Bermuda’s Personal Information Protection Act (PIPA) has been fully in force since January 1, 2025. But many businesses are still unsure if they’re compliant, what compliance actually requires, or what happens if they’re not.
This guide cuts through the legal jargon and gives you a practical, actionable checklist for PIPA compliance in 2026.
What Is PIPA and Who Does It Apply To?
PIPA (Personal Information Protection Act 2016) is Bermuda’s data protection law. It regulates how organizations collect, use, store, and share personal information.
Personal information includes: names, addresses, phone numbers, email addresses; financial information; health and medical records; employee records; IP addresses; and any information that can identify an individual.
Who must comply? Any organization that processes personal information in Bermuda; organizations outside Bermuda that process personal information of Bermuda residents; and your business if you have employees, clients, customers, or website visitors. If you handle any personal data, PIPA applies to you.
The 8 PIPA Principles
1. Accountability: You are responsible for personal information under your control, even if a third party processes it. You need a designated Privacy Officer and documented policies.
2. Identifying Purposes: You must identify why you’re collecting personal information before or at the time of collection.
3. Consent: You must obtain meaningful consent before collecting, using, or disclosing personal information.
4. Limiting Collection: You can only collect personal information that’s necessary for the identified purposes.
5. Limiting Use, Disclosure, and Retention: You can only use personal information for the purposes you identified, and retain it only as long as necessary.
6. Accuracy: Personal information must be accurate, complete, and up-to-date.
7. Safeguards: You must protect personal information with appropriate security measures based on sensitivity.
8. Openness: You must make your privacy practices transparent and easily accessible.
The PIPA Compliance Checklist
Governance and Accountability
- ☐ Designated Privacy Officer responsible for PIPA compliance
- ☐ Written privacy policy publicly available
- ☐ All staff receive PIPA training at onboarding and annually
- ☐ Vendor contracts include data protection clauses
- ☐ Documented incident response plan
Consent and Collection
- ☐ Clear privacy notices at the point of data collection
- ☐ Explicit consent for sensitive data, implied consent for non-sensitive
- ☐ Documented purposes for each type of data collected
- ☐ Data minimization practices in place
- ☐ Opt-out and consent withdrawal processes
Use, Disclosure, and Retention
- ☐ Use limitation procedures
- ☐ Disclosure controls for third-party requests
- ☐ Retention schedule for different data types
- ☐ Secure disposal when retention periods expire
- ☐ Cross-border transfer protections (contractual clauses)
Accuracy and Access
- ☐ Processes to keep personal information accurate
- ☐ Procedure for access requests
- ☐ Procedure for correction requests
- ☐ Response within 45 days (PIPA requirement)
Security Safeguards
- ☐ Risk assessment of data sensitivity
- ☐ Technical controls: encryption, access controls, firewalls, monitoring
- ☐ Physical controls for records and server rooms
- ☐ Administrative controls: policies, training, disciplinary measures
- ☐ Annual incident response tabletop exercises
Openness and Transparency
- ☐ Website privacy policy easily accessible
- ☐ Privacy Officer contact information published
- ☐ Complaint process explained
- ☐ Breach notification procedure for the Privacy Commissioner
Conducting a Privacy Impact Assessment (PIA)
For high-risk activities (new systems, new data uses, mergers), PIPA expects a Privacy Impact Assessment. A simplified PIA covers: Project description (what and why), Personal information involved (what, from whom, how), Privacy risks (what could go wrong, likelihood, impact), Mitigation measures (controls and owners), Consultation (stakeholder feedback), and Conclusion (do benefits outweigh risks, ongoing monitoring).
Common PIPA Compliance Mistakes
Treating PIPA as a one-time project: Compliance is ongoing — annual training, regular audits, continuous monitoring.
Relying on verbal consent: For sensitive data, you need written or recorded consent.
Ignoring vendor compliance: If your cloud provider has a breach, you’re responsible under PIPA.
Not having an incident response plan: Without a plan, you’ll panic and potentially violate breach notification requirements.
Collecting “just in case” data: Excess data increases your risk and compliance burden.
What Happens If You’re Not Compliant?
Consequences include: investigations by the Privacy Commissioner; orders to stop practices or take corrective action; fines up to $250,000 for organizations and $25,000 for individuals; reputational damage; and civil liability. The Commissioner is more likely to work with businesses that demonstrate good faith efforts to comply. The biggest risk is being caught completely unprepared.
Your 90-Day PIPA Compliance Plan
Month 1 (Foundation): Designate a Privacy Officer, draft your privacy policy, conduct a data inventory, review vendor contracts.
Month 2 (Implementation): Implement technical safeguards, conduct employee training, establish access/correction procedures, draft your incident response plan.
Month 3 (Testing): Run a tabletop breach exercise, audit your compliance checklist, conduct PIAs for high-risk activities, schedule your next annual review.
Need Help With PIPA Compliance?
At SohoWizz, we specialize in PIPA compliance for Bermuda’s professional services firms. Our service includes: complete data inventory and risk assessment, custom privacy policy and procedures, employee training programs, vendor contract review, Privacy Impact Assessments, and ongoing compliance monitoring.
BOOK YOUR PIPA COMPLIANCE ASSESSMENT →
Frequently Asked Questions
When did PIPA come into force?
PIPA was passed in 2016 but fully came into force on January 1, 2025. Organizations have been expected to comply since that date.
Do small businesses have to comply with PIPA?
Yes. PIPA applies to all organizations that process personal information, regardless of size. The complexity of your program should be proportionate to the amount and sensitivity of data you handle.
How long do I have to respond to an access request?
PIPA requires you to respond within 45 days of receiving a valid access request, extendable by 30 days in complex cases with notice.
Can I transfer personal data outside Bermuda?
Yes, but you must ensure the recipient provides adequate protection — typically via contractual clauses or comparable privacy laws in the recipient jurisdiction.
What should I do if there’s a data breach?
Follow your incident response plan: contain the breach, assess the impact, notify affected individuals if there’s risk of harm, and notify the Privacy Commissioner if the breach is significant. Document everything.
Last updated: August 2026. About the author: Calvert Harvey is the founder of SohoWizz Technology Solutions and a PIPA compliance specialist for Bermuda’s regulated industries.
