Notice

Use of a Sign-in Book and CCTV Cameras (2020-11-20)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2020-11-20

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against a Public Library (as data controller). The complainant raised concerns about a shared sign-in book that exposed visitors' personal data to other visitors, and about CCTV cameras operating without a privacy notice.

The Ombudsman found issues under the first (fair processing) and seventh (security) data protection principles of the Data Protection Law (DPL). Although the data controller could rely on 'legitimate interests' (health and safety and crime prevention) as a legal basis for the sign-in book and CCTV use, it had failed to implement adequate transparency and security safeguards.

  • Remedial steps agreed: The data controller agreed to erect signage warning individuals they were being filmed by CCTV
  • Introduce a redesigned sign-in book that prevents one visitor from viewing another's personal data
  • Develop internal policies governing how personal data is processed by the organisation
  • Create and make publicly available a privacy notice covering both the sign-in book and CCTV processing

As an informal resolution case summary, this document illustrates how the Ombudsman applies the DPL's fair processing and security principles to common practices (sign-in books, CCTV) rather than creating new binding rules, but it signals the compliance standard the Ombudsman expects from data controllers using similar practices.

Key obligations

  • Data controllers using shared sign-in books must design them so that one individual's personal data is not visible to other individuals signing in
  • Data controllers using CCTV must display signage or notices informing individuals that they are being filmed
  • Data controllers relying on legitimate interests as a legal basis for processing (e.g. health and safety, crime prevention) must still ensure fair processing and adequate security safeguards under the DPL
  • Data controllers must maintain a publicly available privacy notice explaining how personal data (including via sign-in books and CCTV) is processed
  • Data controllers should develop internal policies governing their personal data processing practices

Applies to

data controllers, public authorities

Topics

Version history

2026-07-30

source file (current)