Australian Privacy Commissioner Flags Growing Risks from Consumer Smart Glasses and Calls for Privacy Act Updates

Table of Contents

Australia’s Privacy Commissioner Carly Kind has publicly raised concerns about the rapid arrival of consumer smart glasses and other surveillance wearables, warning that existing privacy laws may not fully address the challenges these devices create. In a recent statement, Kind indicated the Office of the Australian Information Commissioner is closely monitoring the market and considering whether stronger scrutiny or regulatory intervention will be needed as the technology moves from niche to mainstream.Kind framed the issue against the backdrop of Dave Eggers’ 2013 novel The Circle, in which wearable cameras and biometric devices become ubiquitous under the slogan “Secrets are lies. Sharing is caring. Privacy is theft.” What once read as dystopian fiction, she suggested, is beginning to resemble emerging commercial reality.

From Google Glass Failure to a New Wave of Devices

More than a decade after Google’s original Glass project largely failed to gain consumer acceptance, a second generation of smart glasses is arriving. Meta has already launched its Meta Glasses. Google is expected to release Android XR smart glasses later this year, with Apple’s version anticipated in 2027. Lower-cost versions are already appearing in mainstream retail channels, including Kmart and Amazon. OpenAI has also been reported to be developing a wearable device intended to support continuous, ambient data collection for AI assistants.

These devices typically allow wearers to capture images, video and audio discreetly in almost any environment. Unlike fixed cameras in airports or certain retail settings, they move with the individual and can operate with minimal visual cues that recording is taking place. Kind drew a clear distinction between the two models. Place-based surveillance systems, she noted, can be assessed against specific thresholds and justifications. Wearable devices carried by ordinary people introduce a different and more pervasive form of potential surveillance.

“Privacy does not mean an absolute ability to hide oneself at all times,” Kind wrote, “but it does mean the ability to make choices and control the conditions upon which you move about the world.” The widespread adoption of smart glasses and similar devices, she argued, would alter everyday interpersonal interactions in both public and private spaces and reduce individuals’ ability to know when they are being recorded.

Public Attitudes and the Limits of Normalisation Arguments

Some observers contend that society has already adapted to constant recording through smartphones, dash cams, body-worn cameras and facial recognition systems, and that smart glasses simply represent an incremental change. Kind pushed back against that view. Recent OAIC research shows more than 85 percent of Australians report that their privacy concerns have increased over the past five years. Trust in social media platforms and AI companies remains extremely low, and the public continues to express discomfort with online tracking, targeted advertising and biometric technologies.

In Kind’s assessment, the Australian community is unlikely to accept the idea that privacy expectations should simply disappear because recording technology has become more common. The cumulative effect of personalized, always-available surveillance tools could generate new privacy risks, safety concerns and shifts in social norms that existing frameworks are not fully equipped to manage.

Where the Privacy Act Currently Stops

A central limitation of Australia’s Privacy Act is that it applies to organisations and government agencies, not to private individuals. It also requires that an entity collect personal information before the Act’s obligations are triggered. This creates several practical gaps when applied to consumer smart glasses.

When a technology company receives and stores personal information collected through its wearable devices—images of bystanders, voice recordings, or biometric data used for facial recognition—the company will generally fall within the Act’s reach. In those cases, questions of notice, consent and lawful collection become critical. How will companies notify individuals who have been recorded without their knowledge? How will facial recognition features obtain valid consent from people whose faces are analyzed? These issues are already difficult under current law.

The forthcoming Tranche 2 reforms to the Privacy Act are expected to raise the bar further. Proposed changes include a “fair and reasonable” test for collection and use of personal information (including for AI training), higher standards around consent, stronger protections for geolocation data, and an expanded definition of personal information. These reforms would give the OAIC additional tools to scrutinize the developers and operators of surveillance wearables.

However, the Act still does not reach pure individual use. If images or audio are processed and stored only on the device itself, or are transferred directly to a personal computer without passing through a regulated entity’s systems, the collection may fall outside the Privacy Act entirely. In those situations, other legal avenues become relevant. The recently introduced tort of serious invasions of privacy may allow claims against individuals who intentionally invade another person’s privacy and cause serious distress or harm. The forthcoming Digital Duty of Care is also expected to require hardware providers and related entities to take reasonable steps to prevent illegal or harmful activity, particularly involving children.

OAIC Monitoring and Industry Engagement

Kind confirmed that the OAIC is treating the issue as a serious ongoing priority. The office is tracking the commercial rollout of surveillance wearables and has already engaged with at least one company on multiple occasions this year to better understand the technical capabilities of products currently on the market. The agency’s focus is on determining whether additional scrutiny or formal intervention is warranted as adoption grows.

Compliance with the Privacy Act, Kind emphasised, will be only one part of the equation for companies bringing these products to market. Because public trust in technology companies remains low, the threshold for obtaining a genuine social license is high. Devices that enable discreet, continuous recording in everyday settings will face particular scrutiny from both regulators and the public.

Broader Implications for Privacy Governance

The rise of consumer smart glasses highlights a structural tension in modern privacy regulation. Laws designed primarily around organisational data controllers struggle when powerful sensing and recording capabilities are placed in the hands of individuals and the data never leaves the device or a personal cloud account. At the same time, the companies that design, distribute and provide cloud or AI services for those devices retain significant influence over how the technology operates and what safeguards are built in.

Kind’s comments suggest the OAIC sees both sides of the problem. Organizational obligations under the Privacy Act and the coming Tranche 2 reforms will remain central. Yet the agency also recognizes that purely individual recording behavior may require complementary tools—civil claims under the privacy tort, safety obligations under a Digital Duty of Care, and continued public debate about acceptable social norms.

For businesses developing or planning to deploy smart glasses and related wearables in Australia, the practical implications are clear. Product design decisions around on-device versus cloud processing, default recording behaviours, notice mechanisms, facial recognition features, and data retention will all attract regulatory attention. Companies that treat privacy as a secondary consideration risk both formal enforcement and the harder-to-recover loss of public acceptance.

Looking Ahead

Smart glasses and other surveillance wearables are no longer speculative. Multiple major technology companies have committed products to market within the next two years, and lower-cost alternatives are already available. The question is no longer whether the technology will arrive, but whether Australia’s legal and regulatory framework can keep pace with the privacy and social consequences it creates.

Commissioner Kind’s message is that the OAIC is watching closely and is prepared to advocate for the updates needed to protect individuals’ ability to move through public and private spaces without constant uncertainty about whether they are being recorded. Privacy, she concluded, remains a core individual right and a public value in Australia—one the regulator will continue to promote and defend even as wearable surveillance technologies become more common.

Organisations operating in the wearable technology space should treat the current period of regulatory observation as an opportunity to strengthen design choices, transparency practices and compliance programs before more prescriptive rules or enforcement actions follow.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.