CNIL Warns Businesses About the Privacy Risks of AI Smart Glasses
If your business is exploring AI-powered smart glasses, whether for staff use, customer service, or as a product you sell, a recent warning from France's data protection regulator is worth noting. The CNIL has called for collective vigilance around these devices, and while its statement is rooted in French law, the concerns it raises apply just as much to any UK business handling data connected to this fast-growing category of wearable technology.
What Smart Glasses Actually Do
Smart glasses look like ordinary spectacles or sunglasses, but they contain a microphone and camera built into the frame, connected to the wearer's phone through an app. They let the wearer make calls, take photos, record video and listen to music, often triggered entirely by voice. Many are also linked to an AI system, allowing the wearer to ask a chatbot general questions or, more strikingly, questions about their immediate surroundings, such as asking it to describe what they can see or translate what someone nearby is saying.
Why the CNIL Is Concerned
The CNIL's core concern is that smart glasses can capture and interpret data about the people around the wearer in real time, often without those people being aware it is happening at all. As the regulator points out, someone holding up a smartphone to film is a visible, recognisable act. Someone wearing glasses that are quietly recording is not. This lack of visibility is what makes the technology particularly intrusive, and the CNIL has warned it could gradually normalise a form of everyday, low-level surveillance that people have no meaningful way to consent to or opt out of.
A CNIL survey of over 2,000 French adults found that a significant majority, around two thirds, already see connected glasses as a risk to their privacy. The regulator has responded by launching a dedicated action plan and is examining the legal and technical issues involved, including working with other European data protection authorities, since the European Data Protection Board has also commissioned a report into the broader social acceptability of smart glasses. You can read the CNIL's full statement on its smart glasses vigilance page.
What This Means If You Are Considering Smart Glasses
If your business is thinking about deploying smart glasses, whether to give staff hands-free access to information or to build them into a customer-facing product, treat any recording or AI-assisted functionality as processing personal data about third parties, not just about the wearer. That triggers the same obligations that apply to any other personal data processing under UK GDPR, including having a clear lawful basis, being transparent about what is captured, and considering whether a Data Protection Impact Assessment is needed given the scale and sensitivity of what these devices can gather about bystanders who have not agreed to anything.
Practical steps matter here more than they might for other AI tools. Consider whether recording indicators are visible to people nearby, whether footage and audio are retained for longer than necessary, and whether staff wearing the devices in customer-facing settings understand when recording is and is not appropriate. If you are supplying or building smart glasses products rather than simply using them internally, the design choices you make now around visible recording indicators and data minimisation will matter considerably as regulatory attention in this area continues to grow.
The Wider Privacy Risk Behind Smart Glasses
Smart glasses are the latest example of a much broader shift in how personal data gets collected, one that regulators across Europe are increasingly focused on. Traditional privacy risks tend to involve data that people knowingly hand over, such as filling in a form or agreeing to a cookie banner. Smart glasses represent something different: they collect data about people who never chose to be involved at all, and often have no way of knowing it happened. This is sometimes called ambient or incidental data collection, and it sits awkwardly alongside data protection principles that were largely built around the idea of an identifiable moment of collection.
There is also a biometric dimension to consider. Where smart glasses use facial recognition or voice analysis, whether to identify the wearer or to interpret the environment around them, the data involved can meet the legal definition of biometric data, which is treated as a special category of personal data under UK GDPR and carries a higher bar for lawful processing. The permanence of biometric data is part of what makes it higher risk. A password can be changed after a breach, but a person's face cannot.
What This Means for Businesses
While the CNIL's statement is a matter of French law, the underlying concerns are not confined to France. The UK's Information Commissioner's Office has already been directly involved in scrutiny of this technology. Following reports that outsourced human reviewers had access to highly sensitive footage captured by AI smart glasses during the course of training the underlying AI models, the ICO described the allegations as concerning and confirmed it was seeking information from the manufacturer about how it meets its obligations under UK data protection law. The ICO has been clear on the general principle involved, stating that any device processing personal data, including smart glasses, should put users in control and give appropriate transparency about what is collected and how it is used.
If your business is considering issuing smart glasses to staff, whether for logistics, field service, retail or hands-free access to information, you would typically be acting as the data controller for that processing. This is a similar position to a business installing CCTV or a video doorbell, an area where the ICO has already published detailed guidance. A useful legal comparison here is the CJEU's ruling in Ryneš v Úřad pro ochranu osobních údajů, which found that a household's normal exemption from data protection law falls away once a camera captures public space, such as a footpath or a neighbouring property, rather than staying strictly within a private setting. The same logic applies clearly to a camera worn on someone's face as they move through a workplace or public area.
In practice, this means a business deploying smart glasses at any scale should expect to need a documented lawful basis, a Data Protection Impact Assessment given the likely high-risk nature of the processing, an Article 9 condition if biometric or other special category data is involved, clear notices for staff and visitors, restrictions on when audio recording is active, a defined retention period, and proper access controls over who can review captured footage.
The CNIL's action plan is not happening in isolation. The European Data Protection Board has commissioned its own report into the broader social acceptability of smart glasses, expected to be finalised in 2026, and Italy's data protection authority, the Garante, raised similar concerns with manufacturers before the CNIL's statement. This pattern, several national regulators moving on the same issue around the same time, tends to signal that EU-wide guidance is likely to follow, in much the same way that early, fragmented national positions on cookies and adtech eventually converged into harmonised guidance.
For UK businesses, this is worth watching even without a UK-specific announcement yet, because UK GDPR shares the same foundational principles as the EU regime the CNIL and Garante are applying. Regulatory direction of travel in one major European market often signals where UK expectations will settle too, particularly on a technology this visible.
Practical Next Steps If You Are Considering This Technology
If smart glasses are on your radar, whether as an internal tool or a product you plan to sell, start by mapping exactly what data the device captures, including audio, video, location and any biometric processing, before you commit to a rollout. Build in visible indicators that recording is active wherever possible, since the absence of a visible cue is precisely what regulators have flagged as the core risk. Keep retention periods short and defensible, and be prepared to explain, in plain terms, why the device needs to capture what it captures. Given how quickly regulatory attention in this area is developing, taking specific advice before you deploy this technology at scale will put you in a far stronger position than adjusting your approach after a concern is raised.
Smart glasses are a genuinely useful innovation for many people, including for accessibility purposes such as visual or hearing assistance, and the CNIL is careful to acknowledge this. The concern is not the technology itself but how casually it can be deployed without the safeguards that more visible recording devices naturally invite. Given that this is a developing area of regulatory focus across Europe, if your business is considering this technology at any scale, it is worth taking specific advice on your data protection obligations before rolling it out, rather than after concerns are raised.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.