In Bermuda, direct marketing is not governed by a particular law. While email campaigns, phone calls and text messages are central to how businesses reach customers, each of these channels are governed by several laws working together: the Personal Information Protection Act 2016 (“PIPA”), the Electronic Transactions Act 1999 (the “ETA”) and its Standard for Electronic Transactions (the “ETA Standard”), the Electronic Communications Act 2011 (the “ECA”) and the Telecommunications Act 1986. PIPA came fully into force on 1 January 2025, organisations that use personal information for marketing in Bermuda must be in compliance with this privacy framework.

Members of the Conyers Bermuda Regulatory and Risk Advisory team contributed to the Direct Marketing Guidance Note recently published by OneTrust DataGuidance (the “Guidance Note”). The Guidance Note examines the key legal considerations for eMarketing, telemarketing and SMS marketing in Bermuda. It also offers practical insight for businesses navigating Bermuda’s evolving privacy and data protection landscape.

This article summarises the main points in the Guidance Note, focusing on how PIPA and the ETA apply in practice.

Which Laws Regulate Email, Telephone and SMS Marketing in Bermuda?

Broadly, the same legal frameworks apply to email, telephone and SMS/MMS marketing, and additional legislative requirements may also be relevant. The Consumer Protection Act 1999 prohibits unfair business practices, including misleading or deceptive marketing. The Investment Business Act 2003 restricts entering into investment agreements as a result of unsolicited calls. Guidance from the Office of the Privacy Commissioner (“PrivCom”) also applies, including the Guide to PIPA (October 2024) and the Financial Services Providers Guidance Notes (March 2025).

Notably, Bermuda law does not define “direct marketing”, “telemarketing”, “spam” or “B2B marketing”.

Who Enforces Bermuda’s Direct Marketing Rules?

PrivCom enforces PIPA, including where personal information is used for marketing. Additionally, the Regulatory Authority of Bermuda (the “RA”) can make general determinations under the ECA governing unsolicited electronic direct marketing, including automated calling systems and email. Domestic providers in the electronic communications sector (“Sectoral Providers”) are also subject to the RA’s Consumer Protection General Determination.

Can Overseas Companies Market to Bermuda Customers?

Overseas companies should exercise caution. Marketing to Bermuda customers could amount to carrying on business in Bermuda, which is prohibited without a permit under the Companies Act 1981. Whether it does depends on the facts, including how often and in what way the activity takes place. In general, marketing will not breach the prohibition if the company has no presence or premises in Bermuda, and the activity is conducted from outside Bermuda and initiated by the Bermuda person (a “reverse inquiry”).

Bermuda organisations that use overseas marketing platforms or databases remain responsible for PIPA compliance.

What Legal Bases Can Organisations Rely On to Market Under PIPA?

“Legitimate interest”, as found in the GDPR, is not a recognised basis under PIPA. Instead, the main bases for marketing are:

  • Consent;
  • reasonable expectation, which works in a similar but not identical way to legitimate interest and is not available for sensitive personal information; and
  • public availability, where the information is used consistently with the purpose for which it was made public.

Under section 19 of PIPA, individuals have the right to ask an organisation to stop, or not start, using their information for marketing. No prior assessment is legally required before marketing begins. Even so, organisations should check whether PIPA applies and whether a Companies Act permit is needed.

What Does Valid Consent Look Like?

Organisations must provide clear, prominent, easily understood and accessible ways for people to give consent. Consent may be implied from a person’s conduct, except for sensitive personal information. Personal information held before PIPA came into force is treated as having been collected with consent if used consistently with its original purpose.

In practice, Bermuda uses a mixed consent model:

  • opt-in for general use;
  • explicit opt-in for sensitive personal information; and
  • opt-out for marketing.

Consent has no fixed expiry date. It lasts until it is withdrawn, an objection is made under section 19 of PIPA, or its purpose is fulfilled.

What Must Organisations Tell Individuals Before Marketing to Them?

Organisations subject to PIPA are generally obliged to give a privacy notice before or at the time they collect personal information. The notice must cover:

  • the purposes for which the information is used;
  • who it may be disclosed to;
  • the organisation’s identity and contact details;
  • the privacy officer’s contact details; and
  • the individual’s options for limiting use of, accessing, correcting and erasing their information.

No particular format is required, provided the information is clear and accessible. There is also no express requirement to tell people that a call or message is automated.

What Are the Consequences of Non-Compliance?

Failure to comply with PIPA can lead to civil claims. Under section 21 of PIPA, an individual who suffers financial loss or emotional distress because an organisation has not complied with PIPA is entitled to compensation from that organisation. The court determines the amount of compensation for each contravention.

PrivCom cannot impose monetary penalties directly. Following an inquiry, however, it may make orders, including an order requiring an organisation to stop using or to destroy personal information. PIPA offences include willfully or negligently using personal information in a way that is inconsistent with PIPA and likely to cause harm. PIPA offences carry fines of up to $25,000 and/or two years’ imprisonment for individuals, and up to $250,000 for entities.

Where a company commits an offence with the consent or connivance of a director, manager, secretary or similar officer, or because of that person’s neglect, that person is also guilty of the offence and may be prosecuted.

Under the ETA, an intermediary or e-commerce service provider that fails to comply with the ETA Standard can be fined $5,000 if a ministerial warning is not followed. Finally, sending messages intended to cause annoyance or needless anxiety is an offence under section 68 of the ECA.

Conclusion

PIPA sits at the centre of Bermuda’s direct marketing rules. Businesses that use clear consent mechanisms, give proper privacy notices, honour opt-outs and consider regulatory restrictions will be well placed to market effectively and lawfully.

Contact the authors of this article or another member of the Bermuda Regulatory & Risk Advisory team to discuss your business’ regulatory compliance obligations.

Read the full Guidance Note here.

Stay current with our latest legal insights. Subscribe today.