Statement of Guidance
Guide to PIPA: Organisations & overseas third parties
Status not confirmedView on PRIVCOM's website Source document
Summary
This is a short PrivCom guidance page explaining who counts as an 'organisation' and an 'overseas third party' under Bermuda's Personal Information Protection Act (PIPA), and clarifying that organisations remain responsible for PIPA compliance even when they outsource personal information processing to third parties.
- Organisation: Defined broadly as any individual, entity or public authority that uses personal information.
- Overseas third party: An organisation that is not domiciled in Bermuda.
- Ongoing responsibility: Where an organisation engages a third party (by contract or otherwise) to handle personal information, the organisation remains responsible for PIPA compliance at all times.
- Enforcement exposure: PrivCom can take action against organisations under PIPA, and individuals can bring court claims for compensation for financial loss or emotional distress.
- Recommended practice: Organisations should assess and document the status of all personal information and processing activities they carry out.
The guidance is informational and does not itself create new statutory deadlines; it reiterates existing PIPA accountability principles for organisations using third-party processors, including those based overseas.
Key obligations
- Organisations that engage third parties to handle personal information remain responsible for ensuring PIPA compliance at all times.
- Organisations should assess and document the status of all personal information and processing activities they carry out.
Applies to
organisations (as defined under PIPA), overseas third parties
Topics
Version history
2026-07-30