Skip to Content
OPINION

A view from Brussels: Smart glasses — Is social acceptance enough of a guardrail?

As smart glasses become more common, European employers and regulators are grappling with the risks posed by their discreet recording capabilities.

Published
Subscribe to IAPP newsletters

Contributors:

Isabelle Roccia

CIPP/E

Managing Director, Europe

IAPP

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

I found myself chatting with a fellow dog owner about work the other day. She turned out to be a human resources director at a big supermarket chain in Belgium. I asked what her top issue is now, expecting something about dreadful layoffs or abusive medical certificates which spur a lot of chatter here. 

With no hesitation she responded: "smart glasses." She then explained that she is increasingly confronted with employees — at times from labor unions — using smart glasses to stealthily record internal meetings or factory floor operations and then release the recordings on social media or use them as leverage. 

European data protection authorities started positioning on the topic of smart glasses a few years back. Already in 2021, Italy's Garante and Ireland's Data Protection Commission made inquiries to Facebook about the privacy implications of the Ray-Ban Stories smart glasses the company had just launched. 

In the last month, Norway's Datatilsynet published dedicated guidance and France's Commission nationale de l'informatique et des libertés released an action plan, calling for enhanced collective vigilance. Both authorities largely put the onus on citizens to adopt the right and decent actions: Inform nearby individuals when recording, refrain from recording intimate situations and stay alert to others using smart glasses.

These latest recommendations reflect the current state of affairs. At this point, the best line of defense is people's best judgement and the social acceptance test. Just because one can, doesn't mean one should — so to speak. Not the most reassuring approach. 

But guardrails are tricky. The EU General Data Protection Regulation's household exception could apply in some consumer use cases but remain heavily context dependent. The right of personal portrayal might be a robust protection for individuals being filmed, though challenging to exercise. 

In workplace scenarios, guardrails may be easier to anchor in existing rules protecting trade secrets and confidentiality or general workplace policy. 

At the EU level, the Data Act could play an interesting role and introduces the notion of "passively observed data." Its Recital 35 explains that the regulation grants users the right to access "passively observed data," whether it is personal or non-personal data and irrespective of the legal basis of processing.

The toughest stance may come from the Hamburg Commissioner for Data Protection and Freedom of Information. Commissioner Thomas Fuchs recently argued that smart glasses could be fully banned in Germany. Interestingly, the rationale finds its root in post-Stasi legacy, where German law forbids the possession and sale of concealed recording devices disguised as an everyday object. 

The European Data Protection Board study on the social acceptability of smart glasses is expected this summer. Some voices in the European Parliament are also raising concerns and asking the European Commission for a plan. 

Smart glasses have aspects of data security, safety, conformity and, of course, privacy. Innovators and consumers will be confronted with the challenge that laws and norms often don't move as fast as innovation.

All in all, the debate over which safeguards should govern the use of smart glasses may be first and foremost a great teachable privacy moment for us as a society. Moving the societal normative cursor even slightly toward more mindfulness, carefulness and respect for the people around us will be a win no matter what. But it sure won't be enough. 

This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Isabelle Roccia

CIPP/E

Managing Director, Europe

IAPP

Tags:

IoT and personal devicesGDPRPrivacy

Related Stories