Statement of Guidance

Guide to PIPA: Personal information about children

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is PrivCom guidance explaining section 16 of Bermuda's Personal Information Protection Act (PIPA), which imposes special protections when organisations use personal information about children under age 14 in connection with digital or electronic services (information society services). It advises organisations to embed child friendly design and privacy protections into their processing, products, and systems from the outset, and recommends using a Privacy Impact Assessment.

  • Parental consent: Where an information society service is targeted at children, or the organisation has actual knowledge it is using children's personal information and relies on consent, it must obtain consent from a parent or guardian before collecting or using the child's personal information.
  • Verifiable consent: Organisations must be reasonably satisfied that such consent is verifiable as coming only from the child's parent or guardian, and must establish procedures to verify whether an individual is a child when it is reasonably likely the organisation will use a child's personal information.
  • Limits on collecting third party data: Organisations must not seek personal information from a child about other individuals (such as parents' professional, financial, or sociological information), except identity and address details of a parent or guardian solely to obtain consent.
  • Age appropriate privacy notice: When delivering an information society service to a child, an organisation must provide a privacy notice that is easily understandable and appropriate to the child's age.
  • Defence: In legal proceedings for failure to comply with section 16, it is a defence to prove the organisation took such care as was reasonably necessary in all circumstances to comply.

The guidance also stresses that fairness, responsibility, and the best interests of the child (drawing on Article 3 of the UN Convention on the Rights of the Child) should underpin all processing of children's personal information, and recommends a cautious, risk based approach including age verification when it is unclear whether individuals are children.

Key obligations

  • Obtain consent from a parent or guardian before collecting or using a child's personal information when providing an information society service that is targeted at children or where the organisation knows it is processing children's data and relies on consent
  • Ensure such parental or guardian consent is verifiable and can only be obtained from the child's parent or guardian
  • Establish procedures to verify whether an individual is a child when it is reasonably likely the organisation will process a child's personal information
  • Refrain from seeking personal information from a child about other individuals (e.g. parents' professional, financial or sociological information), except identity and address information needed solely to obtain consent
  • Provide a privacy notice to children that is easily understandable and appropriate to their age when delivering an information society service

Applies to

organisations providing information society services (digital or electronic communication services) that use children's personal information

Topics

Version history

2026-07-30

source file (current)