Data Protection Network

Smart Glasses. Smart Policies?

Should organisations be setting standards for staff?

I’ve been following the debate over smart glasses with interest and, on occasion, alarm. On the one hand, the technology is an amazing development for the visually or audibly impaired, on the other an intrusive nightmare from a privacy perspective.

Rather than fixating on the whole ‘pervert glasses’ thing, an issue straying into criminal law, I can see a multitude of other situations in which smart glasses might be used inappropriately. Not just in people’s personal lives, but in the workplace too.

The debate isn’t new

Are those calling for a ban simply luddites? From the printing press to the internal combustion engine to the smartphone, technological breakthroughs have caused moral panics. It’s a natural societal process, one where we gradually adapt to “new norms.” People have been able to use modestly-priced covert recording technology for decades. Elsewhere, it’s normal to have a sea of mobile cameras filming everything from car crashes to pub brawls. At a click of a button, peoples’ lives become content shared on social media, with no care for the privacy of those captured in the footage. Yet few are calling for mobile phones to be banned, or for recording features to be disabled.

Are smart glasses a step too far?

I think these glasses are much more subtle than a mobile phone, arguably much more discrete. The secrecy element, I think, breaks many taboos about everyday expectations of privacy. For example, when I next have an unwelcome encounter with a speedy cyclist with no regard for me and my dog, will I be checking for a light on his glasses before hurling expletives? What if it’s obscured or I don’t spot it? Could my career be over because I’m shared on social media screaming at a MAMIL? (Middle-Aged-Man-In-Lycra).

The other day I found myself engrossed in an LBC phone-in on this topic. The majority of callers seemed to be using the glasses for pure convenience, for things easily achieved with existing tech. I was unpersuaded, to be honest – they strike me as more of a novelty for the terminally nosy.

Then, there came a call from someone blind from birth. She mentioned how the glasses are transforming her life, a fantastic and touching story. Then a surgeon saying he’d spotted one of his team wearing them in the operating theatre. No. Really not appropriate.

My head was spinning.

To ban or not to ban smart glasses?

At a national level, some countries are weighing up an outright ban or at least regulating ‘camera-enabled wearables’. Norway, France and the Netherlands to name a few. Australia’s eSafety Commissioner has called on the smart glasses companies, such as Meta and Snap, to make it much clearer when the glasses are filming and to automatically blur people’s faces.

As ever, though, technology races ahead of legislators. Right now, these devices are being bought and used. Wetherspoons has announced an outright ban, some schools are banning them, cinemas are considering a similar stance, but what about workplace use by our employees, workers and contractors more generally?

The surgeon’s story led me to think about how the NHS and other public bodies might deal with this, and soon. What policies will they adopt? Should they simply ban the glasses, or introduce strict staff guidelines on their use?

Commercial businesses also need to consider the issues. Public-facing businesses using police-style body worn video (BWV), such as supermarkets and security companies, will already have policies tailored to their working environments. What about offices though, especially those dealing with sensitive or otherwise privileged material? There’s isn’t just the potential intrusiveness on people’s privacy in the workplace, there’s also the risk of information breaches. I see a tsunami of issues arising.

It doesn’t stop there. What about charities who work with children or vulnerable adults? Should people working in these situations be able to don a pair of fancy video-capable Ray-Bans? What about people who say they need the glasses as a reasonable adjustment in the workplace?

Too often organisations create a policy after a troubling event. A good example is when employees began setting up ‘work’ WhatsApp groups. Often there are no policies or guidelines for staff on expected behaviour until something goes horribly wrong. Perhaps it would be best to be on the front foot with these glasses. Locking the stable door before the horse bolts is a wise, but strangely rarely adopted, business approach.

What about data protection law?

Data protection legislation such as GDPR / UK GDPR focuses on setting requirements for ‘controllers’ of personal data. This regulates big and small organisations, and even sole traders. The legislation specifically excludes ‘the processing of personal data by an individual in the course of a purely personal or household activity’ – commonly referred to as the ‘household exemption’.

Dashcams, personal-use CCTV and doorbell cameras have already raised the question of when an activity moves beyond a purely personal or household activity. As an example, in 2021 Oxford County Court ruled on a dispute between two neighbours (Fairhurst v Woodard). Dr Fairhurst accused Mr Woodward of installing an overly intrusive Ring doorbell and several other cameras. The judgement was nuanced. It was determined Mr Woodward had a legitimate interest in protecting his home. Ordinary video capture of the street, even if it incidentally caught a neighbour walking past was ruled to generally be within the household exemption. However, the fact that the doorbell had audio enabled with a range wide enough to capture sound way beyond Mr Woodward’s home was ruled to be unlawful – as was the extent of the reach of his cameras.

This is reflected in ICO guidance on domestic CCTV/doorbell cameras. Once devices capture neighbouring properties, shared spaces or a public street beyond what’s incidental, or pick up audio beyond your boundary, you can become a ‘controller’ and thereby need to comply with UK GDPR. I can see smart glasses rapidly heading into this territory.
Interestingly, Luxembourg’s data protection authority has weighed in on the debate; it says buying them is legal, wearing them is legal, but once you start recording people you’re on shakier ground. The legal issues are fast-evolving, involving ethics and etiquette as much as law.

Think smart with smart glasses

Smart glasses can’t be un-invented. Moving forward, governments might ban them,  try to regulate or use existing laws to try and control them. They may have varying degrees of success. But organisations shouldn’t just wait to see what legislation brings. Proactively monitoring developments may well yield significant cost-savings and avoid reputational damage in the future. I’d suggest savvy leaders would be wise to be smart about smart glasses. Set common sense policies which provide staff with your expectations around this controversial and transformative technology.

As a data protection consultant since 2015, Philippa advises and supports a broad range of clients, and delivers data protection training. She also regularly writes GDPR guides to support data protection teams in their day-to-day work.
Data Protection Network