Skip to main content

Carly Kind

Carly Kind
Privacy Commissioner

Published:  

In August, I wrote about the emerging community concern and legal quagmire that is surveillance wearables, increasingly prevalent ambient recording devices that enable always-on, concealed and even covert surveillance of images, sounds and other personal information.

In the intervening period we have seen mounting community concern, culminating in numerous local government bans on smart glasses at sensitive public spaces such as swimming pools, playgrounds and gyms, a GetUp petition against certain brands of the glasses garnering more than 55,000 signatures, and a proposal to restrict the use of smart glasses in federal workplaces and public service offices.

Since August 2026, the Office of the Australian Information Commissioner (OAIC) has undertaken preliminary inquiries with 5 entities providing smart glasses hardware or software to better understand how and where the Privacy Act applies, and to identify how personal information is being protected by those entities who are collecting it. As I noted in my previous blog, existing privacy law is likely to be only one, albeit important, part of the puzzle that companies developing and deploying these tools will need to consider. However, the OAIC can better assist the Australian public, as well as the regulated community, if we are clear about when obligations under the Privacy Act apply and to whom.

The OAIC’s preliminary inquiries were directed to the following entities:

  • Kmart and BDI Technology, retailers which sell smart glasses only and do not develop or operate the underlying software for the device
  • Shenzhen Qingcheng, a software provider that provides the underlying software (includingthe HeyCyan app) which is used with many lower-cost smart glasses sold by Kmart, BDI Technology, Amazon and others
  • Meta, a technology company which manufactures and sells smart glasses and provides the underlying software operating on the device
  • Google, a technology company that plans to manufacture and sell smart glasses and provide the underlying software operating on the device.

Today, we have announced we have opened a formal investigation into Shenzhen Qingcheng, provider of the HeyCyan app. The entity’s failure to respond to our preliminary inquiries, as well as concerns arising from third party analysis of the technology itself as well as the entity’s privacy policy, warrants the use of the full range of the OAIC’s powers to examine the issue, including issuing compulsory information gathering notices.

In parallel, I wanted to share some reflections on the information we obtained and analysed through our preliminary inquiries. While we have not decided to commence an investigation into any of the entities other than Shenzen Qingcheng at this time, this should not be read as any conclusive statement about the compliance or otherwise of the entities under scrutiny reflection on whether the Privacy Act may apply – and where it may not.

The Privacy Act only applies to the handling of personal information

The Australian public is increasingly aware that the Privacy Act does not apply to individuals, but rather to companies and Commonwealth agencies. However, it is also worthwhile clarifying that not all companies are covered by the Act – only those who hold personal information. Providing a device or piece of hardware does not itself bring you under the auspice of the Act, even if that device does collect personal information. The entity responsible for Privacy Act compliance will be the entity that holds the personal information collected.

Accordingly, retailers that sell smart glasses - for example on an ecommerce website - or companies that manufacture them, may not have any Privacy Act obligations if they do not collect any personal information with respect to those devices. Instead, the entity providing the software at use in the device is likely to be the entity that collects and holds the information for the purpose of privacy law. However, as I discuss below the community and shareholders will likely expect retailers to conduct due diligence into the privacy risks of the products they sell, as part of meeting economic, social and governance expectations.

Not all images, recording or other data collected by smart glasses will necessarily be personal information to which the Act applies

The Australian government recently announced plans to reform the Privacy Act in some fundamental ways, including to broaden the definition of personal information. Currently, personal information is information that is about a reasonably identifiable individual. The ‘Tranche 2’ reforms will amend that, such that information that relates to a reasonably identifiable individual will be personal information.

Both ‘about’ and ‘relates to’ would inarguably include images of an individual or recordings of their voice. But would that individual be ‘reasonably identifiable’ for the purposes of the second limb of the definition of personal information?

I recently issued determinations in the matters of Monash IVF and Medmate Australia in which I clarified that ‘reasonably identifiable’ doesn’t only include situations where an individual’s legal identity is apparent, but rather that it includes contexts in which the information permits an entity to ‘single out’ or ‘distinguish’ an individual from others in a way that affects an individual’s rights or interests.

In the case of smart glasses, I think it is likely that it will depend on the context and capabilities of the regulated entity as to whether and in which circumstances the personal information they are collecting is personal information. Entities that already hold extensive information on identifiable individuals who collect images or other data via smart glasses are likely to have the ability to reasonably identify an individual. Circumstances in which recordings contain information including name badges, uniforms or other identifying features, where geolocation data is collected, or an individual’s identity is announced in some other way, are likely to give rise to a collection of personal information. But this may not be in all cases.

In most cases, entities don’t need to obtain your consent to collect your personal information

In its current form, the Privacy Act does not set consent as a mandatory requirement for the collection of personal information except in certain circumstances. In most cases, the bar that entities need to clear to collect your personal information is that it must be reasonably necessary for their functions and activities. This implies that entities should minimise the collection of personal information where possible, and their collection of personal information should be proportionate – if they could perform those functions and activities with less personal information, they should.

Consent is required where the entity is collecting sensitive information; of utmost relevance here is biometrics information. Any smart glasses that include facial recognition functionality are likely collecting biometric information, for which the collecting entity – the provider of the software used by the device – would require an individual’s consent. To clarify, we have not yet identified the use of facial recognition capabilities in smart glasses devices available on the Australian market.

Entities do need to take reasonable steps to notify people that their information has been collected

One of the most uncomfortable features of smart glasses from the perspective of the Privacy Act is the ambient, concealed, and even covert nature of personal information collection. Instinctively, this can feel like it is an affront to our privacy, which after all should be about giving us genuine choice and control over our personal information.

However, many of us already carry around in our pockets everyday devices that similarly permit us to photograph, record and otherwise collect others’ personal information. Smart phones, go-pros, dashcams or doorbells already covertly film other people in public spaces. There would be few willing to argue that privacy law prohibits the bare act of taking a recording of one’s child that incidentally captures other parents and even children in the playground (as opposed to publishing that recording, which is likely to be captured by other legal frameworks). Likewise, it would be difficult to contend that the provider of photo storage apps or cloud-based file storage, such as Apple, has Privacy Act obligations to every individual whose image has been collected through public-space photography and is stored on Apple’s servers.

There is an obligation in the Privacy Act that entities should take reasonable steps to notify individuals of certain matters as are reasonable in the circumstances. This is a highly qualified obligation, because it responds to the particular circumstances of the collection. It is impossible to say conclusively what should be notified by the providers of software used in smart glasses and to whom, but it is difficult to avoid the analogy with photo storage apps.

Smart glasses need to be secure too

To the extent that smart glasses are collecting personal information, and sometimes sensitive personal information, in great volumes, and doing so without the knowledge of affected individuals, the onus on the providing entity to ensure that personal information is secure from misuse, interference, lost and unauthorised access or disclosure is even greater. Data breaches, cyber incidents and other security risks that may eventuate from poor security practices are likely to be even more harmful where the individuals don’t even know their personal information has been collected, and are unable to protect themselves.

Individuals will have difficulty assessing the privacy risks of surveillance and connected devices and will expect retailers to carry out due diligence

Even where companies are not directly responsible for how devices they sell may be used (or misused) the community will rightly expect responsible businesses to conduct due diligence into the products they sell, and to avoid taking steps that encourage unlawful use of their products.

Businesses that fail to do so will likely face at least reputational damage. Accessorial liability is also provided in regulatory powers legislation applicable to the Privacy Act. Alongside commencing this investigation, I have accordingly written to the Australian Retailers Council to ask it to encourage its members to carefully consider the privacy risks of connected and surveillance devices when offering them for sale.

Looking forward to Privacy Act reform

In addition to the above reflections as a result of our preliminary inquiries, we have also had the opportunity to identify how the potential changes to the Privacy Act proposed by the government will further strengthen the application of privacy law to surveillance wearables, including smart glasses. These reforms are likely to raise the bar that entities will have to clear in order to collect personal information using smart glasses, in the following ways:

  • The most substantial change will be the replacement of the ‘reasonably necessary for an entity’s functions and activities’ test with a ‘fair and reasonable test’. The new test will require an entity to look at a range of factors, including the extent to which an individual had genuine choice in the collection of their personal information, as well as the best interests of the child where children are involved.
  • The proposed reforms include classifying ‘precise geolocation tracking data’ as sensitive personal information, requiring an individual’s consent, which will also create a higher bar for entities that collect precise geolocation data via smart glasses. This will be with reforms to strengthen the definition of consent to require consent be voluntary, informed, current specific and unambiguous.
  • The introduction of a right to erasure on large digital platforms will enable individuals to take proactive steps if they believe their personal information has been collected by large digital platforms via smart glasses. However, this is unlikely to affect collection by smaller software providers providing the software in lower cost products.

Given the gaps in Privacy Act coverage with respect to smart glasses, the Australian community is likely to find comfort that the proposed tranche 2 reforms will raise the bar for smart glasses collection. These reforms are likely to become increasingly necessary as we face subsequent generations of surveillance wearables and connected devices, from personal assistant gadgets to ambient recording badges.