Statement of Guidance

Financial Service Provider's Guidance Notes – Final Report (2025-03-07)

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is the final report of PrivCom's Financial Service Provider's Guidance Notes, issued after a public consultation process with Bermuda's financial services industry regarding the application of the Personal Information Protection Act 2016 (PIPA), which took effect on 1 January 2025. It explains how PIPA applies to banks, insurers, reinsurers, captive insurers, trust and corporate service providers, investment firms and holding companies operating in or from Bermuda, and clarifies how PIPA interacts with existing BMA regulatory and AML ATF obligations.

The guidance itself is explicitly stated to be non-binding: PrivCom is not bound by it, and it does not represent PrivCom's final or definitive legal position. It covers when PIPA applies based on physical presence or headquarters location, use of personal information by holding and captive insurance companies, conditions for use and sensitive personal information, privacy notice requirements, individuals' rights, cross-border transfers of personal information, and breach reporting obligations, illustrated through worked case studies.

Areas covered

  • Application of PIPA: Clarifies when PIPA applies to entities physically domiciled in Bermuda, headquartered in Bermuda, or engaged in insurance, reinsurance, holding company or captive insurance activities.
  • Responsibility and compliance: Discusses exemptions, exclusions and how compliance responsibility is allocated among corporate structures and affiliates.
  • Conditions for use of personal information: Addresses lawful bases for use, including incidental, accidental or unintentional access and use.
  • Sensitive personal information: Guidance on handling sensitive personal information, including whether personal titles can act as identifiers.
  • Privacy notices: Explains section 9 requirements for privacy notices and the limited circumstances under section 9(3) where a notice is not required.
  • Rights of individuals and enforcement: Covers individuals' rights, domestic and overseas regulatory bodies, and enforcement considerations.
  • Cross border transfers: Guidance on transferring personal information to third parties domiciled in Bermuda and to overseas third parties.
  • Breach reporting: Addresses breach of security reporting obligations and other exclusions and provisions.

Because this is guidance rather than binding law, it does not itself create new statutory obligations beyond those already in PIPA, but it signals PrivCom's expectations for how financial service providers should demonstrate compliance, including retaining records to justify reliance on privacy notice exemptions.

Key obligations

  • Organisations using personal information in Bermuda, including financial service providers, must comply with PIPA's requirements, including providing a privacy notice under section 9 unless a section 9(3) exemption applies.
  • Where relying on the section 9(3)(b) exemption from providing a privacy notice, organisations should retain records demonstrating the reasonable determination that use of the information falls within individuals' reasonable expectations.

Applies to

banks, deposit companies, investment firms, trust management firms, corporate service providers, insurance companies, reinsurance companies, captive insurance companies, holding companies

Topics

Version history

2026-07-30

source file (current)