PIPA Compliance is Not Just a Domestic Affair

Published: 25 Mar 2024
Type: Insight

As organizations in Bermuda prepare for the full application of the Personal Information Protection Act, 2016 on 1 January 2025 ( PIPA ), they need to keep in mind that PIPA protects the privacy rights of all individuals, regardless of the location of those individuals.


In fact, PIPA has been intentionally designed to protect the privacy rights of individuals from all over the world if their personal information is used in Bermuda. That is because in order for most nations around the world to send personal information to Bermuda for any purpose, Bermuda must have equivalent privacy protection laws to adequately protect the privacy of those individuals, thus establishing Bermuda as a “safe harbor” to receive that personal information from overseas.

Therefore, PIPA is not simply a domestic piece of legislation even though it only applies to the use of personal information in Bermuda. PIPA makes no distinction about the residence, domicile, or geographic location of the individuals that are protected by PIPA. So, if an individual’s personal information is being used in Bermuda, that individual has the right to enforce their rights under PIPA, even if they have to do so remotely from long distances.

There are many reasons and circumstances in which members of the Chamber might collect and use the personal information of foreign individuals in Bermuda.

For example, international visitors to Bermuda might provide their personal information to their hotels, to a retailer, to their vehicle rental agencies, or to various medical service providers here in Bermuda.

Medical records fall into a special category of sensitive personal information under PIPA that can precipitate both more onerous compliance standards as well as an increased potential for financial liability arising from a failure to comply with PIPA. In that regard, medical service providers in Bermuda may maintain a large number of records related to the health and medical treatment of current and past visitors to Bermuda. A breach of PIPA’s standards of safeguard protection by a medical service provider, which causes or contributes to the unauthorized access to, or the wrongful disclosure of, that volume of patient medical records, could result in significant liabilities for that medical service provider; all of which arise from former patients who have no other connection to Bermuda other than the fact that their highly sensitive health information was being maintained in Bermuda.

Also, visitors to Bermuda who seek to establish longer term connections with Bermuda, by opening a bank or investment account, by buying property, by establishing a trust for their family, or even if they are establishing a company or participating in regulated business seeing to be licensed in Bermuda, will likely disclose their personal information for use in Bermuda.

As well, personal information might be provided by persons who are outside of Bermuda to local consulting, accounting or law firms, or to the individual’s employer whose head office is in Bermuda.

Insurance companies operating in Bermuda may have clients who reside outside of Bermuda, and so their personal information associated with administering those policies may be processed in Bermuda. A very common circumstance in the insurance industry, where sensitive personal information of individuals who are resident outside of Bermuda is collected and used in Bermuda, occurs when insurance companies from around the world provide, in the ordinary course of business, comprehensive insurance claims information to their Bermuda reinsurer, in part for the purpose of risk analysis and pricing evaluation.

As most members of the Chamber will appreciate, Bermuda is a jurisdiction that relies very heavily on international business, and so Bermuda’s anti-money laundering and anti-terrorism financing laws associated with “know your customer” requirements demand that a significant amount of personal information about individuals from around the world, much of which may be highly confidential and sensitive, must be collected for evaluation and assessment by both the private and public sectors in Bermuda.

The reality that individuals from around the world, who have no other connection to Bermuda other than the fact that an organization is using their personal information here, can assert their privacy right under PIPA carries some important implications for all organizations who collect and use personal information in Bermuda.

All individuals who have privacy rights under PIPA, even those who live on the other side of the planet and who do not intend to ever visit Bermuda, have a range of rights under PIPA – including the right: to access their personal information; to verify the accuracy, correctness or currency of their personal information; to require corrections to and/or the deletion of that information; to make a complaint about the use of their personal information to the relevant organization; to make such a complaint to Bermuda’s Privacy Commissioner ( including to request to launch an investigation ); to make a claim to the organization for financial compensation under PIPA for any financial loss or emotional distress they may have suffered from a failure of the relevant organization to comply with PIPA; or, to even petition the Privacy Commissioner or the Government to investigate the possible grounds for a regulatory investigation or criminal prosecution under PIPA.

Chamber members must also keep in mind that since Bermuda will so be an international “safe harbour” for the use of personal information, it is likely that any significant breach of PIPA, and any material incidents of unauthorized access to, publication of or use of personal information in Bermuda, may also attract the international attention and scrutiny by both foreign privacy regulators as well as potentially many individuals from around the world who may be adversely affected in those unfortunate circumstances.

Therefore, compliance with PIPA by the Chamber’s members is definitely not just a domestic affair.

First Published in the Bermuda Chamber of Commerce Newsletter (Chamber Insider), April 2024

Share
More publications
IWD website preview
9 Mar 2026

International Women’s Day 2026 Roundtable: Rights. Justice. Action. For all women and girls.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a vision – it’s a call to action.

Dispute Resolution
4 Mar 2026

Bermuda: An Overview of Insurance: Contentious

There has been a recent increase in policyholder disputes involving coverage challenges by (re)insurers in the context of Bermuda high-value, excess-of-loss policies. This is, in part, due to Bermuda’s commercial (re)insurers facing a marked and sustained rise in the volume of claims, incurring claims costs globally of BMD1.1 trillion from 2016 through 2024. The massive volume and quantum of claims can be attributed in part to the significance of the Bermuda (re)insurance market in the global economy, as well as Bermuda’s exposure to catastrophic losses caused by natural disasters over this period. Bermuda’s increased exposure to global (re)insurance risks has naturally resulted in an increase in complex claims and coverage disputes.

Employment-and-Immigration
27 Feb 2026

Pay transparency heading Bermuda’s way?

The culture of secrecy with respect to pay traditionally found in workplaces may soon experience a shift, as global lawmakers and governments have enacted or moved toward enacting legislation to mandate greater pay transparency.

Appleby-Website-Insurance-and-Reinsurance
27 Feb 2026

Bermuda Monetary Authority: Modern, Thoughtful and Competitive

The Bermuda Monetary Authority (BMA) has signaled a clear direction for the future of insurance supervision in Bermuda by the release of its latest Notice on Regulatory Burden Reduction for Better Policyholder Outcomes (Notice).

Appleby-Website-Banking-and-Asset-Finance-1905px-x-1400px
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Banking

Bermuda is not considered an international banking center and only banks licensed by the Bermuda Monetary Authority (BMA) under the Banks and Deposit Companies Act 1999 (BDCA) are entitled to undertake banking businesses in or from Bermuda. As banking is defined as deposit taking (as opposed to lending), international banks are generally able to lend to Bermuda-based borrowers subject to applicable restrictions relating to carrying on business in Bermuda.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Captives)

Bermuda is one of the leading captive insurance markets in the world with over 600 registered captive insurers writing an impressive ~$30 billion of annual gross written premiums.

Appleby-Website-Corporate-Practice
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – General Corporate

The Bermuda Monetary Authority (BMA), an independent body that has been in existence since 1969, is an integrated regulator and supervisor responsible for the licensing, supervision and regulation of financial institutions in Bermuda. The BMA’s mandate includes entities conducting insurance, deposit taking, investment and trust business. The BMA conducts risk-based supervision and enforcement, including enforcing anti-money laundering and counter-terrorist financing standards. The BMA sets prudential rules, issues codes of conduct and devises industry guidance to ensure the jurisdiction adheres to international standards.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Commercial)

The Bermuda Monetary Authority’s (BMA) 2026 Business Plan (Plan) outlines continued strengthening of Bermuda’s position as a leading global insurance and reinsurance jurisdiction.

Technology-and-Innovation-1024x576
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – FinTech

By any serious measure, Bermuda’s FinTech strategy for 2026 is not incremental. It is deliberate. It is disciplined. And it is designed to position Bermuda not as a follower in digital finance — but as a standard-setter.

Appleby-Website-Regulatory-Practice
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Regulatory

Bermuda operates a highly integrated regulatory architecture under which the Bermuda Monetary Authority (BMA) exercises consolidated oversight across insurance, banking, investment business and funds, trusts, corporate service providers, money services and digital asset activity. While the statutory framework has long been risk-based, the previous five years marks a clear evolution in supervisory practices. The BMA moved decisively beyond technical compliance and periodic reporting toward an emphasis on supervisory judgement, governance outcomes and system-wide resilience.