Skip to content

Privacy Compliance

Duncan Card was consulted by the Bermuda Government is 2015 on the drafting of Bermuda’s Personal Information Protection Act 2016, as it more closely follows the privacy legislation in Canada than it does either GDPR data protection law or the Data Protection Act 2018 in the United Kingdom. Prior to leaving his Senior Partnership at Bennett Jones LLP in Canada, and returning to Bermuda to practice law in 2022, Duncan practiced privacy law under very similar legislation to PIPA for almost 20 years.

Today, Duncan is one of the most recognized and sought after authors and professional development speakers on privacy compliance in Bermuda. In the last 4 years, Duncan has provided privacy compliance advice and compliance assistance to over 150 organizations, including: several very well recognized public authorities in Bermuda; many financial service enterprises ( including banks; insurance and reinsurance enterprises ); small to medium size local businesses; many publicly traded multinational corporations; numerous captive insurers and holding companies alike; and, to trade associations ( and their members ) like the Bermuda Health Council, the Bermuda Chamber of Commerce, the Institute of Directors ( Bermuda), the Bermuda Bar Association, and the Bermuda Human Resources Association.

Duncan’s many privacy compliance articles are listed on this website, and even though he no longer practices law, he continues to actively write and teach in this field, and ( through The Advisory Group) provide advice and assistance on all aspects of PIPA compliance and governance matters, including: 

  • PIPA Compliance Audits ( Assessments ) under our “Are you really in compliance with PIPA” review process;
  • How to manage “Access to Personal Information Requests” in response to both internal ( employees ) and external ( clients, patients and customers ) requests;
  • Privacy Officer training and supportive advisory assistance;
  • Advice concerning Privacy Commissioner relations and communications;
  • Security breach reporting and management obligations;
  • Board of Director and C-Suite PIPA governance and compliance presentations;
  • Organization staff and management training on all aspects of PIPA compliance;
  • Privacy Notice reviews and improvements;
  • Consulting services related to digital transformation and PIPA compliance;
  • Consulting services related to AI development and use in compliance with PIPA ( avoiding the compliance pit-falls ) ;
  • Advice related to section 15 export of Personal Information allowance requirements and strategies;
  • All PIPA exclusions, exemptions and qualified exceptions for organizations;
  • Assistance with PIPA’s requirement to “adopt suitable measures and policies” to comply with PIPA at section 5 (1).