Statement of Guidance

Guide to PIPA: Transfer to Overseas Third Party

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This guidance from the Bermuda Privacy Commissioner explains the requirements under Section 15 of PIPA that apply when an organisation transfers personal information to a third party located outside Bermuda. It sets out the legal test organisations must apply before transferring data overseas, the exceptions available, and practical questions organisations should document as part of a transfer risk assessment.

  • Continuing responsibility: An organisation remains responsible under PIPA for personal information it transfers to an overseas third party, whether the recipient uses it on the organisation's behalf or for its own purposes.
  • Pre-transfer assessment: Before transferring, the organisation must assess the level of protection the overseas third party would provide, taking into account the law applicable to that third party.
  • Comparable protection route: If the organisation reasonably believes protection is comparable to PIPA's standard (which may be evidenced by a recognised certification mechanism), it may rely on that comparable protection.
  • Safeguard mechanisms where not comparable: Where comparable protection cannot reasonably be established, the organisation must use contractual mechanisms, binding corporate rules or codes of conduct, or other means to secure comparable protection from the overseas third party.
  • Limited exceptions: A transfer may proceed without the above safeguards if it is necessary for establishing, exercising or defending legal rights, or if it is small-scale, occasional and unlikely to prejudice individuals' rights.
  • Fairness disclosures: Organisations should tell affected individuals the identity of the overseas third party, the destination country, the reason for transfer, the type of information transferred, any right to withdraw consent, and the risks of transferring to a jurisdiction lacking comparable protection.
  • Documentation: Organisations should map data flows and document the specific circumstances of each transfer, including the recipient, location, purpose, categories of data and individuals, security measures, and duration of access, as part of a transfer risk assessment.

The Minister, on the Commissioner's recommendation, may designate certain jurisdictions as providing comparable protection, which organisations can rely on when assessing transfers to those jurisdictions.

Key obligations

  • Organisations remain responsible for compliance with PIPA in relation to personal information transferred to an overseas third party.
  • Before transferring personal information overseas, an organisation must assess the level of protection provided by the overseas third party, including the law applicable to that party.
  • Where the organisation cannot reasonably rely on comparable protection, it must implement contractual mechanisms, binding corporate rules, codes of conduct, or other means to ensure the overseas third party provides comparable protection.
  • Organisations should inform individuals, for fairness, of the identity and location of the overseas third party, the purpose and type of transfer, withdrawal of consent rights, and risks of transfer to a jurisdiction without comparable protection.
  • Organisations should document the specific circumstances of each overseas transfer, including data flows, recipient details, safeguards, and residual risks, as part of a transfer risk assessment.

Applies to

organisations subject to PIPA (Bermuda-based organisations that transfer personal information to overseas third parties)

Topics

Version history

2026-07-30

source file (current)