Advisory

Advice to the Public in Response to the Cyberattack on Government Services (2023-09-29)

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Issued 2023-09-29

Current version last checked: 2026-07-30

Summary

This is a public advisory issued by Bermuda's Office of the Privacy Commissioner (PrivCom) following a cyberattack on Government services in September 2023. It does not confirm whether personal data was accessed, and instead offers general guidance to both organisations and individuals on data security, breach risks, and the future application of Bermuda's Personal Information Protection Act (PIPA).

  • Nature of the document: An informational advisory and guidance piece, not a binding rule or enforcement notice.
  • Current status of PIPA: Substantive PIPA provisions on security safeguards and data breach notification are stated to come into effect on 1 January 2025; PrivCom does not require or expect breach notifications before that date.
  • Guidance for organisations: Points readers to PrivCom's existing resources, including the Guide to PIPA, best practices for privacy programmes, small business advice, and cybersecurity awareness materials.
  • Guidance for individuals: Recommends reviewing external resources (UK NCSC Cyber Aware, US National Cybersecurity Alliance) and considering credit report checks or credit freezes if identity theft is suspected.
  • Future PIPA obligations previewed: Once PIPA takes effect, organisations will be required to notify affected individuals of breaches likely to cause adverse effects, and to maintain safeguards proportional to risk, sensitivity of information, and context.

The advisory is primarily reassurance and education rather than a source of new legal duties, since the relevant PIPA provisions are not yet operative. It signals that formal breach notification and safeguard obligations, and PrivCom's supervisory role over them, will commence on 1 January 2025.

Key obligations

  • From 1 January 2025, once PIPA is in effect, organisations will be required to notify affected individuals of a data breach where loss, disclosure, or access of personal information is likely to adversely affect them, without undue delay and appropriate to the risk of harm.
  • From 1 January 2025, organisations will be required to implement security safeguards against loss, unauthorised access, destruction, use, modification, or disclosure of personal information, proportional to the likelihood and severity of harm, sensitivity of information, and context.

Applies to

organisations holding personal information, members of the public/individuals

Deadlines

  • 1st January 2025: Substantive PIPA provisions on security safeguards and data breach notification are announced to come into effect; PrivCom does not require breach notifications before this date.
  • 15-20 October 2023: Bermuda hosts the Global Privacy Assembly, an international meeting of privacy regulators (informational, not a compliance deadline).

Topics

Version history

2026-07-30

source file (current)