Photo by Osama Madlom on Unsplash
What Australian Businesses Need to Know
Anyone walking through your door could be wearing a camera. Is your business ready?
Once, if someone walked into your business wearing a camera, you would probably notice.
But not anymore. At least, not if that camera is in the form of smart glasses. The thing is that they often look remarkably like ordinary glasses while allowing the wearer to photograph, film, record audio and, increasingly, interact with artificial intelligence. For Australian businesses, this raises a surprisingly broad range of legal questions.
For example, clients have been asking us: Can a customer record your staff? What if someone wearing smart glasses walks through a design studio, factory or confidential meeting? Could they capture a prototype, computer screen or customer information? Can you ask someone to remove their glasses? And what happens if your own employees start using this technology at work?
Australia’s privacy regulator has already published commentary on what it calls “surveillance wearables”, Parliament has created a new statutory cause of action for serious invasions of privacy, and the courts and the Privacy Commissioner have spent the last few years grappling with cameras, biometrics and covert recording in ways that may well foreshadow how smart glasses are treated. So yes, there is law around it and it is no longer abstract.
Do you need to read this?
Potentially any business whose customers, employees, contractors or visitors could wear smart glasses or other recording devices. That is a wider group than many people assume.
It includes retailers and shopping centres, restaurants, cafés and bars, offices and professional services businesses, and medical, health and beauty businesses, where clients may be partially undressed or discussing sensitive matters. It includes gyms and fitness studios with change rooms, manufacturers and warehouses with production lines and processes worth protecting, and fashion, design and creative businesses whose next season may be sitting on a cutting table.
It also extends to galleries, museums and entertainment venues, schools and education providers, hotels and accommodation providers, and, really, any business handling confidential information, intellectual property or commercially sensitive material.
If your business sits in one of these categories, it may be worth pausing to ask a simple question. When did you last look at your policies with a camera you cannot see in mind?
DID YOU KNOW?
Smart glasses can look like ordinary eyewear. The days of conspicuous Google Glass-style headsets are disappearing. Newer devices can incorporate cameras, microphones and AI functions into relatively conventional-looking frames. In an August 2026 blog post, Australia’s Privacy Commissioner observed that, alongside the major technology brands, budget versions are already available through mainstream retailers.
A camera isn’t necessarily the end of the story. Depending on the device and settings, information captured by wearable technology may potentially be processed, stored or transmitted using associated apps, cloud services or AI systems. In 2024, two university students in the United States publicly demonstrated how commercially available smart glasses, combined with online facial search tools, could be used to try to identify strangers in real time. What might a similar setup reveal about the people who walk through your doors?
Australian privacy law doesn’t simply prohibit all recording. Whether the Privacy Act 1988 (Cth) applies can depend on who is collecting the information, why it is being collected and what happens to it afterwards.
Individuals and businesses aren’t necessarily in the same legal position. The Australian Privacy Principles generally regulate “APP entities” rather than every private individual using a recording device for personal purposes. Section 16 of the Privacy Act expressly provides that the APPs do not apply to personal information collected, used or disclosed by an individual only for the purposes of, or in connection with, their personal, family or household affairs.
Many small businesses sit outside the Privacy Act altogether, but not all of them. Under sections 6C and 6D, a business with an annual turnover of $3 million or less is generally a “small business operator” and not an APP entity. There are important exceptions, however, including businesses that provide a health service and hold health information, and businesses that trade in personal information. Do you know which side of that line your business falls on?
Australia now has a statutory tort for serious invasions of privacy. It commenced on 10 June 2025 and potentially adds another dimension to particularly serious cases of intrusion or misuse of private information.
Privacy is only one piece of the puzzle. Smart glasses may also raise issues involving confidential information, copyright, trade secrets, workplace surveillance, anti-discrimination law, contracts and conditions of entry.
That is why businesses may need to think beyond simply putting up a sign saying “No Photography”.
WHAT CAN SMART GLASSES SEE?
If you can imagine someone walking into your workplace and looking at a whiteboard containing next year’s product strategy. Or they could look at an unreleased clothing design sitting on a table. They walk past a computer displaying a customer database. They attend a meeting where pricing, source code or a confidential acquisition is discussed.
The point is, that with a conventional camera, everyone in the room might know that recording is taking place. With smart glasses, perhaps they don’t. Many devices have a small indicator light when recording, but how many of your staff would notice it, or know what it means?
And that is where the legal and commercial questions become interesting. Who owns what was captured? Who is responsible for it? And what, if anything, can your business do about it after the person has walked out the door?
WHAT ABOUT PRIVACY?
The starting point for many Australian businesses will be the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in Schedule 1 to that Act.
Depending on the circumstances, images, voices and other information captured by smart devices may constitute “personal information”, which section 6(1) defines as information or an opinion about an identified individual, or an individual who is reasonably identifiable.
More sensitive technologies, including facial recognition or biometric analysis, can raise additional issues, because biometric information used for automated verification or identification, and biometric templates, fall within the definition of “sensitive information”. Under APP 3.3, sensitive information generally cannot be collected without consent unless an exception applies.
For businesses covered by the Privacy Act, there are several principles worth thinking about. APP 1 deals with transparency: does the business have appropriate practices, procedures and policies dealing with the personal information it collects, and does its privacy policy actually describe what it does?
APP 3 deals with collection: is the collection of personal information reasonably necessary for the business’s functions or activities, and are the stricter requirements for sensitive information being met? APP 5 deals with notification: does someone need to be told that their personal information is being collected, and for what purpose?
APP 6 then asks whether information captured for one purpose is later being used for something else. APP 8 asks whether information is being sent to, or accessed by, recipients outside Australia, which may be a live question where a device syncs to an overseas cloud or AI service. And APP 11 asks what steps are being taken to protect information once it has been captured or stored.
While these questions might seem complex, the Privacy Commissioner has already applied the APPs to cameras in retail settings, for example, in Commissioner Initiated Investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50, the Commissioner found that 7-Eleven had breached APP 3.3 and APP 5 by capturing customers’ facial images through tablets used for in-store feedback surveys. In Commissioner Initiated Investigation into Clearview AI, Inc (Privacy) [2021] AICmr 54, the Commissioner found that scraping facial images from the internet to build a facial recognition tool breached a number of APPs. And in Commissioner Initiated Investigation into Kmart Australia Limited (Privacy) [2025] AICmr 155, it was found that Kmart’s use of facial recognition technology to address refund fraud breached the Privacy Act.
Having said that there is this case to consider as well: the Commissioner Initiated Investigation into Bunnings Group Ltd (Privacy) [2024] AICmr 230, and found that Bunnings’ use of facial recognition in its stores breached the Privacy Act. On review, in Bunnings Group Limited and Privacy Commissioner [2026] ARTA 130 (4 February 2026), the Administrative Review Tribunal found that Bunnings’ collection fell within a “permitted general situation” under section 16A and APP 3.4, so that consent was not required, although it upheld findings that Bunnings had failed to give adequate notice under APP 5 and to meet its APP 1 obligations. The Privacy Commissioner later confirmed that no appeal would be filed. For a business thinking about its own recording technology, the lesson may be that the reasons for collection, and how well they are documented and communicated, can matter a great deal.
The consequences of getting information security wrong have also become more concrete. In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, the Federal Court imposed the first civil penalties under the Privacy Act, totalling $5.8 million, in connection with a data breach and failures relating to APP 11 and the notifiable data breaches scheme. If your business were to collect footage through wearable devices, where would it be stored, and who could get to it?
The Office of the Australian Information Commissioner has also expressly turned its attention to what it calls “surveillance wearables”, including smart glasses.
But the Privacy Act does not necessarily answer every question. Its application depends on the circumstances, including who is doing the recording.
CUSTOMERS MAY WEAR THE GLASSES
If customers were the glasses, things can become more complicated. A customer walking into a shop wearing smart glasses is not necessarily subject to the same Privacy Act obligations as the business itself. As noted above, section 16 carves out personal, family and household affairs, and the Privacy Commissioner has acknowledged that the Act applies to businesses and agencies rather than individuals.
That does not, however, mean that anything goes. Other laws and legal rights may potentially become relevant, depending on what is being recorded, where it occurs and what subsequently happens to the material.
Each State and Territory has its own surveillance devices legislation, and the rules are not uniform. In New South Wales, for example, section 7 of the Surveillance Devices Act 2007 (NSW) generally prohibits using a listening device to record a private conversation, and this can extend to a person who is a party to that conversation unless an exception applies. In Victoria, by contrast, the Surveillance Devices Act 1999 (Vic) is directed at recording private conversations and private activities to which the person recording is not a party. So could a customer lawfully record a conversation with your staff member at the counter? The answer may well depend on which State you are in, whether the conversation was “private” in the statutory sense, and what the customer later does with the recording.
Criminal law may also be relevant in more serious situations. Section 91K of the Crimes Act 1900 (NSW), for instance, makes it an offence to film a person engaged in a private act, such as undressing or showering, without consent and for certain improper purposes, and other jurisdictions have comparable offences.
At a federal level, section 474.17C of the Criminal Code Act 1995 (Cth), inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), now targets using a carriage service to release personal data in a menacing or harassing way, commonly described as “doxxing”. For gyms, clinics, spas and change rooms, these may be particularly important considerations.
There is also the more ordinary question of who controls your premises. At common law, members of the public generally enter business premises under a licence, and the High Court recognised in Halliday v Nevill (1984) 155 CLR 1; [1984] HCA 80 that an implied licence to enter can be limited or withdrawn. The much older decision in Cowell v Rosehill Racecourse Co Ltd (1937) 56 CLR 605; [1937] HCA 17 is still cited on the revocability of a patron’s licence. Conditions of entry may therefore be one practical tool, but are yours drafted clearly enough, and displayed prominently enough, to be relied on?
Businesses may therefore need to consider whether their existing conditions of entry, photography policies, confidentiality arrangements or staff procedures are adequate for wearable technology.
Have a think about this: Would your current “no photography” rule cover continuous recording through smart glasses?
What happens if the person says the glasses are required for accessibility reasons? Some smart glasses are now marketed with features designed to assist people who are blind or have low vision, and sections 23 and 24 of the Disability Discrimination Act 1992 (Cth) make it unlawful, subject to exceptions, to discriminate on the ground of disability in relation to access to premises and the provision of goods and services.
You will also need to be thining about who within the business has authority to ask them to stop recording? And what should that person say?
These questions are much easier to consider before an incident occurs.
WHAT ABOUT CONFIDENTIAL INFORMATION AND TRADE SECRETS?
For some businesses, this may be an even greater concern than privacy. Consider a fashion designer showing an unreleased collection to a supplier. Or a technology company with source code visible on monitors. Or a manufacturer allowing visitors onto a production floor. Or a business conducting confidential negotiations in a meeting room.
Information does not need to be personal information to be extremely valuable. Depending on the circumstances, Australian law relating to breach of confidence, contractual confidentiality obligations and equitable remedies may become relevant.
The classic statement of the equitable action comes from Megarry J in Coco v A N Clark (Engineers) Ltd [1968] FSR 415, and in Australia it is commonly expressed in the four-part formulation of Gummow J in Smith Kline & French Laboratories (Aust) Ltd v Secretary, Department of Community Services and Health (1990) 22 FCR 73 (discussed by the Australian Law Reform Commission here). Broadly, the information must be identified with specificity, have the necessary quality of confidence, have been received in circumstances importing an obligation of confidence, and there must be actual or threatened misuse. Each of those elements invites a practical question. Could your business actually identify what was confidential in the room? Was it treated as confidential, or was it left on a table for anyone to see? And did the visitor know, or ought they to have known, that it was confidential?
COPYRIGHT CAN ENTER THE PICTURE TOO
Smart glasses can also make copying remarkably easy. Artwork on a gallery wall, pages of a book, photographs, architectural plans, computer code, films and other material may be protected by the Copyright Act 1968 (Cth).
Whether recording particular material amounts to copyright infringement will depend on what has been copied and the circumstances. Section 31 gives the copyright owner the exclusive right to reproduce a work in a material form, and infringement generally requires that the whole or a “substantial part” be reproduced without licence. The High Court in IceTV Pty Ltd v Nine Network Australia Pty Ltd (2009) 239 CLR 458; [2009] HCA 14 emphasised that whether a part is substantial is a question of quality rather than simply quantity. A few seconds of footage of a single painting might therefore be more significant, legally, than it first appears.
WHAT ABOUT YOUR STAFF?
There is another side to the problem. Businesses may themselves be tempted to use smart glasses. They could have legitimate applications in training, security, logistics, remote assistance, maintenance or recording work processes.
But introducing wearable recording technology into a workplace can raise privacy, employment and surveillance issues. The applicable rules can also vary between Australian jurisdictions.
AUSTRALIA’S NEW PRIVACY TORT
There is another significant development. The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a statutory tort for serious invasions of privacy, now found in Schedule 2 to the Privacy Act 1988 (Cth), which commenced on 10 June 2025.
It potentially provides a cause of action where there has been an intentional or reckless invasion of privacy involving either an intrusion upon seclusion or misuse of information, provided the statutory requirements are satisfied. Those requirements include that a person in the plaintiff’s position would have had a reasonable expectation of privacy, that the invasion was serious, and that the public interest in the plaintiff’s privacy outweighs any countervailing public interest. Intrusion upon seclusion expressly includes watching, listening to or recording a person’s private activities or private affairs, which is language that sits rather close to what a pair of smart glasses can do.
Importantly for businesses, the tort is not limited to APP entities, and there is no small business exemption. It can apply to individuals and organisations alike, subject to specific exemptions, including for journalists, certain government bodies and people under 18.
Remedies can include damages, injunctions and orders to apologise, and a claim must generally be brought within one year of the plaintiff becoming aware of the invasion, and no later than three years after it occurred. Could your business be the defendant if one of your employees used a wearable device inappropriately at work? Or might your business be the one whose customers or staff have been recorded?
The statutory tort also arrives after years of uncertainty at common law.
The High Court in Lenah Game Meats left the question open, and while lower courts in Grosse v Purvis [2003] QDC 151, Doe v Australian Broadcasting Corporation [2007] VCC 281 and, more recently, Waller (a pseudonym) v Barrett (a pseudonym) [2024] VCC 962 were prepared to recognise some form of privacy action, no appellate court has done so.
That does not mean every unwanted photograph or recording will result in a claim. But covert wearable recording makes the boundaries between ordinary observation, surveillance and intrusion increasingly important.
SO CAN YOU BAN SMART GLASSES FROM YOUR BUSINESS?
Perhaps, but the better question is often what policy is appropriate for your particular business?
A jewellery store, medical clinic, nightclub, law firm and manufacturing plant may have very different reasons for controlling photography and recording. What is the specific risk you are trying to manage in your business? Is it the privacy of your clients, the security of your stock, the confidentiality of your designs, or the safety of your staff?
A blanket prohibition may not always be the right answer either. Businesses may need to consider disability and accessibility issues under the Disability Discrimination Act 1992 (Cth) and State and Territory equivalents, contractual arrangements with suppliers, tenants and landlords, employment obligations and the practicalities of enforcing a policy. Who will actually tell a customer, politely, that their glasses need to come off, and what will happen if they refuse? And if a shopping centre or landlord has its own rules, do yours sit comfortably alongside them?
The real issue is whether your existing legal documents and internal procedures were written for a world in which the camera was obvious. For many businesses, they weren’t.
QUESTIONS WORTH ASKING NOW
Does your business have a photography and recording policy? If so, when was it last updated, and does it mention wearable devices at all? Do your conditions of entry cover wearable devices, and are they displayed where visitors will actually see them?
Do your employment policies deal with smart glasses and AI-enabled recording, both when staff bring their own devices to work and when the business supplies them? Could visitors easily record confidential information, prototypes or computer screens? Do your NDAs and confidentiality provisions adequately address recording and digital capture, or do they assume that confidential information travels only on paper and by email?
What happens if someone refuses to stop recording?
HOW SHARON GIVONI CONSULTING CAN HELP
Smart glasses sit at an unusual intersection of privacy, intellectual property, confidentiality, technology, employment and surveillance law. There is unlikely to be one standard policy that works for every organisation.
Sharon Givoni Consulting can advise businesses on how emerging recording and AI-enabled technologies affect their particular operations. That may include reviewing or preparing privacy policies and collection notices, and considering whether your business is covered by the Privacy Act in the first place.
Please note the above article is general in nature and does not constitute legal advice.
Please email us info@iplegal.com.au if you need legal advice about your brand or another legal matter in this area generally.

