Bermuda Personal Information Protection Act 2016 (PIPA)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Bermuda PIPA Part 1: Preliminary
Application. Section 3 sets out the organisations and processing to which the Act applies (organisations that use personal information in Bermuda, in whole or in part by automated means or held in a structured filing system).
- Determination that the organisation uses personal information and is in scope
- Records of personal information held and processing performed
- Processing wrongly scoped out
- Structured manual records overlooked
Exclusions. Section 4 sets out the matters excluded from the Act (for example personal or domestic use, and certain other excluded processing).
- Analysis of any exclusion relied upon and its basis
- Documentation that excluded processing is genuinely out of scope
- Exclusion claimed without basis
- Excluded and in-scope processing not separated
Bermuda PIPA Part 2: General Principles and Rules
Purpose limitation. Section 10 requires that personal information only be used for the purposes for which it was collected (or a compatible purpose), unless a permitted exception applies.
- Documented purposes for which personal information is collected
- Assessment of compatibility for any new use
- Controls preventing unauthorised secondary use
- Secondary use without a compatible purpose or exception
- Purposes not documented
- Purpose creep
Proportionality. Section 11 requires that the personal information used be adequate, relevant and not excessive in relation to the purposes (data minimisation).
- Assessment that data collected is adequate, relevant and not excessive
- Minimisation controls at collection
- Periodic review of data holdings
- Excessive data collected
- No minimisation assessment
- Data retained beyond need
Integrity of personal information. Section 12 requires personal information to be accurate and, where necessary, kept up to date, and retained only as long as necessary for the purposes.
- Accuracy and update processes
- Retention schedule and disposal records
- Evidence data is not kept longer than necessary
- Inaccurate or outdated data
- No retention schedule
- Data retained indefinitely
Security safeguards. Section 13 requires organisations to protect personal information with appropriate safeguards against loss, unauthorised access, destruction, use, modification or disclosure, proportionate to the risk.
- Technical and organisational security safeguards proportionate to risk
- Access controls, encryption and monitoring as appropriate
- Security oversight of third parties handling the data
- Safeguards not proportionate to risk
- No access controls
- Third-party security not assured
Breach of security. Section 14 requires organisations to notify the Commissioner (and affected individuals where required) without undue delay of a breach of security that is likely to adversely affect an individual.
- Breach response procedure with assessment and notification timelines
- Records of breach notifications to the Commissioner and affected individuals
- Breach register
- Reportable breaches not notified to the Commissioner
- No breach assessment process
- Affected individuals not notified where required
Overseas transfers. Section 15 requires that, before transferring personal information to an overseas third party, the organisation employ appropriate measures to ensure the information receives comparable protection.
- Inventory of overseas transfers and recipients
- Comparable-protection measures (contracts, due diligence) for each transfer
- Assessment that the transferee provides adequate protection
- Overseas transfers without comparable-protection measures
- Transfers not inventoried
- No assessment of the recipient
Children's information. Section 16 imposes specific requirements on the use of personal information about children in the context of information society services.
- Identification of services likely to be used by children
- Age-appropriate consent/verification measures
- Enhanced protections for children's information
- Children's data handled without s16 measures
- No age verification where required
- Notices not child-appropriate
Responsibility and compliance. Section 5 requires every organisation to adopt suitable measures and policies to give effect to its obligations, remain responsible for personal information transferred to others, and designate a representative (privacy officer) for compliance (s5(4)).
- Privacy programme: suitable measures and policies giving effect to PIPA
- Privacy officer appointment record and responsibilities (s5(4))
- Evidence the organisation remains responsible for information it transfers to others
- No privacy officer designated
- No documented measures/policies
- Responsibility for transferred data not retained
Conditions for using personal information. Section 6 sets out the lawful conditions (including consent and other permitted grounds) under which an organisation may use personal information.
- Record of the lawful condition relied on for each use of personal information
- Consent records where consent is the basis
- Assessment of permitted non-consent grounds
- Use without a valid condition under s6
- Consent not demonstrable
- Reliance on a ground that does not apply
Sensitive personal information. Section 7 imposes additional conditions on the use of sensitive personal information (including the categories defined in the Act such as genetic, biometric, health, racial, and other sensitive data).
- Identification of sensitive personal information held
- Additional lawful condition for sensitive-data use under s7
- Enhanced safeguards for sensitive data
- Sensitive data used without an s7 condition
- Sensitive categories not identified
- No enhanced safeguards
Fairness. Section 8 requires that personal information be used in a manner that a reasonable person would consider fair in the circumstances.
- Assessment that uses of personal information are fair in the circumstances
- Avoidance of deceptive or misleading collection/use
- Uses not assessed for fairness
- Deceptive collection practices
Privacy notices. Section 9 requires organisations to provide a clear and accessible privacy notice describing their practices and policies with respect to personal information.
- Published privacy notice(s) covering the matters required by s9
- Process to keep notices current
- Accessibility of notices to individuals
- No privacy notice or incomplete content
- Notice not updated
- Notice not accessible
Bermuda PIPA Part 3: Rights of Individuals
Right of access. Section 17 gives individuals the right to request access to their personal information held by an organisation and information about its use.
- Procedure for handling access requests within statutory timeframes
- Records of access requests and responses
- Identity verification for requesters
- Access requests not handled in time
- No request procedure
- Identity not verified
Access to medical records. Section 18 sets out the specific procedure and safeguards for requests for access to medical records.
- Procedure for medical-record access requests, including any medical-practitioner involvement required
- Records of medical-record access requests and outcomes
- Medical-record requests handled like ordinary access without s18 safeguards
- No practitioner consultation where required
Rectification, blocking, erasure and destruction. Section 19 gives individuals the right to request rectification, blocking, erasure or destruction of their personal information in defined circumstances.
- Procedure for rectification/blocking/erasure/destruction requests
- Records of such requests and actions taken
- Propagation of corrections to third parties where required
- Requests not actioned
- No procedure
- Corrections not propagated
Procedure for requests. Section 20 sets out the procedure for making a request under sections 17, 18 or 19, including timeframes and any fees.
- Documented request procedure aligned to s20 (timeframes, fees, form)
- Logs evidencing adherence to the statutory procedure
- Procedure not aligned to s20
- Statutory timeframes missed
- Improper fees charged
Compensation. Section 21 provides individuals a right to compensation for financial loss or distress caused by a contravention of the Act.
- Awareness of compensation exposure under s21
- Complaint/claim handling records
- Legal review of contraventions giving rise to compensation
- Compensation exposure not assessed
- Claims not handled
- Contraventions not remediated
Bermuda PIPA Part 4: Exemptions
Exemptions. Sections 22 to 25 set out exemptions from the Act, including national security (s22), communication provider (s23), regulatory activity and honours (s24), and a general exemption (s25).
- Documentation of any exemption relied upon and its statutory basis
- Assessment that the exemption conditions are met
- Scope of processing covered by the exemption
- Exemption claimed without meeting its conditions
- Exemption applied too broadly
- No documentation of reliance
Bermuda PIPA Part 5: The Commissioner
The Commissioner. Sections 26 to 37 establish the office of the Privacy Commissioner and set out the Commissioner's appointment, staff, funding, general powers, investigation and inquiry powers, and related duties.
- Records of engagement and cooperation with the Privacy Commissioner
- Responses to Commissioner investigations, inquiries and information requests
- Tracking of Commissioner correspondence to closure
- Commissioner requests not responded to
- Investigations not cooperated with
- Correspondence not tracked
Codes of practice. Section 32 empowers the Commissioner to issue codes of practice; organisations should align their practices with any applicable code.
- Identification of applicable Commissioner codes of practice
- Evidence of alignment with applicable codes
- Gap analysis against codes
- Applicable codes not identified
- Practices not aligned to codes
- No gap analysis
Bermuda PIPA Part 6: Reviews, Complaints and Enforcement
Reviews and complaints. Sections 38 to 43 give individuals the right to ask for a review or initiate a complaint to the Commissioner, and set out the procedure, notification, mediation, inquiry and burden of proof.
- Internal procedure for handling individual reviews/complaints and Commissioner-referred complaints
- Records of complaints, reviews and outcomes
- Cooperation with mediation and inquiries
- Complaints not handled or escalated
- No complaint procedure
- Mediation/inquiry not supported
Orders and enforcement. Sections 44 to 45 set out the Commissioner's power to make orders and the availability of judicial review of the Commissioner's decisions.
- Records of any Commissioner orders and the organisation's compliance
- Remediation of matters subject to orders
- Legal review of order/judicial-review exposure
- Orders not complied with
- Remediation not tracked
- No legal review of enforcement exposure
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Bermuda Personal Information Protection Act 2016 (PIPA) framework page.