Statement of Guidance
Small Business Advice
Status not confirmedView on PRIVCOM's website Source document
Summary
This is informal guidance published by Bermuda's Office of the Privacy Commissioner (PrivCom) aimed at small businesses, charities, clubs, and other small organisations, explaining how the Personal Information Protection Act (PIPA) 2016 applies to them. It emphasises that from 1 January 2025 PIPA applies fully to all organisations regardless of type or size, and PrivCom gains enforcement powers from that date.
- Scope: PIPA applies to any organisation handling personal information in a business context, including one-person startups, sole proprietors, charities, clubs and community groups, regardless of staff numbers.
- Exemptions: PIPA does not cover purely personal or domestic use of information, generic business contact details without a person's name, financial statements, or non-filing paper records.
- Recommended compliance steps: Mapping personal information held, documenting policies and procedures, training staff, conducting privacy impact assessments, creating an incident/breach response plan, and setting up access request procedures.
- Privacy notices: Organisations should have a privacy notice in place before collecting personal information, including on their website, explaining why data is held, how it will be used, and how long it will be retained.
- Security: Security measures should be proportionate to the sensitivity of the personal information held, covering both electronic (e.g. encryption, passwords) and physical (e.g. locked cabinets) safeguards.
- Access requests and breaches: From 1 January 2025 individuals have the right to request their personal information; organisations must be prepared to respond, and must report data breaches likely to adversely affect individuals to PrivCom.
The guidance is advisory in nature and directs readers to PrivCom's separate Guide to PIPA for further detail, but it flags several practical obligations that arise once PIPA takes full effect.
Key obligations
- Have a privacy notice in place before collecting any personal information, including on the organisation's website, describing why information is held, how it will be used, and how long it will be retained
- Implement security measures proportionate to the sensitivity of the personal information held, whether electronic (e.g. encryption, passwords) or physical (e.g. locked filing cabinets)
- Be prepared to respond to individuals' access requests for their personal information once PIPA is in full operation from 1 January 2025
- Report data breaches to PrivCom if the breach is likely to adversely affect an individual
- Have a valid reason or lawful condition for using personal information, and obtain it fairly and lawfully
Applies to
small businesses, clubs, societies, community groups, charities, start-ups, sole proprietors, self-employed individuals, organisations of any type and size
Deadlines
- 1 January 2025: PIPA applies in full to all organisations irrespective of type and size, and PrivCom gains power to take action for non-compliance, including obligations around access requests and breach reporting