Statement of Guidance

Guide to PIPA: Consent

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from the Bermuda Office of the Privacy Commissioner explaining what counts as valid consent under section 6(1)(a) of the Personal Information Protection Act (PIPA), and what organisations should do to obtain, record and manage it. It is not a standalone legal instrument but an interpretive guide with checklists that organisations can use to assess their existing consent practices.

  • Who it targets: Applies to any organisation that processes personal information under PIPA, with specific extra caution flagged for public authorities and employers, who may struggle to show consent is freely given.
  • Standard for consent: Consent must be knowing, freely given, specific, and the organisation must be able to reasonably demonstrate the individual knowingly consented.
  • Explicit vs implied consent: Explains the difference between explicit (active, e.g. ticking a box) and implied (passive, e.g. signage) consent, and notes implied consent cannot be used for sensitive personal information.
  • Good practice checklists: Provides checklists for asking for, recording, and managing consent, including keeping consent requests separate from other terms, naming any overseas third party relying on the consent, and enabling easy withdrawal.
  • Avoiding over reliance on consent: Advises against making consent a precondition of service and flags that consent should not be relied upon where genuine choice cannot be offered.

The guidance recommends organisations review their existing consent mechanisms against these standards, noting that fresh consent is not required if current practices already meet the PIPA standard.

Key obligations

  • Organisations must be able to reasonably demonstrate that an individual has knowingly consented to the use of their personal information.
  • Consent requests must be kept separate from other terms and conditions, and separate consent obtained for separate purposes.
  • Organisations must name any overseas third party who will rely on the consent.
  • Organisations must tell individuals how to withdraw consent and make withdrawal easy at any time.
  • Organisations must keep records evidencing who consented, when, how, and what they were told, including retaining old versions of privacy notices.
  • Organisations must not use pre-ticked boxes, opt-out boxes, or other default settings to obtain consent; consent requires a positive opt-in action.
  • Implied consent must not be relied upon for sensitive personal information.
  • Organisations should regularly review and, where necessary, refresh consent, including building consent reviews into business processes.
  • Public authorities, employers, and organisations with power over individuals should avoid relying on consent unless they can demonstrate it is freely given, and should not penalise individuals who withdraw consent.

Applies to

organisations processing personal information under PIPA, public authorities, employers

Topics

Version history

2026-07-30

source file (current)