PIPA Compliance is Not Just a Domestic Affair

Published: 25 Mar 2024
Type: Insight

As organizations in Bermuda prepare for the full application of the Personal Information Protection Act, 2016 on 1 January 2025 ( PIPA ), they need to keep in mind that PIPA protects the privacy rights of all individuals, regardless of the location of those individuals.

In fact, PIPA has been intentionally designed to protect the privacy rights of individuals from all over the world if their personal information is used in Bermuda. That is because in order for most nations around the world to send personal information to Bermuda for any purpose, Bermuda must have equivalent privacy protection laws to adequately protect the privacy of those individuals, thus establishing Bermuda as a “safe harbor” to receive that personal information from overseas.

Therefore, PIPA is not simply a domestic piece of legislation even though it only applies to the use of personal information in Bermuda. PIPA makes no distinction about the residence, domicile, or geographic location of the individuals that are protected by PIPA. So, if an individual’s personal information is being used in Bermuda, that individual has the right to enforce their rights under PIPA, even if they have to do so remotely from long distances.

There are many reasons and circumstances in which members of the Chamber might collect and use the personal information of foreign individuals in Bermuda.

For example, international visitors to Bermuda might provide their personal information to their hotels, to a retailer, to their vehicle rental agencies, or to various medical service providers here in Bermuda.

Medical records fall into a special category of sensitive personal information under PIPA that can precipitate both more onerous compliance standards as well as an increased potential for financial liability arising from a failure to comply with PIPA. In that regard, medical service providers in Bermuda may maintain a large number of records related to the health and medical treatment of current and past visitors to Bermuda. A breach of PIPA’s standards of safeguard protection by a medical service provider, which causes or contributes to the unauthorized access to, or the wrongful disclosure of, that volume of patient medical records, could result in significant liabilities for that medical service provider; all of which arise from former patients who have no other connection to Bermuda other than the fact that their highly sensitive health information was being maintained in Bermuda.

Also, visitors to Bermuda who seek to establish longer term connections with Bermuda, by opening a bank or investment account, by buying property, by establishing a trust for their family, or even if they are establishing a company or participating in regulated business seeing to be licensed in Bermuda, will likely disclose their personal information for use in Bermuda.

As well, personal information might be provided by persons who are outside of Bermuda to local consulting, accounting or law firms, or to the individual’s employer whose head office is in Bermuda.

Insurance companies operating in Bermuda may have clients who reside outside of Bermuda, and so their personal information associated with administering those policies may be processed in Bermuda. A very common circumstance in the insurance industry, where sensitive personal information of individuals who are resident outside of Bermuda is collected and used in Bermuda, occurs when insurance companies from around the world provide, in the ordinary course of business, comprehensive insurance claims information to their Bermuda reinsurer, in part for the purpose of risk analysis and pricing evaluation.

As most members of the Chamber will appreciate, Bermuda is a jurisdiction that relies very heavily on international business, and so Bermuda’s anti-money laundering and anti-terrorism financing laws associated with “know your customer” requirements demand that a significant amount of personal information about individuals from around the world, much of which may be highly confidential and sensitive, must be collected for evaluation and assessment by both the private and public sectors in Bermuda.

The reality that individuals from around the world, who have no other connection to Bermuda other than the fact that an organization is using their personal information here, can assert their privacy right under PIPA carries some important implications for all organizations who collect and use personal information in Bermuda.

All individuals who have privacy rights under PIPA, even those who live on the other side of the planet and who do not intend to ever visit Bermuda, have a range of rights under PIPA – including the right: to access their personal information; to verify the accuracy, correctness or currency of their personal information; to require corrections to and/or the deletion of that information; to make a complaint about the use of their personal information to the relevant organization; to make such a complaint to Bermuda’s Privacy Commissioner ( including to request to launch an investigation ); to make a claim to the organization for financial compensation under PIPA for any financial loss or emotional distress they may have suffered from a failure of the relevant organization to comply with PIPA; or, to even petition the Privacy Commissioner or the Government to investigate the possible grounds for a regulatory investigation or criminal prosecution under PIPA.

Chamber members must also keep in mind that since Bermuda will so be an international “safe harbour” for the use of personal information, it is likely that any significant breach of PIPA, and any material incidents of unauthorized access to, publication of or use of personal information in Bermuda, may also attract the international attention and scrutiny by both foreign privacy regulators as well as potentially many individuals from around the world who may be adversely affected in those unfortunate circumstances.

Therefore, compliance with PIPA by the Chamber’s members is definitely not just a domestic affair.

First Published in the Bermuda Chamber of Commerce Newsletter (Chamber Insider), April 2024

Share
More publications
Appleby-Website-Insurance-and-Reinsurance
1 Apr 2026

Q1’26 Suggests Cat Bond Issuance Could Reach $20bn Again, Private ILS & Sidecar Surge to Continue

It’s been an exceptionally busy start to the year for the catastrophe bond sector, with Q1’26 officially becoming the second highest Q1 on record in terms of total catastrophe bond issuance, which indicates that 2026 could end up reaching the $20 billion+ milestone once again, Brad Adderley, Managing Partner at law firm Appleby has said.

Trust Disputes
27 Mar 2026

Privy Council decision in X Trusts – redefining the role of the protector

On 19 March 2026, the Judicial Committee of the Privy Council (JCPC) delivered its long-awaited judgment regarding the role of a fiduciary protector in the administration of a trust (A and 6 others (Appellants) v C and 13 others (Respondents) [2026] UKPC 11, on appeal from the Court of Appeal of Bermuda). The decision of the JCPC was unanimous, with the judgment being given by Lords Briggs and Richards.

Appleby-Website-Insurance-and-Reinsurance
26 Mar 2026

Latin American risks and the Bermuda market

Bermuda’s decades-long efforts to welcome Latin American risks to the island’s re/insurance market have borne fruit in the form of the many LatAm captive insurers that have become domiciled here.

Appleby-Website-Insurance-and-Reinsurance
24 Mar 2026

Navigating Bermuda’s New Recovery Planning Requirements: A Roadmap for Commercial Insurers

On 20 March 2026, the Bermuda Monetary Authority (BMA) issued an updated Guidance Note for Recovery Planning Requirements (Guidance Note). The Guidance Note assists Bermuda commercial insurers’ compliance with the obligations set out in the Insurance (Prudential Standards) (Recovery Plan) Rules 2024 (Rules), which became operative on 1 May 2025.

Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
13 Mar 2026

A will trust can keep a home in the family

In Bermuda, a family homestead represents more than financial value; it embodies ancestral heritage and housing security.

Appleby-Website-Employment-and-Immigration
12 Mar 2026

Privacy at Work: What PIPA Means for Bermuda Employers

The Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2025, represents Bermuda’s first comprehensive date protection regime. The legislation regulates the collection, use, disclosure and storage of personal information with the objective of protecting individuals’ privacy while allowing organisations to use data in a responsible and transparent manner. PIPA applies broadly to organisations operating in Bermuda, including employers. As a result, the employment relationship is one of the contexts in which the practical impact of PIPA is the most significant. Employers routinely process large volumes of personal information relating to employees and job applicants, and PIPA imposes obligations that affect recruitment, workplace monitoring, record-keeping, and disciplinary processes.

IWD website preview
9 Mar 2026

International Women’s Day 2026 Roundtable: Rights. Justice. Action. For all women and girls.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a vision – it’s a call to action.

Dispute Resolution
4 Mar 2026

Bermuda: An Overview of Insurance: Contentious

There has been a recent increase in policyholder disputes involving coverage challenges by (re)insurers in the context of Bermuda high-value, excess-of-loss policies. This is, in part, due to Bermuda’s commercial (re)insurers facing a marked and sustained rise in the volume of claims, incurring claims costs globally of BMD1.1 trillion from 2016 through 2024. The massive volume and quantum of claims can be attributed in part to the significance of the Bermuda (re)insurance market in the global economy, as well as Bermuda’s exposure to catastrophic losses caused by natural disasters over this period. Bermuda’s increased exposure to global (re)insurance risks has naturally resulted in an increase in complex claims and coverage disputes.

Employment-and-Immigration
27 Feb 2026

Pay transparency heading Bermuda’s way?

The culture of secrecy with respect to pay traditionally found in workplaces may soon experience a shift, as global lawmakers and governments have enacted or moved toward enacting legislation to mandate greater pay transparency.

Appleby-Website-Insurance-and-Reinsurance
27 Feb 2026

Bermuda Monetary Authority: Modern, Thoughtful and Competitive

The Bermuda Monetary Authority (BMA) has signaled a clear direction for the future of insurance supervision in Bermuda by the release of its latest Notice on Regulatory Burden Reduction for Better Policyholder Outcomes (Notice).