CYPRUS DATA PROTECTION · PRIVACY · HOSPITALITY
The discovery of cameras in restaurant toilets has triggered urgent scrutiny of CCTV practices in Cyprus. For restaurants, hotels and entertainment venues, the legal issue is not whether surveillance may assist security. It is whether each camera is lawful, necessary and proportionate in the particular place where it is installed.
Grigoris Aivazidis · Lawyer and International Tax Adviser · Case Law & Commentary · 29 August 2026
The discovery of cameras in restaurant toilets is an extreme example of unlawful surveillance, but it also exposes a broader compliance problem. Many hospitality businesses install CCTV first and ask legal questions later. Cyprus data-protection law requires the reasoning to operate in the opposite direction.
Whether CCTV cameras in restaurants in Cyprus are lawful depends on more than the fact that a business wants security. The location of the camera, the people it records, the risk it is intended to address, the field of view and the availability of less intrusive measures all matter.
On 26 August 2026, Cyprus Commissioner for Personal Data Protection Maria Christofidou stated that cameras had been found in toilets at restaurants and other establishments. She described the installation of cameras in toilets as prohibited and announced on-site inspections of catering, entertainment and hotel venues from September. The statement was reported by Politis and Cyprus Mail.
The incident is significant well beyond the establishments in which cameras were reportedly found. CCTV is now widely used in restaurants, hotels, offices, retail spaces and apartment buildings. A system installed for a legitimate security purpose can still become unlawful if its cameras record people in places, or in ways, that cannot be justified.
The starting point is the Protection of Natural Persons with regard to the Processing of Personal Data and the Free Movement of such Data Law of 2018, Law 125(I)/2018, together with the General Data Protection Regulation, which applies directly in Cyprus.
The GDPR contains the substantive rules. The Cyprus Law regulates important local matters including the Commissioner’s powers, administrative fines and offences. The legal position is therefore not Cyprus law or EU law. The two operate together.
There is also a constitutional background. Article 15 of the Constitution protects private and family life. That protection carries particular weight where surveillance takes place in a space in which a person has an exceptionally strong and obvious expectation of privacy.
Where recorded footage makes an individual identifiable, the images are personal data. Recording, storing, viewing, retrieving and sharing those images are processing operations for GDPR purposes.
A restaurant, hotel or other venue operating such a system becomes responsible for complying with the data-protection framework. Article 5 GDPR requires processing to be lawful, fair and transparent. It must be collected for a specified and legitimate purpose, limited to what is necessary and retained no longer than necessary.
The issue is not whether surveillance might be useful. Many intrusive forms of surveillance may be useful to a business. The question is whether the particular use of surveillance is necessary and proportionate.
In private-sector CCTV cases, a business may seek to rely on legitimate interests under Article 6(1)(f) GDPR. Protecting property, preventing theft and maintaining security can be legitimate interests.
But that lawful basis has a limit. The processing must be necessary for the stated interest, and the business’s interest must not be overridden by the interests or fundamental rights and freedoms of the people recorded. What a person reasonably expects in the circumstances is relevant to that assessment.
A camera directed at a restaurant entrance after documented break-ins is very different from a camera installed in its toilets. The security objective may be identifiable in both cases, but the connection between filming and the objective, and the gravity of the privacy intrusion, are not remotely comparable.
For cameras inside restaurant toilets, the balancing exercise is exceptionally difficult for a business to survive. The Commissioner has publicly described the practice as prohibited.
The European Data Protection Board gives an almost identical example in its Guidelines 3/2019 on processing of personal data through video devices. It considers a restaurant proposing cameras in sanitary facilities to monitor cleanliness and concludes that the rights of the individuals override the restaurant’s interests. People reasonably expect not to be monitored in toilets.
A business may point to vandalism, drug use, theft or hygiene. Those concerns may be genuine. The problem is proportionality. Staff inspections, access control, physical security arrangements, reporting procedures and, where lawful, cameras outside the area are less intrusive alternatives. Their availability makes it very difficult to argue that recording people while they use sanitary facilities is necessary.
The analysis does not end with the text of the GDPR. The Commissioner’s Office continues to list its 2004 Video Surveillance Directive among the applicable Cyprus CCTV instruments, together with later guidance and the EDPB video-surveillance guidelines.
Businesses should therefore assess their systems against the GDPR, Law 125(I)/2018 and the supervisory approach of the Cyprus Commissioner. A CCTV policy copied from another jurisdiction, or prepared only after installation, is not a substitute for that assessment.
A hidden camera makes the legal position worse because it creates additional transparency concerns. The GDPR ordinarily requires people to be informed about CCTV processing.
But concealment is not the central issue in a toilet. A prominent sign reading “CCTV operates inside these toilets” would not legalise the surveillance. Transparency is only one requirement. The processing must still have a lawful basis and satisfy necessity, proportionality and data-minimisation requirements.
If the surveillance itself cannot be justified, signage cannot cure it.
CCTV is not generally prohibited in restaurants and hotels. Certain locations may be capable of justification where there is a real security risk and the camera is directed only at what genuinely needs protection.
An entrance or exit is different from a toilet. A cash register is different from an entire dining room. A hotel service entrance is different from a swimming pool, leisure area or changing space. The correct assessment should be camera-specific.
For each camera, a business should be able to explain the precise risk addressed, why CCTV is necessary, whether a less intrusive measure is available, what the camera records, how long footage is retained, who may access it and how people have been informed.
No. A Data Protection Impact Assessment is a risk-assessment mechanism. It is not a permit that converts otherwise unlawful surveillance into lawful surveillance.
Article 35 GDPR requires a DPIA where processing is likely to result in a high risk to individuals’ rights and freedoms, with large-scale systematic monitoring of publicly accessible areas identified as a relevant category. The Commissioner referred to impact assessments when discussing businesses operating lawfully, but the purpose of an assessment is to identify and address the risk before processing begins.
If the assessment shows that the surveillance is fundamentally disproportionate, the correct result may be not to install the camera. A DPIA cannot authorise CCTV inside a restaurant toilet.
The Commissioner’s announced inspections should be taken seriously. Law 125(I)/2018 gives the Commissioner additional investigative powers alongside Article 58 GDPR, including powers relevant to access to information, premises and systems.
CCTV compliance cannot therefore exist only on paper. During an inspection, the actual camera angles, recording equipment, storage arrangements, access controls and areas under surveillance may matter as much as the written policy.
Businesses should be ready to demonstrate what their cameras actually record, why each recording is necessary and what practical protections operate around the footage.
There are several possible layers of exposure. Under Article 83 GDPR, infringements of core principles such as Articles 5 and 6 can attract administrative fines of up to €20 million or, for an undertaking, up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher. Those are statutory maximums, not an automatic fine for every unlawful installation.
Section 32 of Law 125(I)/2018 provides for administrative fines in accordance with Article 83. The Cyprus Law also contains criminal offences in specified circumstances. For example, section 33 includes failures to conduct a required DPIA among the offences listed there.
The actual consequence will depend on the nature, gravity and duration of the infringement, the steps taken by the business, the people affected and the Commissioner’s assessment of the facts.
Regulatory enforcement is separate from the rights of individuals. Article 82 GDPR allows a person who has suffered material or non-material damage because of an infringement to seek compensation.
The Court of Justice has made clear in Österreichische Post, C-300/21 that an infringement alone is not sufficient. The claimant must establish an infringement, damage and a causal link. At the same time, the Court confirmed that non-material damage is not subject to a separate minimum seriousness threshold.
For someone recorded while using a toilet, the facts would matter enormously, including whether footage was stored, who accessed it, whether it was shared and what impact the person suffered.
Restaurants, hotels and entertainment venues should review their CCTV systems now, before an inspection or complaint forces the issue. The review should begin with the physical site, not a standard policy.
Each camera should have a documented purpose, a defined field of view, a retention rule, controlled access and a clear answer to the question why less intrusive measures are not sufficient. Cameras in toilets, changing facilities or comparable privacy-sensitive locations should be removed rather than rationalised after the fact.
Where a business has a specific concern about vandalism, theft or misconduct, it should record the incidents, identify the actual risk and implement a proportionate response. Wider coverage may be commercially tempting, but data-protection law requires discipline rather than convenience.
The cameras reportedly discovered in restaurant toilets provide a clear example of where the security interests of a business end and the privacy rights of the individual prevail.
The applicable framework includes the GDPR, Law 125(I)/2018, the Commissioner’s continuing CCTV framework and the constitutional protection of private life. A restaurant cannot justify surveillance inside its toilets simply by invoking security, displaying a CCTV notice or preparing an impact assessment.
The question for a business is not whether CCTV would be useful. It is whether each individual act of surveillance is lawful, necessary and proportionate under Cyprus law.
This publication provides general information and legal commentary on Cyprus data-protection law and CCTV surveillance. It does not constitute legal advice concerning any particular establishment, surveillance system or individual claim. The legality and potential consequences of CCTV processing depend on the particular facts, including the camera location, purpose, field of view, retention arrangements, persons affected and manner in which the footage is accessed or used.
What makes this incident striking is that it is not a difficult borderline CCTV case.
There are legitimate questions around surveillance. A restaurant may need to protect an entrance after repeated burglaries. A hotel may need to secure a cash-handling area. Those cases require an honest assessment of necessity and proportionality.
A camera inside a toilet is different. The privacy intrusion is so serious, and the expectation of privacy so strong, that an ordinary commercial security justification cannot carry the same weight.
The wider lesson is not merely “do not put cameras in toilets”. It is that every camera should have a legal justification before it has a physical location. Identify the risk first, assess whether surveillance is necessary, consider less intrusive alternatives, and then decide where a camera can be positioned without recording more than is required.