PIPA, which received Royal Assent on July 27, 2016, will come into full effect on January 1, 2025, meaning that the clock has started ticking and employers must begin preparing for its impact.

Personal information is defined under PIPA as “any information about an identified or identifiable individual”.

Sensitive personal information, which is a category of personal information, is defined as “any personal information relating to an individual’s place of origin, race, colour, national or ethnic origin, sex, sexual orientation, sexual life, marital status, physical or mental disability, physical or mental health, family status, religious beliefs, political opinions, trade union membership, biometric information or genetic information”.

In practice, the sort of personal information about employees that an employer is likely to have access to and retain includes financial information, pension information, age, security clearance information, drug test results and health records or medical information.

Such information may be obtained by an employer for many reasons, such as for insurance purposes, work permit submission or workplace diversity and equality monitoring.

Personal information should be collected with consent. Where an employer retains personal information prior to PIPA coming into force, it is deemed to have been collected pursuant to consent being given by that individual.

When an employer wishes to use the personal information of an employee, they may rely on provisions in contracts of employment whereby the employee has consented to such use.

It may seem to an employer that consent is the most obvious and straightforward method by which to establish a lawful basis to use the personal information of an employee. However, to rely on consent under PIPA, an employer must “reasonably demonstrate that the individual has knowingly consented”.

The difficulty here is that where there is a clear imbalance of power between an employer and employee, as there almost always is, it could be hard for an employer to show that there was knowing consent.

Instead, employers can rely on alternative bases for use of personal information laid out in PIPA, including showing that the “use of the personal information is necessary in the context of the individual’s present, past or potential employment with the organisation”.

While that approach actually makes it easier for the employer to use the personal information of the employee if the employer is able to show that such use was “necessary in the context of” employment, it may carry a higher risk for potential disputes. This is on the basis that what is necessary in the context of employment is in fact sensitive depending on each individual circumstance; thus it is open to an employee to argue that it was not necessary in the context of their employment to use their personal information.

In preparing for the arrival of PIPA, employers should ensure that they have clear policies in place which address the requirements of, and establish measures to ensure compliance with, the legislation.

For example, PIPA requires an employer to “ensure that any personal information used is accurate, relevant and not excessive to the purposes for which it is used”.

As such, measures and policies that address the handling and retention of data, such as data management, data handling and privacy policies, will require careful consideration.

Employers will need to ensure that the purpose for which the use of personal information is retained is clear, as well as making sure that only personal information that is relevant to the purpose is retained for a proportionate and considered period of time.

Clear policies should also be established regarding the disposal of personal information.

Employers should begin to think about these considerations now to ensure that by January 1, 2025, when PIPA comes into full force, they are compliant.

First Published in The Royal Gazette, Legally Speaking column, July 2023

Share
Twitter LinkedIn Email Save as PDF
More Publications
21 Feb 2024

Bermuda Privacy Law Compliance: Pitfalls to Avoid

Although members of the Chamber are aware that Bermuda’s Personal Information Protection Act, 2016...

19 Feb 2024

Bermuda: An Introduction to Dispute Resolution in 2024

International business is the primary area of economic activity in Bermuda, as a result of not just ...

15 Feb 2024

Preserving wealth in a Bermuda dynastic trust

The Vanderbilt family gained prominence through shipping and railroad empires and eventually various...

8 Feb 2024

Bermuda’s promising telecommunications future

Last year was a stellar one for Bermuda’s positioning in the global array of telecommunications se...

25 Jan 2024

Fund Finance Laws and Regulations 2024 – Bermuda

The Bermuda fund industry sees investment predominantly from North America and Europe, and therefore...

24 Jan 2024

Chambers Insurance & Reinsurance Guide 2024: Bermuda

This guide provides the latest information on sources of insurance and reinsurance law, overseas-bas...

23 Jan 2024

New Limitations on the Length of Stay for Visitors to Bermuda

In November 2022, The Minister of Economy and Labour, the Hon. Jason Hayward, JP, MP, announced that...

18 Jan 2024

Technology Experience a Must for Board Composition

Corporate governance is an enterprise-wide endeavour that addresses all aspects of an organisation. ...

11 Jan 2024

ILS Steps Up When Needed Most

After a robust 2023 for ILS, five experts in this space debated the changing role ILS is playing in ...

10 Jan 2024

The Global – your offshore corporate law questions answered

The Global is Appleby’s quarterly collection of expert insights and analysis on the latest develop...