Bermuda Data Privacy Laws: PIPA Compliance Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 14 primary sources cited on this page. How we verify our legal content

Bermuda Data Privacy Laws: PIPA Compliance Guide (2026)

Frequently Asked Questions

What is PIPA and when did it fully take effect?

PIPA (Personal Information Protection Act 2016) is Bermuda's comprehensive data privacy law. It received Royal Assent on July 27, 2016. Administrative provisions enabling the Privacy Commissioner's office came into force in December 2016. The remaining substantive provisions governing organizational obligations and individual rights came into full operative effect on January 1, 2025.

Who must appoint a Privacy Officer under PIPA?

Every organization subject to PIPA must designate a Privacy Officer. This requirement applies regardless of the organization's size. The Privacy Officer is responsible for PIPA compliance and serves as the contact point for individuals and for the Privacy Commissioner. The role may be outsourced to an external provider, and no Bermuda residency is required.

What is PIPA's breach notification requirement?

Under PIPA Section 14, organizations must notify the Privacy Commissioner and affected individuals 'without undue delay' when a breach of security of personal information is likely to adversely affect an individual. The Act does not specify a fixed number of days. Failure to notify a qualifying breach is a separate criminal offense, carrying fines up to $250,000 for organizations.

What does PIPA mean by 'use' of personal information?

Section 2 defines 'use' as carrying out any operation on personal information, including collecting, obtaining, recording, holding, storing, organising, adapting, altering, retrieving, transferring, consulting, disclosing, disseminating or otherwise making available, combining, blocking, erasing or destroying it. Collection and disclosure are types of use rather than separate categories. An organization may use personal information only if one or more of the eight conditions in Section 6(1) is met, with six further conditions in Section 6(3) where none of the eight can be met. Unlike the GDPR, PIPA does not adopt a consent-first hierarchy.

Who is the current Privacy Commissioner for Bermuda?

Gretchen Tucker is the Privacy Commissioner for Bermuda, appointed effective March 2, 2026. She is the first Bermudian and first woman to hold the post. Tucker is a qualified barrister and holds the IAPP Certified Information Privacy Management (CIPM) designation. She succeeded Alexander White, the inaugural Commissioner.

What are the maximum penalties under PIPA?

Every monetary penalty under PIPA is criminal and is imposed by a court on prosecution under Section 47(3); the Privacy Commissioner cannot levy an administrative fine. The maxima per offence on conviction are a $25,000 fine and up to 2 years imprisonment for an individual on summary conviction, and a $250,000 fine for a person other than an individual on indictment. Directors and managers are personally liable where an organizational offense occurs with their consent, connivance, or through their neglect. Separately, Section 21 lets an individual who suffers financial loss or emotional distress claim compensation from the organization in court.

Can personal information be transferred outside Bermuda?

Yes. PIPA Section 15 permits cross-border transfers provided the overseas third party offers comparable protection or the transferring organization implements contractual mechanisms, binding corporate rules or other means to ensure it. Section 15(3) lets the Minister designate a jurisdiction as comparable on the Commissioner's recommendation, and no jurisdiction is known to have been designated. Section 15(6) exempts transfers necessary for the establishment, exercise or defence of legal rights, and transfers the organization reasonably considers small-scale, occasional and unlikely to prejudice an individual's rights. The transferring organization remains responsible for PIPA compliance regardless of where the data goes.

Does PIPA require consent for all data processing?

No. Consent is one of eight conditions under Section 6(1) on which an organization may use personal information. The others are the reasonable-expectation condition, contract performance, a provision of law that authorises or requires the use (such as AML/ATF KYC), publicly available information, emergency response, a task in the public interest, and the employment relationship with the organization. Section 6(3) adds six further conditions where none of the eight can be met. Sensitive personal information cannot use the reasonable-expectation condition and cannot rest on implied consent, but it can be used under any of the other conditions without consent.

How does PIPA affect Bermuda's insurance and reinsurance sector?

Bermuda insurers and reinsurers handle health data, which is sensitive personal information under the exhaustive Section 7(1) list. Financial information and claims records are not sensitive personal information; they are ordinary personal information used under the Section 6(1) conditions. Cross-border transfers to cedants, retrocessionnaires, and service providers worldwide require an overseas transfer assessment under Section 15(2) unless a Section 15(6) derogation applies. Organizations registered with the BMA must also handle personally identifiable information in accordance with applicable privacy law under the BMA Operational Cyber Risk Management codes.

How long does an organization have to respond to an access request?

Under Section 20(4)(a), organizations must respond within 45 days of receiving a completed written request. Section 20(6) allows an extension of no more than 30 further days, or longer only with the Commissioner's permission, and only in three situations: a large amount of personal information is requested or must be searched, meeting the time limit would unreasonably interfere with operations, or a third party must be consulted. If it extends, the organization must give the reason and say when a response can be expected (Section 20(7)).

Has Bermuda received adequacy recognition under PIPA?

No. Adequacy is a unilateral determination by the receiving jurisdiction, not a reciprocal arrangement Bermuda applies for. PrivCom's Annual Report 2025/2026 records that in February 2026 its Deputy Privacy Commissioner and Legal Counsel met the UK Department for Science, Innovation and Technology's Head of Data Bridge Assessments International Data Flows, who set out the approach Bermuda would need to take to receive a UK adequacy designation. No designation has been made, and in the other direction no jurisdiction is known to have been designated as comparable under Section 15(3), with PrivCom's transfer guidance and its Annual Report 2025/2026 recording none.

What did PrivCom's 2025 GPEN sweep examine?

In November 2025, PrivCom joined 26 other international privacy authorities in examining nearly 900 websites and mobile applications used by children. The sweep found that 72% of platforms allowed circumvention of age assurance, 71% lacked child-tailored privacy information, and 59% required email addresses from users. Results were published March 25, 2026. PrivCom stated it would use the findings to inform its own annual local sweep under PIPA.

Updates

Corrected the statutory framework throughout: the conditions for using personal information are section 6(1) (with the section 6(3) fallbacks), not "section 5(2)"; the exemptions are Part 4 (sections 22 to 25) and preserve the minimum requirements in sections 5, 8, 11, 12 and 13 rather than switching the Act off; there is no police or Regiment exemption, no automated-decision right, no general consent requirement for sensitive personal information, no retaliation offence, and no power for the Privacy Commissioner to impose administrative fines. Added the section 21 compensation right, the section 15(3) designation power and section 15(6) derogations, the section 16 children's provisions, the real section 47 offence list and defences, the three amendments to PIPA (BR 115/2017, 2023:23 in force 1 January 2025, BR 100/2025 in force 3 November 2025), and PrivCom's Annual Report 2025/2026 figures; replaced the EU "safe harbour" narrative with the UK data-bridge engagement PrivCom actually records, and replaced two dead citations including the page's only citation to the statute. Corrected the definition of "organization" to the Section 2 text (any individual, entity or public authority that uses personal information, with no commercial-activity requirement); restored the statutory tests for the consent and contract grounds in Section 6(1) and the "use" vocabulary the Act itself employs; added the Section 19(6) and 19(7) citations to the marketing cessation right; re-anchored the offshore-scope statements to Section 3; narrowed the summary of PrivCom's Financial Service Providers Guidance Notes to the report's own conclusion; and softened the statement that no jurisdiction has been designated under Section 15(3) to what the published sources actually record.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major refresh: added Privacy Officer, Breach Notification, Commencement History and Practical Business Compliance sections, Q1 2025 PrivCom statistics, GPEN sweep findings and the Commissioner Tucker appointment (2 March 2026). Several statements in that revision, including its lawful-use section references, were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log.

Reviewed and approved by an editor

Sources and References

  1. Privacy Commissioner for Bermuda (PrivCom): Official Website(privacy.bm).gov
  2. Personal Information Protection Act 2016 (consolidated text, as amended by BR 115/2017, 2023:23 and BR 100/2025), Bermuda Laws Online(bermudalaws.bm).gov
  3. PrivCom: Official Date of Full PIPA Implementation Announced (June 2023)(privacy.bm).gov
  4. PrivCom: Guide to PIPA(privacy.bm).gov
  5. PrivCom: Breach of Security Guidance(privacy.bm).gov
  6. PrivCom: Participation in 2025 GPEN Sweep (March 2026)(privacy.bm).gov
  7. Government of Bermuda: Office of the Privacy Commissioner for Bermuda(gov.bm).gov
  8. Government of Bermuda: Appointment of New Privacy Commissioner (March 2026)(gov.bm).gov
  9. Appleby: Privacy Law and Compliance Guide 2025 (Bermuda)(applebyglobal.com)
  10. Walkers Global: Guide to Bermuda Privacy Law (January 2025)(walkersglobal.com)
  11. Bermuda Monetary Authority: About PIPA(bma.bm).gov
  12. Royal Gazette: Governor Announces Appointment of Privacy Commissioner (March 4, 2026)(royalgazette.com)
  13. Royal Gazette: Information Commissioner Office Suffers Staff Shortages (March 17, 2026)(royalgazette.com)
  14. Bernews: Gretchen Tucker Named Privacy Commissioner (March 2026)(bernews.com)
  15. UNCTAD: Data Protection and Privacy Legislation Worldwide(unctad.org)
  16. PrivCom: Safeguarding Bermuda, Annual Report 2025/2026 (covering 1 April 2025 to 31 March 2026; transmitted 22 June 2026)(privacy.bm).gov
  17. PrivCom: Financial Service Providers Guidance Notes, Final Report (March 2025)(privacy.bm).gov
  18. PrivCom: Statistics for Q4/2025 (January 28, 2026)(privacy.bm).gov
  19. PrivCom: Statistics for Q1/2025 (June 27, 2025)(privacy.bm).gov
  20. Bermuda Monetary Authority: Insurance Sector Operational Cyber Risk Management Code of Conduct (s 6.10, Data Protection and Governance)(bma.bm).gov
Share: