Statement of Guidance
Guide to PIPA: Security safeguards
Status not confirmedView on PRIVCOM's website Source document
Summary
This is PrivCom Bermuda guidance explaining the security safeguards requirement in Section 13 of the Personal Information Protection Act (PIPA). It sets out what organisations must do to protect personal information they hold, and focuses heavily on encryption as a recommended (though not legally mandated) technical measure.
- Core requirement: Organisations must protect personal information they hold with safeguards against loss, unauthorised access, destruction, use, modification or disclosure, and any other misuse.
- Proportionality: Safeguards must be proportional to the likelihood and severity of potential harm, the sensitivity of the personal information, and the context in which it is held.
- Ongoing review: Safeguards must be subject to periodic review and reassessment, not a one time implementation.
- Encryption guidance: Encryption is highlighted as a best practice for data at rest and in transit, including guidance on symmetric versus asymmetric encryption, key management, algorithm selection, and using current standards (e.g. FIPS 140-2 and FIPS 197 as of July 2023).
- Encryption checklist: Provides a self-assessment checklist covering encryption policy, staff training, technical implementation, awareness of residual risks, and periodic review of encryption solutions.
The guidance is advisory in nature: it clarifies expectations under Section 13 of PIPA and offers practical recommendations (such as encryption policies and HTTPS use) rather than imposing new legal requirements beyond the statute itself.
Key obligations
- Organisations must implement safeguards to protect personal information against loss, unauthorised access, destruction, use, modification, disclosure, or other misuse (PIPA Section 13(1)).
- Safeguards must be proportional to the likelihood and severity of harm, the sensitivity of the personal information, and the context in which it is held (PIPA Section 13(2)).
- Organisations must subject their security safeguards to periodic review and reassessment.
Applies to
organisations (as defined under PIPA) handling personal information
Topics
Version history
2026-07-30