Statement of Guidance

Guide to PIPA: Responsibility and compliance

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This guidance from the Bermuda Privacy Commissioner explains the responsibility and compliance obligations under Section 5 of the Personal Information Protection Act (PIPA). It applies to any organisation that uses personal information and sets out what 'suitable measures and policies' must look like in practice, emphasising a risk based, tailored approach rather than a one-size-fits-all standard.

  • Suitable measures and policies: Organisations must adopt measures and policies giving effect to their obligations and individuals' rights under PIPA, designed around the nature, scope, context and purposes of personal information use and the risk to individuals.
  • Third party engagements: An organisation remains responsible for compliance with PIPA at all times even when it engages a third party, by contract or otherwise, to use personal information on its behalf.
  • Privacy officer: Every organisation must designate a privacy officer with primary responsibility for communicating with the Commissioner; a group of commonly owned or controlled organisations may share one privacy officer as long as each organisation has access to one, and duties may be delegated to others.
  • Reasonable conduct: Organisations must act in a reasonable manner in meeting their PIPA responsibilities.
  • Programmatic elements: Recommended measures include inventorying and mapping personal information use, documenting practices in policies and procedures, training staff, conducting privacy risk analysis (e.g. Privacy Impact Assessments), developing incident and breach response action plans, and creating procedures to handle PIPA Rights Requests.
  • Overseas transfers: Organisations remain responsible for all uses of personal information, including transfers to overseas third parties.

This is explanatory guidance rather than a standalone legal instrument; it interprets existing obligations under Section 5 of PIPA and does not itself introduce new deadlines.

Key obligations

  • Adopt suitable measures and policies giving effect to PIPA obligations and individuals' rights, tailored to the nature, scope, context and purposes of personal information use and associated risk
  • Remain responsible for PIPA compliance when using third parties to process personal information, even where a third party is engaged by contract
  • Designate a privacy officer responsible for communicating with the Commissioner, with shared officers permitted for commonly owned or controlled groups provided each organisation has access to one
  • Act in a reasonable manner when meeting responsibilities under PIPA
  • Implement programmatic elements such as data inventory/mapping, documented policies and procedures, staff training, privacy risk analysis (e.g. Privacy Impact Assessments), breach/incident response action plans, and procedures for handling PIPA Rights Requests
  • Remain responsible for all uses of personal information, including overseas transfers to third parties

Applies to

organisations using personal information

Topics

Version history

2026-07-30

source file (current)