Form
Breach of Security Notification Form
Status not confirmedView on PRIVCOM's website Source document
Summary
This is a standard form issued by the Office of the Privacy Commissioner for Bermuda (PrivCom) for organisations to use when reporting a breach of security (personal information breach) under Bermuda's Personal Information Protection Act (PIPA). It is not for use by individuals reporting concerns, and instead is completed by the organisation that experienced the breach.
- Purpose: Collects details of a personal information breach, including organisation and sector, how and when the breach was discovered, the type and number of individuals affected, categories of personal information involved, and security measures in place.
- Notification duty: Restates the PIPA requirement that an organisation must inform the Commissioner and affected individuals directly and without undue delay if a breach is likely to adversely affect an individual.
- Notification method: Preferred method is letter or email to affected individuals; website notices, posted notices, or social media may be used only where direct notification would cause further harm, is cost prohibitive, or contact information is unavailable.
- Content required: The form and accompanying checklist require details such as the organisation's name, privacy officer contact, date and location of breach, estimated number and type of individuals affected, categories of personal information involved, containment and remediation measures, and whether other regulators (e.g. police) were involved.
- Submission: Completed form is emailed to investigations@privacy.bm; organisations should not include identifiable personal information in the submission.
An accompanying checklist confirms that both the Commissioner and any adversely affected individuals have been notified without undue delay, and lists the specific details that must be included in each notification.
Key obligations
- An organisation must inform the Commissioner and any individuals likely to be adversely affected by a personal information breach directly and without undue delay.
- Notification to affected individuals should occur as soon as possible following the breach, preferably by letter or email, with alternative methods (website, posted notice, social media) used only in limited circumstances.
- When notifying PrivCom, the organisation must complete and submit this form (or otherwise provide equivalent details) including organisation name, privacy officer details, date/time/location of breach, date organisation became aware, estimated number and type of individuals affected, categories of personal information involved, potential harm, security measures, retrieval status, involvement of other regulators, and containment/corrective measures.
- When notifying affected individuals, the organisation must include contact details of a privacy officer or other contact point, the number and type of individuals affected, a description of likely consequences, measures taken or proposed to address the breach, and steps individuals can take to mitigate risk.
- Organisations must not include identifiable personal information within the notification form itself when describing categories of personal information involved.
Applies to
organisations subject to Bermuda's Personal Information Protection Act (PIPA), data controllers across sectors including finance, legal, healthcare, and government departments/agencies
Deadlines
- without undue delay: Organisations must notify the Commissioner and affected individuals without undue delay following discovery of a personal information breach likely to adversely affect an individual.