Bermuda Data Privacy Laws: PIPA Compliance Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 14 primary sources cited on this page. How we verify our legal content

Bermuda's Personal Information Protection Act 2016 (PIPA) became fully operative on January 1, 2025, requiring every organization that collects or uses personal information in Bermuda to appoint a Privacy Officer, notify breaches without undue delay, and use personal information only where one of the conditions in Section 6(1) is met.
Bermuda enacted the Personal Information Protection Act 2016 (PIPA), establishing a comprehensive data privacy framework for the British Overseas Territory. PIPA received Royal Assent on July 27, 2016, and reached full operative effect on January 1, 2025, following a staged commencement that first established the Office of the Privacy Commissioner in December 2016. The Act draws its structural model primarily from Canadian provincial privacy statutes and regulates the "use" of personal information, a term that subsumes collection and disclosure, rather than adopting the consent-first model used in European frameworks.
PIPA was designed to balance the protection of personal information with Bermuda's role as a leading international financial centre, particularly in the insurance, reinsurance, fund administration, and trust sectors. This guide covers the full framework: commencement history, scope and definitions, the conditions for using personal information, the privacy officer requirement, data subject rights, breach notification, overseas transfer rules, enforcement and penalties, and the current state of PrivCom's enforcement posture since January 2025.
Jurisdiction scope: This article addresses the law of personal information protection in Bermuda under the Personal Information Protection Act 2016 (PIPA). It does not address data privacy laws in other British Overseas Territories or in the United Kingdom. For the UK framework, see our UK data privacy laws guide. For the EU framework, see our GDPR guide.
Quick Answer: What Does PIPA Require?
PIPA is Bermuda's omnibus data privacy statute. Section 3 applies it to every organization that uses personal information in Bermuda, where that information is used wholly or partly by automated means or forms part of a structured filing system. Section 2 defines an organization as any individual, entity or public authority that uses personal information, so there is no commercial-activity gate: companies, public authorities, clubs and charities are all in scope, subject only to the Section 4 exclusions. An organization based outside Bermuda is in scope where the use of the personal information itself takes place in Bermuda (Section 3). Any conflicting Bermuda enactment yields to PIPA, except the Human Rights Act 1981.
PIPA's core obligations sit in Part 2. An organization must act in a reasonable manner (Section 5(7)), use personal information only for the specific purposes set out in its privacy notice or purposes related to them (Section 10), keep the information adequate, relevant and not excessive in relation to those purposes (Section 11), and apply safeguards proportionate to the risk and to the sensitivity of the information (Section 13).
PIPA does not mandate a consent-first approach for every processing activity. Section 6(1) lists eight conditions on which an organization may use personal information, of which consent is only one, and Section 6(3) supplies six further conditions where none of those eight can be met.
Organizations must appoint a Privacy Officer, implement proportionate safeguards, provide individuals with privacy notices, respond to access requests within 45 calendar days, and notify PrivCom and affected individuals of privacy breaches without undue delay.
PIPA 2016 and the Office of the Privacy Commissioner
The Personal Information Protection Act 2016 (PIPA) is Bermuda's principal data privacy statute, enacted by the Parliament of Bermuda and receiving Royal Assent on July 27, 2016. PIPA covers every organization that uses personal information in Bermuda, whether a private company or a public authority, with no commercial-activity qualifier. Section 3 fixes that reach by reference to where the use occurs: an organization domiciled outside Bermuda is in scope where the use of the personal information itself takes place in Bermuda. PIPA contains no residency-based extraterritoriality rule.
PIPA functions as omnibus legislation: it covers all sectors (private and public) and, except for the Human Rights Act 1981, overrides any conflicting Bermuda enactment. The statute's structural model draws primarily from Canadian privacy statutes, particularly Alberta's Personal Information Protection Act, and uses North American nomenclature ("organizations," "individuals," "third parties") rather than EU GDPR terminology ("controllers," "data subjects," "processors").
The Office of the Privacy Commissioner for Bermuda (PrivCom) was established as the independent supervisory authority under PIPA. The Commissioner is appointed by the Governor after consultation with the Premier, who must first consult the Opposition Leader (Section 26(2)), for a five-year term that may be renewed once (Section 26(3)). The Commissioner's functions are explicitly insulated from direction or control by any other person or authority. Alexander White served as the inaugural Privacy Commissioner. Gretchen Tucker was appointed Commissioner effective March 2, 2026, becoming the first Bermudian and first woman to hold the post. Tucker holds an IAPP Certified Information Privacy Management (CIPM) designation and is a qualified barrister in Bermuda and the UK (non-practising).
Section 29(1) gives the Commissioner power to investigate compliance, make orders under Section 44, educate the public, receive comments from the public, commission research, comment on an organization's existing or proposed programmes, approve binding corporate rules for overseas transfers, issue formal warnings and admonishments, give guidance and recommendations, and liaise with domestic and foreign law enforcement agencies and regulators. PrivCom also publishes guidance notes, codes of practice and educational materials.
Two powers it does not have are worth naming, because both are commonly assumed. PIPA gives the Commissioner no compliance-audit power over organizations. It also gives no power to impose a fine: every monetary penalty under the Act is criminal and is imposed by a court.
PIPA's Phased Commencement: From 2016 to January 2025
Understanding PIPA's commencement history matters for compliance because organizations may be unsure which obligations applied when.
PIPA received Royal Assent on July 27, 2016, but the substantive privacy provisions did not come into force immediately. The Government brought only the administrative sections into force in December 2016, specifically sections 1, 2, 26, 27, 28, 29, 35, 36, 51, and 52. These provisions were limited to enabling the establishment of the Privacy Commission and the appointment of a Privacy Commissioner. They did not impose obligations on organizations or grant rights to individuals.
The substantive provisions governing personal information protection, individual rights, and organizational obligations were deferred for several years while the Government and PrivCom prepared the market. On June 16, 2023, the Government announced January 1, 2025 as the full commencement date, providing an 18-month preparation window. Commissioner White stated at that announcement:
"We now have an 18-month window for organisations to prepare for PIPA. This course of action has my support, and we have worked closely with our Government colleagues to determine this implementation window. With a single fixed, universal date we can provide legal certainty and avoid confusion about deadline."
On January 1, 2025, all remaining PIPA provisions came into full operative effect. As of that date, every in-scope organization in Bermuda became obligated to comply with the full Act: appointing privacy officers, implementing safeguards, providing privacy notices, handling access requests, and reporting breaches.
PrivCom ran a "Road to PIPA" campaign throughout 2024, publishing weekly compliance steps and guidance notes to help organizations prepare. The campaign addressed privacy officer appointment, data flow mapping, privacy notice drafting, third-party contract updates, and breach response protocols.
Scope, Definitions, and Exemptions
PIPA applies to every organization that uses personal information in Bermuda, where that personal information is used wholly or partly by automated means, and to non-automated use of personal information which forms, or is intended to form, part of a structured filing system (Section 3).
Section 2 defines an organization as any individual, entity or public authority that uses personal information. There is no commercial-activity qualifier and no list of entity types. A company, a public authority, a club, a charity, a trade union or an individual can all be organizations, and the only carve-out for individuals is the personal or domestic purposes exclusion in Section 4(1)(a).
Key definitions
Personal information: Any information about an identified or identifiable individual, including name, address, telephone number, email address, identification numbers, biometric data, financial information, health information, and any information relating to an identifiable individual.
Sensitive personal information: Section 7(1) gives an exhaustive list: place of origin, race, colour, national or ethnic origin, sex, sexual orientation, sexual life, marital status, physical or mental disability, physical or mental health, family status, religious beliefs, political opinions, trade union membership, biometric information and genetic information. Biometric information means physical, physiological or behavioural characteristics allowing unique identification, such as facial images or fingerprint information; genetic information means inherited or acquired genetic characteristics giving unique information about an individual's physiology or health (Section 2). The Minister may amend the list by negative-resolution order (Section 7(4)).
The protections attached to it are narrower than the GDPR equivalent. Sensitive personal information cannot be used under the Section 6(1)(b) reasonable-expectation condition and cannot rest on implied consent (Section 6(2)(b)). It remains usable under any of the other Section 6(1) conditions, including contract, legal requirement, publicly available information, emergency, public interest and employment, with no consent at all.
Section 7(2) is a separate anti-discrimination rule: no organization may use sensitive personal information without lawful authority in order to discriminate against a person contrary to Part II of the Human Rights Act 1981. Section 7(3) lists the five lawful-authority routes: the individual's consent; an order of the court or the Commissioner; criminal or civil proceedings; recruitment or employment where the nature of the role justifies the use; and the purposes of the Beneficial Ownership Act 2025.
Organization: Section 2 defines an organisation as any individual, entity or public authority that uses personal information. The definition carries no commercial-activity qualifier and no list of entity types, and an individual falls outside the Act only through the personal or domestic purposes exclusion in Section 4(1)(a).
Use: Section 2 defines "use" as carrying out any operation on personal information, including collecting, obtaining, recording, holding, storing, organising, adapting, altering, retrieving, transferring, consulting, disclosing, disseminating or otherwise making available, combining, blocking, erasing or destroying it. Collection and disclosure are species of use, not parallel regulated activities, and PIPA does not define "disclosure" separately. Erasing, transferring and combining data all sit inside the Act's obligations.
Exemptions
Two different mechanisms are often run together. Section 4(1) takes a use of personal information outside the Act altogether. Part 4 (Sections 22 to 25) is much narrower: it disapplies Parts 2 and 3 only, and never the minimum requirements.
PIPA does not apply at all to:
- Use of personal information for personal or domestic purposes
- Use for artistic, literary or journalistic purposes with a view to publication in the public interest, so far as necessary to protect freedom of expression
- Business contact information used to contact someone in their capacity as an employee or official of an organization
- Personal information about an individual who has been dead for at least 20 years
- Personal information that has been in existence for at least 150 years
- Personal information transferred to an archival institution on the terms set out in Section 4(1)(f)
- Personal information in a court file used for judicial purposes, and personal notes, communications or draft decisions created by or for a judicial, quasi-judicial or adjudicative officer
- Personal information used by a member of the House of Assembly or the Senate in the exercise of a political function and covered by parliamentary privilege
There is no exemption for the Bermuda Police Service or the Royal Bermuda Regiment. National security is dealt with by Section 22, which is available to any organization only on an exemption certificate signed by the Minister in consultation with the Minister responsible for national security, and the Minister's decision may be appealed to the Supreme Court.
The Part 4 exemptions are:
- Section 22: national security, on a Ministerial exemption certificate
- Section 23: communication providers acting as a conduit for information whose purpose of use they do not determine
- Section 24: regulatory activity protecting the public against financial loss, dishonesty, malpractice or professional incompetence, protecting charities against misconduct or misapplication of property, and securing health and safety at work, plus the conferring of honours
- Section 25: prevention or detection of crime, apprehension or prosecution of offenders, assessment or collection of tax or duty, breaches of ethics for regulated professionals, and the economic or financial interests of Bermuda
Each of Sections 22, 24 and 25 opens with the words "Except for the minimum requirements, Parts 2 and 3 do not apply". Section 2 defines the minimum requirements as Sections 5, 8, 11, 12 and 13. So responsibility and privacy officer designation, fairness, proportionality, data integrity and security safeguards keep binding even inside an exemption. Those requirements continue to bind an organization carrying out crime prevention or national security work, even where the Part 4 exemption is available to it.
Publicly available information is not an exclusion either. It is a condition for use under Section 6(1)(e).
Non-delegable organizational responsibility
Organizations bear non-delegable responsibility for PIPA compliance, including in relation to third-party service providers. Contracting out the processing of personal information does not transfer the compliance obligation. Safeguards must be proportionate to the sensitivity of the personal information and the context in which it is held (PIPA s.13).
Conditions for Using Personal Information: The Section 6 Framework
PIPA's most distinctive feature is that it is not consent-centric. Section 6(1) lists eight conditions, one or more of which must be met before an organization may use an individual's personal information:
- Consent: The personal information is used with the individual's consent and the organization can reasonably demonstrate that the individual knowingly consented (Section 6(1)(a)). Consent may be implied from the individual's conduct only for intended purposes that have already been notified to the individual, and never for sensitive personal information (Section 6(2)(b)).
- Reasonable expectation (not available for sensitive personal information): A reasonable person, giving due weight to the sensitivity of the information, would consider both that the individual would not reasonably be expected to request that the use should not begin or cease, and that the use does not prejudice the rights of the individual. Both limbs must hold.
- Contract: The use of the personal information is necessary for the performance of a contract to which the individual is a party, or for the taking of steps at the individual's request with a view to entering into a contract (Section 6(1)(c)).
- Legal authorization or requirement: The use of the personal information is pursuant to a provision of law that authorises or requires it (Section 6(1)(d)), for example the AML/ATF know-your-customer obligations that apply to financial services firms.
- Publicly available information: The information is publicly available and will be used for a purpose consistent with the purpose for which it was made publicly available.
- Emergency response: The use of the personal information is necessary to respond to an emergency that threatens the life, health or security of an individual or the public (Section 6(1)(f)).
- Public task or official authority: The use of the personal information is necessary to perform a task carried out in the public interest or in the exercise of official authority vested in the organization, or in a third party to whom the personal information is disclosed (Section 6(1)(g)).
- Employment relationship: The use is necessary in the context of an individual's present, past, or potential employment relationship with the organization. The condition does not reach an individual's employment relationship with a different employer, so it will not cover a background-screening use.
Ground 2 is not available for sensitive personal information, and implied consent is not available for it either (Section 6(2)(b)). Sensitive personal information may still be used under any of the other conditions, including contract, legal requirement, publicly available information, emergency, public interest and the employment relationship, with no consent at all.
The Section 6(3) fallback conditions
Where an organization cannot meet any of the eight conditions, Section 6(3) supplies six more. It may use personal information where the information was collected from, or is disclosed to, a public authority authorised or required by statute to provide or collect it; where the use is for the purpose of complying with an order made by a court, individual or body having jurisdiction over the organization; where the use is for contacting the next of kin or a friend of an injured, ill or deceased individual; where the use is necessary to collect a debt owed to the organization or to repay money the organization owes; where the use is in connection with disclosure to the surviving spouse or a relative of a deceased individual and the organization reasonably considers the disclosure appropriate; and where the use is reasonable to protect or defend the organization in a legal proceeding.
Notice requirements
Regardless of which condition is relied on, organizations must take all reasonably practicable steps to provide a privacy notice before or at the time of collection, or as soon afterwards as is reasonably practicable. Section 9(1) requires six items:
- The fact that personal information is being used
- The purposes for which it is or might be used
- The identity and types of individuals or organizations to whom it might be disclosed
- The identity and location of the organization, including how to contact it about its handling of personal information
- The contact details of the privacy officer
- The choices and means the organization provides for limiting the use of, and for accessing, correcting, blocking, erasing and destroying, the individual's personal information
Section 9(1)(e) requires the privacy officer's contact details rather than a name.
Section 9(3) removes the notice obligation altogether where all the personal information the organization holds is publicly available information, or where the organization can reasonably determine that all uses made or to be made of the information are within the reasonable expectations of the individual concerned.
The Privacy Officer Requirement
Every organization subject to PIPA must designate a representative, the Privacy Officer, for the purposes of compliance with the Act, who has primary responsibility for communicating with the Commissioner (Section 5(4)). This requirement is mandatory for all in-scope organizations regardless of size.
Two statutory flexibilities matter for smaller and grouped businesses. Section 5(5) lets a group of organizations under common ownership or control appoint a single Privacy Officer, provided that officer is accessible from each organization. Section 5(6) lets the designated Privacy Officer delegate duties to one or more individuals.
The Privacy Officer serves as the primary point of contact both internally (for staff questions and breach escalation) and externally (for individual rights requests and communications with PrivCom). Privacy notices must include the Privacy Officer's contact details (Section 9(1)(e)), so individuals and the Commissioner know where to reach the role.
The role carries the following core responsibilities:
- Developing and maintaining the organization's PIPA compliance program
- Ensuring privacy notices meet the requirements of Section 9
- Implementing proportionate safeguards under Section 13
- Managing individual access and correction requests within the required timeframes
- Coordinating breach detection, assessment, containment, and notification under Section 14
- Training staff on PIPA obligations
- Overseeing overseas-transfer contracts and vendor assessments under Section 15
The role may be outsourced to an external privacy professional or a shared services provider. There is no Bermuda residency requirement for the Privacy Officer. However, the designee should have a solid understanding of privacy law and sufficient time available to fulfill the responsibilities. For organizations in the financial services sector, the Privacy Officer's function should be coordinated with existing compliance frameworks under BMA regulatory requirements.
Watch out: Appointing a Privacy Officer in name only without genuine authority or resources is unlikely to satisfy PIPA. PrivCom's guidance emphasizes that the Privacy Officer must be able to meaningfully manage compliance, not merely serve as a contact point.
Data Subject Rights
PIPA grants individuals several rights regarding their personal information. These rights apply to any individual whose personal information is held by an organization subject to PIPA.
Right of access: An individual may request access to their personal information, the purposes for which it has been and is being used, and the persons or types of persons to whom it has been and is being disclosed (Section 17(1)). The organization must respond within 45 days of receiving a completed written request (Section 20(4)(a)).
The extension is not open-ended. Section 20(6) allows no more than 30 further days, or longer only with the Commissioner's permission, and only where a large amount of personal information is requested or must be searched, where meeting the time limit would unreasonably interfere with the organization's operations, or where more time is needed to consult a third party. If it extends, the organization must tell the applicant the reason and when a response can be expected (Section 20(7)). An organization need not comply with a manifestly unreasonable request (Section 20(12)), and may charge a fee up to the prescribed maximum, except where the request results in a correction (Section 20(8)).
Right of correction: An individual may make a written request to correct an error or omission in personal information under the organization's control. Where there is an error or omission, the organization must correct it as soon as reasonably practicable and, where it has disclosed the incorrect information to other organizations, send them the corrected information if it is reasonable to do so (Section 19(2) and (3)).
The annotation rule applies to opinions. An organization must obtain the writer's consent before correcting or otherwise altering an opinion, including a professional or expert opinion (Section 19(4)). Only where that consent is withheld must the organization note what is in the individual's written request in a manner that links the request to the opinion (Section 19(5)).
Right to request cessation of use for marketing: Under Section 19(6) an individual may request that an organization cease, or not begin, using their personal information for the purposes of advertising, marketing or public relations. On receiving that request the organization must cease, or not begin, that use (Section 19(7)), and no reason is required.
Right to request cessation on a substantial-harm threshold: Under Section 19(8) an individual may ask an organization to cease, or not to begin, using their personal information where that use is causing or is likely to cause substantial damage or substantial distress to them or to another individual. This is not an unconditional stop-processing right, and the threshold is part of it. On receiving such a request the organization must either cease the use or provide the individual with written reasons why the use is justified (Section 19(9)).
Right to request erasure or destruction: Under Section 19(10) an individual may ask an organization to erase or destroy personal information about them that is no longer relevant for the purposes of its use. The organization must either erase or destroy it, or provide written reasons why the use is justified (Section 19(11)).
Right to complain: An individual who believes an organization has violated PIPA may file a written complaint with the Privacy Commissioner. PrivCom will investigate or facilitate resolution.
Right to compensation: Section 21 entitles an individual who suffers financial loss or emotional distress by reason of an organization's failure to comply with any requirement of the Act to compensation from that organization. The court determines the amount for each contravention (Section 21(3)), and the organization has a defence if it proves it took such care as was in all the circumstances reasonably necessary to comply (Section 21(2)). This route runs directly to court and does not depend on a complaint to PrivCom.
One right readers often expect is absent. PIPA contains no right regarding solely automated decision-making. There is no PIPA equivalent of the GDPR's Article 22 right to human review, and organizations in Bermuda should not assume one exists.
Children in the information society
Section 16 imposes obligations that are easy to miss, because they sit in Part 2 alongside the organizational rules rather than with the rights of individuals.
Where an organization uses a child's personal information in providing an information society service, and either the service is targeted at children or the organization has actual knowledge that it is using children's personal information, and consent is the condition relied on, the organization must obtain consent from a parent or guardian before the information is collected or otherwise used (Section 16(1)). It must be reasonably satisfied that the consent is verifiable, so that it can be obtained only from the child's parent or guardian, and must establish procedures to verify whether an individual is a child where that is reasonably likely (Section 16(2)).
When providing an information society service to a child, an organization must not seek personal information from the child about other individuals, including the professional activity of parents or guardians, financial information or sociological information. The only exception is the identity and address of the child's parent or guardian, used solely to obtain the consent (Section 16(3)). The privacy notice given to a child must be easily understandable and appropriate to the age of the child (Section 16(4)).
A "child" for these purposes is an individual under the age of 14 (Section 16(6)), lower than the 13 to 16 band used under the GDPR. It is a defence to proceedings for failure to comply with Section 16 that the organization took such care as was in all circumstances reasonably necessary to comply (Section 16(5)).
Privacy Breach Notification
PIPA Section 14 establishes mandatory breach notification obligations. An organization that experiences a breach of security of personal information must notify both the Privacy Commissioner and the affected individuals when the breach is "likely to adversely affect an individual."
What triggers notification
The threshold is harm-probability based, not harm-actual. A breach of security means loss, unlawful destruction, or unauthorized disclosure of, or unauthorized access to, personal information. Organizations must assess whether such an event is likely to adversely affect an individual and document that assessment regardless of the conclusion reached.
Timing
Notification to the Commissioner and to affected individuals must occur "without undue delay." PIPA does not prescribe a specific number of days. The flexibility is deliberate: it gives organizations time to contain the breach, assess its scope, and prepare an accurate notification before filing. PrivCom's guidance notes that where a delay occurs, the organization must give reasons.
What the notification must contain
Notification to the Privacy Commissioner must describe:
- The nature of the breach
- The likely consequences for the affected individual(s)
- The measures taken and to be taken to address the breach
PIPA itself prescribes content only for the notification to the Commissioner. For the notification to affected individuals, PrivCom's breach guidance lists three items:
- The name and contact details of any data privacy officer you have, or other contact point where more information can be obtained
- A description of the likely consequences of the personal information breach
- A description of the measures taken or proposed to deal with the personal information breach
Advice on protective steps the individual can take, such as password changes or fraud monitoring, is good practice rather than a listed requirement.
Failure to notify
Failure to notify a qualifying breach is a separate criminal offense under PIPA. Individuals face fines up to $25,000 and/or imprisonment up to 2 years on summary conviction. Organizations face fines up to $250,000 on indictment.
Organizations must maintain documented records of all breaches, including those that did not meet the notification threshold, to demonstrate the assessment process.
Watch out: Service contracts with IT providers and data processors must include a requirement for the vendor to notify the organization of any breach promptly enough to enable the organization to meet its own PIPA reporting obligations to PrivCom and individuals.
Overseas Data Transfers
PIPA Section 15 governs transfers of personal information to an overseas third party, meaning an organization not domiciled in Bermuda. Section 15(1) keeps the transferring organization responsible for compliance with the Act, and Section 15(2) requires it to assess the level of protection the overseas third party provides before making the transfer.
The Act does contain a designation mechanism. Section 15(3) provides that the Minister, on the recommendation of the Commissioner, may designate any jurisdiction as providing a comparable level of protection. No jurisdiction is known to have been designated under that power. Section 15(6) also carves out two situations in which the assessment obligation does not bite at all, so the assessment is not required before every transfer.
The comparable protection assessment
Before transferring personal information to an overseas recipient, the organization must:
- Assess the level of protection actually provided by the overseas recipient
- Assess the level of protection afforded by the law applicable to the overseas recipient's jurisdiction
Where the organization reasonably believes that the overseas recipient does not and will not provide a comparable level of protection, the organization must employ contractual mechanisms, corporate codes of conduct, or other means to ensure comparable protection.
Contractual safeguards should address purpose limitation, security measures consistent with PIPA Section 13, individual access and correction rights, breach notification obligations, and onward transfer restrictions. The organization remains responsible for PIPA compliance regardless of where the transfer goes.
Comparable protection may also be evidenced by the overseas third party's adoption of a certification mechanism recognised by the Commissioner (Section 15(4)), or by binding corporate rules approved by the Commissioner under Section 29(1)(g). Where an organization can reasonably demonstrate that it is unable to comply with Section 15(2), the Commissioner may make an order permitting the transfer, provided the transfer does not undermine the individual's rights (Section 29(1)(l)).
When the assessment is not required
Section 15(6) applies notwithstanding Sections 15(1) to (5). An organization may transfer personal information to an overseas third party where the transfer is necessary for the establishment, exercise or defence of legal rights. It may also transfer where, having assessed all the circumstances surrounding the transfer, it reasonably considers the transfer to be small-scale, occasional, and unlikely to prejudice the rights of an individual. Those three limbs are conjunctive: all three must hold.
Designations under Section 15(3)
No jurisdiction is known to have been designated under Section 15(3) as providing a comparable level of protection. PrivCom's transfer guidance reproduces the subsection without naming a designated jurisdiction, and its practical guidance is written throughout around transfers to a country that does not provide a comparable level of protection. PrivCom's Annual Report 2025/2026 records no designation either. An organization that wants to rely on a designation should confirm the current position with PrivCom rather than assume one exists, and should otherwise plan on the footing that the recipient jurisdiction is not comparable.
Adequacy also runs the other way, and it is a unilateral determination by the receiving jurisdiction rather than a reciprocal arrangement Bermuda applies for. PrivCom's Annual Report 2025/2026 records that in February 2026 the Deputy Privacy Commissioner and Legal Counsel met Sam Roberts, Head of Data Bridge Assessments International Data Flows at the UK Department for Science, Innovation and Technology, who set out the approach Bermuda would need to take to receive an adequacy designation from the UK. Such a designation would let UK organizations transfer personal information to Bermuda on the footing that Bermuda's protection is not materially lower than UK law provides. No designation has been made, and the report records no EU application.
Financial services sector
Many Bermuda-based organizations in the insurance, reinsurance, and fund administration sectors routinely transfer personal information to affiliates, cedants, retrocessionnaires, and service providers worldwide. These organizations must maintain a record of overseas transfer assessments and ensure that data processing agreements flow PIPA obligations downstream to each processor.
Enforcement and Penalties
PIPA establishes a graduated enforcement framework administered by the Privacy Commissioner.
The Commissioner's orders
On completing an inquiry, the Commissioner disposes of the matter by making an order under Section 44 or by issuing a formal warning or public admonishment. An order may:
- Direct an organization to give, reconsider or refuse access to personal information
- Require an obligation imposed by the Act to be performed, including specific steps to remedy a breach
- Require a right set out in the Act to be observed
- Specify that personal information be corrected, erased, deleted or destroyed, and where reasonably practicable require third parties to be notified
- Require an organization to stop using personal information in contravention of the Act
- Require an organization to destroy personal information used contrary to the Act
- Require an organization to provide specific information to people after a breach likely to cause significant harm
A copy of an order may be filed with the Registrar of the Supreme Court, after which it is enforceable as a judgment or order of that Court (Section 44(7)). The organization must comply within 50 days of being given a copy (Section 45(1)). Any person aggrieved by a decision of the Commissioner may apply to the Supreme Court for a review within 45 days of being given a copy of the order, and the order is stayed until that application is dealt with (Section 45(2) to (4)).
Criminal penalties (Section 47)
PIPA gives the Privacy Commissioner no power to impose an administrative fine. Every monetary penalty under the Act is criminal, imposed by a court on prosecution under Section 47(3), and the figures below are maxima per offence on conviction rather than per violation.
| Entity type | Offense | Maximum penalty |
|---|---|---|
| Individual | Summary conviction | $25,000 fine and/or 2 years imprisonment |
| Organization | Indictment | $250,000 fine |
For every offence under Section 47(2), including failure to notify a breach, it is a defence for the organization or individual to prove to the court's satisfaction that they acted reasonably in the circumstances that gave rise to the offence (Section 47(4)). In determining whether an offence has been committed, the court must consider whether the person followed any relevant code of practice issued by the Minister at the time (Section 47(5)).
Director and manager personal liability
Where an organization commits a PIPA offense with the consent or connivance of a director or manager, or where the offense is attributable to that person's neglect, the director or manager is personally liable for the offense and subject to individual penalties. This provision makes governance-level accountability explicit.
Criminal offenses
Section 47(1) creates offences for:
- Wilfully or negligently using, or authorising the use of, personal information inconsistently with Part 2 in a manner likely to cause harm
- Wilfully gaining or attempting to gain access to personal information inconsistently with the Act in a manner likely to cause harm
- Disposing of, altering, falsifying, concealing or destroying personal information, or directing another person to do so, in order to evade an access request
- Obstructing the Commissioner or an authorised delegate
- Knowingly making a false statement to, or knowingly misleading, the Commissioner
- Knowingly or recklessly failing to comply with the Section 34(1) restrictions on disclosure by the Commissioner or staff
Section 47(2) adds offences for:
- Failing to comply with an order made by the Commissioner
- Failing to comply with a notice served by the Commissioner
- Contravening Section 7 (sensitive personal information)
- Disposing of, altering, falsifying, concealing or destroying evidence during an investigation or inquiry by the Commissioner
- Failing to notify a breach of security to the Commissioner in accordance with Section 14
PIPA creates no offence of retaliating against an individual for exercising PIPA rights.
The private right of action
Enforcement does not run only through PrivCom. Section 21 entitles an individual who suffers financial loss or emotional distress by reason of an organization's failure to comply with any requirement of the Act to compensation from that organization, in an amount the court determines for each contravention. The organization's defence is that it took such care as was in all the circumstances reasonably necessary to comply. For most readers this is the most direct route to a remedy, and it does not depend on the Commissioner taking up the matter.
Sector-Specific Considerations
Insurance and reinsurance
Bermuda is one of the world's leading insurance and reinsurance centers. Organizations in this sector handle substantial volumes of personal information, including health data for life and health insurance policies, claims data, policyholder financial information, and medical records from cedants and retrocessionnaires. Health data is sensitive personal information under Section 7(1). Financial information and claims records are not: the Section 7(1) list is exhaustive and contains no financial category, so those are ordinary personal information used under the Section 6(1) conditions like anything else. Classifying claims and policyholder financial data as sensitive would push an insurer toward a consent model the Act does not require.
Cross-border transfers are a routine feature of Bermuda reinsurance operations. Reinsurers must maintain overseas-transfer assessments for each jurisdiction to which they send personal information, and must ensure that reinsurance treaties and data processing agreements include PIPA-compliant data protection clauses.
BMA dual compliance for financial services
The BMA's Operational Cyber Risk Management codes of conduct require registrants to assess their compliance against applicable data protection requirements and, where personally identifiable information is processed, to handle it in accordance with the data protection and privacy laws relevant to each jurisdiction of operation. The code does not make a PIPA breach automatically a code violation, but a PIPA failure by a registrant can raise questions under the code as well as with PrivCom. Organizations should coordinate their PIPA compliance programs with their existing BMA cyber risk management frameworks.
PrivCom has examined this overlap directly. Its Financial Service Providers Guidance Notes, published in March 2025 and summarised in the Annual Report 2025/2026, concluded that no material issues were identified regarding the application of PIPA, particularly with respect to the commercial and administrative activities of organizations operating within Bermuda's financial services sector, and that potential challenges to an organization's ability to process some types of personal information, and to share data within organizations, between organizations and across borders, are adequately addressed by PIPA Sections 6, 7, 15 and 25.
AML/ATF and KYC interaction
AML/ATF know-your-customer obligations authorize financial services firms to collect identity data, beneficial ownership information, and transaction profiles under PIPA Section 6(1)(d), which permits use pursuant to a provision of law that authorises or requires it, without needing explicit consumer consent. However, such data remains subject to all PIPA obligations regarding safeguarding, retention, individual access rights, and breach notification.
Trust and corporate services
Trust companies and corporate service providers process personal information of settlors, beneficiaries, directors, and shareholders. PIPA compliance must be coordinated with BMA regulatory requirements, professional obligations, and the PIPA obligations of any overseas affiliates or service providers to whom information is transferred.
International business and captive insurance
Bermuda's substantial captive insurance and international business sector operates across multiple jurisdictions. These organizations must navigate PIPA alongside the GDPR, the UK Data Protection Act 2018, and relevant US state privacy laws, particularly for organizations with US employees or US policyholders.
Practical Business Compliance
Organizations newly subject to PIPA's full obligations from January 1, 2025 should work through the following compliance steps:
Step 1: Designate a Privacy Officer. Every in-scope organization must name a Privacy Officer and publish that person's contact details in privacy notices. The role can be outsourced; no Bermuda residency is required.
Step 2: Map your data flows. Identify every category of personal information collected, the purpose, the condition for use under Section 6(1) or Section 6(3), who has access internally, and where data is sent externally (including overseas transfers).
Step 3: Update privacy notices. Ensure all privacy notices carry the Privacy Officer's contact details, describe the purposes of collection, identify disclosure recipients, and explain the choices and means available to individuals. Privacy notices must satisfy the six requirements in Section 9(1).
Step 4: Implement proportionate safeguards. Section 13 requires safeguards proportionate to the sensitivity of the personal information and the context in which it is held. Document the safeguards in place for each data category.
Step 5: Establish a breach response protocol. Define who has authority to declare a breach, who notifies PrivCom and individuals, and how the organization will document its assessment of whether a breach meets the Section 14 notification threshold.
Step 6: Review overseas-transfer contracts. Where you rely on contractual safeguards, ensure the vendor or affiliate that receives personal information from Bermuda is bound by an agreement containing PIPA-comparable protections, breach notification clauses, and onward transfer restrictions. A contract is not needed for every transfer: Section 15(4) lets you rely on the recipient's own comparable protection or a recognised certification mechanism, and Section 15(6) covers transfers necessary for legal rights and transfers that are small-scale, occasional and unlikely to prejudice an individual's rights.
Step 7: Train staff. PIPA obligations apply to all staff who handle personal information. Annual training on PIPA basics, privacy notice requirements, and breach identification is a recommended minimum.
Step 8: For BMA registrants, coordinate your cyber risk management framework. The BMA cyber codes require personally identifiable information to be handled in accordance with the privacy laws relevant to each jurisdiction of operation, so a PIPA failure can raise code questions too. Align your breach response protocols with your existing BMA Operational Cyber Risk Management procedures.
Recent Developments (2025-2026)
The Act has been amended three times. The consolidated text on Bermuda Laws Online carries the note "[Amended by: BR 115 / 2017; 2023 : 23; BR 100 / 2025]". BR 115/2017 substituted the definition of "Minister" in Section 2, effective 7 December 2017. The Personal Information Protection Amendment Act 2023 (2023 : 23) amended Sections 2, 4(4), 9(1)(e) and (f), 18(2), the Section 19 heading, Section 29(1)(n), Section 37(1) and Section 52(2), and inserted the vacancy provision at Section 26(6), all effective 1 January 2025. So the version that came into full force is not the 2016 text as enacted. BR 100/2025 amended Section 7 effective 3 November 2025, adding the purposes of the Beneficial Ownership Act 2025 as a lawful authority for using sensitive personal information.
January 1, 2025: Full PIPA commencement. All substantive PIPA provisions came into operative effect, imposing binding obligations on every in-scope organization. The staged implementation from 2016 to 2025 concluded.
June 27, 2025: PrivCom's inaugural statistical report. PrivCom published its first quarterly statistics report, covering January through March 2025. The report recorded 5 personal information breaches affecting more than 3,000 individuals (4 concluded, 1 remaining open). PrivCom received 6 formal written requests (2 for review, 4 complaints), 4 of which closed by resolution before formal investigation, and fielded 22 general queries.
November 2025: GPEN sweep on children's privacy. PrivCom joined 26 other international privacy authorities in the Global Privacy Enforcement Network 2025 sweep, examining nearly 900 websites and mobile applications used by children. Findings published March 25, 2026 identified that 72% of platforms allowed circumvention of age assurance measures, 71% lacked child-tailored privacy information, and 59% required email addresses. PrivCom indicated it would use the results to inform its own annual local sweep.
March 2, 2026: Commissioner Tucker appointed. Gretchen Tucker succeeded Alexander White as Privacy Commissioner, becoming the first Bermudian and first woman to hold the post. Tucker is a qualified barrister and IAPP CIPM-certified privacy professional who co-chaired the IAPP Bermuda KnowledgeNet Chapter for over five years before her appointment.
Early 2026: PrivCom capacity and 2026 strategy. Following the transition period after Commissioner White's departure, PrivCom was working toward a full staff complement of 14, with an annual budget of $2.39 million. Public education workshops were reduced from 14 in 2024-25 to 4 planned for 2026-27, with PrivCom intending to reorient toward targeted engagement with individual organizations rather than broad public workshops.
January 28, 2026: Q4/2025 statistics. PrivCom's most recent quarterly release recorded five reported personal information breaches (three closed during the quarter, two open, one of them reopened on new information), ten written requests (five requests for review and five complaints) and thirteen general queries, all closed informally.
June 22, 2026: PrivCom's first Annual Report. "Safeguarding Bermuda", the Annual Report 2025/2026, was transmitted to be laid before each House of the Legislature under Section 37. Covering 1 April 2025 to 31 March 2026, it records 30 written requests (8 requests for the Commissioner to review an organization's failure to act, 22 complaints), 25 reported personal information breaches (21 reviewed and closed, 4 active at year end; 10 accidental disclosure, 7 unauthorised use by an employee, 8 unauthorised use by an external third party) and 43 general queries, all of the queries closed informally. It also sets out the leadership sequence: Alexander White served until 30 September 2025, Deputy Privacy Commissioner E. Angie Farquharson held an acting appointment, and Gretchen Tucker took office on 2 March 2026.
Adequacy: a UK track, not an EU one. No adequacy designation has been made in either direction. The Annual Report 2025/2026 records that in February 2026 PrivCom's Deputy Privacy Commissioner and Legal Counsel met the UK Department for Science, Innovation and Technology's Head of Data Bridge Assessments International Data Flows, who set out the approach Bermuda would need to take to receive a UK adequacy designation.
Disclaimer
This article presents general legal information about Bermuda's Personal Information Protection Act 2016 (PIPA). It covers the Personal Information Protection Act 2016 as consolidated on Bermuda Laws Online and amended by BR 115/2017, 2023 : 23 and BR 100/2025, together with PrivCom's published guidance and reports through the Annual Report 2025/2026, checked as of September 10, 2026. This article is not legal advice and does not create a solicitor-client or attorney-client relationship. Privacy law requirements vary by organization type, size, sector, and the nature of the personal information processed. Organizations and individuals should consult a lawyer licensed in Bermuda for advice on their specific situation.
Authorities Cited
Frequently Asked Questions
What is PIPA and when did it fully take effect?
PIPA (Personal Information Protection Act 2016) is Bermuda's comprehensive data privacy law. It received Royal Assent on July 27, 2016. Administrative provisions enabling the Privacy Commissioner's office came into force in December 2016. The remaining substantive provisions governing organizational obligations and individual rights came into full operative effect on January 1, 2025.
Who must appoint a Privacy Officer under PIPA?
Every organization subject to PIPA must designate a Privacy Officer. This requirement applies regardless of the organization's size. The Privacy Officer is responsible for PIPA compliance and serves as the contact point for individuals and for the Privacy Commissioner. The role may be outsourced to an external provider, and no Bermuda residency is required.
What is PIPA's breach notification requirement?
Under PIPA Section 14, organizations must notify the Privacy Commissioner and affected individuals 'without undue delay' when a breach of security of personal information is likely to adversely affect an individual. The Act does not specify a fixed number of days. Failure to notify a qualifying breach is a separate criminal offense, carrying fines up to $250,000 for organizations.
What does PIPA mean by 'use' of personal information?
Section 2 defines 'use' as carrying out any operation on personal information, including collecting, obtaining, recording, holding, storing, organising, adapting, altering, retrieving, transferring, consulting, disclosing, disseminating or otherwise making available, combining, blocking, erasing or destroying it. Collection and disclosure are types of use rather than separate categories. An organization may use personal information only if one or more of the eight conditions in Section 6(1) is met, with six further conditions in Section 6(3) where none of the eight can be met. Unlike the GDPR, PIPA does not adopt a consent-first hierarchy.
Who is the current Privacy Commissioner for Bermuda?
Gretchen Tucker is the Privacy Commissioner for Bermuda, appointed effective March 2, 2026. She is the first Bermudian and first woman to hold the post. Tucker is a qualified barrister and holds the IAPP Certified Information Privacy Management (CIPM) designation. She succeeded Alexander White, the inaugural Commissioner.
What are the maximum penalties under PIPA?
Every monetary penalty under PIPA is criminal and is imposed by a court on prosecution under Section 47(3); the Privacy Commissioner cannot levy an administrative fine. The maxima per offence on conviction are a $25,000 fine and up to 2 years imprisonment for an individual on summary conviction, and a $250,000 fine for a person other than an individual on indictment. Directors and managers are personally liable where an organizational offense occurs with their consent, connivance, or through their neglect. Separately, Section 21 lets an individual who suffers financial loss or emotional distress claim compensation from the organization in court.
Can personal information be transferred outside Bermuda?
Yes. PIPA Section 15 permits cross-border transfers provided the overseas third party offers comparable protection or the transferring organization implements contractual mechanisms, binding corporate rules or other means to ensure it. Section 15(3) lets the Minister designate a jurisdiction as comparable on the Commissioner's recommendation, and no jurisdiction is known to have been designated. Section 15(6) exempts transfers necessary for the establishment, exercise or defence of legal rights, and transfers the organization reasonably considers small-scale, occasional and unlikely to prejudice an individual's rights. The transferring organization remains responsible for PIPA compliance regardless of where the data goes.
Does PIPA require consent for all data processing?
No. Consent is one of eight conditions under Section 6(1) on which an organization may use personal information. The others are the reasonable-expectation condition, contract performance, a provision of law that authorises or requires the use (such as AML/ATF KYC), publicly available information, emergency response, a task in the public interest, and the employment relationship with the organization. Section 6(3) adds six further conditions where none of the eight can be met. Sensitive personal information cannot use the reasonable-expectation condition and cannot rest on implied consent, but it can be used under any of the other conditions without consent.
How does PIPA affect Bermuda's insurance and reinsurance sector?
Bermuda insurers and reinsurers handle health data, which is sensitive personal information under the exhaustive Section 7(1) list. Financial information and claims records are not sensitive personal information; they are ordinary personal information used under the Section 6(1) conditions. Cross-border transfers to cedants, retrocessionnaires, and service providers worldwide require an overseas transfer assessment under Section 15(2) unless a Section 15(6) derogation applies. Organizations registered with the BMA must also handle personally identifiable information in accordance with applicable privacy law under the BMA Operational Cyber Risk Management codes.
How long does an organization have to respond to an access request?
Under Section 20(4)(a), organizations must respond within 45 days of receiving a completed written request. Section 20(6) allows an extension of no more than 30 further days, or longer only with the Commissioner's permission, and only in three situations: a large amount of personal information is requested or must be searched, meeting the time limit would unreasonably interfere with operations, or a third party must be consulted. If it extends, the organization must give the reason and say when a response can be expected (Section 20(7)).
Has Bermuda received adequacy recognition under PIPA?
No. Adequacy is a unilateral determination by the receiving jurisdiction, not a reciprocal arrangement Bermuda applies for. PrivCom's Annual Report 2025/2026 records that in February 2026 its Deputy Privacy Commissioner and Legal Counsel met the UK Department for Science, Innovation and Technology's Head of Data Bridge Assessments International Data Flows, who set out the approach Bermuda would need to take to receive a UK adequacy designation. No designation has been made, and in the other direction no jurisdiction is known to have been designated as comparable under Section 15(3), with PrivCom's transfer guidance and its Annual Report 2025/2026 recording none.
What did PrivCom's 2025 GPEN sweep examine?
In November 2025, PrivCom joined 26 other international privacy authorities in examining nearly 900 websites and mobile applications used by children. The sweep found that 72% of platforms allowed circumvention of age assurance, 71% lacked child-tailored privacy information, and 59% required email addresses from users. Results were published March 25, 2026. PrivCom stated it would use the findings to inform its own annual local sweep under PIPA.
Updates
Corrected the statutory framework throughout: the conditions for using personal information are section 6(1) (with the section 6(3) fallbacks), not "section 5(2)"; the exemptions are Part 4 (sections 22 to 25) and preserve the minimum requirements in sections 5, 8, 11, 12 and 13 rather than switching the Act off; there is no police or Regiment exemption, no automated-decision right, no general consent requirement for sensitive personal information, no retaliation offence, and no power for the Privacy Commissioner to impose administrative fines. Added the section 21 compensation right, the section 15(3) designation power and section 15(6) derogations, the section 16 children's provisions, the real section 47 offence list and defences, the three amendments to PIPA (BR 115/2017, 2023:23 in force 1 January 2025, BR 100/2025 in force 3 November 2025), and PrivCom's Annual Report 2025/2026 figures; replaced the EU "safe harbour" narrative with the UK data-bridge engagement PrivCom actually records, and replaced two dead citations including the page's only citation to the statute. Corrected the definition of "organization" to the Section 2 text (any individual, entity or public authority that uses personal information, with no commercial-activity requirement); restored the statutory tests for the consent and contract grounds in Section 6(1) and the "use" vocabulary the Act itself employs; added the Section 19(6) and 19(7) citations to the marketing cessation right; re-anchored the offshore-scope statements to Section 3; narrowed the summary of PrivCom's Financial Service Providers Guidance Notes to the report's own conclusion; and softened the statement that no jurisdiction has been designated under Section 15(3) to what the published sources actually record.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Major refresh: added Privacy Officer, Breach Notification, Commencement History and Practical Business Compliance sections, Q1 2025 PrivCom statistics, GPEN sweep findings and the Commissioner Tucker appointment (2 March 2026). Several statements in that revision, including its lawful-use section references, were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log.
Reviewed and approved by an editor
Sources and References
- Privacy Commissioner for Bermuda (PrivCom): Official Website(privacy.bm).gov
- Personal Information Protection Act 2016 (consolidated text, as amended by BR 115/2017, 2023:23 and BR 100/2025), Bermuda Laws Online(bermudalaws.bm).gov
- PrivCom: Official Date of Full PIPA Implementation Announced (June 2023)(privacy.bm).gov
- PrivCom: Guide to PIPA(privacy.bm).gov
- PrivCom: Breach of Security Guidance(privacy.bm).gov
- PrivCom: Participation in 2025 GPEN Sweep (March 2026)(privacy.bm).gov
- Government of Bermuda: Office of the Privacy Commissioner for Bermuda(gov.bm).gov
- Government of Bermuda: Appointment of New Privacy Commissioner (March 2026)(gov.bm).gov
- Appleby: Privacy Law and Compliance Guide 2025 (Bermuda)(applebyglobal.com)
- Walkers Global: Guide to Bermuda Privacy Law (January 2025)(walkersglobal.com)
- Bermuda Monetary Authority: About PIPA(bma.bm).gov
- Royal Gazette: Governor Announces Appointment of Privacy Commissioner (March 4, 2026)(royalgazette.com)
- Royal Gazette: Information Commissioner Office Suffers Staff Shortages (March 17, 2026)(royalgazette.com)
- Bernews: Gretchen Tucker Named Privacy Commissioner (March 2026)(bernews.com)
- UNCTAD: Data Protection and Privacy Legislation Worldwide(unctad.org)
- PrivCom: Safeguarding Bermuda, Annual Report 2025/2026 (covering 1 April 2025 to 31 March 2026; transmitted 22 June 2026)(privacy.bm).gov
- PrivCom: Financial Service Providers Guidance Notes, Final Report (March 2025)(privacy.bm).gov
- PrivCom: Statistics for Q4/2025 (January 28, 2026)(privacy.bm).gov
- PrivCom: Statistics for Q1/2025 (June 27, 2025)(privacy.bm).gov
- Bermuda Monetary Authority: Insurance Sector Operational Cyber Risk Management Code of Conduct (s 6.10, Data Protection and Governance)(bma.bm).gov