
Smart glasses are becoming increasingly capable, discreet and commonplace. But as cameras, microphones and artificial intelligence become embedded in everyday eyewear, organisations need to consider what their use could mean for workplace privacy, data protection and security. From employees recording colleagues without realising it to the capture of commercially sensitive information, smart glasses introduce risks that traditional workplace policies may not yet address. Here, we look at the key privacy concerns surrounding smart glasses, what their use could mean in the workplace, and the practical steps organisations can take to manage the risk.
What are Smart Glasses?
Smart glasses are either prescription glasses or sunglasses that have microphones and cameras built into their frame which can be connected to a third-party device like a mobile phone. Some smart glasses also utilise artificial intelligence to provide real time information to the wearer. These devices allow users to control their mobile phone functions and record audio / video.
Privacy Concerns:
The use of these technologies has sparked international concerns from privacy professionals and concerned citizens who may not realise their personal data is being captured and processed by Meta due to the discreet nature of these devices. Although some smart glasses have flashing lights to indicate that recording is taking place, some users can utilise third party services to disable these lights to make the devices even more discreet.
According to a BBC report, Meta has said that subcontracted workers might sometimes review content, including films and images, captured by its AI smart glasses for the purpose of improving the “user experience”. Footage captured and reviewed by these smart technologies includes very sensitive information and intimate personal moments without users being aware that Meta subcontractors were reviewing this data. Although Meta has said that some personal data was blurred before review, this was not 100% accurate, and some faces could be seen.
In January 2026, CNIL (the French data protection regulator) carried out a survey to determine people’s feelings around smart glasses with 67% of respondents reporting that they feel ‘mistrust, discomfort, worry or even annoyance’.
Meta has started rolling out an update to combat this where camera functionality will not work if the light has been tampered with!
Smart Glasses in the Workplace:
Due to the discreet nature of smart wearable devices, there is an increased risk of both intentional and inadvertent privacy and security breaches. These technologies may facilitate corporate espionage, whether through the deliberate capture of commercially sensitive information or the accidental recording of confidential data. They also create the potential for the intentional or unintentional recording of colleagues, which may raise privacy concerns and undermine trust within the workplace. As a result, the presence of such devices can contribute to discomfort among staff and foster perceptions of surveillance, potentially impacting employee confidence, relationships and workplace culture.
Where an organisation deploys these devices as part of its business operations, rather than for an individual employee’s personal use, data protection obligations are likely to apply. Unlike traditional CCTV systems, which are typically installed in fixed public locations and accompanied by clear signage, smart wearable technologies present unique privacy challenges. These devices allow users to record whatever they are viewing and are not restricted to a specific location or field of view.
As the cameras are integrated into items that are not traditionally associated with recording, they can be difficult for individuals to identify. As a result, people may be unaware that they are being recorded, creating a risk that the organisation may not meet its transparency obligations under data protection legislation.
Furthermore, establishing a lawful basis for this processing may prove challenging. Unless the organisation obtains valid, informed consent from all individuals captured, reliance on an alternative lawful basis, such as legitimate interests, may be difficult to justify. Given the potentially intrusive nature of the processing and the discreet design of the devices, individuals may have limited awareness or expectation that recording is taking place.
Even where a Legitimate Interests Assessment (LIA) is conducted, it is likely to conclude that the organisation’s interests do not outweigh the impact on the rights, freedoms and privacy expectations of the individuals being recorded. Organisations should carefully assess whether the use of such devices is necessary, proportionate, and capable of meeting data protection requirements before deployment.
Why Smart Glasses create a different privacy risk
The challenge with smart glasses is not simply that they can record. Smartphones can do that too. The difference is how easily recording can blend into ordinary behaviour. A camera positioned at eye level can capture people, documents, screens and conversations from the wearer’s point of view, while those nearby may have little indication that recording is taking place. For employers, this makes smart glasses a data protection issue, a security issue and an employee trust issue at the same time.
Do organisations need a Smart Glasses workplace policy?
For many organisations, existing acceptable use, bring your own device (BYOD), information security and privacy policies may not explicitly address wearable recording technology. A dedicated smart glasses policy, or a clear update to existing policies, can help define where devices are prohibited, when recording is permitted, how personal and confidential information should be handled, and how suspected misuse should be reported. This is particularly important in areas where sensitive personal data, confidential conversations, intellectual property or customer information may be visible or discussed.
Recommendations:
- Prohibit the use of smart wearable recording devices in sensitive areas
- Develop and implement a clear workplace policy and rules around the use of smart wearables with recording capabilities
- Undertake a Data Protection Impact Assessment (DPIA) and assess the relevant legal basis where the company intends to deploy smart wearables as part of its business operations
- Conduct regular staff awareness training
- Consider the wider employee relations impact and gather feedback from employees
- Establish a reporting and escalation process for suspected misuse, unauthorised recordings, or data protection incidents involving smart wearable devices
- Periodically review the effectiveness and necessity of any authorised deployments of smart technology
Smart Glasses and workplace privacy: frequently asked questions
Can employees wear Smart Glasses at work?
That will depend on the organisation, the purpose of use and the environment. Employers should consider whether recording-enabled wearables create privacy, confidentiality, security or employee relations risks and set clear rules accordingly.
Do Smart Glasses create GDPR and data protection risks?
Yes. Where smart glasses are used by an organisation to capture identifiable people, voices or other personal information, data protection obligations are likely to apply. Organisations should consider transparency, purpose, data minimisation, security, retention and the lawful basis for processing before deployment.
Should organisations carry out a DPIA before deploying Smart Glasses?
Where an organisation intends to deploy smart glasses in a way that is likely to result in a high risk to individuals, a Data Protection Impact Assessment (DPIA) can help identify and reduce those risks before the technology is introduced. The assessment should consider what is captured, who may be recorded, where information is processed or shared, the technical and organisational measures in place to mitigate risk and whether the proposed use is necessary and proportionate.
What should a Smart Glasses workplace policy cover?
At a minimum, organisations should consider permitted and prohibited uses, sensitive or restricted areas, recording rules, handling of personal and confidential information, security requirements, incident reporting and consequences for misuse. The policy should also be supported by staff awareness and periodic review as the technology evolves.
How NormCyber Can Help
Our Data Protection Consultancy service helps organisations adopt and manage smart glasses technology with confidence, ensuring privacy, security, governance, and compliance are embedded throughout the entire lifecycle. Whether deploying organisation owned devices or addressing situations where employees, contractors or visitors bring their own smart glasses into the workplace, we help organisations assess risks, conduct DPIAs, establish appropriate policies, manage data sharing and recording practices, and support with the implementation of proportionate technical and organisational measures. We regularly work with organisations handling sensitive information to ensure personal data is processed lawfully, transparently, and securely while balancing innovation with the rights and expectations of individuals. To learn more about how Norm can support your organisation with data protection, governance and smart glasses compliance, visit our Data Protection Services page.






