Statement of Guidance
Guidance on Vendors, Third Parties, and Overseas Data Transfers
Status not confirmedView on PRIVCOM's website Source document
Summary
This is explanatory guidance from Bermuda's Office of the Privacy Commissioner (PrivCom) on how organisations using personal information in Bermuda must handle vendors, third parties, and cross border data transfers under the Personal Information Protection Act (PIPA). It walks through PIPA sections 5, 13, and 15 and explains the practical steps organisations can take to meet their obligations when outsourcing or sending data overseas.
- Vendor and third party use (section 5): An organisation that engages a vendor or third party to handle personal information remains fully responsible for PIPA compliance at all times, and must act reasonably and apply appropriate security safeguards (section 13).
- Recommended vendor management steps: Set internal standards for outsourcing partners, run a vendor evaluation process (survey, questionnaire, audit), conduct due diligence, document responsibilities in an enforceable contract, and monitor the relationship for ongoing compliance.
- Overseas third party transfers (section 15): Before transferring personal information to an overseas third party, the organisation must assess the level of protection that third party provides, including the protection afforded by the laws applicable to it, and remains responsible for PIPA compliance regarding that information.
- Relying on comparable protection: An organisation may rely on a reasonable belief that overseas protection is comparable to PIPA, evidenced by a Commissioner-recognised certification mechanism (e.g. the APEC Cross Border Privacy Rules System) or a Ministerial equivalency designation for a jurisdiction.
- Where comparability is not established: If certification or equivalency does not apply, the organisation must use contractual mechanisms, corporate codes of conduct (including binding corporate rules), or other means to ensure the overseas third party provides comparable protection.
- Other transfer bases: Transfers may also be permitted where necessary to uphold the organisation's legal rights, or where the transfer is assessed as small scale, occasional, and unlikely to prejudice an individual's rights.
- Notice obligations: Even when relying on a third party's certification, the Bermudian organisation remains responsible to the individual and must give appropriate notice, including about the overseas transfer and the certification relied upon, and must ensure section 6 conditions are met.
The guidance is informational and interpretive rather than creating new legal rules; it clarifies existing PIPA obligations and indicates PrivCom will issue further guidance on related topics in future.
Key obligations
- Organisations that engage a vendor or third party to use personal information remain responsible for PIPA compliance at all times and must act in a reasonable manner with appropriate security safeguards.
- Before transferring personal information to an overseas third party, an organisation must assess the level of protection that third party provides, including the law applicable to it.
- An organisation may only rely on comparable overseas protection where it has a reasonable belief supported by applicable law or a Commissioner-recognised certification mechanism.
- Where comparable protection cannot be established via equivalency designation or recognised certification, the organisation must use contractual mechanisms, corporate codes of conduct (including binding corporate rules), or other means to ensure comparable protection before transferring data overseas.
- Organisations relying on an overseas third party's certification must still provide individuals with appropriate notice, including about the transfer overseas and reliance on the certification mechanism, and ensure section 6 conditions are satisfied.
- Small scale or occasional overseas transfers may only proceed where assessed as unlikely to prejudice the rights of an individual.
Applies to
organisations that use personal information in Bermuda, vendors and third parties engaged by such organisations, overseas third parties receiving personal information