Smart glasses with features such as video recording, screenshot capture and music playback are becoming increasingly common. However, they also introduce new security and privacy risks that are not covered by existing policies.
Unlike smartphones and other camera-equipped devices, smart glasses make recording far more difficult to detect.
What new risks smart glasses pose
How to mitigate these risks in practice
When to seek additional support
Smart glasses refer to eyewear with integrated camera, microphone and wireless connection. They often include features such as video recording, in-lens displays for navigation or translation, and AI-powered assistance.
These glasses are sold in optician shops and are available with prescription lenses. They are designed to be indistinguishable from eyewear. The only visible difference is a small indicator light that signals the glasses are filming video.
Smart glasses are not inherently harmful and can offer meaningful benefits. In everyday life, they may support people with hearing impairments or peripheral vision loss. In professional settings, they could help surgeons during complex procedures, assist engineers with technical tasks, and enable more immersive learning experiences.
Smart glasses include new technology that is embedded in regular looking eyewear. We are so used to people wearing glasses that we do not associate them with filming, recording voice or using AI features. That is exactly what causes new risks current security, privacy and security policies may not cover.
Trade secrets. Uncovering trade secrets no longer requires hidden mics or microscopic cameras. They can be recorded and shared, even in real-time simply by a visitor or an employee wearing regular looking eye glasses.
Under EU laws, including the Trade Secrets Directive, information must be protected through reasonable steps appropriate to the circumstances to be considered as a trade secret. Because those circumstances evolve with technological developments, organizations should account for emerging risks such as smart glasses. Including clear instructions on the use of smart glasses in security policies can help demonstrate that appropriate protective measures are in place.
Security risks. With new smart glasses, new risks to both physical and information security arise. Many of these risks arise because it can be difficult to identify anything unusual about a visitor, client, or employee wearing them.
From the security perspective, wearing smart glasses allows someone to gather detailed information about security measures: camera locations, blueprints, pin-codes, company's personnel cards and security guards schedule without anyone paying attention. This information could be later used for malicious purposes.
From an information security perspective, the smart glasses are something that are outside your device management and information security measures. Hacking smart glasses is feasible - these risks are no longer theoretical.
Privacy risks. Smart glasses create privacy risks in addition to those affecting trade secrets and security. Recording of images clearly constitutes processing of personal data (CJEU C-212/13). The controller must implement appropriate measures to ensure that personal data is processed lawfully and securely. These measures clearly include written policies and employee training. Responsibility cannot be shifted to employees; the controller remains accountable for actions taken by employees in the course of their work.
Additional privacy risks associated with smart glasses include undisclosed data transfers to third countries, potential access by third parties and lack of transparency. The data gathered is often synchronized into a a customer cloud outside EU/EEA and could be reviewed by external annotators. A small light indicating recording is unlikely to meet transparency requirements under applicable privacy laws, including GDPR (articles 12-14).
The mitigation process for risks posed by smart glasses does not require an entirely new compliance program. It requires defining your position, writing that position into binding documents and implementing it so it works in the day-to-day life.
Decide your position. There are three common positions to smart glasses: prohibited on premises, permitted subject to stated conditions or permitted. The position should be tailored to industry, use zones and sensitivity of the data processed.
Write that into policies. Write the position into relevant policies, such as visitor policy, information security policy and privacy policy. If it is more feasible, you can also write a new appendix to be included into existing policies. To support organizations adopting this hybrid approach, we have prepared a template visitor policy that permits smart glasses in designated areas while restricting their use elsewhere.
Implement it in practice. This is often the most challenging step. Communicate the policy clearly to visitors, employees, and anyone else affected, and designate a specific person to handle questions or concerns.
Smart glasses may pose particularly significant risks in regulated industries such as healthcare and technology. Large and complex sites may require a tailored approach for each facility and zone.
Additional support may also be valuable when an employer provides AI-enabled smart glasses. In that situation, the AI system’s risk classification, liability, and data protection implications should be assessed carefully.
If you are determining how smart glasses should be addressed in your site rules, contracts, or governance processes, contact Regulyn for additional support.
EDPS: Technology Report No 1: Smart glasses and data protection
CNIL: Smart glasses: Compedium of G7 data protection and privacy authorities approaches
BBC: Regulator contacts Meta over workers watching intimate AI glasses videos