Statement of Guidance

Guide to PIPA: Breach of security

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from Bermuda's Office of the Privacy Commissioner explaining the breach of security notification duties under section 14 of the Personal Information Protection Act (PIPA). It applies to any organisation that handles personal information and sets out when and how breaches must be reported to the Commissioner and to affected individuals, along with practical checklists and scenarios.

  • Notification trigger: A breach of security leading to loss, unlawful destruction, unauthorised disclosure of, or access to personal information that is likely to adversely affect an individual must be notified.
  • Order of notification: The organisation must first notify the Commissioner without undue delay, then notify any affected individual without undue delay.
  • Content of notification to Commissioner: Must describe the nature of the breach, its likely consequences for the individual, and the measures taken and to be taken to address it.
  • Content of notification to individuals: Should include contact details of a data privacy officer or contact point, a description of likely consequences, measures taken or proposed, and practical advice to help individuals protect themselves.
  • Record-keeping: Organisations must keep a record of all personal information breaches, even those not required to be notified, documenting facts, effects, and remedial action taken (section 14(2)).
  • Overseas third parties: If an overseas third party processing personal information suffers a breach, it must inform the organisation without undue delay; the organisation remains responsible, and breach-reporting terms should be included in the contract per sections 15(4) and 15(5).
  • Non-compliance penalties: Failing to notify the Commissioner of a notifiable breach is an offence under section 47(3), punishable on summary conviction by a fine up to $25,000 or imprisonment up to two years (individuals), or a fine up to $250,000 (non-individuals) on indictment.

The guidance also recommends preparing breach response plans, risk assessment processes, staff training, and contingency plans for handling increased data subject requests following a breach, though these broader recommendations are good-practice advice rather than strict PIPA requirements.

Key obligations

  • Notify the Commissioner without undue delay of any breach of security likely to adversely affect an individual.
  • After notifying the Commissioner, notify any affected individual without undue delay.
  • Include in the Commissioner notification a description of the nature of the breach, its likely consequences, and measures taken or to be taken to address it.
  • Provide affected individuals with contact details of a data privacy officer or contact point, a description of likely consequences, and measures taken or proposed, including advice on protective steps.
  • Keep a record of all personal information breaches, regardless of whether notification is required, documenting facts, effects, and remedial action (section 14(2)).
  • Ensure contracts with overseas third parties processing personal information require prompt notification of any breach to the organisation, in accordance with sections 15(4) and 15(5).
  • Document the justification for any decision not to notify the Commissioner or individuals where a breach is assessed as unlikely to cause adverse effects.

Applies to

organisations that process personal information (data controllers under PIPA), overseas third parties engaged to process personal information

Deadlines

  • without undue delay: Organisations must notify the Commissioner of a notifiable breach without undue delay.
  • without undue delay: Organisations must notify affected individuals of a breach without undue delay, after notifying the Commissioner.
  • without undue delay: An overseas third party processing personal information must inform the organisation of a breach without undue delay upon becoming aware of it.

Topics

Version history

2026-07-30

source file (current)