Products Services Automation About Contact
All guides

26 August 2026

What PIPA means for a Bermuda business website

Bermuda's privacy law has been in full force since January 2025. What it actually changes about the website and systems a small business runs.

Written by Chris Bennett , co-founder & developer at dotbm.

Bermuda’s Personal Information Protection Act came into full force on 1 January 2025, and there is no small-business exemption in it. If your website has a contact form, a mailing list, a booking page or an analytics script, the Act applies to you as it applies to a bank. Most of the writing about it is aimed at compliance departments that already have lawyers. This is the other version: what it changes about the systems you run.

This is orientation, not legal advice. For the legal programme itself, talk to a Bermuda lawyer, and read the Privacy Commissioner’s own guidance, which is free and better than any summary.

You hold more personal information than you think

PIPA defines personal information as any information about an identified or identifiable individual. That is a wider net than most people picture. On a typical Bermuda business site it catches the contact form, the newsletter signup, the booking or enquiry system, order records, staff photographs and bios, CCTV if you have it, and in most configurations the analytics too.

A separate and stricter category, sensitive personal information, covers things like health, race, place of origin, religious beliefs, political opinions, sexual orientation, biometric and genetic data. A physiotherapy practice or a recruitment agency crosses into that category without doing anything unusual.

The part that bites in Bermuda

Section 15 governs sending personal information outside Bermuda, and it catches local businesses for a reason that has nothing to do with negligence: almost nothing a Bermuda business uses is hosted in Bermuda.

Your website is probably on a server in the United States or Europe. Your form submissions land in a mailbox run by Google or Microsoft. Your newsletter sits with Mailchimp. Your bookings sit with whoever wrote the booking software. Every one of those is an overseas transfer.

Section 15 does not ban that. What it requires is that before you transfer, you have assessed the protection the overseas recipient actually provides, and the protection given by the law of the country they are in. That is a prospective assessment, made before the transfer rather than explained afterwards, and it applies to each one.

In practice that means keeping a list. Which services hold personal information for you, what each one holds, where it physically sits, and what the contract with them says about it. Most of the businesses we deal with have never written that list down, and writing it down is most of the work.

It is also the lever you have. Every service you can remove from that list is one fewer assessment to make and one fewer place your customers’ details can leak from. dotbm self-hosts its own site analytics rather than sending visitor data to a third party, which is one line on a list instead of one more overseas processor. That kind of choice is worth making deliberately at build time rather than discovering later.

The three things you need in place

A privacy notice that describes what you actually do. Not a template that describes what a generic company might do. If your form collects a phone number and your template does not mention phone numbers, the notice is wrong.

A named privacy officer. PIPA requires organisations to designate one, and there is no carve-out for small businesses. In a five-person company that person is usually the owner. Naming them is the requirement; having a department is not.

A way to answer an access request. Individuals can ask what you hold about them, and you have 45 days to respond, extendable by 30 in some circumstances. Forty-five days is generous until you try to find every copy of somebody’s details across a mailbox, a CRM and a spreadsheet.

When something goes wrong

A breach that is likely to adversely affect someone has to be reported both to the Privacy Commissioner and to the affected individual, without undue delay. If you delay, you have to explain why. There is no threshold of size below which it stops applying.

The penalties are real: up to $250,000 for an organisation, and up to $25,000 and two years’ imprisonment for an individual.

Where to start

Write the list of who holds personal information for you. Everything else, the notice, the officer, the access process, follows from knowing what you actually have and where it actually is. If your site was built by somebody who is no longer around, what to look for in a local developer covers how to work out what you are running, and you can always ask us to go through it with you.