On 7 August the Privacy Commissioner, Carly Kind, published a piece on surveillance wearables. The headline point was regulatory: the OAIC is “giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence in order to understand if scrutiny and intervention is required or warranted”, and has “engaged with one entity on at least two occasions this year to further understand the technical specifications”.
Most of the coverage will treat that as a privacy story about individuals in public places, which it largely is. The Commissioner’s concern leads with the exploitation of vulnerable people, specifically children and victims of domestic violence.
But one item in her list of harmful uses is the one your business can actually do something about this week: corporate espionage, data theft, extortion or bribery.
The devices are already here, and more are coming
Meta Glasses are on sale now. Google plans to launch Android XR glasses later this year. Apple’s own product is due in 2027. Cut-price versions are already appearing at Kmart and Amazon. OpenAI has plans for a wearable designed for the ambient collection of data to feed an AI assistant.
The Commissioner draws a distinction worth borrowing. There is a meaningful difference, she writes, between place-based surveillance in airports and certain retail spaces, which has to meet a threshold to be justified, and surveillance wearables “in the hands of every roving individual, designed for discretion (or even concealment)”.
Designed for discretion. That is the whole problem in three words, and it is a physical security problem before it is a privacy one.
Your control assumes the camera is visible
Go and read your visitor procedure. Most say something close to “no photography or recording without authorisation”, and most were written when a camera meant a phone held up at arm’s length, which is a visible, socially obvious act that a receptionist or a host can challenge.
Glasses look like glasses. There is nothing to challenge.
If you hold ISO 27001, the control that actually addresses this is Annex A 7.6, working in secure areas, which is about the rules that apply to people once they are inside a controlled space. Almost nobody has re-read 7.6 since their Statement of Applicability was signed, because it is a short control that has felt settled for years.
It has stopped being settled. Several neighbouring controls carry the same buried assumption:
- A 7.2, physical entry. Your entry controls check who someone is and whether they are expected. They do not check what they are wearing.
- A 7.7, clear desk and clear screen. This control exists so information is not visible to people who should not see it. It assumes exposure is momentary and requires someone to be looking. A recording device makes exposure permanent and reviewable at leisure.
- A 5.14, information transfer. Recording is transfer. It just does not look like transfer, because no file moves through anything you monitor.
This is a control that fails silently
Here is why it is worth an auditor’s attention rather than a policy update.
Most information security failures leave a trace. A login is recorded, a file movement is logged, a data loss rule fires, a mail gateway blocks something. You find out, eventually, because a system tells you.
A visitor recording your whiteboard, your production floor, your screens or a conversation generates no log, no alert and no incident. There is nothing to detect, nothing to review and nothing to correlate. If it happens, you do not learn about it from your monitoring. You learn about it from the consequences, if you ever learn about it at all.
That means the only control that finds this is a physical walk-through during a clause 9.2 internal audit, where someone stands in reception and asks what actually happens when a visitor arrives wearing them. Not what the procedure says happens.
We made a similar point about the virtual equivalent in AI meeting bots and the recorder nobody invited. Same failure mode, different room.

Where the law lands, and where it does not
Worth being clear on this, because it changes who carries the risk.
The Privacy Act applies to businesses and government agencies, not to individuals, and only when those entities collect personal information. So where a tech company receives and stores what the glasses capture, that company has obligations, and the Commissioner raises real questions about how they will meet them, particularly around notifying people that they have been recorded and obtaining consent for facial recognition.
But where the data stays on the device, the Act may not reach it at all. In that situation the residual remedy is the recently introduced tort of serious invasions of privacy, which is a claim an affected individual brings, not a regulatory obligation on you.
Read that from your own position. If a visitor records your secure area, privacy law is not the thing that protects your information. Your physical controls are. There is no regulator standing behind this one for you.
Tranche 2 of the Privacy Act may change the balance for the device makers, with a fair and reasonable test for collection and use, higher consent standards and more protection for geolocation data. The forthcoming Digital Duty of Care will reach hardware providers too. None of that puts a control at your reception desk.
What to do
This is a policy line, a sign and a question. Not a project.
Say the word. Update your visitor and secure area rules so they name recording-capable eyewear and wearables explicitly, rather than relying on “cameras” to cover it. Ambiguity is what gets argued about after the fact.
Ask at reception. One question during sign-in, the same way you ask about laptops in some environments. The point is not to catch people out. It is that a rule nobody states is a rule nobody follows.
Decide where it actually matters. Do not attempt a site-wide ban you cannot enforce. Identify the genuinely sensitive areas, the ones where a recording would hurt, and apply the control there properly.
Brief the people who host visitors. Reception cannot enforce this alone, because most of the exposure happens after someone has been escorted past the front desk.
Put it in the audit scope. Add it to the physical security walk-through so it gets looked at routinely by someone whose job is to notice.
Check your contractors and their equipment. Body-worn cameras are now common in trades, security and logistics for entirely legitimate reasons. That is a supplier conversation, not a visitor one.
What to watch, and why this piece will change
Update, 3 September 2026: this trigger has fired. The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 was released on 31 August and is open for consultation until 18 September. Its Consultation Paper puts wearable surveillance technologies, described as including smart glasses and ear buds, along with connected vehicles, out for comment. At this stage these are consultation questions rather than draft provisions, so nothing here changes what your visitor policy has to say today. What it does confirm is that the regulator interest described above has become a formal line of inquiry. The parts of the draft that do carry proposed obligations, including a 72 hour notification clock, are covered in what your data breach response plan has to prove.
This is a regulator signalling, not a deadline. Nothing here obliges you to do anything by a date. That makes it worth saying plainly what would change the picture, because three things are coming.
Google’s Android XR glasses, later this year. The Commissioner named this launch specifically. It moves smart glasses from early adopters to a mainstream product with a major platform behind it, which is the point at which your reception desk starts seeing them regularly rather than occasionally.
Whether the OAIC moves from monitoring to intervention. The post says the office is watching the market to understand if scrutiny and intervention is required or warranted, and has already engaged with one manufacturer twice this year. If that becomes formal guidance or an assessment, the compliance position changes for the device makers and expectations on businesses hosting visitors will firm up with it.
Privacy Act Tranche 2. Still a commitment with no Bill and no commencement date, but the proposed fair and reasonable test, higher consent standards and expanded definition of personal information would all bear on how these devices can lawfully operate.
We will update this article as those land rather than write new ones, so it stays the single place to look.
Where this fits
Physical and environmental controls are one of the four themes of Annex A and the one that gets the least attention in most ISO 27001 information security management systems, because it is the least technical part of a standard people assume is technical. That is precisely why it drifts. If you want the wider map, we have set out what the Annex A controls actually cover.
The Commissioner’s post is not a compliance deadline and nothing in it obliges you to act. It is a regulator saying, on the record, that this is coming and that it is watching. The organisations that will handle it well are the ones that spend twenty minutes on it now, while it is still a policy line, rather than after somebody walks out with a quarter’s worth of your roadmap on a memory card.
Sources
- Carly Kind, Privacy Commissioner, Surveillance wearables – are we through the looking glass(es)?, OAIC, 7 August 2026
- OAIC, research and training resources, including the Australian Community Attitudes to Privacy Survey
Privacy law, surveillance device law and workplace surveillance law differ between Australian states and territories, and all three are changing.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











