Skip to main content

Bermuda

A tangle of red cable resolving into ordered documents as it passes through Bermuda, ending at a Canadian seal

Canadian business with a Bermuda entity

Your Canadian privacy programme does not travel as far as you think

Most of it does. The parts that do not are few, specific, and expensive to find late — and three of them have no Canadian equivalent at all, so there is nothing to map them from. We assess the difference. We do not then build it for you.

72 hours

To report a material cyber event to the Bermuda Monetary Authority — from becoming aware it occurred or may occur.Cyber Risk Code

45 days

To answer an access request under PIPA, extendable by 30. Canada runs a different clock.PIPA

31 March 2028

Compliance deadline for operational resilience, with an annual self-assessment before it.Resilience Code

$250,000

Maximum fine for an organisation. Directors and officers can be personally liable.PIPA offences

Two regulators, and most people only know about one

A Canadian group with a Bermuda subsidiary usually discovers Bermuda privacy law first, if at all. Bermuda's Personal Information Protection Act reached full implementation on 1 January 2025 and is enforced by the Office of the Privacy Commissioner. That much tends to arrive by email from a law firm.

What arrives later, and matters more to an insurance entity, is that the Bermuda Monetary Authority has required a cyber risk management programme since 2021 — including an annual internal assessment covering data protection law compliance. In Bermuda that law is PIPA. So privacy is not a legal-department matter sitting to one side of the business; it is inside an assessment obligation owed to the prudential regulator.

The two regimes do not line up, and the clearest place to see it is an incident. One set of facts, assessed twice, against two different tests, on two different clocks — and an incident can cross one threshold and not the other.

What your Canadian programme already covers

  • Accountability, with a designated individual
  • Consent as the primary ground for using personal information
  • Sensitivity judged in context, case by case
  • Openness about policies and practices
  • Access requests answered within 30 days
  • Breach reporting on a real risk of significant harm, with a 24-month breach log
  • Accountability for transfers, discharged by contract

What Bermuda still wants

  • A named privacy officer, published in the notice
  • Eight conditions of use, of which consent is only one
  • A statutory list of sensitive information, needing explicit consent
  • Prescribed notice content, including the officer's name and the deletion right
  • 45 days, extendable by 30
  • Notification where a breach is likely to adversely affect an individual
  • A documented assessment of protection before information leaves Bermuda

Three of these cannot be met by mapping something you already have, because Canada has no equivalent: the statutory category of sensitive information, the right to deletion, and the assessment required before a transfer.

Why this work goes offshore

In a jurisdiction of 64,000 people, independence is structurally hard

The pool of qualified assessors on the island is small, and the firms best placed to audit a control set are frequently the firms that built it. That is not a criticism of anyone; it is arithmetic. It is also the exact conflict this practice exists to refuse, which is why an off-island assessor is not a second-best option in Bermuda — it is the straightforward way to get an opinion nobody has to discount.

We do not remediate what we assess. In Bermuda that rule is worth more than it is anywhere else.

What we do

Start here · free

The delta sheet. Ten places where PIPA asks for something PIPEDA does not, with room to record where you stand and who owns it.

  • What your programme already covers, and what it does not
  • The three areas that have to be built rather than mapped
  • Counts itself once you have filled it in

Free

No form, no email required. Take it and use it.

For the certified

You hold ISO/IEC 27001:2022. This is what the BMA's two codes still want that the standard does not give you.

  • Ten requirements mapped against the standard
  • Seven covered or close to it; three not
  • Two of those three no certificate can ever satisfy

CAD $95

Buy the BMA to ISO 27001 delta — CAD $95

Secure checkout by Stripe · files emailed within one working day. Includes the scope trap most groups miss: whether the certificate covers the Bermuda entity at all.

The two-hour question

Does your group's ISO 27001 certificate actually include the Bermuda entity? Group certificates routinely exclude small offshore subsidiaries, and a certificate that excludes the entity evidences nothing about it.

CAD $450

Buy the scope check — CAD $450

Secure checkout by Stripe · your written answer within five working days of us receiving your certificate scope. Often the cheapest uncomfortable finding you will buy.

The assessment

Cross-border data map and transfer assessment. Which entity is responsible for what, what information crosses, which safeguards apply, and what evidence exists that anyone decided it on purpose.

CAD $1,450

Invoiced rather than paid by card, because we scope it with you first. Fixed price, agreed before we start, and delivered with a transfer register you keep.

Scoped work

Priced on scope

The dual-clock incident exercise. One incident, three regulators, three thresholds, three clocks. The Cyber Code requires response and recovery to be tested annually, so this is a fixture rather than a one-off.

Priced on scope

Independent validation of your resilience self-assessment. A self-assessment a board signs without external challenge is the board's own opinion of itself.

Priced on scope

Assurance on the parent as the service provider. Where the Bermuda entity's outsourcing arrangement is your Canadian shared service centre, the parent is the third party under supervision. We assess it and you hand the result to your subsidiary.

Priced on scope

A board session, not a report. Ninety minutes with a Canadian board on what its Bermuda subsidiary exposes it to, including the personal liability its directors may not know they carry.

Physical security assessment is delivered on the island. Travel is quoted separately and at cost.

Who would do the work

Maya Chen

Maya Chen

Canada and Bermuda privacy governance

Works across Canadian privacy law and Bermuda's PIPA, on which entity is responsible, what crosses a border, and what evidence exists that it was decided deliberately. Holds CIPP/C, CIPP/E, CIPM, FIP and CDPSE.

Henry Cole

Henry Cole

Security assessment and incident work

Takes the technical and physical half: control testing, incident response, and translating what a review found into what a board has to decide. Holds CISA, CISSP, CRISC and CISM, all verifiable by public register.

You will be told who is working on your engagement before it starts, and what they are certified in. The rest of the team is here.

What we will not do

We will not be your outsourced CISO

The BMA's Cyber Risk Code expressly permits that function to be outsourced, and it would be good recurring revenue. We will not take it from an organisation we assess, because it is remediation wearing a job title. We also do not place insurance, and this is not legal advice — we are not admitted in Bermuda, and questions of interpretation belong with Bermuda counsel. We will say so rather than guess.

It costs us work. That is what makes the findings worth anything.

There is no charge for the first conversation and no obligation at the end of it. If your exposure turns out to be smaller than you feared, we will tell you that rather than sell you something.

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.