PIPA, which received Royal Assent on July 27, 2016, will come into full effect on January 1, 2025, meaning that the clock has started ticking and employers must begin preparing for its impact.

Personal information is defined under PIPA as “any information about an identified or identifiable individual”.

Sensitive personal information, which is a category of personal information, is defined as “any personal information relating to an individual’s place of origin, race, colour, national or ethnic origin, sex, sexual orientation, sexual life, marital status, physical or mental disability, physical or mental health, family status, religious beliefs, political opinions, trade union membership, biometric information or genetic information”.

In practice, the sort of personal information about employees that an employer is likely to have access to and retain includes financial information, pension information, age, security clearance information, drug test results and health records or medical information.

Such information may be obtained by an employer for many reasons, such as for insurance purposes, work permit submission or workplace diversity and equality monitoring.

Personal information should be collected with consent. Where an employer retains personal information prior to PIPA coming into force, it is deemed to have been collected pursuant to consent being given by that individual.

When an employer wishes to use the personal information of an employee, they may rely on provisions in contracts of employment whereby the employee has consented to such use.

It may seem to an employer that consent is the most obvious and straightforward method by which to establish a lawful basis to use the personal information of an employee. However, to rely on consent under PIPA, an employer must “reasonably demonstrate that the individual has knowingly consented”.

The difficulty here is that where there is a clear imbalance of power between an employer and employee, as there almost always is, it could be hard for an employer to show that there was knowing consent.

Instead, employers can rely on alternative bases for use of personal information laid out in PIPA, including showing that the “use of the personal information is necessary in the context of the individual’s present, past or potential employment with the organisation”.

While that approach actually makes it easier for the employer to use the personal information of the employee if the employer is able to show that such use was “necessary in the context of” employment, it may carry a higher risk for potential disputes. This is on the basis that what is necessary in the context of employment is in fact sensitive depending on each individual circumstance; thus it is open to an employee to argue that it was not necessary in the context of their employment to use their personal information.

In preparing for the arrival of PIPA, employers should ensure that they have clear policies in place which address the requirements of, and establish measures to ensure compliance with, the legislation.

For example, PIPA requires an employer to “ensure that any personal information used is accurate, relevant and not excessive to the purposes for which it is used”.

As such, measures and policies that address the handling and retention of data, such as data management, data handling and privacy policies, will require careful consideration.

Employers will need to ensure that the purpose for which the use of personal information is retained is clear, as well as making sure that only personal information that is relevant to the purpose is retained for a proportionate and considered period of time.

Clear policies should also be established regarding the disposal of personal information.

Employers should begin to think about these considerations now to ensure that by January 1, 2025, when PIPA comes into full force, they are compliant.

First Published in The Royal Gazette, Legally Speaking column, July 2023

Share
X.com LinkedIn Email Save as PDF
More Publications
Appleby-Website-Employment-and-Immigration
27 Mar 2025

Entering and Exiting Bermuda for Visa-Controlled Nationals

As it stands, with direct commercial flights to and from Bermuda only going from the United Kingdom,...

Appleby-Website-Corporate-Practice
27 Mar 2025

How foreign companies become Bermuda companies

Bermuda, renowned as a global business hub, offers a robust legal and regulatory framework that attr...

Appleby-Website-Insurance-and-Reinsurance
24 Mar 2025

Bridging the USD51 trillion gap: asset-intensive reinsurance in Bermuda

In this article we examine the rise and regulatory landscape of Asset-Intensive Reinsurance (AIR) in...

Appleby-Website-Privacy-and-Data-Protection
20 Mar 2025

PIPA Guidance on Financial Services (Bermuda)

This month, the Privacy Commissioner of Bermuda released his Financial Services Guidance Notes: Fin...

IWD Grid Capture
8 Mar 2025

International Women’s Day 2025 roundtable: Rights. Equality. Empowerment.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a...

Corporate
28 Feb 2025

Bermuda Monetary Authority’s proposed resilience code

The Bermuda Monetary Authority, which well understands the operational risks associated with financi...

Dispute Resolution
25 Feb 2025

Bermuda: An Introduction to Dispute Resolution 2025

The stable, competitive regulatory and legal regime in Bermuda continues to ensure its place as a hu...

Appleby-Website-Banking-and-Financial-Services
19 Feb 2025

Recent Updates on BVI, Cayman and Bermuda laws

Entities incorporated or registered in the British Virgin Islands (BVI), Cayman Islands and Bermuda ...

Appleby-Website-Employment-and-Immigration
18 Feb 2025

Fostering Respect: the Importance of Bullying and Sexual Harassment Policies in Bermuda (Part 2)

Under the Employment Act 2000 (EA), it is a requirement for an employer to not only have a compliant...

Technology and Innovation
31 Jan 2025

Bermuda Monetary Authority’s 2025 Tech Commitment

A focus on the crucial and enabling role that technology plays across all financial service sectors ...