Home » Blog » Meta Glasses: Addressing the Privacy Concerns of Bystanders and Data Controllers

Meta Glasses: Addressing the Privacy Concerns of Bystanders and Data Controllers

Authored By: Chukwukaima Vivian Fabian-Egun

University of Dundee

Introduction

“Is someone recording me?” is becoming an increasingly relevant question as wearable technology becomes ‘indistinguishable’[1] from ordinary consumer products. The development of camera-enabled smart glasses has created a new form of surveillance in which individuals can capture photographs, video and audio while appearing simply to be wearing conventional eyewear. Meta’s Ray-Ban smart glasses provide a particularly important example because they combine a discreet camera with artificial-intelligence functionality.

The growing controversy surrounding these devices reflects both ethical and legal concerns. Venues in the United Kingdom have increasingly considered or introduced restrictions on camera-enabled smart glasses,[2] while recent public debate has focused on the possibility of individuals being recorded without their knowledge. Recently,the UK Cinema Association reported that cinemas were considering restrictions on smart glasses because of recording and piracy concerns,[3] while other UK venues and institutions have already introduced restrictions.[4]

The central legal difficulty, however, extends beyond whether the glasses should be permitted in particular locations. It concerns the allocation of responsibility for the personal data captured by the device. Where an individual records a bystander, the individual may potentially become a data controller if the processing falls within the scope of the UK General Data Protection Regulation (UK GDPR).[5] At the same time, Meta may undertake additional processing when footage or images are transmitted to its cloud infrastructure for artificial-intelligence functions. This creates uncertainty over which party determines the purposes and means of processing at each stage and, consequently, which party bears responsibility under data-protection law.

This article argues that the principal difficulty created by AI-enabled smart glasses is not simply that existing law fails to regulate the technology. Rather, the technology exposes uncertainty within the existing framework concerning the allocation of responsibility between the individual wearer, the technology provider and the person being recorded.

Dismantling Meta’s Data Controller Illusion

The starting point is the concept of the data controller. Article 4(7) UK GDPR [6]defines a controller by reference to the person or body that determines the purposes and means of processing personal data.[7] The designation is important because a controller is responsible for ensuring that processing complies with the UK GDPR,[8] including the principles contained in Article 5[9] and the requirement for a lawful basis under Article 6.[10] The Information Commissioner’s Office (ICO) confirms that a controller remains responsible for compliance even where another party processes personal data on its behalf.[11]

In the context of smart glasses, it would therefore be incorrect to assume that Meta automatically bears responsibility for every recording made through its product. If an individual decides to record people in a public street for their own purposes, the individual may determine both the purpose and means of that processing.[12] Depending on the circumstances, the individual could therefore potentially satisfy the definition of a controller.[13]

The relevant question, however, is who determines why and how personal data is processed. The distinction is particularly important because the wearer may have little awareness of the legal consequences of their activity. A consumer may regard the glasses as equivalent to an ordinary pair of sunglasses or a conventional camera. However, if the individual is processing identifiable personal data outside the scope of the domestic purposes exclusion, the legal obligations of a controller may become relevant.[14]

The ICO states that individuals processing personal data solely for purely personal or household activities fall outside the scope of the UK GDPR.[15] However, the ICO also emphasises that this depends on the purpose of the processing and must be considered on a case-by-case basis.[16]The legal issue is therefore whether the particular processing activity is genuinely personal or household in nature.

The Household Exclusion and Ryneš

Article 2(2)(c) UK GDPR[17] excludes processing carried out by an individual in the course of a purely personal or household activity from the Regulation. Examples include taking pictures with family and more. The difficulty arises when personal technology is used to record people outside the user’s private sphere.

The leading authority is František Ryneš v Úřad pro ochranu osobních údajů (Case C-212/13).[18] The case concerned a camera installed on a family home for the protection of the owners.[19] The camera also captured public space. The Court of Justice of the European Union held that such processing did not fall within the purely personal or household exemption because the surveillance extended, even partially, into public space.[20]

Ryneš [21]is particularly relevant to smart glasses because both situations involve technology operated by a private individual that captures people outside the individual’s private sphere. However, the case should not be overstated. Ryneš[22] concerned Directive 95/46/EC[23] rather than the UK GDPR. Its importance lies in the interpretation of the concept of purely personal or household activity and the narrow approach taken towards an individual relying on that exclusion.

The case therefore provides a strong basis for arguing that a consumer cannot automatically rely upon the household exclusion[24] merely because the recording device is personally owned. The purposes, scale and circumstances of processing must therefore be considered.If the household exclusion does not apply, the next question is whether the processing has a lawful basis under Article 6 UK GDPR.[25]

Article 6[26] requires at least one lawful basis for processing personal data. The available bases include consent, contract, legal obligation, vital interests, public task and legitimate interests.[27] The concept of asking for the consent of a bystander when recording becomes relevant. This is because consent is not the only possible basis. This is an important distinction because the absence of consent does not automatically make every recording unlawful.Valid consent must involve a clear indication of the individual’s wishes for a specific purpose.[28] In many street-recording situations, the bystander may not know that they are being recorded and therefore has no opportunity to provide meaningful consent.

The other lawful bases may also be difficult to establish depending on the circumstances. Contractual necessity, for example, concerns processing necessary for a contract with the relevant individual or steps taken at their request before entering into a contract. A contract between Meta and the glasses owner does not automatically create a contractual basis for processing the personal data of an unrelated bystander. Legal obligation and vital interests are similarly unlikely to provide a general justification for ordinary recreational recording of members of the public.[29]

Public task is also unlikely to apply to an ordinary private consumer because Article 6(1)(e)[30] concerns processing necessary for a task in the public interest or the exercise of official authority with a clear basis in law. The most significant alternative is therefore likely to be legitimate interests.

Legitimate interests require an assessment of the controller’s interest, the necessity of the processing and the rights and freedoms of the data subject. A consumer might argue that recording is necessary for personal documentation, security or another legitimate purpose.[31] However, the strength of that argument depends on the circumstances. Continuous recording of strangers, particularly where the recording is unnecessary or disproportionate to the purpose pursued,[32] creates a much more difficult balancing exercise.

Cloud-Based AI Processing and Meta’s Role

The legal analysis becomes more complicated when the smart glasses communicate with cloud-based artificial-intelligence systems.Meta’s current Ray-Ban information explains that certain camera-based AI features can involve sending photographs to Meta’s cloud for AI processing. [33]Meta states that the information is used to provide the requested feature and, in protected form, to improve its products. Meta also states that its newer glasses do not use facial-recognition technology.

This is significant because the processing may extend beyond the initial act of recording. For example, an individual may use the glasses to look at a landmark and ask Meta AI to identify it. The image captured by the glasses may then be transmitted to Meta for processing.[34] The person standing beside the landmark may consequently become part of the captured image even though they were not the intended subject of the interaction.

This creates a distinction between the initial capture and subsequent processing. At the initial stage, the wearer may determine the purpose of capturing the image. At a later stage, Meta may determine the purposes and means of processing that occur through its AI infrastructure.[35] The legal status of each party therefore requires a factual assessment rather than an automatic conclusion that either the consumer or Meta is always the controller.If Meta determines the purposes of processing independently from the user’s instructions, it may assume controller responsibilities for that processing. If the parties jointly determine the purposes and means, the concept of joint controllership may become relevant. Conversely, if Meta processes information solely on behalf of a controller and according to that controller’s instructions, the legal relationship may instead involve a processor.

The position becomes particularly significant where Meta processes information through human reviewers.[36] If Meta uses the information for a new commercial purpose, such as improving its products or AI systems, independently of the user’s original purpose, this may indicate that Meta is determining its own purpose for the processing. In such circumstances, Meta may have controller responsibilities for that subsequent processing rather than simply acting as a processor on behalf of the consumer.However ,Meta does plan on cutting 90 percent of its human reviewers for content moderation.[37]

If information from that interaction is subsequently used to improve Meta’s AI products, this does not necessarily mean that the user controls every subsequent purpose for which the information is processed. Instead, the purposes for which Meta subsequently uses the information must be examined separately.

Bystander Privacy and the Problem of Consent

The position of the bystander represents the strongest ethical and legal concern.Traditional photography already allows individuals to photograph people in public without necessarily asking every person for permission. Smart glasses, however, alter the practical nature of the activity. The camera is embedded in ordinary-looking eyewear, meaning that the person being recorded may not know when recording has started.Meta has introduced a visible LED intended to indicate when photographs, videos or livestreams are being captured.[38] However, there have been comments on how the LED light is not even noticeable at all.[39]

A visible recording indicator may provide a technological safeguard, but it does not itself establish a lawful basis for processing. Similarly, the fact that a person is physically present in a public place does not necessarily mean that they have surrendered all control over the use of their personal data.

The question is therefore not whether individuals have an absolute right never to be photographed in public. Rather, the issue is whether the particular processing is fair, lawful, proportionate and transparent according to Articles 12 [40]and 13 [41]of the UK GDPR, and whether there is accessible notice to data subjects.

Article 82 and Individual Liability

The question of liability further demonstrates why responsibility cannot simply be transferred to the manufacturer.Where an individual qualifies as a controller and processing breaches the UK GDPR, Article 82[42]  provides a potential route to compensation for individuals who suffer damage. The ICO[43] confirms that an individual can bring a claim directly against a controller and that non-material damage, including distress, may be relevant to compensation.

This means that the legal responsibility associated with a smart-glass recording could, in an appropriate case, extend to the wearer rather than automatically resting with Meta. The claimant would need to establish the relevant infringement and damage, and the controller may have arguments concerning responsibility and the circumstances of the processing.

The concept also raises the issue of whether, where a bystander’s face or voice is captured and sent to Meta’s servers and subsequently reviewed by humans, the bystander may have rights such as the right to access their personal data.[44] However, this would depend on whether Meta is acting as a controller in relation to that processing and whether the relevant information constitutes the bystander’s personal data.

Critical Evaluation

Through exploring the shifting roles of data controlling that Meta may try to pass on to the consumer, as well as the consent of bystanders and their rights, it is important to examine the practical nature of Meta’s products.

Meta presents itself as being involved and aware of privacy concerns, particularly through the use of an LED light [45]intended to warn bystanders that they are being recorded. However, it is important to question whether these safeguards provide meaningful protection in practice. If the LED is difficult to notice, then the existence of a recording indicator may provide limited transparency to the person being recorded.

This raises a wider question about whether Meta’s privacy safeguards are genuinely effective or whether they risk becoming more theatrical than practical. The presence of an LED may create the appearance that bystanders are being given notice, while in reality a person may still have no reasonable way of knowing that they are being recorded.

The issue therefore goes beyond whether Meta has technically introduced a privacy safeguard. The more important question is whether that safeguard meaningfully protects the rights of the person being recorded and provides genuine transparency about how their personal data is being processed.

Conclusion

The concept of data controlling and bystander privacy concerns emphasises concerns over the dismantling of public anonymity. Technology has found loopholes in order to slowly eradicate privacy and seek data from individuals under the guise of third parties or consumer technology. Meta’s smart glasses demonstrate how the boundaries between personal use, commercial processing and surveillance are becoming increasingly difficult to distinguish.

The issue is therefore not simply whether individuals should be allowed to record in public, but who should be responsible when personal data is captured, processed and potentially used for further purposes. The wearer may initially control the recording, while Meta may become involved when that information is transferred to its cloud infrastructure and processed through its AI systems. This creates uncertainty over where responsibility begins and where it ends.

Ultimately, the development of AI-enabled smart glasses demonstrates that existing data-protection principles remain relevant, but their application becomes more difficult as technology becomes increasingly discreet and interconnected. The law must therefore continue to examine not only who owns the technology, but who controls the data and for what purpose it is ultimately being used.

Bibliography

Cases

František Ryneš v Úřad pro ochranu osobních údajů (C-212/13) EU:C:2014:2428

Legislation and EU Instruments

Data Protection Act 2018

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) [2016] OJ L119/1

Books, Articles and Academic Sources

Bhardwaj D, Ponticello A, Tomar S, Dabrowski A and Krombholz K, ‘In Focus, Out of Privacy: The Wearer’s Perspective on the Privacy Dilemma of Camera Glasses’ in Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI ’24) (Association for Computing Machinery 2024) 577:1–577:18 https://doi.org/10.1145/3613904.3642242 accessed 23 August 2026.

Websites and Online Sources

Doughty Street Chambers, ‘Through the Looking Glass: Ray-Ban Meta, Privacy and the Law in the UK’ https://insights.doughtystreet.co.uk/post/102mtvc/through-the-looking-glass-ray-ban-meta-privacy-and-the-law-in-the-uk accessed 23 August 2026

European Data Protection Board, ‘Data controller or data processor’ https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en accessed 23 August 2026.

European Union, ‘Official Journal of the European Union’ https://eur-lex.europa.eu/TodayOJ/index.html accessed 23 August 2026

eMarketer, ‘Meta plans to replace 90% of content moderation processes with AI’ https://www.emarketer.com/content/meta-plans-replace-90–of-content-moderation-processes-with-ai accessed 23 August 2026

GDPR-Info, ‘Article 6 GDPR’ https://gdpr-info.eu/art-6-gdpr/ accessed 23 August 2026

Information Commissioner’s Office, ‘A guide to lawful basis’ https://ico.org.uk/for-organisations/advice-and-services/lawful-basis/a-guide-to-lawful-basis/ accessed 23 August 2026

Information Commissioner’s Office, ‘Data protection principles, definitions and key terms’ https://ico.org.uk/for-organisations/advice-for-small-organisations/getting-started-with-gdpr/data-protection-principles-definitions-and-key-terms/ accessed 23 August 2026.

Information Commissioner’s Office, ‘Previously asked questions’ https://ico.org.uk/for-organisations/advice-and-services/innovation-advice/previously-asked-questions/ accessed 23 August 2026

LexisNexis, ‘Processing personal data: conducting a legitimate interest assessment’ https://www.lexisnexis.co.uk/legal/guidance/processing-personal-data-conducting-a-legitimate-interest-assessment accessed 23 August 2026

Markeviciute E, ‘Meta smart glasses ban ignores Europe’s wider surveillance threat’ (Euronews, 21 August 2026) https://www.euronews.com/next/2026/08/21/ban-metas-smart-raise-surveillance-fears-across-europe accessed 23 August 2026.

Meta, ‘Meta AI glasses’ https://www.meta.com/en-gb/help/ai-glasses/718045509827730/ accessed 23 August 2026

Meta, ‘Prioritizing Content Review’ https://transparency.meta.com/en-gb/policies/improving/prioritizing-content-review/ accessed 23 August 2026

Meta, ‘Ray-Ban Meta Display’ https://www.meta.com/gb/ai-glasses/meta-ray-ban-display/ accessed 23 August 2026

Harrison Dupré M, ‘Did someone wearing Meta Glasses film you today? Are you sure?’ (The Guardian, 19 August 2026) https://www.theguardian.com/technology/ng-interactive/2026/aug/19/meta-glasses-privacy-surveillance accessed 23 August 2026.

Horton H, ‘Meta glasses banned from courts in England and Wales’ (The Guardian, 11 August 2026) https://www.theguardian.com/technology/2026/aug/11/meta-glasses-banned-from-courts-in-england-and-wales accessed 23 August 2026.

Radiocoms, ‘GDPR Video Recording’ https://www.radiocoms.co.uk/gdpr-video-recording/ accessed 23 August 2026

University of Oxford, ‘Expert comment: Meta glasses privacy protections neglect those being watched’ (16 July 2026) https://www.ox.ac.uk/news/2026-07-16-expert-comment-meta-glasses-privacy-protections-neglect-those-being-watched accessed 23 August 2026

[1] Egle Markeviciute, ‘Meta smart glasses ban ignores Europe’s wider surveillance threat’ (Euronews, 21 August 2026) https://www.euronews.com/next/2026/08/21/ban-metas-smart-raise-surveillance-fears-across-europe accessed 23 August 2026.

[2] Helena Horton, ‘Meta glasses banned from courts in England and Wales’ (The Guardian, 11 August 2026) https://www.theguardian.com/technology/2026/aug/11/meta-glasses-banned-from-courts-in-england-and-wales accessed 23 August 2026.

[3] Egle(n1)

[4] Horton(n2)

[5] General Data Protection Regulation 2018

[6] Article 4(7) General Data Protection Regulation 2018

[7] ibid

[8] General Data Protection Regulation 2018

[9] Article 5 General Data Protection Regulation 2018

[10] Article 6 General Data Protection Regulation 2018

[11] Information Commissioner’s Office, ‘Data protection principles, definitions and key terms’ https://ico.org.uk/for-organisations/advice-for-small-organisations/getting-started-with-gdpr/data-protection-principles-definitions-and-key-terms/ accessed 23 August 2026.

[12] European Data Protection Board, ‘Data controller or data processor’ https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en accessed 23 August 2026.

[13] Ibid.

[14] Divyanshu Bhardwaj, Alexander Ponticello, Shreya Tomar, Adrian Dabrowski and Katharina Krombholz, ‘In Focus, Out of Privacy: The Wearer’s Perspective on the Privacy Dilemma of Camera Glasses’ in Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI ’24) (Association for Computing Machinery 2024) 577:1–577:18 https://doi.org/10.1145/3613904.3642242 accessed 23 August 2026.

[15] Information Commissioner’s Office, ‘Previously asked questions’ https://ico.org.uk/for-organisations/advice-and-services/innovation-advice/previously-asked-questions/ accessed 23 August 2026.

[16] Ibid

[17] Article 2(2)(c) General Data Protection Regulative.

[18] Ryneš v. Úřad pro ochranu osobních údajů, Case C-212/13 (C..J.E.U 2014)

[19] Ibid

[20] ibid

[21] Ryneš v. Úřad pro ochranu osobních údajů, Case C-212/13 (C..J.E.U 2014)

[22] Ryneš v. Úřad pro ochranu osobních údajů, Case C-212/13 (C..J.E.U 2014)

[23] European Union, ‘Official Journal of the European Union’ https://eur-lex.europa.eu/TodayOJ/index.html accessed 23 August 2026.

[24] Article 2(2)(c ) General Data Protection Regulative.

[25] Article 6 General Data Protection Regulative.

[26] ibid

[27] ‘Article 6 GDPR’ (GDPR-Info) https://gdpr-info.eu/art-6-gdpr/ accessed 23 August 2026.

[28] Radiocoms, ‘GDPR Video Recording’ https://www.radiocoms.co.uk/gdpr-video-recording/ accessed 23 August 2026.

[29] Information Commissioner’s Office, ‘A guide to lawful basis’ https://ico.org.uk/for-organisations/advice-and-services/lawful-basis/a-guide-to-lawful-basis/ accessed 23 August 2026.

[30] Article 6(1) ( e) General Data Protection Regulation

[31] LexisNexis, ‘Processing personal data: conducting a legitimate interest assessment’ https://www.lexisnexis.co.uk/legal/guidance/processing-personal-data-conducting-a-legitimate-interest-assessment accessed 23 August 2026.

[32] ibid

[33] Meta, ‘Meta AI glasses’ https://www.meta.com/en-gb/help/ai-glasses/718045509827730/ accessed 23 August 2026.

[34] ibid

[35] Doughty Street Chambers, ‘Through the Looking Glass: Ray-Ban Meta, Privacy and the Law in the UK’ https://insights.doughtystreet.co.uk/post/102mtvc/through-the-looking-glass-ray-ban-meta-privacy-and-the-law-in-the-uk accessed 23 August 2026.

[36] Meta, ‘Prioritizing Content Review’ https://transparency.meta.com/en-gb/policies/improving/prioritizing-content-review/ accessed 23 August 2026.

[37] eMarketer, ‘Meta plans to replace 90% of content moderation processes with AI’ https://www.emarketer.com/content/meta-plans-replace-90–of-content-moderation-processes-with-ai accessed 23 August 2026.

[38] Meta, ‘Ray-Ban Meta Display’ https://www.meta.com/gb/ai-glasses/meta-ray-ban-display/ accessed 23 August 2026.

[39] Maggie Harrison Dupré, ‘Did someone wearing Meta Glasses film you today? Are you sure?’ (The Guardian, 19 August 2026) https://www.theguardian.com/technology/ng-interactive/2026/aug/19/meta-glasses-privacy-surveillance accessed 23 August 2026.

[40] Article 12 GDPR

[41] Article 13 GDPR

[42] Article 82 GDPR

[43] Information Commissioner’s Office, ‘Data protection principles, definitions and key terms’ (n 8).

[44] University of Oxford, ‘Expert comment: Meta glasses privacy protections neglect those being watched’ (16 July 2026) https://www.ox.ac.uk/news/2026-07-16-expert-comment-meta-glasses-privacy-protections-neglect-those-being-watched accessed 23 August 2026.

[45] Meta (n38)

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top