TL;DR:
- Camera-equipped smart glasses from Meta, Snap, Xreal, and Android XR devices are becoming a real enterprise tool — not just a gadget
- UK GDPR and the DPA 2018 apply to any footage or images captured, even passively, and the ICO has been clear that “wearable” doesn’t mean “exempt”
- Businesses deploying smart glasses need a lawful basis for capture, appropriate signage, and a clear data handling policy before employees take them into the field
Smart glasses with onboard cameras have been theoretically possible for over a decade. They’re now practically deployable. Meta’s Ray-Ban collaboration ships units with dual 12MP cameras. Snap’s latest Spectacles are in the hands of developers and enterprise pilots. Xreal’s Air 2 Ultra pairs with Android XR for hands-free mixed reality with a live camera feed. Whether you’re thinking about field service, warehouse operations, remote expert assistance, or clinical training, the hardware has caught up with the use case.
The legal framework, though, was written before any of this existed at consumer scale. And while the technology has matured, the compliance questions haven’t gone away — they’ve just become more urgent as deployments move from lab to real-world environments.
What the Law Actually Covers
UK GDPR (as retained post-Brexit) and the Data Protection Act 2018 apply whenever you’re processing personal data. A camera that captures images of identifiable individuals in a workplace, public space, or customer-facing environment is processing personal data. The fact that the camera is built into a pair of glasses rather than mounted on a wall doesn’t change that analysis.
The ICO has made this explicit in its guidance on surveillance and newer imaging technologies. Wearable cameras are in scope. That means:
- You need a lawful basis for capturing footage or images (legitimate interests, legal obligation, consent, or another Article 6 ground)
- You’re subject to data minimisation requirements — capture only what you actually need for the stated purpose
- You need to satisfy transparency obligations — individuals should know they’re being recorded
- Data must be retained only as long as necessary and handled securely
- You need processes in place for subject access requests if footage contains identifiable individuals
For employees using smart glasses as a work tool, the lawful basis is usually legitimate interests (for operational purposes like remote assistance) or, in some sectors, legal obligation. For customers and bystanders — people who happen to be in shot — it gets more complicated.
The Bystander Problem
This is the hardest part. When a field engineer wearing smart glasses walks into a customer’s home to diagnose a boiler fault, the camera sees more than the boiler. It sees family photos on the wall. It might see a child in the background. It captures identifiable details about a private residence.
If that footage is streamed to a remote expert, stored in a cloud platform, or reviewed for training purposes, you’re processing personal data about people who didn’t agree to participate and who may not even know it’s happening.
The “I didn’t notice the camera” problem is real — the current generation of smart glasses are increasingly indistinguishable from regular eyewear. Meta’s Ray-Ban frames have a small LED indicator that lights when recording, but research has consistently shown that bystanders don’t notice or don’t recognise what it signals.
The ICO’s position is that transparency about recording is a genuine obligation, not a nice-to-have. In practice, this means:
Signage in business premises. If your engineers wear smart glasses while on site at customer locations, customers should be informed before the visit that recording may occur. A line in your pre-appointment communications and a brief verbal notice on arrival is a sensible minimum.
Data capture scoping. If the use case is remote assistance, does it require continuous recording or only active capture during diagnostic steps? Designing the system around targeted capture rather than always-on recording reduces your data footprint and your compliance exposure.
Footage handling policy. Who can access recordings? How long are they kept? Are they processed by AI systems (for object recognition, transcription, or analysis)? Each of these layers adds obligations.
Enterprise Deployments: What Good Looks Like
Several sectors are already running smart glasses pilots at scale: utilities field operations, NHS clinical training, manufacturing quality control, logistics picking assistance. The organisations doing this well have a few things in common.
They started with a data protection impact assessment (DPIA) before deployment. The ICO expects a DPIA for any high-risk processing — and wearable cameras in customer-facing or public environments meet that threshold. A DPIA doesn’t have to be a massive document; it’s a structured way of identifying risks and mitigations before you encounter them in the field.
They built employee training into the rollout. Engineers wearing smart glasses need to understand what they’re permitted to capture, when they should pause or stop recording, and how to respond if a customer asks about the camera. This isn’t complex training, but it has to happen.
They chose platforms with appropriate data processing agreements in place. If footage is routed through a cloud platform — whether that’s a remote assistance tool like TeamViewer Frontline, Scope AR, or a custom solution — the platform is a data processor under UK GDPR. You need a Data Processing Agreement in place before you go live.
Android XR and the AI Layer
The newest wrinkle is AI-enabled smart glasses. Android XR devices and the latest Meta platform updates can run on-device AI that analyses the camera feed in real time — identifying objects, surfaces, and in some implementations, recognising text or faces. This creates a processing layer that goes beyond simple recording.
If your smart glasses deployment involves AI analysis of footage (not just capture and transmission), your lawful basis analysis and DPIA need to explicitly address that processing. Automated analysis of biometric-adjacent data — faces, gait, voice — attracts additional scrutiny under UK GDPR Article 9 in some interpretations, and the ICO has flagged real-time recognition technologies as a priority area.
The technology is moving faster than the regulatory guidance. The ICO’s current work on AI and biometrics will produce more specific guidance, but the underlying principles are already clear: camera-based data capture, automated or otherwise, requires deliberate compliance design from the start of your deployment — not bolted on after the fact.
Smart glasses are genuinely useful enterprise tools. The organisations that will get the most out of them in the next few years are the ones treating privacy compliance as part of the deployment project, not a barrier to it.