Notice

Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20)

Office of the Privacy Commissioner for Bermuda (PRIVCOM) · Bermuda

Issued 2025-01-20

Current version last checked: 2026-07-30

Summary

This is a public statement from Bermuda's Privacy Commissioner responding to press coverage of the Department of Education's reported cybersecurity incident involving vendor PowerSchool, which appears to be the first major breach notification handled under PIPA. The Commissioner declines to comment on the specifics of an ongoing, confidential investigation but uses the occasion to clarify how PIPA's breach notification requirement operates in practice.

  • Notification trigger: An organisation using personal information must notify PrivCom of a breach of security without undue delay, based on a two part test: there must be an action such as unauthorised access, and a determination that this is likely to have an adverse effect on an individual.
  • Timing: Notification should occur without undue delay; organisations may take reasonable time to assess and validate the situation, but delay becomes undue if it increases the likelihood or severity of harm.
  • Preliminary notification: Organisations uncertain whether a breach meets the harm threshold may make a preliminary notification to PrivCom for guidance before certainty is reached.
  • Tools provided: PrivCom provides an electronic breach notification form on its website (Organisations Hub) and template letters organisations can use to notify affected individuals.
  • Standard of care: Suffering a breach does not itself imply wrongdoing; organisations are expected to maintain reasonable safeguards proportional to the risk of harm from the personal information they hold, not a standard of perfection.

The Commissioner also publicly commends the Department of Education and Commissioner Richards for proactive transparency and cooperation, signalling PrivCom's expectations for how organisations should engage with the office during a breach response.

Key obligations

  • Organisations using personal information must notify PrivCom of a breach of security without undue delay when the breach involves an action (e.g. unauthorised access) that is likely to adversely affect an individual.
  • Organisations should assess and validate a suspected breach promptly, avoiding delay that would increase the likelihood or severity of harm to affected individuals.
  • Organisations should put in place reasonable measures and safeguards proportional to the risk of harm to individuals arising from their use of personal information.

Applies to

organisations using personal information under PIPA

Deadlines

  • without undue delay: Organisations must notify PrivCom of a qualifying breach of security without undue delay after becoming aware of it.

Topics

Version history

2026-07-30

source file (current)