Statement of Guidance

Guidance on Collection and Usage of Data for Contact Tracing (2020-06-19)

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from Bermuda's Office of the Privacy Commissioner (PrivCom) addressing how organisations collecting personal data for COVID-19 contact tracing (for example under the Government's Outdoor Dining directions) should handle that data in light of the Personal Information Protection Act 2016 (PIPA). It is framed as a set of frequently asked questions and best-practice recommendations rather than a binding rule, and it notes that the relevant PIPA provisions had not yet entered into force at the time of writing.

  • Legal basis: Collection of contact tracing data required by Government emergency regulations is treated as falling under PIPA Section 6(1)(d), use pursuant to a provision of law that authorises or requires it.
  • Purpose limitation: Data collected for Government-mandated contact tracing should only be used by authorised public health officials for that purpose, not for marketing, research, or other business uses, unless separate valid consent is obtained.
  • Documentation and fairness: Organisations should document their collection and storage policies and clearly explain to individuals what data is collected and why.
  • Proportionality: Only collect the information actually needed for contact tracing purposes, nothing extra.
  • Integrity and retention: Keep collected information accurate and retain it no longer than necessary for its purpose.
  • Security safeguards: Protect stored data against loss or unauthorised use, for example through locked storage or password protection, and limit access to staff who need it.

The guidance closes by inviting organisations with further privacy questions to contact the Office of the Privacy Commissioner, which remains available for consultation despite remote working arrangements during the pandemic.

Key obligations

  • Organisations collecting contact tracing data should document their collection and storage policies and procedures
  • Organisations should clearly explain to individuals what data is being collected and why (fairness)
  • Organisations should not collect more personal information than is needed for contact tracing (proportionality)
  • Organisations should keep contact tracing data accurate and retain it no longer than necessary for its purpose
  • Organisations should implement security safeguards (e.g. locked storage, passwords, restricted access) to protect contact tracing data from loss or unauthorised use
  • Organisations must not use contact tracing data for purposes other than authorised contact tracing (e.g. marketing or research) without obtaining valid additional consent from the individual
  • Business owners or independent individuals should not themselves undertake contact tracing or location tracking; data should be held only for use by authorised officials

Applies to

organisations collecting personal information for contact tracing, restaurants and bars (e.g. under Outdoor Dining directions), businesses subject to Government contact tracing requirements

Topics

Version history

2026-07-30

source file (current)