Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Your Visitor Policy Says No Cameras. Your Visitors Are Wearing Them.

On 7 August the Privacy Commissioner, Carly Kind, published a piece on surveillance wearables. The headline point was regulatory: the OAIC is “giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence in order to understand if scrutiny and intervention is required or warranted”, and has “engaged with one entity on at least two occasions this year to further understand the technical specifications”.

Most of the coverage will treat that as a privacy story about individuals in public places, which it largely is. The Commissioner’s concern leads with the exploitation of vulnerable people, specifically children and victims of domestic violence.

But one item in her list of harmful uses is the one your business can actually do something about this week: corporate espionage, data theft, extortion or bribery.

The devices are already here, and more are coming

Meta Glasses are on sale now. Google plans to launch Android XR glasses later this year. Apple’s own product is due in 2027. Cut-price versions are already appearing at Kmart and Amazon. OpenAI has plans for a wearable designed for the ambient collection of data to feed an AI assistant.

The Commissioner draws a distinction worth borrowing. There is a meaningful difference, she writes, between place-based surveillance in airports and certain retail spaces, which has to meet a threshold to be justified, and surveillance wearables “in the hands of every roving individual, designed for discretion (or even concealment)”.

Designed for discretion. That is the whole problem in three words, and it is a physical security problem before it is a privacy one.

Your control assumes the camera is visible

Go and read your visitor procedure. Most say something close to “no photography or recording without authorisation”, and most were written when a camera meant a phone held up at arm’s length, which is a visible, socially obvious act that a receptionist or a host can challenge.

Glasses look like glasses. There is nothing to challenge.

If you hold ISO 27001, the control that actually addresses this is Annex A 7.6, working in secure areas, which is about the rules that apply to people once they are inside a controlled space. Almost nobody has re-read 7.6 since their Statement of Applicability was signed, because it is a short control that has felt settled for years.

It has stopped being settled. Several neighbouring controls carry the same buried assumption:

  • A 7.2, physical entry. Your entry controls check who someone is and whether they are expected. They do not check what they are wearing.
  • A 7.7, clear desk and clear screen. This control exists so information is not visible to people who should not see it. It assumes exposure is momentary and requires someone to be looking. A recording device makes exposure permanent and reviewable at leisure.
  • A 5.14, information transfer. Recording is transfer. It just does not look like transfer, because no file moves through anything you monitor.

This is a control that fails silently

Here is why it is worth an auditor’s attention rather than a policy update.

Most information security failures leave a trace. A login is recorded, a file movement is logged, a data loss rule fires, a mail gateway blocks something. You find out, eventually, because a system tells you.

A visitor recording your whiteboard, your production floor, your screens or a conversation generates no log, no alert and no incident. There is nothing to detect, nothing to review and nothing to correlate. If it happens, you do not learn about it from your monitoring. You learn about it from the consequences, if you ever learn about it at all.

That means the only control that finds this is a physical walk-through during a clause 9.2 internal audit, where someone stands in reception and asks what actually happens when a visitor arrives wearing them. Not what the procedure says happens.

We made a similar point about the virtual equivalent in AI meeting bots and the recorder nobody invited. Same failure mode, different room.

Tilt-shift view of a pair of ordinary looking glasses on a reception counter beside a visitor sign-in book and lanyard, with an out of focus office and whiteboard behind
The sign-in book catches the name. It does not catch what walked in on their face.

Where the law lands, and where it does not

Worth being clear on this, because it changes who carries the risk.

The Privacy Act applies to businesses and government agencies, not to individuals, and only when those entities collect personal information. So where a tech company receives and stores what the glasses capture, that company has obligations, and the Commissioner raises real questions about how they will meet them, particularly around notifying people that they have been recorded and obtaining consent for facial recognition.

But where the data stays on the device, the Act may not reach it at all. In that situation the residual remedy is the recently introduced tort of serious invasions of privacy, which is a claim an affected individual brings, not a regulatory obligation on you.

Read that from your own position. If a visitor records your secure area, privacy law is not the thing that protects your information. Your physical controls are. There is no regulator standing behind this one for you.

Tranche 2 of the Privacy Act may change the balance for the device makers, with a fair and reasonable test for collection and use, higher consent standards and more protection for geolocation data. The forthcoming Digital Duty of Care will reach hardware providers too. None of that puts a control at your reception desk.

What to do

This is a policy line, a sign and a question. Not a project.

Say the word. Update your visitor and secure area rules so they name recording-capable eyewear and wearables explicitly, rather than relying on “cameras” to cover it. Ambiguity is what gets argued about after the fact.

Ask at reception. One question during sign-in, the same way you ask about laptops in some environments. The point is not to catch people out. It is that a rule nobody states is a rule nobody follows.

Decide where it actually matters. Do not attempt a site-wide ban you cannot enforce. Identify the genuinely sensitive areas, the ones where a recording would hurt, and apply the control there properly.

Brief the people who host visitors. Reception cannot enforce this alone, because most of the exposure happens after someone has been escorted past the front desk.

Put it in the audit scope. Add it to the physical security walk-through so it gets looked at routinely by someone whose job is to notice.

Check your contractors and their equipment. Body-worn cameras are now common in trades, security and logistics for entirely legitimate reasons. That is a supplier conversation, not a visitor one.

What to watch, and why this piece will change

Update, 3 September 2026: this trigger has fired. The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 was released on 31 August and is open for consultation until 18 September. Its Consultation Paper puts wearable surveillance technologies, described as including smart glasses and ear buds, along with connected vehicles, out for comment. At this stage these are consultation questions rather than draft provisions, so nothing here changes what your visitor policy has to say today. What it does confirm is that the regulator interest described above has become a formal line of inquiry. The parts of the draft that do carry proposed obligations, including a 72 hour notification clock, are covered in what your data breach response plan has to prove.

This is a regulator signalling, not a deadline. Nothing here obliges you to do anything by a date. That makes it worth saying plainly what would change the picture, because three things are coming.

Google’s Android XR glasses, later this year. The Commissioner named this launch specifically. It moves smart glasses from early adopters to a mainstream product with a major platform behind it, which is the point at which your reception desk starts seeing them regularly rather than occasionally.

Whether the OAIC moves from monitoring to intervention. The post says the office is watching the market to understand if scrutiny and intervention is required or warranted, and has already engaged with one manufacturer twice this year. If that becomes formal guidance or an assessment, the compliance position changes for the device makers and expectations on businesses hosting visitors will firm up with it.

Privacy Act Tranche 2. Still a commitment with no Bill and no commencement date, but the proposed fair and reasonable test, higher consent standards and expanded definition of personal information would all bear on how these devices can lawfully operate.

We will update this article as those land rather than write new ones, so it stays the single place to look.

Where this fits

Physical and environmental controls are one of the four themes of Annex A and the one that gets the least attention in most ISO 27001 information security management systems, because it is the least technical part of a standard people assume is technical. That is precisely why it drifts. If you want the wider map, we have set out what the Annex A controls actually cover.

The Commissioner’s post is not a compliance deadline and nothing in it obliges you to act. It is a regulator saying, on the record, that this is coming and that it is watching. The organisations that will handle it well are the ones that spend twenty minutes on it now, while it is still a policy line, rather than after somebody walks out with a quarter’s worth of your roadmap on a memory card.

Sources

  • Carly Kind, Privacy Commissioner, Surveillance wearables – are we through the looking glass(es)?, OAIC, 7 August 2026
  • OAIC, research and training resources, including the Australian Community Attitudes to Privacy Survey

Privacy law, surveillance device law and workplace surveillance law differ between Australian states and territories, and all three are changing.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Miniature industrial yard with a mobile crane on outriggers and timber packing inside a taped exclusion zone, and a worker in hi-vis at a table with a lift plan
    Your Plant Risk Assessment Is a Document. Is It a Control?

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire