Category: Privacy

Your Security Camera Vendor Wants to Cover Your Bathroom – Is that Worth 3 Years in Jail?

A security vendor offers you a great deal: a full camera package for your office or clinic, including units for “every room” — bathrooms included. Before you say yes, here’s the one word that should stop you: no.

Installing a camera in a bathroom isn’t a gray area. In most states, it’s either a specific criminal offense, an actionable civil tort, or both — regardless of whether you own the building, whether employees consented to “general” workplace monitoring, or whether your intent was purely about theft prevention.

All Kinds of Laws and Regulations Are Against Your Vendor’s Sales Pitch

Video surveillance law in the U.S. is a patchwork, but one principle is close to universal: people have a reasonable expectation of privacy in spaces where they may be nude or partially undressed — bathrooms, locker rooms, and changing areas top that list in nearly every jurisdiction.

The following layers of law apply here:

1. The federal wiretap/ECPA gap doesn’t help you here. Most security cameras don’t record audio, which is why they generally fall outside the federal Wiretap Act and the Electronic Communications Privacy Act (those statutes govern communications, not silent video). Business owners sometimes hear “no audio recorded, no ECPA problem” and assume that means video is unregulated. It isn’t. ECPA’s silence on soundless video just means you have to look elsewhere — and state law fills that gap fast, especially for restrooms.

2. State statutes specifically ban restroom and changing-area recording. California, for example, expressly forbids video recording in restrooms, locker rooms, and places where people change clothes. Many states have similar “video voyeurism” or “unlawful surveillance” statutes that criminalize recording — or even just installing recording equipment — in a place where someone has a reasonable expectation of privacy, whether or not any footage is ever viewed or used. These are often felony-level offenses, and consent from you as the business owner is irrelevant; the person being recorded is the one whose consent (or knowledge) matters.

3. Healthcare and other regulated settings add another layer. If you run a medical office, a bathroom camera also raises immediate collateral problems: patients or staff visible on camera in a restroom implicates dignity and privacy obligations that go well beyond HIPAA’s technical safeguards — it’s the kind of fact pattern that turns into a licensing board complaint, a media story, or both.

4. Even without a specific statute, common law will find you. Every U.S. jurisdiction recognizes some version of the tort of intrusion upon seclusion: intentionally intruding on someone’s private affairs in a way that would be “highly offensive to a reasonable person.” A camera in a bathroom is the textbook example courts use to illustrate this tort. That means even in a state without a dedicated criminal statute, an employee, patient, or customer who discovers the camera can sue you civilly — and juries tend to have little patience for this fact pattern.

What Does Puerto Rico’s Constitution and Penal Code Say?

If you operate in Puerto Rico, your exposure is arguably higher than in the 50 states, as the right to privacy here isn’t left to a patchwork of state statutes and common-law torts. It’s written directly into the Constitution.

Article II, Section 8 of the Puerto Rico Constitution states: “Toda persona tiene derecho a protección de ley contra ataques abusivos a su honra, a su reputación y a su vida privada o familiar” (Every person has the right to protection of law against abusive attacks on their honor, reputation, and private or family life). What makes this different from the U.S. Constitution is that the Puerto Rico Supreme Court has held that this right applies directly between private parties, not just against government action. In Arroyo v. Rattan Specialties, Inc., 117 D.P.R. 35 (1986), the Court held that the right to privacy operates ex propio vigore — on its own force — and can be asserted by one private citizen against another, including an employer against an employee. That means a bathroom camera dispute in Puerto Rico doesn’t need a separate statute to become a constitutional violation; the Constitution itself solves the controversy.

The Puerto Rico Penal Code then backs this up with a specific criminal provision. Article 168 of the Puerto Rico Penal Code, titled “Illegal recording of images”, makes it a crime for any person, without legal justification or a legitimate investigative purpose, to use electronic or digital video equipment — with or without audio — to conduct secret surveillance in private places, or in any other place where a reasonable expectation of privacy exists. A bathroom is about as clear an example of that as exists. Conviction of this crime carries a 3 year imprisonment penalty, and if the convicted party is a corporation (or any legal person), they face a criminal fine of up to $10,000, on top of civil liability.

Put together, that’s 3 independent legal problems stacked on top of each other for accepting the salesperson’s offer: a constitutional privacy violation that doesn’t require a lawsuit-specific statute to exist, a specific criminal statute naming the conduct, and civil liability for damages. There’s no version of “we didn’t think it applied to us” that survives this situation.

What Will “Getting This Wrong” Cost You?

You will face real exposure across all fronts, notably:

  • Criminal liability: Many state voyeurism/unlawful surveillance statutes are felonies, carrying fines and potential jail time for the person who installs or operates the equipment — that could be you, personally, not just “the business.”
  • Civil damages: Intrusion-upon-seclusion claims, among other tort claims, can result in compensatory damages, and courts in the US have allowed punitive damages where the conduct is found egregious — a bathroom camera is close to the paradigm case.
  • Employment claims: If the person recorded is an employee, expect this to also surface as a hostile work environment or wrongful termination claim if discipline follows the discovery.
  • Reputational cost: Unlike a data breach notice, this is the kind of story that runs on local news with your business’s name in the headline. There’s no regulator fine that costs you more than the client and patient trust it destroys.

Why Should You Care About This?

Because although you might think the sales pitch sounds reasonable, you could end up in a lot of trouble. “Fully covered and protected business” sounds like a good security practice, and most business owners installing these systems aren’t trying to do anything invasive — they’re thinking about delivery problems, break-ins, shoplifting, and slip-and-fall liability. However, your good intent doesn’t matter for most of these statutes, and it won’t matter to a jury either. The law doesn’t ask whether you meant well; it asks whether a reasonable person would find being recorded in that space highly offensive. In a bathroom, the answer is already decided.

This is also a useful moment to audit your entire camera plan, not just the bathroom question — because the same vendor conversation is a good opportunity to think through where cameras are legally fine (entrances, sales floors, hallways, parking areas) versus where they cross the line (restrooms, break-rooms used for nursing mothers, private offices with an expectation of confidentiality).

What Can You Do to Comply?

  1. Decline any bathroom, locker room, or changing-area camera outright. There’s no notice, consent form, or signage that fixes this. Don’t install it, and don’t let a vendor bundle it into a package “in case you change your mind.”
  2. Map your camera locations against expectation-of-privacy zones. Entrances, registers, storage, parking, and common work areas are generally fine. Restrooms, changing rooms, and private offices are not.
  3. Put your monitoring policy in writing. For the cameras you do install, a written policy — reviewed by an attorney — that discloses locations, purpose, and retention helps establish notice and reduces the risk of a monitoring-related claim from staff.
  4. Check your state’s specific statute. Voyeurism and unlawful-surveillance laws vary — some cover only “for sexual gratification” purposes, others cover any recording in a private space regardless of purpose. If you operate in Puerto Rico, the relevant provision is Article 168 of the Penal Code — broader than many mainland statutes since it isn’t limited to a sexual-purpose requirement.
  5. Train whoever manages the footage. Access controls and retention limits for legitimate camera footage matter too — who can view it, how long it’s kept, and how it’s secured.

The Bottom Line

Say yes to the cameras. Say no to the bathroom units — every time, no exceptions, regardless of how the package is bundled or how good the discount is. This is one of the few areas of privacy law where there’s no compliant way to do the thing at all; the only right answer is not installing it.

If you’re building out a security camera plan for your office, clinic, or retail space and want a compliance check before you sign anything, book a consultation — better to ask before the cameras go up than after.

This post is for general informational purposes and does not constitute legal advice. Camera and surveillance laws vary by state; consult an attorney about the rules that apply to your specific location and industry.

A Puerto Rico Agency Exposed 1 Million Social Security Numbers and Denied Anything Happened. What Would You Do If This Happened to Your Business?

Can a government agency simply decide a data exposure doesn’t count as a breach — and walk away from its notification duties because of that decision? This is presently playing out in Puerto Rico. Investigative reporters at Centro de Periodismo Investigativo and ProPublica discovered that CRIM (Puerto Rico’s Municipal Revenue Collection Center) had a security gap in its public property-mapping tool, Catastro Digital, that let anyone who understood how the site requested data download unprotected personal information — including the Social Security numbers of roughly 1 million people — without ever needing a username or password. 

The reporters notified CRIM directly in mid-June, with specifics on the exact server and folders involved. CRIM’s executive director publicly denied any breach had occurred, said the agency wouldn’t notify affected citizens because no protected information was “at risk,” and — separately — never reported the incident to the Puerto Rico Innovation and Technology Service (“PRITS”), Puerto Rico’s own government IT oversight agency, despite a legal requirement to do so. Whatever position CRIM ultimately takes, this is a useful, real case study in exactly what Puerto Rico law requires when personal data is exposed — and what happens when an entity takes the position that it wasn’t.

Two Different Puerto Rico Laws Are in Play Here — And They Point in Different Directions

This story is a good illustration of something worth understanding clearly: Puerto Rico has two separate statutes governing incidents like this, and they don’t route to the same place.

  1. Puerto Rico’s Cybersecurity Law, Law Number 40 of January 18, 2024 (“Law 40“) – This law applies government agencies and government contractors. CRIM is a government agency, so it is bound by Act 40’s requirements: set minimum cybersecurity standards, conduct mandatory annual risk assessments, and — central to this story — establish a protocol requiring agencies to inform PRITS (Puerto Rico’s Innovation & Technology Service) of any suspected security incident. According to CPI and ProPublica, CRIM did not do that here.
  2. The Puerto Rico Data Breach Notification Act, Law Number 111 of 2005 (“Law 111”) — the breach notification law covered in our previous post about Oriental and Evertec — applies broadly. Its definition of “entity” explicitly includes agencies, boards, commissions, and instrumentalities of all 3 branches of Puerto Rico’s government, not just private businesses. CRIM, as a government agency, appears to be as covered by Law 111 as much as Oriental Bank. The law’s trigger — unauthorized access to a personal information file containing a name paired with a Social Security number, readable without special encryption — maps directly onto what was reportedly exposed here.

These statutes differ on which agency handles a breach. Under Article 7 of Law 111, when a breach happens at a government agency or public corporation, jurisdiction doesn’t go to DACO (the path a private business like Oriental Bank would follow) — it goes to the Puerto Rico Ombudsman (Oficina del Procurador del Ciudadano), which is required to designate a specialized prosecutor for exactly this kind of case. That’s a meaningfully different enforcement track than the private-sector cases we covered before.

“I Don’t Run a Government Agency. Why Should I Care About This?”

If you’re a business owner reading this and thinking “I’m not a government agency, so this doesn’t apply to me” — here are a few reasons why this story is still directly relevant to you:

  • If you have contracts with the Puerto Rican Government, its municipalities, or public corporations, Law 40 might apply to you. Article 2 of the Law extends its applicability to government contractors with regards to the public services it provids and information generated through the contracts. If you have a contract with the government, you should know exactly how Law 40 affects your work.
  • “We don’t think it’s a breach” isn’t a compliance strategy — it’s a gamble. Law 111’s notification trigger is unauthorized access to protected personal information, not a company’s (or agency’s) own characterization of the severity. If your business takes the position that an exposure “doesn’t count,” you’re making a legal judgment call that a regulator, a court, or an investigative reporter could later disagree with — and by then, the notification clock has already been running and you will face substantial penalties.
  • Discovery by a third party is worse than discovery by you. CRIM didn’t find this — journalists did, gave the agency specifics, and still got a public denial. If your business’s data breach is discovered by a customer, a competitor, or a reporter instead of your own IT department, the story becomes as much about the response as the incident itself.
  • Vendor and platform exposure isn’t limited to obvious “hacks.” This wasn’t a sophisticated intrusion — it was a public-facing tool that simply didn’t properly protect the access to underlying personal data. The same category of risk exists anywhere a business exposes forms, APIs, dashboards, or downloadable reports to the public without checking exactly what data those tools can actually return.
  • A slow or defensive public response compounds the exposure. Whatever the legal outcome here, the reputational and regulatory scrutiny that follows a denial — rather than a prompt, transparent response — tends to be worse than the underlying incident, especially once the story is already public.

Is Your Business Ready if Something Like This Happened to It?

  • Treat “is this a breach?” as a legal question, not a public relations question. Run any exposure through Law 111’s and Law 40’s actual definitions before deciding whether notification is required — not through how the incident might look in a headline.
  • Test what your public-facing tools can actually return, not just what they display by default. A search interface that “doesn’t show” sensitive data in its normal results can still expose that data through the underlying request structure, exactly as reported here.
  • Know which regulator has jurisdiction before an incident happens. Private businesses answer to DACO; government agencies and public corporations answer to the Ombudsman. Knowing the process in advance avoids losing time figuring it out during an active incident.
  • Determine how Law 40 might apply to you. If any of your businesses handles data as part of its obligations set in a Puerto Rico government contract, you need to know how  – and whether – this law reaches that specific part of your work.
  • Build a notification decision tree in advance, so that answering the question “was this a breach?” isn’t being decided reactively, under scrutiny, by whoever happens to be fielding the press call that day.

Conclusion

This story is a real-time example of what happens when a public or private entity takes the position that an exposure isn’t a legally significant breach, instead of analyzing the situation through potentially applicable laws and regulations. Puerto Rican law doesn’t leave the answer to the question “was this a breach?” purely to the discretion of the entity holding the data — Law 111 defines it, Law 40 layers on separate obligations for government agencies and their contractors, and neither framework disappears just because an executive says that nothing happened. 

For any business — not just government agencies — the lesson is the same one from our last post: know your obligations, know your regulator, and don’t let the first time you think seriously about either be the day a reporter calls asking why a million Social Security numbers were downloadable from your website without a password.

If you want to make sure your business — or your government contracts — actually comply with Puerto Rico’s data security and breach notification laws, please book a consult with us today. We’ll help you build the decision tree, the vendor terms, and the response plan before an incident forces you to build them under pressure.

[2026-07-16]