Transparency is a legal requirement under Pipa

Published: 26 May 2026
Type: Insight

Major companies across the European Union have faced substantial fines between 2019 and 2024, estimated at a total of €930 million (about $1.08 billion), not only for cyberattacks or data breaches, but also for issues such as noncompliant privacy notices. A common theme in many cases has been a lack of transparency.


With the Personal Information Protection Act 2016 becoming fully effective on January 1, 2025, transparency has transitioned from a best practice to a legal requirement for organisations using personal information in Bermuda.

At the heart of this transparency are privacy notices. Under section nine of Pipa, a “Privacy Notice” is a clear and easily accessible statement about an organisation’s practices and policies with respect to personal information. It should be provided before or at the time personal information is collected, and include the mandatory disclosures set out in section nine in order to ensure full compliance.

Simply put, it is a document designed to inform individuals about how their personal information is being used.

A compliant privacy notice will include six elements:

  • A clear statement that personal information is being used
  • The purposes for which personal information might be used
  • The identity and types of individuals or organisations personal information may be shared with
  • The identity and location of the organisation
  • The contact details of the privacy officer
  • The ways in which an organisation offers individuals to limit the use of and for accessing, correcting, blocking, erasing or destroying their information

There are two scenarios where a privacy notice is not required.

First, where personal information held by an organisation is already publicly available. For example, information shared in a newspaper article.

Second, where use of the personal information is within the reasonable expectations of the individual.

When determining whether your privacy notice is compliant, it is important to distinguish between the EU’s General Data Protection Regulation and Pipa. Both provide a framework of rights and duties designed to give individuals greater control over their personal information.

However, although the compliance frameworks of the GDPR and Pipa are substantially aligned in principle, Pipa introduces distinct jurisdictional nuances, including some specific, stricter requirements.

Organisations should recognise that, while it is important to align data protection standards across their overseas companies, they should be cautious of the “global policy” adoption trap. A unified framework provides a strong foundation but cannot override the statutory requirements unique to Pipa.

Although the terms “policy” and “notice” are frequently used interchangeably, Pipa distinguishes between transparency obligations, which are addressed through a privacy Notice, and internal governance requirements, which are typically addressed through policies and procedures.

The primary audience for privacy notices is the general public whom an organisation may collect personal information from. For example, organisations operating online must provide a privacy notice informing users of data collection during their visit, particularly when users voluntarily submit details for account creation or newsletters.

Privacy policies are internal documents designed for employees, that serve as an organisation’s “suitable measures policy” to give effect to its obligations and the rights of individuals, as set out under section five of Pipa. These measures and policies should be designed to consider the nature, scope, context, purpose, and risk of the organisation’s information use.

Privacy policies require a more tailored approach than privacy notices.

The Privacy Commission’s Guide to Pipa states that internal privacy policies should include:

  • Data mapping and inventory
  • Documenting personal information use practices
  • Staff training and awareness
  • Security safeguards
  • Breach/incident response plan
  • Response to access requests

In a future column, I will dive into the details of the implications of a noncompliant privacy notice.

First Published in The Royal Gazette, Legally Speaking column, May 2026

Share
More publications
Appleby-Website-Insurance-and-Reinsurance
8 May 2026

Outsourcing considerations for Bermuda insurers

As Bermuda insurers engage with third-party service providers to support their business functions, the Bermuda Monetary Authority has clarified its regulatory expectations surrounding outsourcing arrangements and operational resilience.

Economic Substance
27 Apr 2026

Economic substance regime now falls under Cita

Recent amendments to Bermuda’s economic substance regime have transferred regulatory responsibility from the Registrar of Companies to the Corporate Income Tax Agency.

Appleby-Website-Private-Client-and-Trusts-Practice
22 Apr 2026

Regulation, Regulation, Regulation

The article discusses updates to global trust guidance and regulation, as well as beneficial ownership and the regulatory burden on trustees that comes with increased transparency.

Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
15 Apr 2026

Purpose trusts: Bermuda’s answer to modern asset structuring

Purpose trusts represent a notable development in modern trust law, particularly within offshore financial jurisdictions such as Bermuda. Unlike traditional private trusts, which are established for the benefit of identifiable beneficiaries, purpose trusts are created to achieve specific objectives or purposes. Historically, common law jurisdictions were reluctant to recognise such arrangements due to the absence of beneficiaries capable of enforcing the trust. However, legislative reforms in Bermuda have significantly expanded the scope of trust law by expressly validating noncharitable purpose trusts. Through the enactment of the Trusts (Special Provisions) Act 1989 (‘the 1989 Act’), Bermuda introduced a statutory framework that allows trusts to exist for defined purposes, provided certain legal requirements are satisfied. This innovation has made Bermuda a leading jurisdiction for the establishment of purpose trusts, particularly in the fields of international finance, corporate structuring and private wealth management. This article examines the legal foundations of purpose trusts under Bermuda law, focusing on their historical development, statutory framework, requirements for validity, enforcement mechanisms and practical applications.

Website-Code-Bermuda-1
10 Apr 2026

Bermuda Regulatory Update – Economic Substance Amendment Act 2026

On 31 March 2026, the Economic Substance Amendment Act 2026 and the Economic Substance Amendment Regulations 2026 (together, the “2026 Amendments”) came into force, enacting changes to the Economic Substance Act 2018 (“ES Act”) and Economic Substance Regulations 2018.

ICLG Fintech 21 cover
10 Apr 2026

Digital asset developments and Bermuda’s regulatory readiness

While frightening to some, “finance bros” and “tech bros” are now wearing the same gilets as traditional finance products and structures are being infused with digital asset adaptation.

Appleby-Website-Insurance-and-Reinsurance
1 Apr 2026

Q1’26 Suggests Cat Bond Issuance Could Reach $20bn Again, Private ILS & Sidecar Surge to Continue

It’s been an exceptionally busy start to the year for the catastrophe bond sector, with Q1’26 officially becoming the second highest Q1 on record in terms of total catastrophe bond issuance, which indicates that 2026 could end up reaching the $20 billion+ milestone once again, Brad Adderley, Managing Partner at law firm Appleby has said.

Trust Disputes
27 Mar 2026

Privy Council decision in X Trusts – redefining the role of the protector

On 19 March 2026, the Judicial Committee of the Privy Council (JCPC) delivered its long-awaited judgment regarding the role of a fiduciary protector in the administration of a trust (A and 6 others (Appellants) v C and 13 others (Respondents) [2026] UKPC 11, on appeal from the Court of Appeal of Bermuda). The decision of the JCPC was unanimous, with the judgment being given by Lords Briggs and Richards.

Appleby-Website-Insurance-and-Reinsurance
26 Mar 2026

Latin American risks and the Bermuda market

Bermuda’s decades-long efforts to welcome Latin American risks to the island’s re/insurance market have borne fruit in the form of the many LatAm captive insurers that have become domiciled here.