Statement of Guidance
Privacy in the Workplace (PrivCom Guidance, August 2024)
Status not confirmedView on PRIVCOM's website Source document
Summary
This is PrivCom (Office of the Privacy Commissioner for Bermuda) guidance, issued August 2024, explaining how the Personal Information Protection Act 2016 (PIPA) applies to employers when they collect, use, and store personal information about employees, former employees, and job applicants. It is not new legislation itself but an interpretive guide to existing PIPA obligations in the employment context, covering general data protection principles, legal conditions for processing, occupational health data, monitoring of staff, and employee rights.
- Scope of personal information: Clarifies that PIPA does not cover pure business contact information but does cover content of emails, HR records, and similar data that identifies an employee.
- General principles: Employers must comply with fairness, privacy notices, purpose limitation, proportionality, integrity of information, and security safeguards (PIPA sections 5, 8-13).
- Legal conditions for use: Processing must rest on a recognised legal condition such as consent, contract, legal obligation, emergency, public interest task, or the reasonable person test, with extra care for sensitive personal information.
- Occupational health and medical records: Sets out obligations around handling employee medical records, including access under PIPA section 18.
- Monitoring and surveillance: Covers employer policies on CCTV, vehicle tracking, computer/internet/email monitoring, employee monitoring software, and covert surveillance, requiring proportionate, justified, and documented use.
- Retention: Personal information must be retained only as long as necessary and then securely destroyed, deleted, or erased.
- Employee rights: Employees, former employees, and unsuccessful applicants have rights to access their personal information (section 17), access medical records (section 18), and request correction, blocking, erasure or destruction (section 19).
Employers must be able to demonstrate compliance with these principles and respond to individual rights requests within statutory time limits, extendable in complex cases. The guidance also notes that even where a PIPA exemption might apply, employers must still meet minimum requirements (responsibility and compliance, fairness, proportionality, integrity, and security safeguards) and document their reasoning.
Key obligations
- Employers must designate a Privacy Officer as required generally under PIPA
- Employers must use employee personal information lawfully and fairly (section 8) and be able to demonstrate compliance with all PIPA principles
- Employers must provide employees with a privacy notice under section 9 containing the specified elements (purpose of use, disclosure recipients, organisation identity/contact details, privacy officer contact details, and choices for exercising rights)
- Employers must limit use of personal information to purposes specified in the privacy notice and avoid incompatible further use (section 10)
- Employers must not hold more personal information than necessary and must assess proportionality of use (section 11)
- Employers must keep personal information accurate, up to date, and not retained longer than necessary (section 12)
- Employers must implement security safeguards proportional to risks of loss, unauthorised access, or misuse (section 13)
- Employers must report breaches of security to the Privacy Commissioner without undue delay (section 14)
- When relying on a PIPA exemption, employers must document how they concluded the exemption applies and how compliance would interfere with the exempted purpose
- Employers must respond to employee access requests (sections 17, 18, 19) within 45 days of receipt, extendable by up to 30 additional days for complex requests, and must promptly notify the employee of any extension and the reason for it
- Employers relying on provisions (e.g. sections 23-25) to restrict an employee's exercise of rights must identify the specific provision relied upon and explain how compliance would interfere with the exempted purpose
- Where a third party is engaged to process data, the employer organisation remains responsible for fulfilling employee access requests, not the third party
Applies to
employers, organisations under PIPA
Deadlines
- 45 days: Employers must respond to an employee's access request (section 17), medical records request (section 18), or correction/blocking/erasure/destruction request (section 19) within 45 days of receipt
- additional 30 days: Response time to rights requests may be extended by up to 30 further days if the request is complex, with prompt notice to the employee explaining why