Bermuda's Personal Information Protection Act 2016 came fully into force on 1 January 2025. Since then, procurement conversations involving any vendor outside the territory have acquired a new opening question, and it is usually asked before anyone discusses the work itself.
The question is generally phrased as whether PIPA allows an overseas agency at all. That framing is wrong in a way that makes the conversation harder than it needs to be, because the Act contains no such prohibition. What it contains is a process, an allocation of responsibility, and a set of consequences for skipping either.
This article works through what Section 15 actually requires, where the scope of the Act genuinely is uncertain, and how a search or AI visibility programme can be designed so that most of it never touches personal information in the first place. It is general information about the statute rather than legal advice, and anything touching Bermuda personal data should be confirmed with Bermuda counsel and your privacy officer.
What Section 15 says
The provision governing transfers to an overseas third party sets out a sequence rather than a barrier.
The organisation remains responsible for compliance with the Act in respect of personal information transferred. Before transferring, it must assess the level of protection that the overseas party will provide. In making that assessment it must take account of the protection afforded by the law applicable to that party. And where a comparable level of protection is not established, it must employ contractual mechanisms, corporate codes of conduct including binding corporate rules, or other means to provide it.
Read that as a workflow and it becomes manageable. Assess, document, close any gap contractually, retain accountability. Nothing in it turns on the vendor's passport.
An overseas third party, for these purposes, is a third party not domiciled in Bermuda. The general responsibility for third parties sits alongside this at Section 5(3), which is worth knowing because it establishes the same principle for domestic arrangements: engaging someone else to do the processing does not move the accountability.
A Process, Not a Prohibition
Section 15 does not ban overseas transfer. It sets out what has to happen first, and who carries the consequence if it does not.
You remain responsible
Transferring personal information to an overseas third party does not transfer accountability for compliance. It stays with the Bermuda organisation throughout.
Assess before transferring
The assessment of the protection provided by the overseas party happens before the transfer, not after an incident and not during a renewal.
Consider the applicable law
The protection afforded by the law that applies to the overseas party is part of the assessment, alongside the party's own practice.
If comparable protection is not established, secure it another way
Contractual mechanisms, corporate codes of conduct including binding corporate rules, or other means. The gap is closed, not accepted.
And separately, from Privacy Commissioner guidance
Where information has been anonymised, the transfer restrictions do not apply and it may be moved outside Bermuda freely. That single sentence determines how the measurement layer of a search programme should be designed.
Section references and the anonymisation position are drawn from the Act and from Office of the Privacy Commissioner guidance on transfers to overseas third parties. General information, not legal advice.
The scope question, where two common summaries both mislead
Here is where most published commentary goes wrong, and it goes wrong in both directions.
One version says PIPA has extraterritorial reach, full stop, so any foreign agency handling Bermuda data is directly in scope. Another says PIPA only applies to organisations in Bermuda, so a foreign agency never is. We found both stated flatly in otherwise careful research material prepared for this project, sometimes in documents produced by the same system on the same day.
The actual test is neither. PIPA applies to organisations that use personal information in Bermuda, regardless of where the individual whose information is being used is based.
The trigger is the use of personal information in Bermuda. Not the location of the organisation. Not the residence of the individual.
From that, several things follow. An organisation headquartered in Bermuda will generally be treated as operating in Bermuda. An organisation headquartered elsewhere may or may not be, depending on the facts of the arrangement, and Bermuda counsel has suggested the Economic Substance Regulations 2018 as a reference point for what headquartered means in this context. And critically, PIPA does not work the way the European regime does: simply providing goods and services to individuals in Bermuda, or monitoring their behaviour from abroad, does not on its own pull a foreign organisation into scope. The Privacy Commissioner's own material distinguishes PIPA from the European approach on precisely this point.
What this means practically for a Bermuda platform engaging a foreign agency is more useful than the scope debate itself. Whether or not the agency is independently in scope, the Bermuda organisation's obligations under Sections 5(3) and 15 are unambiguous and unaffected. The assessment has to happen. The accountability stays home.
So the productive procurement question is not whether PIPA reaches the vendor. It is whether the vendor can evidence its safeguards well enough for the Bermuda organisation to discharge its own obligation.
The Trigger Is Use In Bermuda
Not where the organisation sits. Not where the individual lives. Two common summaries of PIPA get this wrong in opposite directions.
The test
PIPA applies to organisations that use personal information in Bermuda, regardless of where the individual whose information is used happens to be.
Where it is straightforward
Headquartered in Bermuda, using personal information: in scope
No connection to Bermuda at all: out of scope
Bermuda organisation sending data to a foreign vendor: section 15 applies to the Bermuda organisation
Where it is fact-dependent
Foreign organisation with operations touching Bermuda: depends on the facts
Merely marketing to people in Bermuda from abroad: not sufficient on its own
Merely monitoring behaviour of people in Bermuda: not sufficient on its own
This reading follows Bermuda counsel commentary on the Act and the Privacy Commissioner's own comparison of PIPA with the European regime, which it distinguishes on precisely this point. Where scope is genuinely uncertain for a particular arrangement, Bermuda counsel should determine it. General information, not legal advice.
The comparability mechanism, and why it changes less than expected
A recurring hope in these conversations is that a jurisdiction might appear on some approved list and remove the problem.
A mechanism does exist. Privacy Commissioner guidance refers to the possibility of a formal designation by the minister declaring that a jurisdiction's law is comparable to PIPA, and the office has published a template for conducting a Section 15 analysis of comparable laws. The guidance is also usefully realistic about what comparability means: a law does not have to duplicate PIPA, and differences do not automatically mean the protection is not comparable, since a difference may produce greater, lesser or equivalent protection. Different penalty levels, for instance, may have comparable effect in economies of different sizes.
But here is the part that matters, and it is stated explicitly in the guidance. A ministerial designation would address only one element of the Section 15 analysis. Regardless of whether an organisation concludes that the overseas party's jurisdiction provides comparable protection, it must still assess that party's own organisational, administrative and technical processes and internal safeguards to satisfy itself that operational practice is secure.
So the vendor assessment happens either way. Waiting for a list is waiting for something that would remove perhaps a third of the work.
The better response is to prepare the assessment pack before it is requested. In our experience the material a Bermuda privacy officer actually needs is unglamorous and finite: what personal information will be transferred and why, which fields specifically, where it will be stored and processed, who has access, how long it is retained, how it is deleted, what happens in an incident, and what contractual commitments back all of it. An agency that produces that on request looks organised. An agency that produces it unprompted at proposal stage removes a procurement stage entirely.
The vetting culture this sits inside
Section 15 is easier to understand when you see what surrounds it, because the assessment obligation is not an isolated privacy requirement. It is one instance of a supervisory posture that runs through the whole territory.
From 1 October 2026, any person vetted by the Bermuda Monetary Authority as a key person at a financial institution regulated for anti-money-laundering purposes must submit a police clearance certificate no more than twelve months old alongside their personal declaration. The requirement extends to changes of key person, and applications received complete before that date are not affected. The sectors named include corporate service providers, trust business, investment business, fund administration and investment funds.
To be precise about scope, because this gets stretched: the requirement applies to key persons inside the regulated institution, meaning those subject to fit and proper assessment under the minimum criteria for licensing. It does not apply to external agency personnel. We have seen it claimed that remote agency staff with administrative access must observe the same vetting protocol. That claim is not in the notice, and repeating it would be inventing an obligation.
What the requirement does tell you is the temperature of the room. Alongside it sit recovery planning obligations that became operative on 1 May 2025 for designated commercial insurers, with updated regulatory guidance issued in March 2026 and scope thresholds set around a three-year rolling average of USD 10 billion in total assets or USD 5 billion in gross written premium.
A supervisor tightening background checks on senior individuals and requiring formal recovery documentation from large insurers is a supervisor whose regulated entities will not treat a vendor privacy assessment as a formality. Arrive prepared.
Section 5(3), the provision that survives every scope argument
There is a reason we keep returning to responsibility rather than to scope.
Section 5(3) establishes that an organisation remains responsible for compliance with the Act in respect of personal information transferred to a third party. It does not distinguish between domestic and overseas third parties. Section 15 then restates and extends that responsibility for the overseas case specifically.
Notice what this means for the argument that consumes most of the oxygen in these conversations. Whether or not the foreign agency is independently within the Act's scope, the Bermuda organisation's position is identical. It assesses. It documents. It closes any gap contractually. It remains accountable.
So a procurement conversation that spends three weeks establishing whether the vendor is technically caught by the statute has spent three weeks on a question that changes nothing about what has to happen next. The productive question is narrower and answerable: can this vendor evidence its safeguards well enough for us to discharge an obligation we carry regardless?
That reframing is worth making explicitly with a privacy officer, because it moves the conversation from a legal debate with no clean answer to a documentation exercise with a finite checklist.
Designing most of the programme out of scope
This is the part that gets overlooked, and it is the most useful finding in the whole area.
Privacy Commissioner guidance on transfers states that where information has been anonymised, the transfer restrictions do not apply and the organisation is free to transfer it outside Bermuda.
Now consider what a search and AI visibility programme actually consists of. Public search queries. Corporate entity names. Page URLs. Rankings. Engine outputs. Citation records. Structured data. Content drafts. None of that contains an identified or identifiable individual.
Which means the measurement layer of the programme, the part that runs continuously and generates the reporting, can be built to sit entirely outside the transfer regime. Not by exemption or interpretation, but by construction.
Exposure enters through specific, identifiable doors: lead form submissions, enquiry records, CRM data shared for campaign work, session-level analytics configured to retain user identifiers, and monitoring of named individuals rather than corporate entities. Every one of those is a design decision, and every one of them can be scoped deliberately rather than inherited by default.
| Search or GEO activity | Personal information involved? | Section 15 exposure | Design control |
|---|---|---|---|
| Rank tracking on public queries | None | Outside the transfer regime | Keep it that way. No user-level identifiers appended for convenience |
| AI citation and prompt monitoring | None if prompts are category-level and entity names are corporate | Outside the transfer regime | Prohibit named-individual prompts unless separately assessed |
| Aggregate analytics reporting | None once genuinely aggregated | Low, subject to genuine anonymisation | Aggregate by default rather than on request. Check re-identification risk in small samples |
| Session-level or user-level analytics | Frequently yes, depending on configuration | Medium | Configure retention and identifier settings deliberately, and document the reasoning |
| Lead form data and enquiry records | Yes, by definition | High | Full section 15 assessment, processing agreement, retention schedule, deletion procedure |
| CRM records shared for campaign work | Yes | High | Minimise fields transferred. Most campaign work does not require the full record |
| Uploading client records into a third-party AI tool | Yes, plus onward transfer to the tool provider | High, and layered | Prohibit without documented approval. The tool provider is a further overseas party in its own right |
The pattern in that table is worth stating directly, because it inverts the usual assumption. The bulk of a technical search and GEO programme carries essentially no personal information exposure. The exposure clusters in a small number of activities, most of them optional or configurable. A programme designed with this in mind has a much narrower Section 15 footprint than one where the question was asked after the tooling was chosen.
The privacy officer, and why to identify them early
Every organisation using personal information in Bermuda must designate a privacy officer. There is no exemption by size or sector. The role can be outsourced, the officer does not need to be resident in Bermuda, and their contact details must be published.
For procurement purposes this person is the relevant counterparty on everything above. Identifying them at the start of a vendor conversation rather than three weeks in tends to shorten the process considerably, because the assessment they need to perform is the thing standing between proposal and contract.
Enforcement, and what the numbers say
The Office of the Privacy Commissioner published its first full-year annual report covering April 2025 to March 2026. It recorded 30 written requests, comprising 22 complaints and eight review requests, along with 25 reported personal information breaches and 43 general enquiries.
Those are modest numbers, and it would be easy to read them as a quiet regime. That reading misses the trajectory. The office has signalled a transition from the education phase that accompanied the Act coming into force toward active enforcement, and the Commissioner who took office in March 2026 named developing an informed strategic enforcement approach as an immediate priority.
On penalties, the Act provides that an individual committing an offence is liable on summary conviction to a fine not exceeding 25,000 dollars, imprisonment for up to two years, or both, while an organisation is liable on indictment to a fine not exceeding 250,000 dollars. Directors and officers can be personally liable where an offence is committed with their consent or connivance or is attributable to their neglect. Amounts are in Bermudian dollars, pegged at par to the US dollar.
The organisational maximum is not, by international standards, a very large number. The director liability provision is the part that changes behaviour, and it is the part that explains why these questions now arrive early in procurement rather than late.
What to actually do
For a Bermuda organisation considering an overseas agency: identify your privacy officer and involve them at proposal stage rather than at contract stage. Map what personal information the engagement genuinely requires, which is usually far less than the default tooling would collect. Ask the vendor for the assessment pack described above, and treat an inability to produce it as the finding it is. Document the Section 15 assessment and keep it, because the assessment being done is the compliance position, and an undocumented assessment is indistinguishable from none.
For an agency working with Bermuda clients: arrive with the processing agreement and the data-flow map already written. Design the measurement layer to hold no personal information, and say so in the proposal rather than in an appendix. Never claim the Bermuda organisation's responsibility has transferred, because it has not and a privacy officer will know that immediately. And be precise about scope rather than reassuring about it, because the flat statements in both directions are the ones that get caught.
Tessar Napitupulu writes about how privacy regimes across jurisdictions shape the design of search and AI visibility programmes in Cited or Silent, available as a free gated edition, with retailer editions on Amazon, Google Play and Apple Books.
Frequently Asked Questions
Does PIPA prohibit using an agency based outside Bermuda?
No. There is no prohibition on overseas processing anywhere in the Act. Section 15 sets a process rather than a ban: before transferring personal information to an overseas third party, the organisation must assess the level of protection that party provides, including the protection afforded by the law applicable to it, and where a comparable level is not established must employ contractual mechanisms, corporate codes of conduct including binding corporate rules, or other means to secure it. The question is never whether the vendor is foreign. It is whether the assessment was done and documented.
Does PIPA apply to a vendor located outside Bermuda?
It can, and the answer is fact-dependent rather than automatic. The trigger is the use of personal information in Bermuda, not the location of the organisation and not the residence of the individual. An organisation headquartered in Bermuda will generally be treated as operating in Bermuda. An organisation headquartered elsewhere may or may not be, depending on the facts of what it does and where. This is materially different from the European approach, where targeting or monitoring individuals in a territory can pull a foreign organisation into scope on its own. PIPA does not work that way, and anyone stating flatly that it does, or flatly that it never reaches foreign firms, is oversimplifying in one direction or the other.
Who stays responsible if the overseas vendor gets it wrong?
The Bermuda organisation does. Section 5(3) provides that an organisation remains responsible for compliance with the Act in respect of personal information transferred to a third party, and Section 15 restates that responsibility specifically for overseas transfers. Delegating the processing does not delegate the accountability. This is why a competent vendor should arrive with the processing agreement and data-flow documentation already prepared rather than waiting to be asked for them.
Is Indonesia on an approved list of countries under PIPA?
There is a mechanism for a minister to designate a jurisdiction's law as comparable to PIPA, and no designation removes the underlying obligation. The Privacy Commissioner's guidance is explicit that such a designation would address only one element of the Section 15 analysis, and that the organisation must still assess the overseas party's own organisational, administrative and technical processes and safeguards to satisfy itself that operational practice is secure. So the vendor assessment happens either way. The practical consequence is that preparing the assessment pack in advance is more useful than waiting for a list.
Does rank tracking or AI citation monitoring trigger PIPA?
Generally not, if the monitoring is designed to hold no personal information. The Privacy Commissioner's guidance states that where information has been anonymised, the transfer restrictions do not apply and it may be transferred outside Bermuda freely. Public search queries, corporate entity names, page URLs and engine outputs contain no identified or identifiable individual. Exposure enters when lead forms, CRM records, session-level analytics or monitoring of named individuals come into scope, and those are design decisions rather than inevitabilities.
What are the penalties under PIPA?
An individual committing an offence under the Act is liable on summary conviction to a fine not exceeding 25,000 dollars, or imprisonment for up to two years, or both. An organisation is liable on indictment to a fine not exceeding 250,000 dollars. Directors and officers can be personally liable where an offence is committed with their consent or connivance or is attributable to their neglect. Amounts are in Bermudian dollars, pegged at par to the US dollar. This is general information about the statute rather than legal advice.
Do we need a privacy officer, and can we outsource the role?
Every organisation using personal information in Bermuda must designate a privacy officer, with no exemption for size or sector. The role can be outsourced and the officer is not required to be resident in Bermuda. The individual's contact details must be published. In practice the privacy officer is the person your agency will be dealing with on vendor assessment, so identifying them early shortens procurement considerably.
How active is enforcement, in practice?
The Office of the Privacy Commissioner's first full-year annual report, covering April 2025 to March 2026, recorded 30 written requests comprising 22 complaints and eight review requests, 25 reported personal information breaches and 43 general enquiries. Those are modest numbers for a first full year of the Act being in force. The signalled direction matters more than the volume: the office has indicated a shift from the education phase toward enforcement, and the current Commissioner named developing an informed strategic enforcement approach as an immediate priority on taking office in March 2026.
Does the new key persons police clearance requirement apply to our agency staff?
No. From 1 October 2026, any person vetted by the Bermuda Monetary Authority as a key person at a financial institution regulated for anti-money-laundering purposes must submit a police clearance certificate no more than twelve months old with their personal declaration, and the requirement covers changes of key person. Key person means someone subject to fit and proper assessment under the minimum criteria for licensing, that is a holder of a significant or controlling interest or a person performing a senior management or other key function within the regulated institution itself. External vendor personnel are not covered. We flag this because the opposite claim circulates, and inventing an obligation for a client is as damaging as missing a real one.
Sources & References:
- Personal Information Protection Act 2016 (Bermuda), fully in force 1 January 2025. This commencement date was corroborated independently across all eight research documents compiled for this project and confirmed against Office of the Privacy Commissioner and law firm sources. VERIFIED.
- Section 15, transfers to an overseas third party: the organisation remains responsible for compliance; must assess the level of protection the overseas party will provide before transferring; must take account of the protection afforded by the law applicable to that party; and where comparable protection is not established must employ contractual mechanisms, corporate codes of conduct including binding corporate rules, or other means. Section 5(3) establishes general responsibility for personal information transferred to third parties. An overseas third party is defined as a third party not domiciled in Bermuda. VERIFIED against Office of the Privacy Commissioner guidance on transfers to overseas third parties.
- Anonymised information: Office of the Privacy Commissioner guidance states that where information has been anonymised the transfer restrictions do not apply and it may be transferred outside Bermuda freely. VERIFIED against PrivCom published guidance.
- Comparability designation: PrivCom guidance refers to the possibility of formal designation by the minister that a jurisdiction's law is comparable to PIPA, and the office has published a template for section 15 analysis of comparable laws. The guidance states expressly that such a designation addresses only one element of the section 15 analysis, and that the organisation must still assess the overseas party's own organisational, administrative and technical processes and internal safeguards. VERIFIED.
- Scope of the Act: PIPA applies to organisations using personal information in Bermuda, regardless of where the individual is based. An organisation headquartered in Bermuda would likely be treated as operating in Bermuda; an organisation headquartered elsewhere may or may not be, depending on the facts, with the Economic Substance Regulations 2018 suggested as a reference for the meaning of headquarters. PIPA is distinguished from the European regime in that provision of goods or services to individuals in Bermuda, or monitoring of their behaviour from abroad, is not on its own sufficient to bring a foreign organisation into scope. Sources: Bermuda counsel commentary on the PIPA guidance notes, and the Office of the Privacy Commissioner's own comparison of PIPA with GDPR. VERIFIED. Note that two of the eight research documents prepared for this project stated the scope position flatly and in opposite directions; both were incorrect and the position above reflects verification against primary and counsel sources.
- Privacy officer: every organisation must designate a privacy officer, without exemption by size or sector. The role may be outsourced and the officer need not be resident in Bermuda. Contact details must be published. VERIFIED, corroborated across four independent research sources.
- Penalties: an individual is liable on summary conviction to a fine not exceeding BMD 25,000, imprisonment for up to two years, or both; an organisation is liable on indictment to a fine not exceeding BMD 250,000. Directors and officers may be personally liable where an offence is committed with their consent or connivance or is attributable to their neglect. Bermudian dollar pegged at par to the US dollar. REPORTED, corroborated across three research documents and law firm commentary. The specific section number for the penalty provision could not be confirmed and is therefore not cited.
- Enforcement statistics: Office of the Privacy Commissioner annual report for the period 1 April 2025 to 31 March 2026, tabled June 2026, recording 30 written requests (22 complaints and eight review requests), 25 reported personal information breaches and 43 general enquiries. VERIFIED against the published report.
- Commissioner succession: the first Privacy Commissioner served from January 2020 to 30 September 2025; the current Commissioner was appointed with effect from 2 March 2026 and identified development of an informed strategic enforcement approach as an immediate priority. VERIFIED. Individual office holders are not named in the body of this article because the position changes and this material is intended to remain accurate over time.
- Key persons requirement: Bermuda Monetary Authority notice, effective 1 October 2026, requiring any person vetted as a key person at an anti-money-laundering regulated financial institution to submit a police clearance certificate no more than twelve months old with their personal declaration form, extending to changes of key person, with applications received complete before that date unaffected. Sectors named include corporate service providers, trust business, investment business, fund administration and investment funds. Reported by Bermuda press from 13 August 2026. VERIFIED. The claim that this requirement extends to external agency personnel appeared in research material prepared for this project, is not contained in the notice, and is expressly rejected in the body text.
- Recovery planning: section 6G of the Insurance Act 1978, introduced by amendments effective 30 May 2024, with recovery plan rules operative from 1 May 2025 for designated commercial insurers and insurance groups. Scope is determined by the Authority rather than applying automatically, with thresholds including a three-year rolling average of USD 10 billion in total assets or USD 5 billion in gross written premium. Updated guidance issued 20 March 2026. VERIFIED.
- This article is general information about Bermuda statute and regulatory guidance. It is not legal advice. Arrangements involving Bermuda personal information should be reviewed by qualified Bermuda counsel and by the organisation's designated privacy officer.