
Canadian business with a Bermuda entity
Your Canadian privacy programme does not travel as far as you think
Most of it does. The parts that do not are few, specific, and expensive to find late — and three of them have no Canadian equivalent at all, so there is nothing to map them from. We assess the difference. We do not then build it for you.
72 hours
To report a material cyber event to the Bermuda Monetary Authority — from becoming aware it occurred or may occur.Cyber Risk Code
45 days
To answer an access request under PIPA, extendable by 30. Canada runs a different clock.PIPA
31 March 2028
Compliance deadline for operational resilience, with an annual self-assessment before it.Resilience Code
$250,000
Maximum fine for an organisation. Directors and officers can be personally liable.PIPA offences
Two regulators, and most people only know about one
A Canadian group with a Bermuda subsidiary usually discovers Bermuda privacy law first, if at all. Bermuda's Personal Information Protection Act reached full implementation on 1 January 2025 and is enforced by the Office of the Privacy Commissioner. That much tends to arrive by email from a law firm.
What arrives later, and matters more to an insurance entity, is that the Bermuda Monetary Authority has required a cyber risk management programme since 2021 — including an annual internal assessment covering data protection law compliance. In Bermuda that law is PIPA. So privacy is not a legal-department matter sitting to one side of the business; it is inside an assessment obligation owed to the prudential regulator.
The two regimes do not line up, and the clearest place to see it is an incident. One set of facts, assessed twice, against two different tests, on two different clocks — and an incident can cross one threshold and not the other.
What your Canadian programme already covers
- Accountability, with a designated individual
- Consent as the primary ground for using personal information
- Sensitivity judged in context, case by case
- Openness about policies and practices
- Access requests answered within 30 days
- Breach reporting on a real risk of significant harm, with a 24-month breach log
- Accountability for transfers, discharged by contract
What Bermuda still wants
- A named privacy officer, published in the notice
- Eight conditions of use, of which consent is only one
- A statutory list of sensitive information, needing explicit consent
- Prescribed notice content, including the officer's name and the deletion right
- 45 days, extendable by 30
- Notification where a breach is likely to adversely affect an individual
- A documented assessment of protection before information leaves Bermuda
Three of these cannot be met by mapping something you already have, because Canada has no equivalent: the statutory category of sensitive information, the right to deletion, and the assessment required before a transfer.
Why this work goes offshore
In a jurisdiction of 64,000 people, independence is structurally hard
The pool of qualified assessors on the island is small, and the firms best placed to audit a control set are frequently the firms that built it. That is not a criticism of anyone; it is arithmetic. It is also the exact conflict this practice exists to refuse, which is why an off-island assessor is not a second-best option in Bermuda — it is the straightforward way to get an opinion nobody has to discount.
We do not remediate what we assess. In Bermuda that rule is worth more than it is anywhere else.
What we do
The delta sheet. Ten places where PIPA asks for something PIPEDA does not, with room to record where you stand and who owns it.
- What your programme already covers, and what it does not
- The three areas that have to be built rather than mapped
- Counts itself once you have filled it in
Free
No form, no email required. Take it and use it.
You hold ISO/IEC 27001:2022. This is what the BMA's two codes still want that the standard does not give you.
- Ten requirements mapped against the standard
- Seven covered or close to it; three not
- Two of those three no certificate can ever satisfy
CAD $95
Buy the BMA to ISO 27001 delta — CAD $95
Secure checkout by Stripe · files emailed within one working day. Includes the scope trap most groups miss: whether the certificate covers the Bermuda entity at all.
Does your group's ISO 27001 certificate actually include the Bermuda entity? Group certificates routinely exclude small offshore subsidiaries, and a certificate that excludes the entity evidences nothing about it.
CAD $450
Buy the scope check — CAD $450
Secure checkout by Stripe · your written answer within five working days of us receiving your certificate scope. Often the cheapest uncomfortable finding you will buy.
Cross-border data map and transfer assessment. Which entity is responsible for what, what information crosses, which safeguards apply, and what evidence exists that anyone decided it on purpose.
CAD $1,450
Invoiced rather than paid by card, because we scope it with you first. Fixed price, agreed before we start, and delivered with a transfer register you keep.
Scoped work
Priced on scope
The dual-clock incident exercise. One incident, three regulators, three thresholds, three clocks. The Cyber Code requires response and recovery to be tested annually, so this is a fixture rather than a one-off.
Priced on scope
Independent validation of your resilience self-assessment. A self-assessment a board signs without external challenge is the board's own opinion of itself.
Priced on scope
Assurance on the parent as the service provider. Where the Bermuda entity's outsourcing arrangement is your Canadian shared service centre, the parent is the third party under supervision. We assess it and you hand the result to your subsidiary.
Priced on scope
A board session, not a report. Ninety minutes with a Canadian board on what its Bermuda subsidiary exposes it to, including the personal liability its directors may not know they carry.
Physical security assessment is delivered on the island. Travel is quoted separately and at cost.
Who would do the work
Maya Chen
Canada and Bermuda privacy governance
Works across Canadian privacy law and Bermuda's PIPA, on which entity is responsible, what crosses a border, and what evidence exists that it was decided deliberately. Holds CIPP/C, CIPP/E, CIPM, FIP and CDPSE.
Henry Cole
Security assessment and incident work
Takes the technical and physical half: control testing, incident response, and translating what a review found into what a board has to decide. Holds CISA, CISSP, CRISC and CISM, all verifiable by public register.
You will be told who is working on your engagement before it starts, and what they are certified in. The rest of the team is here.
What we will not do
We will not be your outsourced CISO
The BMA's Cyber Risk Code expressly permits that function to be outsourced, and it would be good recurring revenue. We will not take it from an organisation we assess, because it is remediation wearing a job title. We also do not place insurance, and this is not legal advice — we are not admitted in Bermuda, and questions of interpretation belong with Bermuda counsel. We will say so rather than guess.
It costs us work. That is what makes the findings worth anything.
There is no charge for the first conversation and no obligation at the end of it. If your exposure turns out to be smaller than you feared, we will tell you that rather than sell you something.