Statement of Guidance

Guide to PIPA: Communication provider exemption

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This guidance from the Bermuda Privacy Commissioner explains the communication provider exemption under section 23 of the Personal Information Protection Act (PIPA). It clarifies that certain organisations acting as conduits for personal data transmitted by third parties are not liable for breaches committed while acting in that capacity.

  • Who qualifies: A communication provider is defined as an internet service provider, telecommunications provider, or other organisation that acts as a conduit for personal information transmitted by a third party and does not determine the purpose of using that information.
  • Scope of exemption: The organisation itself, along with its directors, officers, and authorised agents, is not liable under PIPA for any breach committed while acting as a communication provider.
  • Limits: The exemption only applies while the organisation is acting purely as a conduit; it does not cover situations where the organisation determines the purpose of using the personal information.

This is explanatory guidance rather than a rule imposing new duties; it does not create filing requirements or deadlines but helps organisations assess whether their activities fall within the section 23 exemption.

Applies to

communication providers, internet service providers, telecommunications organisations, directors, officers or authorised agents of communication providers

Topics

Version history

2026-07-30

source file (current)