Augmented Advocacy Series (Bermuda): PIPA and Anonymisation

Published: 29 Oct 2024
Type: Insight

With the Personal Information Protection Act 2016 (PIPA) coming into force on 1 January, organisations in Bermuda face the critical challenge of balancing stringent data protection requirements with the increasing demand for data-driven information systems.

The use of these systems requires access to vast amounts of data, raising compliance concerns among tech-forward organisations.

PIPA applies to every organisation that uses personal information in Bermuda where that personal information is used wholly or partly by automated means or where it forms part of a structured filing system.

Under PIPA personal information (PI) means any information about an identified or identifiable individual.

The use of PI includes any operation performed on it, such as collecting, obtaining, recording, holding, storing, organising, adapting, altering, retrieving, transferring, consulting, disclosing, disseminating or otherwise making available, combining, blocking, erasing or destroying it.

Organisations must ensure that the use of PI is limited to specific purposes, as outlined under PIPA. If the purpose for using PI changes, consent should be obtained from the individual before their PI is used for the new purpose.

We note, however, that PIPA applies only to PI as defined above.

This means that where information is not about an identified or identifiable individual, that information will fall outside of PIPA’s scope.

Accordingly, where data is appropriately anonymised so that it does not constitute personal information, it can be used for other purposes, including information systems.

PIPA does not mention or define the term “anonymisation”. Interestingly, the 2024 amendment to the Bermuda Health Council Act 2004 refers to anonymisation of identifying information; however, it does not provide a definition, either.

Absent further regulatory guidance on this point and based on the definition of PI in PIPA, PI is therefore “anonymised” when it cannot be used on its own, or with any other information, to deduce or determine the identity of the individual to whom it relates, directly or indirectly.

There are various factors to consider when determining the degree of anonymisation needed. It is often not as simple as removing one’s name, address or phone number.

The amount and type of information needed to identify an individual can vary based on factors such as location and the source or form of the information.

Information may be unique — and thus identifying — within Bermuda’s smaller population compared with large, densely populated cities such as London or New York.

Biometric and genetic information are examples of PI that pose a higher risk of identification due to their distinctive nature, particularly in smaller populations.

Some more examples:

  • In a medical context: a distinct set of physical characteristics or medical conditions, that are not expressly associated with the name of an individual, could identify an individual patient and thus constitute PI.
  • In a finance context: a unique combination of rare financial instruments, investment types, and geographic locations could identify a specific investor.
  • In a real estate context: details about a property transaction, such as a landmark building or a specific location in a niche market, could lead to the identification of the buyer or seller.

As modern technology’s reliance on data continues to increase, organisations must be cognisant of the implications for data protection.

Anonymising data is one method of safeguarding PI but it requires careful examination and consideration of various factors.

When in doubt, obtaining consent from the individual to which the PI relates is the safest approach to ensuring your organisation remains compliant with its PIPA obligations.

Failing to adhere to these obligations could result in a potential fine of up to $250,000 or imprisonment for up to two years.

Authored by Associate Ligaya Sanchez-Wilson and Trainee Akira McDonald. 

First Published in The Royal Gazette, Legally Speaking column, October 2024

Share
More publications
Employment-and-Immigration
27 Feb 2026

Pay transparency heading Bermuda’s way?

The culture of secrecy with respect to pay traditionally found in workplaces may soon experience a shift, as global lawmakers and governments have enacted or moved toward enacting legislation to mandate greater pay transparency.

Appleby-Website-Insurance-and-Reinsurance
27 Feb 2026

Bermuda Monetary Authority: Modern, Thoughtful and Competitive

The Bermuda Monetary Authority (BMA) has signaled a clear direction for the future of insurance supervision in Bermuda by the release of its latest Notice on Regulatory Burden Reduction for Better Policyholder Outcomes (Notice).

Appleby-Website-Corporate-Practice
24 Feb 2026

Receivership - Does a fixed charge rank ahead of a banking or fiscal privilege?

The question of priority ranking between the different types of securities in Mauritius is not purely technical. It is a fundamental question at the very heart of creditor protection, enforcement and the stability and security of secured lending.

Appleby-Website-Banking-and-Asset-Finance-1905px-x-1400px
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Banking

Bermuda is not considered an international banking center and only banks licensed by the Bermuda Monetary Authority (BMA) under the Banks and Deposit Companies Act 1999 (BDCA) are entitled to undertake banking businesses in or from Bermuda. As banking is defined as deposit taking (as opposed to lending), international banks are generally able to lend to Bermuda-based borrowers subject to applicable restrictions relating to carrying on business in Bermuda.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Captives)

Bermuda is one of the leading captive insurance markets in the world with over 600 registered captive insurers writing an impressive ~$30 billion of annual gross written premiums.

Appleby-Website-Corporate-Practice
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – General Corporate

The Bermuda Monetary Authority (BMA), an independent body that has been in existence since 1969, is an integrated regulator and supervisor responsible for the licensing, supervision and regulation of financial institutions in Bermuda. The BMA’s mandate includes entities conducting insurance, deposit taking, investment and trust business. The BMA conducts risk-based supervision and enforcement, including enforcing anti-money laundering and counter-terrorist financing standards. The BMA sets prudential rules, issues codes of conduct and devises industry guidance to ensure the jurisdiction adheres to international standards.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Commercial)

The Bermuda Monetary Authority’s (BMA) 2026 Business Plan (Plan) outlines continued strengthening of Bermuda’s position as a leading global insurance and reinsurance jurisdiction.

Technology-and-Innovation-1024x576
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – FinTech

By any serious measure, Bermuda’s FinTech strategy for 2026 is not incremental. It is deliberate. It is disciplined. And it is designed to position Bermuda not as a follower in digital finance — but as a standard-setter.

Appleby-Website-Regulatory-Practice
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Regulatory

Bermuda operates a highly integrated regulatory architecture under which the Bermuda Monetary Authority (BMA) exercises consolidated oversight across insurance, banking, investment business and funds, trusts, corporate service providers, money services and digital asset activity. While the statutory framework has long been risk-based, the previous five years marks a clear evolution in supervisory practices. The BMA moved decisively beyond technical compliance and periodic reporting toward an emphasis on supervisory judgement, governance outcomes and system-wide resilience.

Dispute Resolution
17 Feb 2026

Bermuda: A Dispute Resolution Overview

Bermuda continues to be an established offshore disputes jurisdiction, supported by a specialist commercial court and the increasing use of arbitration to resolve complex commercial and private wealth disputes.