PIPA Guidance on Financial Services (Bermuda)

Published: 20 Mar 2025
Type: Insight

This month, the Privacy Commissioner of Bermuda released his Financial Services Guidance Notes: Final Report.


After seeking, and receiving, input from the financial services sector last year, and issuing a draft report last September, Alexander White’s report is a comprehensive 52-page review of his views about how the Personal Information Privacy Act applies to the financial services sector.

Although the report confirms that the views expressed are not legally binding, that he is not bound by the report’s guidance, nor does the report set out his final or definitive position on any particular matter, it nevertheless provides a well considered and thoughtful review of the key questions that financial service providers have raised in the months leading up to, and since, PIPA’s full implementation on January 1.

An important context of the report, and why Commissioner White’s guidance is so welcome, is that Bermuda’s financial services are highly reliant on technology to capture, process and analyse data — so much of which includes personal information.

A controversy about PIPA’s interpretation that the report arguably settles is its guidance that all organisations — including holding companies and captives — that collect and disclose personal information about their directors, officers and ultimate owners for AML/ATF and other legally required determinations are subject to PIPA because such activities, even if performed by third parties on their behalf, constitute that organisation’s “use” of personal information in Bermuda.

That welcome clarification is best expressed in the report with the explanation that where “…an ‘organisation uses’ or is ‘using’ personal information under PIPA, Section 5(3) of PIPA states that the responsibility for compliance with PIPA is an ongoing regulatory compliance obligation for the captive insurer or holding company, irrespective of any third-party appointment”.

Another important controversy that the report addresses is whether the actual role of an organisation’s privacy officer can be outsourced to an unrelated third party.

The nuanced considerations offered by the Privacy Commissioner on that topic are important and must be considered in their totality.

However, Commissioner White suggests that there may be some circumstances where an organisation can “… elect to appoint a third-party [service provider] to act as [the organisation’s] privacy officer” and “smaller organisations may consider the value of obtaining the services of a corporate service provider capable of acting as their privacy officer”.

Bermuda’s financial services sector will also welcome the Privacy Commissioner’s guidance that an organisation’s ability to rely on PIPA’s qualified national security, regulatory activity and general exemptions is not limited to the public sector, and that circumstances may exist for the private sector to rely on those exemptions to “effectively fall outside the remit of PIPA”.

PIPA provides several grounds of allowance to permit an organisation to export personal information from Bermuda to an overseas third party. The legislation’s various grounds for export allowance primarily rest, in different ways, on whether the recipient jurisdiction provides comparable protections to PIPA.

Comparable PIPA protection may be achieved under PIPA by virtue of: the exporter’s assessment of such comparability — for the US, that will include federal and state law assessments — or if the governing export (services) agreement provides comparable protections; or if there are binding corporate codes of conduct that apply to the overseas recipient; or if the minister responsible designates that jurisdiction as providing a comparable level of protection.

Even though the minister has not yet designated any jurisdiction as providing “adequate protection”, the report states that all such comparability determinations must still be followed by a process of evaluating the business practices of the recipient to assess any PIPA noncompliance risk.

In that regard, the Privacy Commissioner’s guidance is highly instructive: “For the avoidance of doubt, a formal designation by the minister declaring that a jurisdiction’s law is ‘comparable’ to PIPA … would address only one element of Section 15: … the organisation should proceed to evaluating the business practices of the recipient.

“Whether or not an organisation concludes that the jurisdiction of an overseas third party provides a comparable level of data privacy protection, the organisation … must still assess the overseas third party’s organisational, administrative and technical processes and internal safeguards in order to determine that the overseas third party’s operational practices are secure and effectively provide a level of protection that satisfies the organisation’s obligations under PIPA.”

At more than 22,000 words, the report serves as much welcome guidance that makes a complex regime of data protection and privacy compliance much more accessible to organisations and individuals alike.

Commissioner White’s self-described proactive “listen, learn and engage” approach is destined to result in an improved awareness and understanding of PIPA for all organisations in Bermuda.

First Published in The Royal Gazette, Legally Speaking column, March 2025

Share
More publications
Appleby-Website-Employment-and-Immigration
12 Mar 2026

Privacy at Work: What PIPA Means for Bermuda Employers

The Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2025, represents Bermuda’s first comprehensive date protection regime. The legislation regulates the collection, use, disclosure and storage of personal information with the objective of protecting individuals’ privacy while allowing organisations to use data in a responsible and transparent manner. PIPA applies broadly to organisations operating in Bermuda, including employers. As a result, the employment relationship is one of the contexts in which the practical impact of PIPA is the most significant. Employers routinely process large volumes of personal information relating to employees and job applicants, and PIPA imposes obligations that affect recruitment, workplace monitoring, record-keeping, and disciplinary processes.

IWD website preview
9 Mar 2026

International Women’s Day 2026 Roundtable: Rights. Justice. Action. For all women and girls.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a vision – it’s a call to action.

Dispute Resolution
4 Mar 2026

Bermuda: An Overview of Insurance: Contentious

There has been a recent increase in policyholder disputes involving coverage challenges by (re)insurers in the context of Bermuda high-value, excess-of-loss policies. This is, in part, due to Bermuda’s commercial (re)insurers facing a marked and sustained rise in the volume of claims, incurring claims costs globally of BMD1.1 trillion from 2016 through 2024. The massive volume and quantum of claims can be attributed in part to the significance of the Bermuda (re)insurance market in the global economy, as well as Bermuda’s exposure to catastrophic losses caused by natural disasters over this period. Bermuda’s increased exposure to global (re)insurance risks has naturally resulted in an increase in complex claims and coverage disputes.

Employment-and-Immigration
27 Feb 2026

Pay transparency heading Bermuda’s way?

The culture of secrecy with respect to pay traditionally found in workplaces may soon experience a shift, as global lawmakers and governments have enacted or moved toward enacting legislation to mandate greater pay transparency.

Appleby-Website-Insurance-and-Reinsurance
27 Feb 2026

Bermuda Monetary Authority: Modern, Thoughtful and Competitive

The Bermuda Monetary Authority (BMA) has signaled a clear direction for the future of insurance supervision in Bermuda by the release of its latest Notice on Regulatory Burden Reduction for Better Policyholder Outcomes (Notice).

Appleby-Website-Banking-and-Asset-Finance-1905px-x-1400px
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Banking

Bermuda is not considered an international banking center and only banks licensed by the Bermuda Monetary Authority (BMA) under the Banks and Deposit Companies Act 1999 (BDCA) are entitled to undertake banking businesses in or from Bermuda. As banking is defined as deposit taking (as opposed to lending), international banks are generally able to lend to Bermuda-based borrowers subject to applicable restrictions relating to carrying on business in Bermuda.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Captives)

Bermuda is one of the leading captive insurance markets in the world with over 600 registered captive insurers writing an impressive ~$30 billion of annual gross written premiums.

Appleby-Website-Corporate-Practice
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – General Corporate

The Bermuda Monetary Authority (BMA), an independent body that has been in existence since 1969, is an integrated regulator and supervisor responsible for the licensing, supervision and regulation of financial institutions in Bermuda. The BMA’s mandate includes entities conducting insurance, deposit taking, investment and trust business. The BMA conducts risk-based supervision and enforcement, including enforcing anti-money laundering and counter-terrorist financing standards. The BMA sets prudential rules, issues codes of conduct and devises industry guidance to ensure the jurisdiction adheres to international standards.

Appleby-Website-Insurance-and-Reinsurance
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – Insurance (Commercial)

The Bermuda Monetary Authority’s (BMA) 2026 Business Plan (Plan) outlines continued strengthening of Bermuda’s position as a leading global insurance and reinsurance jurisdiction.

Technology-and-Innovation-1024x576
19 Feb 2026

Bermuda Monetary Authority 2026 Business Plan: Overview & Expertise – FinTech

By any serious measure, Bermuda’s FinTech strategy for 2026 is not incremental. It is deliberate. It is disciplined. And it is designed to position Bermuda not as a follower in digital finance — but as a standard-setter.