Australia’s privacy tsar warns new laws may be needed for smart glasses

The rapidly growing popularity of discreet, camera-equipped smart glasses — headlined by Meta’s popular Ray-Ban model and Kmart’s budget Anko offering — has spurred Australia’s top privacy official to sound an urgent alarm over unaddressed surveillance risks, arguing that current national privacy regulations are ill-equipped to manage the emerging technology and may require sweeping new legislation.

In a detailed public blog post, Australian Privacy Commissioner Carly Kind warned that the booming market for smart glasses, with major tech giants Google and Apple expected to release their own competing models by 2027, will reshape the very nature of personal interactions in both public and private spaces. This shift, she argued, will erode the ability of Australians to make informed decisions about their own privacy, as members of the public can no longer be certain when they are being filmed, recorded, or photographed without their knowledge or consent.

Against this backdrop, Kind said policymakers must seriously evaluate whether updated or entirely new privacy legislation is required to mitigate emerging risks. Current Australia’s Privacy Act only applies to data collection activities conducted by businesses and government agencies, not to individual users of the devices, creating a critical regulatory gap.

While tech companies that receive and store personal data captured by these wearable surveillance devices are technically required to comply with existing privacy law, Kind raised serious doubts about whether firms can actually meet their existing legal obligations. She highlighted key unaddressed questions: how will companies notify people that their images or voice recordings have been captured and stored? If devices include facial recognition functionality, how can companies guarantee they have obtained explicit consent from every person whose biometric data is processed by the technology?

Following Kind’s warning, Australia’s Attorney-General Michelle Rowland confirmed she has written to the privacy commissioner to flag the potential privacy threats posed by the new technology and requested that the issue be prioritized for review. Rowland emphasized that privacy is a foundational right that enables all people to live with dignity and free from fear, noting that smart glasses differ from other recording technologies because of their ability to capture media discreetly, making it nearly impossible for people to know when they are being recorded.

Rowland added that the federal government has full confidence in the Office of the Australian Information Commissioner (OAIC) to identify emerging privacy risks and develop workable mitigation strategies, and the government is currently advancing the next phase of national privacy reform to ensure regulations remain fit for purpose in the fast-evolving digital age.

Kind acknowledged that for most users, the privacy risks posed by widespread smart glasses adoption will be minimal and mild. The vast majority of captured personal data will likely sit unused in corporate data centers without ever being processed or used in a way that impacts everyday people, and the technology could even deliver public benefits in some use cases — for example, the deployment of body-worn cameras for law enforcement and security professionals.

However, she stressed that there are high-stakes exceptions to this benign use pattern. Bad actors can easily deploy smart glasses for harmful purposes: to covertly surveil or exploit vulnerable populations, including children and domestic violence survivors, or for malicious ends such as corporate espionage, data theft, extortion, and bribery. Beyond direct safety threats, the widespread mainstream adoption of surveillance wearables will shift long-held societal norms around privacy, eroding core community values around personal autonomy in public spaces.

Currently, the Australian federal government is conducting a review of the second tranche of national privacy reforms, which Kind said will likely expand the scope of privacy law to create new safeguards for consumers and new oversight requirements for smart glass developers. Under the proposed reform framework, for example, companies will be required to prove that their collection and use of personal information — including data used to train artificial intelligence models — is both fair and reasonable. Additional proposed changes, including higher consent requirements, stronger protections for geolocation data, and a broader definition of what counts as personal information, will give the privacy regulator more power to scrutinize new wearable technologies.

Even with these reforms, a key gap remains: existing privacy law does not cover personal information collected and stored locally by individual users, putting this data outside the scope of regulatory oversight. While recent developments in tort law and the upcoming Digital Duty of Care regulations will partially address this gap in some scenarios, Kind said the OAIC is still investigating whether additional regulatory intervention is necessary to close all remaining loopholes.

The regulator has already engaged directly with at least one major smart glasses developer twice this year to gain a deeper understanding of the technical specifications of currently available devices. Kind noted that as public trust in large technology companies remains at historic lows, the threshold for earning social approval to roll out new surveillance-enabled technology will remain high.

Meta, which launched its latest generation of Ray-Ban smart glasses earlier this year with retail prices starting at $400 AUD, has published user guidelines that advise customers to “respect people’s preferences” and stop recording when anyone requests not to be recorded. The company also requires users to leave the device’s recording indicator LED light unobscured, and reminds users to follow all local laws, prohibiting use of the glasses for harmful activities including harassment, privacy violations, and capturing sensitive information such as ATM pin codes.