Statement of Guidance

Guide to PIPA: Access to personal information

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is PrivCom guidance explaining how organisations subject to Bermuda's Personal Information Protection Act (PIPA) must handle individuals' requests to access their personal information. It summarises the statutory access right in section 17 and the request procedure in section 20, and gives practical checklists and FAQ-style guidance for compliance.

  • Scope of access right: Individuals can request a copy of their personal information, the purposes for which it is used, and the persons or types of persons to whom and circumstances in which it has been disclosed.
  • Form of request: Requests must be made in writing; no specific wording or reference to legislation is required, and third parties (e.g. relatives, lawyers) may request on an individual's behalf if authorised.
  • Response timeline: Organisations must acknowledge receipt promptly and respond to a completed request within 45 days, which can be extended by up to 30 days in specified circumstances (e.g. large volume of information, unreasonable interference with operations, need to consult a third party), with notice to the applicant of the reason and expected timing.
  • Fees: A fee up to the prescribed maximum may be charged, except where the request results in correcting an error or omission, or where a professional regulatory body prohibits charging a fee.
  • Refusals and exemptions: Organisations may refuse access where an exemption or restriction under section 17(2)-(3) applies (e.g. legal privilege, commercial confidentiality, ongoing investigations, third-party information) or where the request is manifestly unreasonable, but must inform the applicant in writing of the reasons and of their right to complain to PrivCom.
  • Children's requests: Organisations should assess whether a child is mature enough to understand their rights and respond accordingly, using clear and plain language, while allowing a parent or guardian to act on the child's behalf where authorised or in the child's best interests.
  • Third-party information: Where a request would reveal another individual's personal information, organisations should consider redaction and may withhold or disclose it only where consent is given or disclosure is reasonable without consent, keeping a record of the decision.
  • Identity verification: Organisations may ask applicants for identification to verify identity; the 45 day response clock does not start until identity information is received.
  • Enforcement: Failure to comply with an access request may result in PrivCom action or a court application by the applicant, including for compensation.

The guidance also includes two self-assessment checklists (preparing for and complying with access requests) intended to help organisations build internal processes for handling access requests consistently and within statutory timeframes.

Key obligations

  • Organisations must respond to a completed access request within 45 days of receipt
  • Organisations must promptly acknowledge in writing receipt of an access request, including the date of request, and specify any additional detail needed to complete it
  • If extending the response period by up to 30 days, the organisation must notify the applicant of the reason for the extension and the expected response time
  • Organisations may charge a fee for access requests only up to the prescribed maximum, and must not charge where the request corrects an error or omission or where a professional regulatory body prohibits charging
  • If refusing a request, the organisation must inform the applicant in writing of the reasons for refusal and of their right to complain to the Commissioner
  • Where a request involves another individual's information, the organisation must consider redaction and keep a record of its decision to disclose, withhold, or redact
  • Organisations must respond to the applicant whether or not they decide to disclose third-party information

Applies to

organisations processing personal information subject to PIPA

Deadlines

  • 45 days: Time within which an organisation must respond to a completed access request from receipt of the written request
  • 30 days: Maximum additional extension period an organisation may take to respond to a request under specified circumstances (e.g. large volume of information, operational interference, third-party consultation)

Topics

Version history

2026-07-30

source file (current)