Bermuda

data protection

55 Bermuda regulatory document(s) tagged data protection.

Practice-note overview · reflects instruments as at 2026-07-30. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

Bermuda's data protection regime is built on the Personal Information Protection Act 2016 (PIPA), which became fully operative on 1 January 2025 after a staggered commencement. It applies broadly, and most of the indexed material is PrivCom guidance interpreting its provisions.

Who PIPA catches

  • Every organisation: Any individual, entity or public authority that uses personal information in Bermuda, whether by automated means or as part of a structured filing system.
  • Personal information: Any information relating to an identified or identifiable individual, including names, dates of birth, photographs, video footage, email addresses, telephone numbers, IP addresses and cookie identifiers; inaccurate information about an individual still qualifies.
  • Sensitive personal information: A defined subcategory (section 7) covering place of origin, race, colour, ethnic origin, sex, sexual life or orientation, marital and family status, physical or mental health or disability, religious beliefs, political opinions, trade union membership, and biometric and genetic information, subject to enhanced protection.
  • Overseas processing: Organisations remain subject to PIPA even where they engage a third party, including an overseas third party, to process personal information on their behalf.

PrivCom guidance confirms PIPA's reach for particular sectors, including financial service providers (banks, insurers, reinsurers, captive insurers, trust and corporate service providers, investment firms and holding companies) based on physical presence or headquarters location, and for health service providers and medical professionals handling patient information.

BMA cyber and reporting instruments

Separate Bermuda Monetary Authority instruments indexed here impose operational and data-related obligations on specific regulated populations. The Digital Asset Business Operational Cyber Risk Management Codes apply to all Digital Asset Business registrants, and the Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules apply to registered Insurance Marketplace Providers.

Sources: Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Personal Information Protection Act 2016 · Guide to PIPA: Key Definitions · Guide to PIPA: What is personal information? · Guide to PIPA: Organisations & overseas third parties · Financial Service Provider's Guidance Notes – Final Report (2025-03-07) · Guidance Note: Protecting Personal Information in the Medical Field · Personal Information Protection Amendment Act 2023 (2023:23)


Key duties

Under PIPA, organisations carry a set of continuing accountability, transparency, and security obligations. All organisations, even those with a partial exemption, must comply with the minimum requirements in sections 5 (responsibility and compliance), 8 (fairness), 11 (proportionality), 12 (integrity) and 13 (security safeguards).

Governance and accountability

  • Privacy programme: Adopt suitable measures and policies giving effect to PIPA obligations and individuals' rights, tailored to the nature, scope, context, purposes and risk of the personal information used.
  • Privacy officer: Designate a privacy officer with primary responsibility for communicating with the Commissioner; commonly owned or controlled groups may share one provided each organisation has access to it.
  • Records: Maintain records of personal information and processing activities, and keep a record of all security breaches regardless of whether they are notifiable.
  • Third-party responsibility: Remain responsible for compliance at all times when engaging vendors or third parties, applying due diligence and appropriate security safeguards.

Lawful use and transparency

  • Lawful condition: Use personal information only where a section 6 condition applies (such as consent, contractual necessity, legal authorisation, publicly available information, emergency, public interest or official authority, or the employment relationship).
  • Sensitive information: Use sensitive personal information only under lawful authority, and never to discriminate contrary to Part II of the Human Rights Act 1981.
  • Privacy notices: Provide a clear privacy notice under section 9 before or at the time of collection (or as soon as reasonably practicable afterwards), covering use, purposes, recipients, organisation and privacy officer contact details, and individuals' choices.
  • Purpose and proportionality: Limit use to the stated or related purposes (section 10), and keep information adequate, relevant, not excessive, accurate, and retained no longer than necessary (sections 11 and 12).
  • Security safeguards: Implement safeguards proportional to the likelihood and severity of harm, sensitivity and context, subject to periodic review (section 13).

Breach notification

On a breach of security likely to adversely affect an individual, the organisation must notify the Commissioner without undue delay (describing the nature, likely consequences and remedial measures), and then notify affected individuals without undue delay. Records of all breaches must be kept even where notification is not required.

Individual rights requests

  • Access: Respond to a completed written access request within 45 days of receipt, extendable by up to 30 days in specified circumstances with notice to the applicant; the clock does not start until any identity information is received.
  • Correction and blocking: Respond to correction requests without undue delay and within 45 days (extendable), and act on blocking requests, including stopping use for direct marketing on request.
  • Erasure and refusals: Handle erasure or destruction requests, and where a request is refused inform the individual in writing of the reasons and their right to complain to PrivCom.
  • Fees: Fees may be charged only up to a Minister-prescribed maximum (not yet set as at 1 January 2025), must be reasonable and not profit-generating, and must not be charged where the request corrects an error or omission or where a professional body prohibits it.

Overseas transfers

Before transferring personal information to an overseas third party, an organisation must assess whether the law applicable to the recipient provides protection comparable to PIPA (section 15). It may proceed by reasonably concluding the law is comparable (including relying on a Ministerial designation or recognised certification mechanism such as APEC CBPR), by using safeguards such as contractual clauses or binding corporate rules, or by relying on a legal exception; section 6 conditions must also be met.

BMA cyber and filing duties

  • DAB cyber programme: Digital Asset Business registrants must run an operational cyber risk management programme, have the board approve a cyber risk policy at least annually, appoint a CISO, document and retain risk assessments for at least five years, run an annual IT audit plan, annually test business continuity and disaster recovery plans, and notify the Authority of cyber reporting events. Existing DABs had compliance deadlines of 30 June 2023 (2022 Code) and 30 June 2024 (2024 Code).
  • Insurance Marketplace return: Insurance Marketplace Providers must file an annual statutory financial return including governance, outsourcing, cyber risk self-assessment, AML/ATF and sanctions information; the indexed schedule does not itself state the filing deadline.

Sources: Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Personal Information Protection Act 2016 · Guide to PIPA: Key Definitions · Guide to PIPA: Principles · Guide to PIPA: Responsibility and compliance · Guide to PIPA: Conditions for personal information use · Guide to PIPA: Sensitive personal information · Guide to PIPA: Fairness · Guide to PIPA: Privacy notices · Guide to PIPA: Purpose limitation · Guide to PIPA: Proportionality · Guide to PIPA: Integrity of personal information · Guide to PIPA: Security safeguards · Guide to PIPA: Breach of security · Guide to PIPA: Transfer to Overseas Third Party · Guide to PIPA: Consent · Guide to PIPA: Access to personal information · Guide to PIPA: Correction & blocking · Guide to PIPA · Financial Service Provider's Guidance Notes – Final Report (2025-03-07) · Individuals' Guide to PIPA (December 2024) · Guidance Note: Protecting Personal Information in the Medical Field · Guidance Note: Transfer of Personal Information to Overseas Third Parties and Comparable Jurisdictions · Guidance on Vendors, Third Parties, and Overseas Data Transfers · Guidance for Organisations on Fees for PIPA Rights Requests


Exemptions and carve-outs

PIPA distinguishes between activities excluded entirely from its scope (section 4) and partial exemptions under Part 4, which relieve organisations of some obligations only to the extent compliance would prejudice the relevant purpose. PrivCom guidance stresses that exemptions must be assessed case by case and documented, not applied routinely.

Exclusions (section 4)

  • Personal or domestic use: Personal or household activity, such as an individual photographing or filming for personal enjoyment, falls outside PIPA.
  • Journalistic and artistic use: Artistic, literary or journalistic use for publication in the public interest is excluded.
  • Business contact information: Use of business contact information to reach an individual in their employee or official capacity is excluded.
  • Old personal data: Information about individuals dead for at least 20 years, or in existence for at least 150 years, is excluded.
  • Judicial and parliamentary: Court file information used by judges or law enforcement, personal notes of those in a judicial or quasi-judicial capacity, archival institution transfers under pre-existing access agreements, and use covered by parliamentary privilege are excluded.

Partial exemptions (Part 4)

  • National security (s.22): Parts 2 and 3 (other than the minimum requirements) do not apply where used to safeguard national security, but only under a valid exemption certificate signed by the Minister; affected persons may appeal to the Supreme Court.
  • Communication provider (s.23): An ISP, telecommunications provider or other conduit that does not determine the purpose of using personal information (and its directors, officers and authorised agents) is not liable under PIPA for breaches committed while acting purely as a conduit.
  • Regulatory activity and honours (s.24): A limited exemption for personal information used to discharge specified public-interest regulatory functions (e.g. protecting the public in financial services, professional conduct, charity oversight, and workplace health and safety) and for the conferring of honours.
  • General exemption (s.25): Applies to purposes such as crime prevention and detection, apprehension or prosecution of offenders, tax assessment or collection, investigation of professional ethics breaches, and Bermuda's economic and financial interests.

Partial exemptions never displace the minimum requirements (sections 5, 8, 11, 12 and 13), and organisations must revert to full compliance once an exemption ceases to apply. Separately, a privacy notice is not required under section 9(3) where all personal information held is publicly available or where all uses fall within individuals' reasonable expectations; PrivCom expects organisations to retain records justifying reliance on that exemption.

Sources: Personal Information Protection Act 2016 · Guide to PIPA: Key Definitions · Guide to PIPA: What is personal information? · Guide to PIPA: Principles · Guide to PIPA: Sensitive personal information · Guide to PIPA: Fairness · Guide to PIPA: Privacy notices · Guide to PIPA: Exemptions · Guide to PIPA: National security exemption · Guide to PIPA: Communication provider exemption · Guide to PIPA: Regulatory activity & honours exemption · Guide to PIPA: General exemption · Guide to PIPA · Financial Service Provider's Guidance Notes – Final Report (2025-03-07) · Guidance Note: Recording People at Public Events (Part 1: Individuals)


Enforcement and penalties

PIPA establishes the Office of the Privacy Commissioner with powers to investigate, inquire, issue codes of practice, order compliance, and handle reviews and complaints. Non-compliance with orders, notices or the sensitive information provisions is an offence.

Offences and fines

  • Individuals: On summary conviction, a fine up to $25,000 or imprisonment up to two years, or both.
  • Organisations: On conviction on indictment, a fine up to $250,000.
  • Breach notification failure: Failing to notify the Commissioner of a notifiable breach is an offence under section 47(3), attracting the same summary and indictment penalties.

Individuals may also bring court claims for compensation under section 21 for financial loss or distress caused by non-compliance, and failure to comply with a rights request may lead to PrivCom action or a court application.

BMA cyber codes

For Digital Asset Business registrants, non-compliance with the Operational Cyber Risk Management Codes is treated as a factor in assessing whether the registrant conducts business in a sound and prudent manner. The indexed BMA instruments do not otherwise set out specific fine amounts.

Sources: Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Personal Information Protection Act 2016 · Guide to PIPA: Organisations & overseas third parties · Guide to PIPA: Breach of security · Individuals' Guide to PIPA (December 2024)

Documents

CitationRegulatorType
Advice to the Public in Response to the Cyberattack on Government Services (2023-09-29)PRIVCOMAdvisory
Breach of Security Notification FormPRIVCOMForm
Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20)PRIVCOMNotice
Consultation Paper - Regulation of Digital Identity Service Provider Business (2024-11-22)BMAConsultation Paper
Consultation Paper - Regulation of Digital Identity Service Provider Business - Part II (2025-07-21)BMAConsultation Paper
Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024)BMACode
Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022)BMACode
Financial Service Provider's Guidance Notes – Final Report (2025-03-07)PRIVCOMStatement of Guidance
Guidance Note: Protecting Personal Information in the Medical FieldPRIVCOMStatement of Guidance
Guidance Note: Recording People at Public Events (Part 1: Individuals)PRIVCOMStatement of Guidance
Guidance Note: Transfer of Personal Information to Overseas Third Parties and Comparable JurisdictionsPRIVCOMStatement of Guidance
Guidance for Organisations on Fees for PIPA Rights RequestsPRIVCOMStatement of Guidance
Guidance on Collection and Usage of Data for Contact Tracing (2020-06-19)PRIVCOMStatement of Guidance
Guidance on Vendors, Third Parties, and Overseas Data TransfersPRIVCOMStatement of Guidance
Guide to PIPAPRIVCOMStatement of Guidance
Guide to PIPA: Access to medical recordsPRIVCOMStatement of Guidance
Guide to PIPA: Access to personal informationPRIVCOMStatement of Guidance
Guide to PIPA: Breach of securityPRIVCOMStatement of Guidance
Guide to PIPA: Communication provider exemptionPRIVCOMStatement of Guidance
Guide to PIPA: Conditions for personal information usePRIVCOMStatement of Guidance
Guide to PIPA: ConsentPRIVCOMStatement of Guidance
Guide to PIPA: Correction & blockingPRIVCOMStatement of Guidance
Guide to PIPA: ExemptionsPRIVCOMStatement of Guidance
Guide to PIPA: FairnessPRIVCOMStatement of Guidance
Guide to PIPA: General exemptionPRIVCOMStatement of Guidance
Guide to PIPA: Integrity of personal informationPRIVCOMStatement of Guidance
Guide to PIPA: Key DefinitionsPRIVCOMStatement of Guidance
Guide to PIPA: National security exemptionPRIVCOMStatement of Guidance
Guide to PIPA: Organisations & overseas third partiesPRIVCOMStatement of Guidance
Guide to PIPA: Personal information about childrenPRIVCOMStatement of Guidance
Guide to PIPA: PrinciplesPRIVCOMStatement of Guidance
Guide to PIPA: Privacy noticesPRIVCOMStatement of Guidance
Guide to PIPA: ProportionalityPRIVCOMStatement of Guidance
Guide to PIPA: Purpose limitationPRIVCOMStatement of Guidance
Guide to PIPA: Regulatory activity & honours exemptionPRIVCOMStatement of Guidance
Guide to PIPA: Responsibility and compliancePRIVCOMStatement of Guidance
Guide to PIPA: Security safeguardsPRIVCOMStatement of Guidance
Guide to PIPA: Sensitive personal informationPRIVCOMStatement of Guidance
Guide to PIPA: Transfer to Overseas Third PartyPRIVCOMStatement of Guidance
Guide to PIPA: What is personal information?PRIVCOMStatement of Guidance
Individuals' Guide to PIPA (December 2024)PRIVCOMStatement of Guidance
Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - SchedulesBMARule
Joint Statement on AI-Generated Imagery and the Protection of Privacy (2026-02-23)PRIVCOMAdvisory
PIPA/GDPR CrosswalkPRIVCOMStatement of Guidance
Personal Information Protection Act 2016PRIVCOMAct
Personal Information Protection Act 2016 Commencement Day Notice 2016 (BR 110/2016)PRIVCOMNotice
Personal Information Protection Act 2016 Commencement Day Notice 2024 (BR 115 / 2024)PRIVCOMNotice
Personal Information Protection Amendment Act 2023 (2023:23)PRIVCOMAct
PrivCom Advises the Public on Cyberattacks (2024-03-28)PRIVCOMAdvisory
Privacy Officer Mini GuidePRIVCOMStatement of Guidance
Privacy in the Workplace (PrivCom Guidance, August 2024)PRIVCOMStatement of Guidance
Recognition of the APEC CBPR System as a Certification Mechanism for Overseas Data Transfers (2021-03-02)PRIVCOMNotice
Section 15 Checklist for OrganisationsPRIVCOMForm
Small Business AdvicePRIVCOMStatement of Guidance
Stakeholder Letter - Consultation on the Proposed Framework for Digital Identity Service Providers (DISP) (2025-04-29)BMAConsultation Paper