Statement of Guidance

Guide to PIPA: What is personal information?

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from Bermuda's Office of the Privacy Commissioner explaining how the term personal information is defined and applied under the Personal Information Protection Act (PIPA). It is aimed at organisations trying to determine whether information they hold or use about individuals in Bermuda falls within PIPA's scope.

  • Definition: Personal information is any information relating to an identified or identifiable individual, including names, dates of birth, photographs, video footage, email addresses, telephone numbers, IP addresses and cookie identifiers.
  • Sensitive personal information: A defined subcategory covering place of origin, race, colour, sex, sexual life, health, disabilities, religious beliefs, and biometric or genetic information, which may only be used in more limited circumstances.
  • Scope of PIPA: PIPA applies to personal information used wholly or partly by automated means, or used other than by automated means where it forms part of a structured filing system.
  • Exclusions: Information about organisations (companies, public authorities) is not personal information; business contact information used to contact someone in their employee or official capacity is excluded; information about individuals dead for at least 20 years, or in existence for at least 150 years, is excluded.
  • Identifiability test: An individual is identifiable if they can be distinguished from others using the information alone or in combination with other reasonably available information, including future technological developments.
  • Context matters: The same information may be personal information for one organisation but not another, depending on the purpose of use, and inaccurate information about an individual still qualifies as personal information.

The guide is explanatory rather than prescriptive, using illustrative questions and examples to help organisations self-assess whether their data handling activities engage PIPA, including where identifiability depends on combining datasets or considering context, purpose and impact.

Key obligations

  • Organisations must assess whether information they use relates to an identified or identifiable individual, considering it alone and in conjunction with other reasonably available information
  • Organisations must consider the nature, scope, context and risk of information use, including content, purpose and likely impact on the individual, when determining if information relates to an individual
  • Organisations have a continuing obligation to reassess whether an individual is identifiable as circumstances or technology change over time
  • Where it is unclear whether information is personal information, organisations should treat it with care, have a clear reason for using it, and hold and dispose of it securely
  • Organisations must apply extra care and limit use of sensitive personal information given its higher sensitivity

Applies to

organisations using personal information of individuals in Bermuda

Topics

Version history

2026-07-30

source file (current)