PIPA Compliance is Not Just a Domestic Affair

Published: 25 Mar 2024
Type: Insight

As organizations in Bermuda prepare for the full application of the Personal Information Protection Act, 2016 on 1 January 2025 ( PIPA ), they need to keep in mind that PIPA protects the privacy rights of all individuals, regardless of the location of those individuals.


In fact, PIPA has been intentionally designed to protect the privacy rights of individuals from all over the world if their personal information is used in Bermuda. That is because in order for most nations around the world to send personal information to Bermuda for any purpose, Bermuda must have equivalent privacy protection laws to adequately protect the privacy of those individuals, thus establishing Bermuda as a “safe harbor” to receive that personal information from overseas.

Therefore, PIPA is not simply a domestic piece of legislation even though it only applies to the use of personal information in Bermuda. PIPA makes no distinction about the residence, domicile, or geographic location of the individuals that are protected by PIPA. So, if an individual’s personal information is being used in Bermuda, that individual has the right to enforce their rights under PIPA, even if they have to do so remotely from long distances.

There are many reasons and circumstances in which members of the Chamber might collect and use the personal information of foreign individuals in Bermuda.

For example, international visitors to Bermuda might provide their personal information to their hotels, to a retailer, to their vehicle rental agencies, or to various medical service providers here in Bermuda.

Medical records fall into a special category of sensitive personal information under PIPA that can precipitate both more onerous compliance standards as well as an increased potential for financial liability arising from a failure to comply with PIPA. In that regard, medical service providers in Bermuda may maintain a large number of records related to the health and medical treatment of current and past visitors to Bermuda. A breach of PIPA’s standards of safeguard protection by a medical service provider, which causes or contributes to the unauthorized access to, or the wrongful disclosure of, that volume of patient medical records, could result in significant liabilities for that medical service provider; all of which arise from former patients who have no other connection to Bermuda other than the fact that their highly sensitive health information was being maintained in Bermuda.

Also, visitors to Bermuda who seek to establish longer term connections with Bermuda, by opening a bank or investment account, by buying property, by establishing a trust for their family, or even if they are establishing a company or participating in regulated business seeing to be licensed in Bermuda, will likely disclose their personal information for use in Bermuda.

As well, personal information might be provided by persons who are outside of Bermuda to local consulting, accounting or law firms, or to the individual’s employer whose head office is in Bermuda.

Insurance companies operating in Bermuda may have clients who reside outside of Bermuda, and so their personal information associated with administering those policies may be processed in Bermuda. A very common circumstance in the insurance industry, where sensitive personal information of individuals who are resident outside of Bermuda is collected and used in Bermuda, occurs when insurance companies from around the world provide, in the ordinary course of business, comprehensive insurance claims information to their Bermuda reinsurer, in part for the purpose of risk analysis and pricing evaluation.

As most members of the Chamber will appreciate, Bermuda is a jurisdiction that relies very heavily on international business, and so Bermuda’s anti-money laundering and anti-terrorism financing laws associated with “know your customer” requirements demand that a significant amount of personal information about individuals from around the world, much of which may be highly confidential and sensitive, must be collected for evaluation and assessment by both the private and public sectors in Bermuda.

The reality that individuals from around the world, who have no other connection to Bermuda other than the fact that an organization is using their personal information here, can assert their privacy right under PIPA carries some important implications for all organizations who collect and use personal information in Bermuda.

All individuals who have privacy rights under PIPA, even those who live on the other side of the planet and who do not intend to ever visit Bermuda, have a range of rights under PIPA – including the right: to access their personal information; to verify the accuracy, correctness or currency of their personal information; to require corrections to and/or the deletion of that information; to make a complaint about the use of their personal information to the relevant organization; to make such a complaint to Bermuda’s Privacy Commissioner ( including to request to launch an investigation ); to make a claim to the organization for financial compensation under PIPA for any financial loss or emotional distress they may have suffered from a failure of the relevant organization to comply with PIPA; or, to even petition the Privacy Commissioner or the Government to investigate the possible grounds for a regulatory investigation or criminal prosecution under PIPA.

Chamber members must also keep in mind that since Bermuda will so be an international “safe harbour” for the use of personal information, it is likely that any significant breach of PIPA, and any material incidents of unauthorized access to, publication of or use of personal information in Bermuda, may also attract the international attention and scrutiny by both foreign privacy regulators as well as potentially many individuals from around the world who may be adversely affected in those unfortunate circumstances.

Therefore, compliance with PIPA by the Chamber’s members is definitely not just a domestic affair.

First Published in the Bermuda Chamber of Commerce Newsletter (Chamber Insider), April 2024

Share
More publications
Appleby-Website-Privacy-and-Data-Protection
13 Feb 2026

Employee access limits under Pipa

The Personal Information Protection Act 2016 has been in effect for more than a year now, and employers in Bermuda are now fielding requests from their employees to access and review their employment records — all of them.

Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
29 Jan 2026

Navigating estate administration in Bermuda

When a loved one dies, families are often left to navigate not only grief but also a complex legal and administrative process known as estate administration.

Appleby-Website-Insurance-and-Reinsurance
23 Jan 2026

Bermuda: Chambers Insurance & Reinsurance Guide 2026

The guide provides the latest information on sources of insurance and reinsurance law, overseas-based insurers or reinsurers, making an insurance contract, intermediary involvement, alternative risk transfer (ART) transactions, warranties, conditions precedent, insurance disputes and insurtech.

Fund Finance
22 Jan 2026

Fund Finance Laws and Regulations 2026 – Bermuda

The Bermuda fund industry sees investment predominantly from North America and Europe, and therefore trends in the Bermuda fund finance market track the major onshore markets. Although there is no overall data reporting service for the local fund finance market, anecdotal reports from many of the major facility lenders, as well as Appleby practitioners, anticipate that there will continue to be a high demand for capital call or subscription line facilities. That is not to say, of course, that other structures such as NAV facilities will not be utilised.

Appleby-Website-Corporate-Practice
16 Jan 2026

Extracting capital from a Bermuda company

It is widely accepted that one of the main purposes of a business is to create value for its shareholders, who contribute significant capital into entities, hoping that value will be returned to them.

Appleby_preview_Bermuda_1
9 Jan 2026

Bermuda Prohibits Bearer Shares and Nominee Directors

On 21 November 2025, Bermuda passed the Companies (Prohibition of Bearer Shares and Nominee Directors) Amendment Act 2025 (Act). The Act, which came into full force on 10 December 2025, amends both the Companies Act 1981 (Companies Act) and Limited Liability Company Act 2016 (Limited Liability Company Act) in respect of bearer shares, nominee directors, alternate directors and beneficial ownership record keeping for companies and limited liability companies (LLCs) discontinuing to another jurisdiction.

Appleby-Website-Insurance-and-Reinsurance
5 Jan 2026

Cat Bond Issuance Well-Placed to Reach $20bn Again In ‘26, Fueled by Momentum & Proven Success

Annual catastrophe bond issuance hit record heights for the third consecutive year in 2025, and as Brad Adderley, Managing Partner at law firm Appleby’s Bermuda office highlights, given the significant activity and momentum observed in the market, it would not be unexpected for the market to achieve $20 billion once more in 2026

Appleby-Website-Insurance-and-Reinsurance
22 Dec 2025

Collateralised insurers benefit from flexible forms of capital

Bermuda’s well established corporate regulatory regime offers a variety of corporate vehicles that can be used to support insurance-linked securities.

Technology and Innovation
2 Dec 2025

Do cryptocurrencies count as money?

When Satoshi Nakamoto first proposed bitcoin in 2008, he described it as a “peer-to-peer electronic cash system”.

050-Insolvency-Restructuring-Grid-Image
27 Nov 2025

Bermuda: Americas Restructuring Review 2026

This article discusses the defining features of Bermuda’s insolvency landscape and the primary insolvency and rescue procedures available under Bermuda law, including compulsory liquidations, provisional liquidations and schemes of arrangements.