Skip to main content

Carly Kind

Carly Kind
Privacy Commissioner

Published:  

In his 2013 dystopian novel The Circle, author Dave Eggers describes a fictional future dominated by “all-seeing, all-knowing” tech companies who promote the mainstream use of wearable surveillance technologies – pins that contain cameras, health and biometrics bracelets, and microchip trackers for young children. Consumer uptake is encouraged through the deployment to the catchy slogan, “Secrets are lies. Sharing is caring. Privacy is theft”.

Reading the book at the time it was published, I was captivated by the dark future it projected. Today, I am concerned how closely it aligns with the reality we see emerging around us. And I am vitally interested in how our privacy laws can meet the challenge – and where they may not.

A decade after Google’s failed attempt to launch Google Glass – futuristic spectacles that an enabled a user to record photos and videos, issue voice commands and view data overlaid on a transparent screen – we are seeing the growth of surveillance wearables available on the consumer market. This time it is Meta leading the charge with its Meta Glasses, but others will soon follow their lead – Google plans to launch Android XR smart glasses later this year, with Apple’s own product launching in 2027. Cut price versions are beginning to be offered by mainstream retailers such as Kmart and Amazon. OpenAI has its own secretive plans to launch a wearable device to facilitate the ambient collection of data to power AI assistants.

Just as when Google launched its original version, the public conversation is quickly turning to the implications for personal privacy of a new spate of wearables that permit a wearer to record images, video and sound in any environment, from a public bathroom to the local pub. There are those who will say that the prevalence of smart phones, Go-Pros, dash cams and other recording devices, not to mention facial recognition technology, means that this time round smart glasses will land in a society much more used to being recorded, in which online and offline surveillance has already become normalised, and therefore individuals should no longer have a reasonable expectation that they can live private or anonymous lives.

But the Australian community is likely to disagree. More than 85% of them recently told us in a privacy attitudes survey that their concerns about privacy have only increased in the last five years. Across the board, Australians are discontent with practices such as online tracking, targeted advertising, and biometrics technologies, and indicate that they have almost no trust in social media and AI companies.

In my view, there is a meaningful difference between place-based surveillance, such as that we find in airports and in certain retail spaces which have been able to meet the relevant thresholds to justify its deployment, and surveillance wearables in the hands of every roving individual, designed for discretion (or even concealment). Privacy does not mean an absolute ability to hide oneself at all times, but it does mean the ability to make choices and control the conditions upon which you move about the world. The proliferation of smart glasses – and their future peers, such as wearable pins or advanced earbuds – would fundamentally alter our experience of interpersonal interactions, in both private and public spaces, and undermine our ability to make some of those choices. Without knowing, we could be filmed, recorded or photographed at any time.

For the most part, the implications of being so recorded would be few, and mild – our images and opinions would take up space in a data centre somewhere but would be unlikely to be used or analysed in any way that materially affects us. There may even be benefits that flow from the use of surveillance wearables in certain sectors, the way bodycams are aiding retail security objectives. But there will be exceptions to benign usage – where smart glasses users are able to use the tech in harmful ways to exploit or surveil vulnerable groups, such as children or victims of domestic violence, or for other untoward ends, such as corporate espionage, data theft, extortion or bribery. Beyond safety concerns, there is also the impact on community values and the public interest in privacy. In aggregate, the effects of mainstreamed surveillance wearables would be the emergence of new privacy risks, new safety concerns, and new societal norms.

It would also require consideration of whether we need new laws. Australia’s Privacy Act only applies to businesses and government agencies, not to individuals, and it only applies when those entities collect personal information.

In circumstances where a tech company is receiving and storing personal information collected by surveillance wearables, they’ll have to make sure they’re complying with privacy law. And there are real questions as to whether they will be able to do so – how will they notify individuals that their images or voice has been recorded? If they’re making facial recognition features available, how will they ensure that they have the consent of the people whose faces the tech is analysing?

The Australian government is currently in the process of developing the Tranche 2 reforms to the Privacy Act, which are likely to include expanding the scope of application of privacy law in ways that create additional hurdles for the developers of surveillance wearables. Under the proposed reforms, for example, entities will need to be able to demonstrate that their collection and use of personal information, including to train AI models, is both fair and reasonable. Higher standards around consent, more protections on geolocation data and an expanded definition of personal information are also likely to strengthen my hand as Australia’s privacy regulator in scrutinising these tools.

But the coverage of the Privacy Act stops short of personal information collection by individuals themselves. So, where the data collected through wearables is processed on the device itself or is otherwise not within the control of a regulated entity, for example because the images are stored directly on the device until uploaded to a personal computer, it may not fall within the remit of the Act, necessitating the use of other legal means for redress. In such circumstances, the recently introduced tort of serious invasions of privacy would be available for claims against individuals, where a smart glasses user intentionally contravened another’s privacy and that person suffered serious distress, offence or harm as a result. And the forthcoming Digital Duty of Care will require entities – including hardware providers - to take reasonable steps to maintain processes and systems that, among other things, prevent activity that is illegal or harmful to children.

As Australia’s privacy regulator we are giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence in order to understand if scrutiny and intervention is required or warranted. We have engaged with one entity on at least two occasions this year to further understand the technical specifications of surveillance wearables on offer.

But compliance with existing privacy law is likely to be only one part of the puzzle that companies developing and deploying these tools will need to consider. As long as public trust in technology companies remains extremely low, the bar for establishing a social licence for rolling out new tech will be high. We may have become more inured to the presence of surveillance in our daily lives over the past decade, but the majority of the Australian public would reject the contention that “privacy is theft”. Privacy remains a vitally important individual right and public value in Australia, and we at the OAIC will continue to promote and protect it even as surveillance wearables proliferate.