Skip to content

Evidence request lists

Bermuda Personal Information Protection Act 2016 (PIPA)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Bermuda PIPA Part 1: Preliminary

BM-PIPA-3
Application

Application. Section 3 sets out the organisations and processing to which the Act applies (organisations that use personal information in Bermuda, in whole or in part by automated means or held in a structured filing system).

Artefacts an auditor will ask for
  • Determination that the organisation uses personal information and is in scope
  • Records of personal information held and processing performed
Where this commonly fails
  • Processing wrongly scoped out
  • Structured manual records overlooked
BM-PIPA-4
Exclusions

Exclusions. Section 4 sets out the matters excluded from the Act (for example personal or domestic use, and certain other excluded processing).

Artefacts an auditor will ask for
  • Analysis of any exclusion relied upon and its basis
  • Documentation that excluded processing is genuinely out of scope
Where this commonly fails
  • Exclusion claimed without basis
  • Excluded and in-scope processing not separated

Bermuda PIPA Part 2: General Principles and Rules

BM-PIPA-10
Purpose limitation

Purpose limitation. Section 10 requires that personal information only be used for the purposes for which it was collected (or a compatible purpose), unless a permitted exception applies.

Artefacts an auditor will ask for
  • Documented purposes for which personal information is collected
  • Assessment of compatibility for any new use
  • Controls preventing unauthorised secondary use
Where this commonly fails
  • Secondary use without a compatible purpose or exception
  • Purposes not documented
  • Purpose creep
BM-PIPA-11
Proportionality

Proportionality. Section 11 requires that the personal information used be adequate, relevant and not excessive in relation to the purposes (data minimisation).

Artefacts an auditor will ask for
  • Assessment that data collected is adequate, relevant and not excessive
  • Minimisation controls at collection
  • Periodic review of data holdings
Where this commonly fails
  • Excessive data collected
  • No minimisation assessment
  • Data retained beyond need
BM-PIPA-12
Integrity of personal information

Integrity of personal information. Section 12 requires personal information to be accurate and, where necessary, kept up to date, and retained only as long as necessary for the purposes.

Artefacts an auditor will ask for
  • Accuracy and update processes
  • Retention schedule and disposal records
  • Evidence data is not kept longer than necessary
Where this commonly fails
  • Inaccurate or outdated data
  • No retention schedule
  • Data retained indefinitely
BM-PIPA-13
Security safeguards

Security safeguards. Section 13 requires organisations to protect personal information with appropriate safeguards against loss, unauthorised access, destruction, use, modification or disclosure, proportionate to the risk.

Artefacts an auditor will ask for
  • Technical and organisational security safeguards proportionate to risk
  • Access controls, encryption and monitoring as appropriate
  • Security oversight of third parties handling the data
Where this commonly fails
  • Safeguards not proportionate to risk
  • No access controls
  • Third-party security not assured
BM-PIPA-14
Breach of security

Breach of security. Section 14 requires organisations to notify the Commissioner (and affected individuals where required) without undue delay of a breach of security that is likely to adversely affect an individual.

Artefacts an auditor will ask for
  • Breach response procedure with assessment and notification timelines
  • Records of breach notifications to the Commissioner and affected individuals
  • Breach register
Where this commonly fails
  • Reportable breaches not notified to the Commissioner
  • No breach assessment process
  • Affected individuals not notified where required
BM-PIPA-15
Transfer of personal information to an overseas third party

Overseas transfers. Section 15 requires that, before transferring personal information to an overseas third party, the organisation employ appropriate measures to ensure the information receives comparable protection.

Artefacts an auditor will ask for
  • Inventory of overseas transfers and recipients
  • Comparable-protection measures (contracts, due diligence) for each transfer
  • Assessment that the transferee provides adequate protection
Where this commonly fails
  • Overseas transfers without comparable-protection measures
  • Transfers not inventoried
  • No assessment of the recipient
BM-PIPA-16
Personal information about children in the information society

Children's information. Section 16 imposes specific requirements on the use of personal information about children in the context of information society services.

Artefacts an auditor will ask for
  • Identification of services likely to be used by children
  • Age-appropriate consent/verification measures
  • Enhanced protections for children's information
Where this commonly fails
  • Children's data handled without s16 measures
  • No age verification where required
  • Notices not child-appropriate
BM-PIPA-5
Responsibility and compliance

Responsibility and compliance. Section 5 requires every organisation to adopt suitable measures and policies to give effect to its obligations, remain responsible for personal information transferred to others, and designate a representative (privacy officer) for compliance (s5(4)).

Artefacts an auditor will ask for
  • Privacy programme: suitable measures and policies giving effect to PIPA
  • Privacy officer appointment record and responsibilities (s5(4))
  • Evidence the organisation remains responsible for information it transfers to others
Where this commonly fails
  • No privacy officer designated
  • No documented measures/policies
  • Responsibility for transferred data not retained
BM-PIPA-6
Conditions for using personal information

Conditions for using personal information. Section 6 sets out the lawful conditions (including consent and other permitted grounds) under which an organisation may use personal information.

Artefacts an auditor will ask for
  • Record of the lawful condition relied on for each use of personal information
  • Consent records where consent is the basis
  • Assessment of permitted non-consent grounds
Where this commonly fails
  • Use without a valid condition under s6
  • Consent not demonstrable
  • Reliance on a ground that does not apply
BM-PIPA-7
Sensitive personal information

Sensitive personal information. Section 7 imposes additional conditions on the use of sensitive personal information (including the categories defined in the Act such as genetic, biometric, health, racial, and other sensitive data).

Artefacts an auditor will ask for
  • Identification of sensitive personal information held
  • Additional lawful condition for sensitive-data use under s7
  • Enhanced safeguards for sensitive data
Where this commonly fails
  • Sensitive data used without an s7 condition
  • Sensitive categories not identified
  • No enhanced safeguards
BM-PIPA-8
Fairness

Fairness. Section 8 requires that personal information be used in a manner that a reasonable person would consider fair in the circumstances.

Artefacts an auditor will ask for
  • Assessment that uses of personal information are fair in the circumstances
  • Avoidance of deceptive or misleading collection/use
Where this commonly fails
  • Uses not assessed for fairness
  • Deceptive collection practices
BM-PIPA-9
Privacy notices

Privacy notices. Section 9 requires organisations to provide a clear and accessible privacy notice describing their practices and policies with respect to personal information.

Artefacts an auditor will ask for
  • Published privacy notice(s) covering the matters required by s9
  • Process to keep notices current
  • Accessibility of notices to individuals
Where this commonly fails
  • No privacy notice or incomplete content
  • Notice not updated
  • Notice not accessible

Bermuda PIPA Part 3: Rights of Individuals

BM-PIPA-17
Access to personal information

Right of access. Section 17 gives individuals the right to request access to their personal information held by an organisation and information about its use.

Artefacts an auditor will ask for
  • Procedure for handling access requests within statutory timeframes
  • Records of access requests and responses
  • Identity verification for requesters
Where this commonly fails
  • Access requests not handled in time
  • No request procedure
  • Identity not verified
BM-PIPA-18
Access to medical records

Access to medical records. Section 18 sets out the specific procedure and safeguards for requests for access to medical records.

Artefacts an auditor will ask for
  • Procedure for medical-record access requests, including any medical-practitioner involvement required
  • Records of medical-record access requests and outcomes
Where this commonly fails
  • Medical-record requests handled like ordinary access without s18 safeguards
  • No practitioner consultation where required
BM-PIPA-19
Rectification, blocking, erasure and destruction

Rectification, blocking, erasure and destruction. Section 19 gives individuals the right to request rectification, blocking, erasure or destruction of their personal information in defined circumstances.

Artefacts an auditor will ask for
  • Procedure for rectification/blocking/erasure/destruction requests
  • Records of such requests and actions taken
  • Propagation of corrections to third parties where required
Where this commonly fails
  • Requests not actioned
  • No procedure
  • Corrections not propagated
BM-PIPA-20
Procedure for making a request

Procedure for requests. Section 20 sets out the procedure for making a request under sections 17, 18 or 19, including timeframes and any fees.

Artefacts an auditor will ask for
  • Documented request procedure aligned to s20 (timeframes, fees, form)
  • Logs evidencing adherence to the statutory procedure
Where this commonly fails
  • Procedure not aligned to s20
  • Statutory timeframes missed
  • Improper fees charged
BM-PIPA-21
Compensation for financial loss or distress

Compensation. Section 21 provides individuals a right to compensation for financial loss or distress caused by a contravention of the Act.

Artefacts an auditor will ask for
  • Awareness of compensation exposure under s21
  • Complaint/claim handling records
  • Legal review of contraventions giving rise to compensation
Where this commonly fails
  • Compensation exposure not assessed
  • Claims not handled
  • Contraventions not remediated

Bermuda PIPA Part 4: Exemptions

BM-PIPA-22
Exemptions

Exemptions. Sections 22 to 25 set out exemptions from the Act, including national security (s22), communication provider (s23), regulatory activity and honours (s24), and a general exemption (s25).

Artefacts an auditor will ask for
  • Documentation of any exemption relied upon and its statutory basis
  • Assessment that the exemption conditions are met
  • Scope of processing covered by the exemption
Where this commonly fails
  • Exemption claimed without meeting its conditions
  • Exemption applied too broadly
  • No documentation of reliance

Bermuda PIPA Part 5: The Commissioner

BM-PIPA-26
The Privacy Commissioner: establishment and powers

The Commissioner. Sections 26 to 37 establish the office of the Privacy Commissioner and set out the Commissioner's appointment, staff, funding, general powers, investigation and inquiry powers, and related duties.

Artefacts an auditor will ask for
  • Records of engagement and cooperation with the Privacy Commissioner
  • Responses to Commissioner investigations, inquiries and information requests
  • Tracking of Commissioner correspondence to closure
Where this commonly fails
  • Commissioner requests not responded to
  • Investigations not cooperated with
  • Correspondence not tracked
BM-PIPA-32
Codes of practice

Codes of practice. Section 32 empowers the Commissioner to issue codes of practice; organisations should align their practices with any applicable code.

Artefacts an auditor will ask for
  • Identification of applicable Commissioner codes of practice
  • Evidence of alignment with applicable codes
  • Gap analysis against codes
Where this commonly fails
  • Applicable codes not identified
  • Practices not aligned to codes
  • No gap analysis

Bermuda PIPA Part 6: Reviews, Complaints and Enforcement

BM-PIPA-38
Reviews and complaints

Reviews and complaints. Sections 38 to 43 give individuals the right to ask for a review or initiate a complaint to the Commissioner, and set out the procedure, notification, mediation, inquiry and burden of proof.

Artefacts an auditor will ask for
  • Internal procedure for handling individual reviews/complaints and Commissioner-referred complaints
  • Records of complaints, reviews and outcomes
  • Cooperation with mediation and inquiries
Where this commonly fails
  • Complaints not handled or escalated
  • No complaint procedure
  • Mediation/inquiry not supported
BM-PIPA-44
Commissioner's orders and judicial review

Orders and enforcement. Sections 44 to 45 set out the Commissioner's power to make orders and the availability of judicial review of the Commissioner's decisions.

Artefacts an auditor will ask for
  • Records of any Commissioner orders and the organisation's compliance
  • Remediation of matters subject to orders
  • Legal review of order/judicial-review exposure
Where this commonly fails
  • Orders not complied with
  • Remediation not tracked
  • No legal review of enforcement exposure
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Bermuda Personal Information Protection Act 2016 (PIPA) framework page.