Statement of Guidance

Guide to PIPA

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is PrivCom's Guide to PIPA, a plain-English explanatory guide (not the statute itself) covering the Personal Information Protection Act, which became fully operative in Bermuda on 1 January 2025. It is aimed at privacy officers and others responsible for data protection, explaining the principles, individual rights, and obligations that organisations using personal information in Bermuda must follow.

  • Who it applies to: Any organisation (individual, entity, or public authority) that uses personal information in Bermuda, including where overseas third parties are engaged to process data on the organisation's behalf.
  • Minimum requirements: All organisations, even those with partial exemptions, must comply with sections 5 (responsibility and compliance), 8 (fairness), 11 (proportionality), 12 (integrity of personal information), and 13 (security safeguards).
  • Twelve core principles: Responsibility and compliance, conditions for using personal information, sensitive personal information, fairness, privacy notices, purpose limitation, proportionality, integrity, security safeguards, breach of security, transfer to overseas third parties, and personal information about children.
  • Individual rights: Access to personal information (including medical records), and correction, blocking, erasure, and destruction of personal information.
  • Exemptions: National security, communication provider, regulatory activity and honours, and a general exemption (e.g. crime prevention, tax collection) that apply only to the extent PIPA compliance would prejudice the relevant purpose.

The guide also explains liability: individuals can bring compensation claims against organisations for breaches, and PrivCom has enforcement powers under PIPA. Organisations are encouraged to assess and document their personal information processing activities to determine their level of compliance obligation.

Key obligations

  • Organisations must comply with the PIPA minimum requirements (responsibility and compliance, fairness, proportionality, integrity of personal information, and security safeguards) regardless of any exemptions.
  • Organisations must maintain records of personal information and processing activities.
  • Organisations remain responsible for PIPA compliance even where a third party (including an overseas third party) is engaged to process personal information, and must ensure contracts with overseas third parties comply with PIPA.
  • Organisations must provide privacy notices and use personal information fairly, including obtaining consent where required.
  • Organisations must respond to individuals' access requests, including requests for correction, blocking, erasure, and destruction of personal information.
  • Organisations must notify individuals of personal information security breaches, except where the general or other exemptions validly apply.
  • Organisations relying on a partial exemption must still comply with PIPA to the extent that compliance would not prejudice the exempt purpose.

Applies to

organisations using personal information in Bermuda, overseas third parties engaged by Bermuda organisations, public authorities

Deadlines

  • 1 January 2025: Date of full implementation of PIPA (the Personal Information Protection Act), after partial enactment in 2016.

Topics

Version history

2026-07-30

source file (current)