities or public authorities that use personal information in Bermuda)

Deadlines

  • 2 December 2016: Sections 1, 2, 26, 27, 28, 29, 35, 36, 51 and 52 came into operation.
  • 1 January 2025: The remainder of the Act, including the substantive data protection obligations, came into operation.
  • without undue delay: Organisations must notify the Commissioner and then affected individuals following a security breach likely to adversely affect an individual.
  • within five years of the Act's coming into operation: The Minister must carry out a comprehensive review of the Act.
  • within 18 months after beginning the review: The Minister must submit a review report to the House of Assembly.

Related documents

Topics

Version history

2026-07-30

source file (current)