Smart glasses highlight gaps in privacy laws

In June, reality star Kylie Jenner posted her latest collaboration on social media — a new design for Meta’s line of AI-powered “smart glasses”. Images of her wearing the glasses filled social media, as did videos of her teenage self lamenting the lack of privacy she was afforded because of her fame. The irony was unmissable: how is Ms. Jenner, who was once so worried about privacy, now promoting a device that enables surveillance?
Smart glasses are the latest addition to the wearable technology space. It is also a dangerous example of how current laws are unable to keep up with today’s tech innovation.
According to Meta, these glasses allow you to see and answer calls, messages, and notifications via voice command. Built-in speakers help you listen to music and an integrated camera enables you to capture photos or videos through the lenses. Meta describes these glasses as “normal-looking eyewear with discreetly integrated glasses technology.” Hidden from the naked eye, these glasses contain “tiny speakers, microphones, [and] a lightweight camera.” The tech giant isn’t shying away from how inconspicuous these features are; rather, it is flaunting it.
Privacy and data concerns
In India, the glasses, which have been advertised everywhere, retail at around ₹25,000. Stickers that claim to completely cover the LED recording indicator are also widely available. Meta says that if the LED is covered, the glasses will block the recording until the sticker is removed. Yet, workarounds are just a Google search away. The glasses also make a shutter sound when they start and stop recording, but this is not a strong indicator that you are being recorded. Further, Meta argues that the glasses are “designed for privacy, controlled by you.” But this “control” is limited to the wearer, and not the recorded subject, such as requiring additional verification before use.
The website adds, “Meta collects data needed to help ensure that your glasses and app are reliable, secure and operating normally.” An investigation by Swedish newspapers Svenska Dagbladet and Goteborgs-Posten found that Meta’s contracted workers, who sometimes review the data to track user experience, were able to view sensitive content filmed on the smart glasses, including wearers using the toilet. In a comment to BBC News, Meta said its privacy policy states that it sometimes uses contractors to review data shared with them.
In this context, concerns about women’s privacy have grown. Data from the National Crime Records Bureau (NCRB) show that in 2023, before the glasses entered the market, there were 3,678 cases of women-centred cybercrimes. Of these, 2,767 cases involved the transmission or publication of sexually explicit material. Consider how much easier these glasses would make it to record people without their knowledge, including in private spaces. The potential risks to children are equally concerning. In 2023, the NCRB recorded over 698 cases related to the use or storage of child sexual abuse material. If adults cannot often recognise when the glasses are recording, a child certainly cannot.
These risks are compounded by the glasses’ battery life, offering 4-9 hours of active use. This means entire movies can be recorded, university lectures can be taped, confidential documents scanned, and patient information collected. It also means that even those who are not intentionally engaging in malpractice could invariably do so — by capturing something private in the frame’s periphery, for example. Ultimately, these glasses allow for the extensive, non-consensual collection of data.
Lacuna in the law
India’s laws today do little to protect people from this surveillance. The Digital Personal Data Protection Act, 2023 (DPDPA) is technologically agnostic, making the purpose of data collection the key consideration. In a public space, people can neither grant consent nor monitor how their information is used.
Following the landmark K.S. Puttaswamy vs. Union of India 2017 judgment, reasonable expectation of privacy was recognised as a fundamental right under Article 21. This means that people, even in public spaces, don’t generally expect to be captured in detail. But the DPDPA excludes information that is made publicly available. Hence, the reasonable expectation of privacy granted by Puttaswamy is not met because the Act does not regulate how someone is being recorded in public. The Act’s scope is diluted further since there are minimal indicators that you could be in someone’s frame, unlike someone recording on their phone.
This combination of rapid tech innovation and a lack of legal regulation and public awareness creates the perfect storm. With devices such as these glasses becoming common, people may be collecting information with little knowledge of where the data are being used. Without legal safeguards, digital accountability risks becoming an afterthought.
Banning such devices isn’t practical from a business or tech standpoint. Meta might be the biggest player in this space today, but Google and Reliance are also entering the smart glasses market. As wearable tech becomes more advanced, banning it will become increasingly difficult. Instead, laws should be framed with an understanding of how AI is changing the landscape. There is a need for assessments on how technology will evolve, the risks that may accompany it, and the government’s responsibility in ensuring that citizens are adequately protected.
sonikka.l@thehindu.co.in




Leave a Reply