Legal Insights

OAIC flags regulatory focus on surveillance wearables: what you need to know

• 17 August 2026 • 5 min read

 

On 7 August 2026, the Office of the Australian Information Commissioner (OAIC) published a blog post titled ‘Surveillance wearables – are we through the looking glass(es)?’ in which Privacy Commissioner Carly Kind confirmed that the OAIC is ‘giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence to understand if scrutiny and intervention is required or warranted’.

This signals a potential shift in the OAIC's regulatory posture towards consumer wearable devices equipped with cameras, microphones and biometric sensors, and carries practical implications for organisations developing, deploying or procuring these technologies.

Notably, this aligns with the OAIC's published 2025–26 Regulatory Priorities, which explicitly identify 'new surveillance technologies such as location data tracking in apps, cars and other devices' as an enforcement focus area under the theme of 'rights preservation in new and emerging technologies'.

Key takeaways

  1. Manufacturers and distributors: The OAIC has already engaged with at least one entity on at least two occasions this year regarding the technical specifications of surveillance wearables. If you are developing or selling such products in Australia, anticipate regulatory engagement and be prepared to demonstrate privacy compliance.
     
  2. Organisations deploying wearables internally: The focus of the Commissioner's blog is squarely on personal consumer wearables, rather than the lawful deployment of body-worn cameras or similar devices in regulated operational contexts (such as policing, transport or retail loss prevention), which raises distinct regulatory considerations. That said, organisations permitting staff or visitors to use personal smart glasses in workplaces or customer-facing settings should review their exposure to claims under the statutory tort, existing Australian Privacy Principles (APP) obligations and the relevant state or territory surveillance device legislation.
     
  3. Prepare for Tranche 2: The ‘fair and reasonable’ test, expanded personal information definition, and enhanced consent requirements will create additional hurdles for data collection through wearables. Consider conducting privacy impact assessments now.
     
  4. Social licence matters: Commissioner Kind emphasised that while public trust in technology companies remains extremely low, the bar for establishing social licence for new tech will be high, compliance alone may not be enough. 

The landscape

A decade after Google's failed launch of Google Glass, a new generation of surveillance wearables is entering the consumer market. Meta is leading with its Meta Glasses, Google plans to release Android XR smart glasses later this year, and Apple's own product is expected in 2027. Mainstream retailers including Kmart and Amazon are beginning to offer budget versions, and OpenAI reportedly has plans to launch a wearable device for ambient data collection to power AI assistants.

Commissioner Kind noted that more than 85% of Australians have told the OAIC in a recent privacy attitudes survey that their concerns about privacy have only increased in the last five years. 

Regulatory levers

The OAIC identified several current and forthcoming legal frameworks that bear on surveillance wearables:

  • Privacy Act Tranche 2 Reforms: The proposed reforms are likely to require entities to demonstrate that their collection and use of personal information (including to train AI models) is both ‘fair and reasonable’. Higher consent standards, greater protections for geolocation data and an expanded definition of personal information are also anticipated. 
     
  • Statutory Tort for Serious Invasions of Privacy: Since 10 June 2025, individuals can sue for serious invasions of privacy where another person has intruded upon their seclusion or misused their information, the invasion was intentional or reckless, and the public interest in privacy outweighs countervailing interests. Commissioner Kind noted this tort would be available where a smart glasses user intentionally contravened another's privacy. 
     
  • Digital Duty of Care: The forthcoming Digital Duty of Care will require entities, including hardware providers, to take reasonable steps to prevent activity that is illegal or harmful to children. 
     
  • State and Territory Surveillance Laws: Separately from the Privacy Act, each state and territory has its own surveillance device legislation some which criminalise the recording of private conversations without consent (carrying penalties of up to 5 years' imprisonment in NSW). These laws vary significantly: some require all-party consent to record, while others permit one-party consent in certain circumstances. Interestingly, the Commissioner's blog does not reference these state-based regimes, but the OAIC acknowledges elsewhere that state laws are the primary framework governing surveillance and recording by individuals. A person using smart glasses to covertly record a private conversation may be committing a criminal offence under these statutes regardless of whether the Privacy Act applies.
     
  • Gaps: Where wearable data is processed on-device and not within the control of a regulated entity, it may fall outside the Privacy Act's coverage, highlighting the limits of the current framework for personal-use scenarios. 

Looking ahead

The OAIC's blog post is not yet formal guidance or enforcement action, but it is a clear and deliberate signal of regulatory interest. OAIC blogs and speeches from the Commissioner have consistently foreshadowed the direction of regulatory scrutiny and, ultimately, enforcement action. 

Organisations operating in the wearables ecosystem should treat this as an early warning and begin assessing their privacy posture against both current obligations and the forthcoming Tranche 2 reforms.

For further information on how these developments may affect your organisation

Please contact our Privacy, Data & Information Law team

Sonia Sharma

Sonia has wide ranging experience advising on technology, cyber, telecommunication and general commercial matters, specialising in cyber and data resilience advice.

View profile

Harriet Royle

Harriet advises both private and public sector organisations on a range of commercial projects with a focus on complex IT outsourcing, transformation, information technology and telecommunications.

View profile

Recent articles

Online Access