Statement of Guidance

PIPA/GDPR Crosswalk

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is a reference table published by the Bermuda Privacy Commissioner mapping provisions of Bermuda's Personal Information Protection Act (PIPA) to their corresponding or related provisions under the EU General Data Protection Regulation (GDPR). It is a comparative guidance tool, not a binding instrument, intended to help organisations and practitioners understand how PIPA concepts and terminology align with GDPR equivalents.

  • Crosswalk table: Lists each PIPA section number and name alongside the corresponding GDPR article number and name, covering topics such as access rights, breach notification, conditions for processing, exclusions, transfers overseas, and security safeguards.
  • Terminology index: Provides a glossary matching PIPA terms to GDPR equivalents, e.g. individual to data subject, organisation to controller/processor, personal information to personal data, privacy officer to data protection officer, and use/using to processing.

The document does not itself create new legal duties; it is an interpretive aid for organisations already subject to PIPA who also need to understand GDPR alignment, for example when handling cross border data transfers or comparing compliance obligations.

Applies to

organisations subject to PIPA, data controllers and processors handling personal information in or from Bermuda

Topics

Version history

2026-07-30

source file (current)