Advisory

PrivCom Advises the Public on Cyberattacks (2024-03-28)

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Issued 2024-03-28

Current version last checked: 2026-07-30

Summary

This is a public advisory from Bermuda's Office of the Privacy Commissioner (PrivCom) reminding organisations and individuals about cybersecurity and data breach risks. It restates prior guidance rather than creating new rules, and explains how Bermuda's Personal Information Protection Act (PIPA) will govern security safeguards and breach notification once its substantive provisions take effect.

  • PIPA timing: Substantive PIPA provisions on security safeguards and data breach notification are confirmed to come into effect on 1 January 2025; PrivCom does not require or expect breach notifications to its office before that date.
  • Security safeguards: Once in effect, PIPA will require organisations to protect personal information with safeguards proportional to the likelihood and severity of harm, sensitivity of the information, and context, rather than a one-size-fits-all standard.
  • Breach notification: Organisations will need to notify affected individuals of breaches likely to adversely affect them, without undue delay and proportional to the risk of harm; not every incident triggers a notification duty.
  • PrivCom role: PrivCom will have the ability to instruct organisations on further steps after a breach and will investigate whether the organisation's risk analysis and safeguards were reasonable.
  • Guidance resources: PrivCom points organisations to its Guide to PIPA, best practice guides on privacy programmes, small business advice, and cybersecurity blogs, and points individuals to external resources (NCSC, National Cybersecurity Alliance, credit freeze options) for self-protection.

The document is educational in nature; it does not itself impose new legal duties but signals the obligations organisations will face under PIPA from 1 January 2025 onward and encourages preparatory steps such as data mapping.

Key obligations

  • From 1 January 2025, organisations must implement security safeguards proportional to the likelihood and severity of harm, sensitivity of information, and context to protect personal information under PIPA.
  • From 1 January 2025, organisations must notify affected individuals, without undue delay, of data breaches likely to adversely affect them, as required under PIPA.
  • Organisations are encouraged (though not yet legally required before 1 January 2025) to map the personal information they hold and their data flows as part of Road to PIPA preparation, to aid future breach response.

Applies to

organisations that collect, hold, or process personal information, general public and individuals in Bermuda

Deadlines

  • 1 January 2025: Substantive PIPA provisions on security safeguards and data breach notification are announced to come into effect; PrivCom does not require breach notifications before this date.

Topics

Version history

2026-07-30

source file (current)