PIPA, which received Royal Assent on July 27, 2016, will come into full effect on January 1, 2025, meaning that the clock has started ticking and employers must begin preparing for its impact.

Personal information is defined under PIPA as “any information about an identified or identifiable individual”.

Sensitive personal information, which is a category of personal information, is defined as “any personal information relating to an individual’s place of origin, race, colour, national or ethnic origin, sex, sexual orientation, sexual life, marital status, physical or mental disability, physical or mental health, family status, religious beliefs, political opinions, trade union membership, biometric information or genetic information”.

In practice, the sort of personal information about employees that an employer is likely to have access to and retain includes financial information, pension information, age, security clearance information, drug test results and health records or medical information.

Such information may be obtained by an employer for many reasons, such as for insurance purposes, work permit submission or workplace diversity and equality monitoring.

Personal information should be collected with consent. Where an employer retains personal information prior to PIPA coming into force, it is deemed to have been collected pursuant to consent being given by that individual.

When an employer wishes to use the personal information of an employee, they may rely on provisions in contracts of employment whereby the employee has consented to such use.

It may seem to an employer that consent is the most obvious and straightforward method by which to establish a lawful basis to use the personal information of an employee. However, to rely on consent under PIPA, an employer must “reasonably demonstrate that the individual has knowingly consented”.

The difficulty here is that where there is a clear imbalance of power between an employer and employee, as there almost always is, it could be hard for an employer to show that there was knowing consent.

Instead, employers can rely on alternative bases for use of personal information laid out in PIPA, including showing that the “use of the personal information is necessary in the context of the individual’s present, past or potential employment with the organisation”.

While that approach actually makes it easier for the employer to use the personal information of the employee if the employer is able to show that such use was “necessary in the context of” employment, it may carry a higher risk for potential disputes. This is on the basis that what is necessary in the context of employment is in fact sensitive depending on each individual circumstance; thus it is open to an employee to argue that it was not necessary in the context of their employment to use their personal information.

In preparing for the arrival of PIPA, employers should ensure that they have clear policies in place which address the requirements of, and establish measures to ensure compliance with, the legislation.

For example, PIPA requires an employer to “ensure that any personal information used is accurate, relevant and not excessive to the purposes for which it is used”.

As such, measures and policies that address the handling and retention of data, such as data management, data handling and privacy policies, will require careful consideration.

Employers will need to ensure that the purpose for which the use of personal information is retained is clear, as well as making sure that only personal information that is relevant to the purpose is retained for a proportionate and considered period of time.

Clear policies should also be established regarding the disposal of personal information.

Employers should begin to think about these considerations now to ensure that by January 1, 2025, when PIPA comes into full force, they are compliant.

First Published in The Royal Gazette, Legally Speaking column, July 2023

Share
Twitter LinkedIn Email Save as PDF
More Publications
10 Jun 2024

Bankruptcy & Restructuring – Planning for Failure

The sudden collapse of Lehman Brothers in September 2008 sent shockwaves around the globe. As the la...

4 Jun 2024

Bermuda’s cybersecurity law transformation is well underway

We are almost six month into 2024, and this year has already been transformative for IT and cyber se...

23 May 2024

Regulatory oversight is key for Bermuda’s insurance sector

Bermuda’s thriving insurance and reinsurance sector requires effective regulatory oversight if it ...

9 May 2024

It is all about the data

All successful enterprises have a voracious appetite for data. The advanced abilities of IT systems ...

3 May 2024

Best Practices for Conducting Investigations into Employee Grievances

Grievance procedures are very important, but often overlooked, procedures that all employers should ...

25 Apr 2024

Trusts, and how they came to be

What traces its history through Ancient Rome and the Crusades, can have many de facto owners, none a...

8 Apr 2024

Electronic dissemination of corporate communications by Hong Kong listed issuers from an offshore perspective

In June 2023, The Stock Exchange of Hong Kong Limited published consultation conclusions to its cons...

3 Apr 2024

Bermuda: Lack of New Players Is Supporting Strong Interest in ILS

All signs point to another very strong year for the catastrophe bond and related insurance-linked se...

2 Apr 2024

Choosing the right structure for your business in Bermuda

Anyone seeking to set up a business in Bermuda has a variety of options, depending on the nature of ...

25 Mar 2024

PIPA Compliance is Not Just a Domestic Affair

As organizations in Bermuda prepare for the full application of the Personal Information Protection ...