# Smart Glasses at Work: A Governance Guide for DPOs and AI Officers

Canonical URL: https://xpertdpo.com/smart-glasses-work-governance-dpo-ai-officers/

Content type: Article

Published: 2026-08-27T21:13:00+01:00

Updated: 2026-08-27T21:13:01+01:00

Author: Philipa Jane Farley, Head of Legal and Operations

Summary: Smart glasses can improve accessibility and frontline work, but cameras, microphones and AI services create difficult privacy, employment, security, safety and confidentiality questions for organisations considering workplace deployment at scale.

## Article

*Practical guidance for DPOs, AI officers, privacy teams, security leaders, HR and procurement teams assessing smart glasses in organisational environments.*

 Smart glasses are moving from demonstrations and specialist industrial deployments into ordinary workplaces. Some provide captions, navigation or prompts. Others contain cameras, microphone arrays, location and motion sensors, app ecosystems and AI services that can interpret what the wearer sees and hears. A small number are designed to build an enduring memory of the wearer’s day.

 For organisations, the governance question is not whether a device looks like a pair of glasses. It is what each enabled function does, which people it affects, where the information travels and whether the organisation can control the result.

 That distinction matters. A display-only prompt used as a disability accommodation does not present the same risk as an always-listening assistant in a client meeting. A time-limited remote-support session on a managed industrial headset is not the same as a worker privately live-streaming from a production area. A camera used to scan a barcode is not equivalent to facial identification, even where both functions use the same sensor.

 The answer should not be a reflexive ban on an entire class of assistive and operational technology. Nor should smart glasses be treated as harmless consumer accessories that happen to connect to an app. Organisations need a function-led governance model with genuine permission routes, defined prohibitions and enough technical control to make the policy real.

### Smart glasses are not one technology

 The current market already contains materially different products and operating models.

| Capability type | Typical functions | Governance significance |
| --- | --- | --- |
| Display-led glasses | Prompts, navigation, teleprompter, captions and translated text | May operate with limited environmental capture, but the data source and processing route still matter |
| Capture-led glasses | Photographs, video, audio, calls and live streaming | Affect colleagues, customers and bystanders who may not know what is being recorded |
| AI-assistant glasses | Voice interaction, scene analysis, summarisation and contextual answers | Add model providers, prompts, outputs, logs, training terms and possible international transfers |
| Memory-oriented glasses | Persistent transcription or systems designed to remember conversations, places and objects | Create acute minimisation, transparency, retention, records and confidentiality problems |
| Industrial assisted-reality devices | Work instructions, remote expert support, inspection and guided maintenance | Can offer strong operational value but also create worker-monitoring, safety and supplier-control risks |

 The products themselves illustrate the range. Meta explains that capture and streaming activate notification LEDs on its AI glasses. The [Irish Data Protection Commission](https://www.dataprotection.ie/sites/default/files/uploads/2026-02/DPC%20EN_AR%202023_Final_ACO1.pdf) has previously engaged with Meta on whether people being captured receive effective notice and reported design changes including a larger privacy LED and a recording blink pattern. Those measures improve signalling, but a visible light does not determine lawful basis, purpose limitation or whether recording is appropriate in a particular workplace.

 Brilliant Labs describes Halo as an open-source AI glasses platform with a conversational agent and long-term memory. Mentra describes camera-enabled glasses, an app ecosystem and AI features involving third-party providers. These are not merely variations in styling. They produce different controller-role, security, transfer and change-control questions.

> **XpertDPO view:** The frame is not the assessment object. Each enabled function, its data flows and its operating environment should be assessed separately.

### Where smart glasses can genuinely help

 There are credible reasons for organisations to explore smart glasses.

 In field service and maintenance, a worker can receive instructions without taking their hands away from the task. A remote expert can see a bounded live view and help diagnose equipment. In warehousing and logistics, a display can direct picking or confirm an item while reducing repeated handling of a handheld device. In inspection and training, a managed headset can guide a worker through a procedure or allow a specialist to assess a site remotely.

 EU-OSHA has examined assisted-reality devices for remote occupational-safety assessments and identifies wider uses for smart personal protective equipment, hazard detection and augmented training. Those uses may reduce travel, bring expertise into hazardous environments and support safer decisions. They still require testing against the real job, physical environment and equipment standards.

 Accessibility uses deserve equal weight. Live captions may support a deaf or hard-of-hearing worker. Navigation or visual prompts may support someone with a visual, cognitive or neurological impairment. Translation can improve communication for a worker or customer. A display can reduce context switching or provide discreet reminders without recording the surrounding environment.

 Retail, hospitality and care organisations may see further opportunities: product lookup, stock location, translation, task prompts, remote support and hands-free access to approved information. The closer the function comes to health data, vulnerable people, private homes or behavioural assessment, however, the more demanding the governance becomes.

 The purpose needs to remain precise. Glasses approved to show an equipment checklist should not quietly become a productivity-monitoring device. A translation function should not acquire an unlimited meeting transcript. A remote-support feed should not become a reusable training library because storage was the vendor default.

### What the glasses see, hear, infer and send elsewhere

 The visible recording is only part of the data map.

 Depending on the device and enabled services, smart glasses may process photographs, video, live streams, voice commands, ambient audio, transcripts, location, direction of movement, head position, device identifiers, contact information, app usage, nearby objects and information shown on screens or documents. AI services may then produce descriptions, translations, summaries, classifications, reminders or inferred context.

 The processing path may involve the glasses, a paired phone, an employer account, a consumer account, the device manufacturer, an app developer, a cloud relay, a model provider, support personnel and analytics services. A feature described as local may still produce telemetry or account logs. An open-source device operating system does not make proprietary cloud infrastructure, first-party apps or third-party models open or locally controlled.

 The initial assessment should therefore answer five questions:

1. Which sensors and permissions does the function activate?
2. What raw and derived information is created?
3. Which device, app, cloud, model and support parties receive it?
4. Which party decides the purposes and essential means of each processing operation?
5. What is retained, reused, exported or available to other apps?

 This is where consumer and enterprise operating models can diverge sharply. An organisation may want the supplier to act only on documented instructions, while the supplier’s consumer terms reserve separate purposes for product analytics, safety, service improvement or model development. Calling the supplier a processor in the contract does not settle the question if the facts show that it determines purposes of its own.

 The analysis may identify the organisation as controller for the workplace use, the supplier as processor for one service, the supplier as separate controller for account or telemetry processing, and another provider as a subprocessor or independent controller for an AI feature. Joint control may need consideration where purposes and essential means are determined together. The EDPB’s controller and processor guidance should be applied to the actual processing, not the commercial label.

### GDPR, bystanders and the DPIA gate

 Smart glasses can affect people who never chose to use them. A worker may capture colleagues, visitors, customers, residents, patients, children or members of the public from a first-person viewpoint. The device may also reveal special-category information incidentally, including health, disability, religion, trade-union activity or biometric information.

 The organisation needs an Article 6 lawful basis for each organisational purpose and an Article 9 condition where special-category processing is intended. Consent will often be an unsuitable foundation in employment and other contexts involving imbalance or limited choice. A recording indicator or sign can support transparency, but it does not create a lawful basis and cannot cure processing that is unnecessary or disproportionate.

 Necessity needs to be tested against less intrusive alternatives. Could display-only prompts deliver the benefit? Can a barcode be processed locally without retaining an image? Can remote support be activated for a defined session rather than left available throughout a shift? Can captions be generated on the device and discarded immediately? Can the camera be physically disabled in restricted areas?

 A DPIA should be the expected starting gate for camera-enabled, monitoring, biometric, vulnerable-person or continuous-memory deployments. The Article 29 Working Party’s WP248 DPIA guidelines, subsequently endorsed by the EDPB, identify systematic monitoring, innovative technology, vulnerable data subjects, sensitive data and evaluation or scoring among the criteria that can indicate high risk. The Irish DPC’s DPIA list also includes systematic observation or control where people may not be aware of the processing or the controller’s identity.

 That does not mean every display-only accommodation automatically requires a full DPIA. It means the organisation should complete and retain a reasoned screening decision, and should not wait until procurement or a pilot has made meaningful change commercially difficult.

 Where a DPIA identifies residual high risk that the organisation cannot sufficiently mitigate, Article 36 GDPR requires prior consultation with the competent supervisory authority before the processing begins. That is an escalation route, not a substitute for redesigning an avoidably intrusive deployment.

> **Operational point:** A DPIA should be capable of changing the device, configuration, location, purpose or decision to deploy. If every answer was fixed before the assessment began, it is not functioning as a governance control.

 Individual rights also need an operational route. The organisation should know whether it can search, isolate, export, redact and delete relevant information. A data subject access request cannot be answered by saying that the information sits inside the vendor’s AI memory. Equally, preserving unlimited raw recording merely to make future searches possible would conflict with minimisation and retention requirements.

### Recording law does not stop at GDPR

 GDPR compliance does not resolve every question about recording a conversation or image.

 National laws may govern interception, recording of private communications, image and personality rights, employment surveillance, confidentiality and the admissibility or use of recordings. The legal position can depend on the country, whether the wearer participates in the conversation, the expectation of privacy, the location, the purpose and the people affected. Some rules may create criminal as well as civil exposure.

 An EU-wide smart-glasses policy should therefore contain a local-law gate. The central policy can define the approved capability and minimum controls, but local legal review should determine whether audio, video or streaming can be used in each jurisdiction and context. A green classification at group level cannot override a national prohibition or a stricter consent rule.

### The EU AI Act: some uses are prohibited, others may be high-risk

 Smart glasses are not automatically high-risk AI systems. The intended purpose and actual use determine the classification.

 The first distinction is between prohibited practices and high-risk use cases. An organisation cannot manage a prohibited practice into acceptability by adding another policy control. The AI Act prohibits specified forms of biometric categorisation and, subject to narrow exceptions for medical or safety reasons, the use of AI systems to infer emotions in the workplace. These prohibitions have applied since February 2025.

 Other functions may become high-risk because of how they are used. If data from smart glasses is used to allocate tasks based on individual behaviour or characteristics, monitor or evaluate worker performance, or make decisions affecting employment, the Annex III employment category may be engaged. Automated decisions producing legal or similarly significant effects also require a separate Article 22 GDPR analysis.

 The current application dates must be stated accurately. Following [Regulation (EU) 2026/1744, the Digital Omnibus on AI](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32026R1744), the high-risk rules for Annex III systems are scheduled to apply from 2 December 2027, while high-risk systems embedded in regulated products under Annex I are scheduled for 2 August 2028. Prohibited-practice rules are already applicable, and relevant transparency obligations began applying in August 2026. Existing GDPR, employment, equality and safety duties continue regardless of the later high-risk timetable. This timetable is correct as at 27 August 2026.

 Organisations should therefore classify the AI function now, record the rationale and design controls against the likely obligations rather than waiting for the final application date. The analysis should distinguish AI Act roles from GDPR roles: an organisation may be a GDPR controller and AI Act deployer, while a vendor may be a processor for one data flow and the AI Act provider of the system.

### Worker rights, consultation, safety and accessibility

 Wearable technology can change how work feels as well as how data is processed.

 A worker may experience glasses as useful assistance, constant oversight or both. A first-person feed can expose not only task performance but pace, mistakes, conversations, breaks and interactions with colleagues or customers. The Irish DPC’s guidance on employer vehicle tracking makes the broader point that workplace tracking should not become general monitoring of staff. The ICO similarly treats continuous audio or video monitoring as particularly intrusive.

 The deployment process should identify whether collective consultation, works council approval or co-determination rights apply. These are not interchangeable across Europe. In some jurisdictions, the relevant employee-representation process is a legal gate rather than a good-practice conversation. The UK and each EU Member State also have their own employment and equality framework.

 Physical safety requires its own review. A device may obstruct peripheral vision, distract the wearer, create notification overload or interfere with hearing protection, prescription eyewear, helmets or rated eye protection. A consumer device should not be assumed to meet the impact, environmental or compatibility requirements of industrial PPE. Instructions need to explain when prompts or live support must stop, particularly around vehicles, machinery, heights or emergency activity.

 Accessibility prevents the policy from becoming a blunt ban. A worker may rely on captions, prompts, navigation or visual assistance as a reasonable accommodation. The European Accessibility Act has applied to specified products and services since June 2025, while national equality and employment laws create their own duties. An accommodation does not remove the need for safeguards, but the organisation should consider whether the required benefit can be delivered through an approved configuration with capture disabled, local processing, limited permissions or restricted use zones.

### Confidentiality, intellectual property and discoverable records

 The most immediate intellectual-property risk is often not uncertainty about who owns an AI-generated sentence. It is the silent loss of control over information the organisation already values.

 Smart glasses can capture source code, prototypes, manufacturing processes, unreleased products, pricing, customer lists, whiteboards, security layouts, documents and screen content. They can also record legal advice, HR discussions, board material or negotiations. A visitor wearing personal glasses may create the same exposure as an employee.

 Trade-secret protection depends in part on reasonable steps to preserve secrecy. Organisations should be able to show where sensor-enabled devices are restricted, how visitors are informed, which approved devices can enter sensitive areas and what technical or disciplinary controls support the rule. The policy should distinguish confidentiality and trade-secret protection from copyright, database rights, contractual restrictions and ownership of new outputs.

 Records management needs equal attention. Transcripts, images, summaries and AI memories may become corporate records, evidence in litigation, material relevant to an investigation or information within the scope of a rights request. Automatic deletion may need to be suspended when a litigation hold or investigation applies. Conversely, keeping ambient recordings without a defined purpose creates unnecessary privacy, security and discovery exposure.

 Privilege also needs careful handling. Sending legal advice or a privileged discussion to an external AI service may complicate the confidentiality analysis and contractual position. Legal teams should define where glasses cannot be used and which approved services, if any, may process privileged material.

### Security, suppliers and app ecosystems

 Smart glasses should be treated as connected endpoints, not fashion accessories.

 The review should cover account security, pairing, encryption, local storage, device loss, remote wipe, permission management, camera and microphone controls, support access, firmware, vulnerability handling, app installation, cloud logs, model providers and end-of-support dates. Open app ecosystems increase the need for permission review, code provenance, app approval and change monitoring.

 Consumer accounts are particularly difficult to govern. The organisation may be unable to enforce settings, retrieve logs, disable cloud features, separate personal and business material or remove access when employment ends. Enterprise management capability should be treated as a deployment requirement for more than occasional low-risk use.

 International access and model processing should be assumed to require investigation. The transfer assessment should cover the device supplier, app operator, cloud relay, support teams and third-party AI providers, together with onward transfers and the actual scope of any regional-hosting commitment.

 The Cyber Resilience Act places lifecycle-security and vulnerability-handling obligations principally on manufacturers and other economic operators. A deploying employer should use those requirements as a procurement and assurance lever rather than presenting itself as the manufacturer. It should ask about the support period, security updates, incident reporting, technical documentation and the effect of integrating third-party components.

 Our guidance on [cloud AI due diligence](https://xpertdpo.com/cloud-ai-due-diligence-privacy-security-governance/) and [AI vendor evidence packs](https://xpertdpo.com/ai-vendor-due-diligence-questionnaires-and-evidence-packs/) provides a wider route for testing supplier claims against terms, configurations and evidence.

### Personal glasses, BYOD and restricted environments

 Personal ownership does not make professional processing household activity. Once a worker uses personal smart glasses for organisational work, or captures information in a professional or commercial context, the organisation needs to consider its own role and obligations.

 A workable policy should regulate capabilities and context rather than relying on appearance. Ordinary corrective glasses are not the issue. The questions are whether a device can capture, stream, infer, identify, store or connect to unapproved services, and whether those functions can be disabled and evidenced.

 Organisations can define zones and activities such as:

| Position | Examples | Typical response |
| --- | --- | --- |
| Green | Display-only prompts; approved navigation; locally processed captions with no retention | Permit under ordinary acceptable-use and accessibility controls |
| Amber | Time-limited remote support; approved translation; barcode scanning; bounded training capture | Require named purpose, managed device, DPIA screening, visible activation, restricted retention and approved locations |
| Red | Covert recording; always-on memory; facial identification without a separately lawful approved case; workplace emotion inference; performance scoring from first-person data; unapproved live streaming | Prohibit, with no local manager override |

 The colour is not universal. An amber audio function may become red under local recording law or in a confidential meeting. A green display function may become amber if it receives sensitive information or logs the wearer’s location. The classification belongs to the use case, jurisdiction, people and configuration.

 The [companion checklist](https://xpertdpo.com/smart-glasses-workplace-dpia-procurement-policy-checklist/) uses a separate four-level scale for physical environments. That zone model sits alongside this capability classification; it does not replace it.

> **Policy point:** Govern the capability that creates the risk, not the fact that the technology is worn on the face.

 Accessibility requests need a defined exception route rather than an informal manager decision. The review should identify the functional need, less intrusive configurations, restricted environments and who can approve the accommodation without requiring unnecessary disclosure of medical information.

### A deployment model DPOs and AI officers can use

 The governance route should connect privacy, AI, security, employment, accessibility, safety, procurement and information management without making the DPO the owner of every decision.

1. Define the precise function, user group, environment and expected benefit.
2. Inventory the active sensors, permissions, apps, AI services and outputs.
3. Map raw, inferred and logged data across device, phone, cloud, model and support parties.
4. Allocate GDPR, AI Act, product, employment and operational roles separately.
5. Screen for prohibited uses, high-risk AI, DPIA requirements and local recording restrictions.
6. Test necessity, alternatives, bystander effects, accessibility and physical safety.
7. Obtain supplier evidence on terms, transfers, security, updates, retention, deletion and change control.
8. Define approved settings, zones, activation methods, records handling and incident routes.
9. Run a bounded pilot with success, stop and reassessment criteria.
10. Record the approval, residual risks, responsible service owner and review triggers.

 The companion article, [Smart Glasses in the Workplace: DPIA, Procurement and Policy Checklist](https://xpertdpo.com/smart-glasses-workplace-dpia-procurement-policy-checklist/), turns this model into a practical set of questions and controls.

### Where the DPO and AI officer fit

 The operational owner should remain accountable for the purpose, deployment and service outcome.

 The DPO advises on lawful processing, necessity, proportionality, rights, transparency, DPIA quality and residual data-protection risk. The AI officer coordinates AI inventory, role and risk classification, prohibited-use screening, technical documentation, human oversight and lifecycle monitoring. Security assesses the endpoint, accounts, apps, cloud path and incident controls. HR and employee representatives address monitoring, consultation, fairness and accommodation. Safety specialists assess physical use. Procurement and legal test terms, supplier evidence, IP, confidentiality and remedies.

 Those roles should meet around one use-case record. Parallel reviews that never compare assumptions can each be competent and still approve an incoherent deployment.

### The XpertDPO view

 Smart glasses should not be governed as either harmless eyewear or inevitable surveillance.

 The sensible position is managed permission for defined functions, clear prohibition of unlawful or uncontrollable uses, and an accommodation route that protects accessibility rather than treating it as an exception to be discouraged. The organisation should know what the glasses can do, which functions are enabled, where the data travels, who is responsible and what evidence supports the decision.

 A policy alone cannot create that control. The practical work sits in configuration, procurement, consultation, assessment, training, restricted environments and review of change. That is how organisations can use smart glasses where they genuinely help without quietly introducing an unmanaged recording and AI-processing system into ordinary work.

 Our [AI Governance and DPIA Lifecycle Support](https://xpertdpo.com/ai-governance-dpia-lifecycle-support/) helps organisations connect DPIAs, AI classification, vendor evidence and operational approval. [DPO Support](https://xpertdpo.com/dpo-support/) provides senior independent challenge where an in-house team needs a second view before deployment.

### Sources and further reading

- [European Commission, AI Act regulatory framework and current application timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)
- [Regulation (EU) 2024/1689, Artificial Intelligence Act](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689)
- [Regulation (EU) 2026/1744, Digital Omnibus on AI](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32026R1744)
- [Consolidated Artificial Intelligence Act, current version 27 July 2026](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng)
- [European Commission, AI Omnibus enters into force](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force)
- [EDPB, Guidelines 07/2020 on controller and processor concepts](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-072020-concepts-controller-and-processor-gdpr_en)
- [EDPB, endorsed WP29 guidelines, including WP248 rev.01 on DPIAs](https://www.edpb.europa.eu/endorsed-wp29-guidelines_en)
- [EDPB, DPIA guidance for organisations](https://www.edpb.europa.eu/sme/be-compliant/be-compliant_en)
- [Irish DPC, processing operations requiring a DPIA](https://www.edpb.europa.eu/sites/default/files/decisions/ie_dpc_data-protection-impact-assessment.pdf)
- [Irish DPC, Annual Report 2023, Ray-Ban Meta Smart Glasses engagement](https://www.dataprotection.ie/sites/default/files/uploads/2026-02/DPC%20EN_AR%202023_Final_ACO1.pdf)
- [Irish DPC, Employer Vehicle Tracking](https://dataprotection.ie/en/dpc-guidance/employer-vehicle-tracking)
- [ICO, Data protection and monitoring workers](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/data-protection-and-monitoring-workers/)
- [European Commission, European Accessibility Act](https://commission.europa.eu/strategy-and-policy/policies/justice-and-fundamental-rights/disability/european-accessibility-act-eaa_en)
- [European Commission, Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
- [EU-OSHA, Assisted-reality devices for remote OSH assessment](https://healthy-workplaces.osha.europa.eu/sites/hwc/files/hwc/publication/Assisted-reality-device-remote-OSH-assessments-audit_case-study_EN.pdf)
- [European Commission, Trade secrets](https://single-market-economy.ec.europa.eu/industry/strategy/intellectual-property/trade-secrets_en)
- [Meta, Responsible innovation in AI glasses](https://www.meta.com/actions/responsible-innovation/)
- [Brilliant Labs, Halo](https://brilliant.xyz/products/halo)
- [Mentra, Privacy Notice](https://mentraglass.com/privacy-policy)
- [Mentra, Enterprise smart-glasses platform](https://mentraglass.com/)
- [XpertDPO, Service Robots and Embodied AI: A Governance Guide for DPOs](https://xpertdpo.com/service-robots-embodied-ai-governance/)
- [XpertDPO, Which Laws Apply to Service Robots?](https://xpertdpo.com/service-robots-eu-laws-compliance/)

## General Information Only

This article is provided for general information and does not constitute legal, regulatory, or professional advice. Data protection obligations depend on the specific facts, context, and jurisdiction involved. You should not rely on this content as a substitute for advice tailored to your organisation.

If you would like support with a specific issue, please contact us: https://xpertdpo.com/contact/
