Technology continues to advance in a way that many find exciting – but also in a way that can create worrying issues to cope with. Recent pronouncements about the potentially life changing powers of AI may send shivers down your spine, but not all technology announcements are necessarily so potentially apocalyptic. One such example is smart glasses.
Smart glasses look like ordinary spectacles. Really, that is at the heart of the problem.
A pair of Ray-Ban Meta glasses, for example, has a small camera in the corner of the frame, microphones in the arms and a connection to an AI assistant that can describe whatever the wearer is looking at. Using them, the wearer can take a photograph, record video or capture audio simply by tapping the frame or giving a spoken command. There are some slight safeguards. A small light is meant to signal recording, but most people never notice it and, anyway, it is not difficult to hide. Newer models even have a display inside the lens. This allows the wearer to read messages, follow directions or see an AI response without looking at their phone. Not that Meta glasses are the only ones available. Google, Samsung, Snap and a growing number of Chinese manufacturers are all in the market. In fact more than seven million pairs of AI glasses were reported to have been sold last year.
Some of the uses of smart glasses are beneficial. People with sight or hearing loss, for example, have described the glasses as transformative with real time captions, spoken descriptions and instant translation having a genuine value for them. As a consequence, any sensible discussion of this topic has to keep in mind that there are those for whom the technology is a good thing. Equally, and inevitably, there are those who will want to use the glasses for nefarious purposes.
The difficulty is that the same device that makes life easy for the person with a disability makes it easy for someone to make covert recordings of business information, pictures of people in compromising or embarrassing situations and inappropriate images just as effortless. Someone using a phone to film you has to hold it up and you can see it. Someone wearing smart glasses simply looks at you.
Recent developments have raised this issue to a point where it needs serious consideration. In March the Information Commissioner's Office wrote to Meta after an investigation by two Swedish newspapers reported that outsourced contractors in Nairobi were reviewing footage captured by Ray-Ban Meta users. The workers described seeing people undressing, using the bathroom and discussing their relationships, and in some cases exposing bank cards and personal documents. Meta said recordings are used to improve its AI only where users have opted in. The ICO described the allegations as concerning and asked for an explanation. Whatever the outcome, the episode showed that footage from the glasses does not necessarily stay with the wearer.
The response has been quick. HM Courts and Tribunals Service announced in August that camera glasses will be confiscated on entry to any court or tribunal building in England and Wales and returned on the way out. Also in August, JD Wetherspoon banned Meta glasses from its pubs. Cinemas, theatres, schools and gyms have followed. Instagram has tightened its rules after a wave of accounts posting secret footage of women filmed through the glasses. Indeed, more than seventy privacy organisations have written to Meta asking it not to add facial recognition, which the company is reported to be considering.
Researchers have already shown that the glasses can be paired with publicly available face search tools to identify a stranger in the street and pull up their address and family details within seconds. The potential for danger to ordinary person from this is obvious.
Whereas for most businesses the risk from the use of smart glasses is embarrassment and possibly a data protection complaint, for a law firm the stakes are far higher.
Think about what passes through a firm in an ordinary week. A client sits in reception waiting to discuss a divorce. A screen in an open plan office shows the draft terms of a takeover that has not yet been announced. A file on a desk names a protected witness or a child in care proceedings. None of this is meant to leave the building. All of it can be captured by a pair of glasses worn by a visitor, a contractor, a job applicant or a member of staff. If such information is being uploaded to the cloud, how can the wearer be certain that outsourced contractors in Nairobi – or indeed anyone else - aren’t accessing the information and possibly using it to their own advantage?
The consequences run beyond the ordinary data breach. Legal professional privilege can be lost if privileged material reaches a third party. In a family or criminal matter the disclosure of an address or a hearing date can put someone in physical danger. In corporate work the leak of a deal or a dispute can move a share price and attract the attention of the FCA. A firm holding information about an organised crime group or a sanctioned individual would be exposing far more than a client's privacy.
Then there is the regulatory position. Paragraph 6.3 of the SRA Codes of Conduct requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. Under the UK GDPR you must be able to show appropriate technical and organisational measures to protect personal data. Much of the data held by a law firm falls within the special categories or concerns criminal allegations, and both attract higher obligations. A recording taken by a member of staff on their own glasses is still processing carried out within your organisation. The household exemption that protects purely personal use falls away once the wearer is at work and recording clients, colleagues or documents. In the eyes of the ICO the firm, not the individual, will be the controller.
The court position is the clearest part of the picture. Section 41 of the Criminal Justice Act 1925 prohibits photography in court and section 9 of the Contempt of Court Act 1981 prohibits unauthorised sound recording. Both have been in force for decades and HMCTS has simply confirmed that camera glasses fall within them. The service has said there will be no exception of the kind that allows phones into court buildings, because the glasses can record without drawing attention. Anyone arriving at a court or tribunal wearing them will have them taken at security. A solicitor or barrister who used the glasses inside a courtroom would be committing a contempt and professional consequences would follow.
There are practical points. If you or your staff wear prescription smart glasses you will need a spare pair of conventional spectacles for court days. If a client or witness is likely to arrive wearing them, warn them in advance. Remote hearings deserve a mention too. A participant joining by video from home could easily be wearing glasses that record the hearing, and recording a remote hearing is an offence in its own right. It is worth reminding clients and witnesses of that when you send joining instructions.
Client meetings are where the risk is least controlled. A client may arrive wearing the glasses without a second thought. A client may also record a meeting deliberately, either to keep a record of the advice or in the hope of catching the solicitor out. A client who records their own meeting is unlikely to be committing an offence, and the recording may well be admissible if a complaint or a negligence claim follows. What was said is already recorded in your attendance note, but tone, hesitation and informal remarks are not. That is uncomfortable for the solicitor and worse for anyone else in the room. A joint meeting with the other side, a mediation or a conference with an expert all involve people who have not agreed to be filmed.
The simplest approach is to say something. A short line at the start of any meeting, asking that recording devices including smart glasses be switched off or removed, sets the expectation and gives you a basis for action if it is ignored. Putting the same request in your client care letter and on a notice at reception reinforces it. Where a client wants to record for a legitimate reason, such as a memory or hearing difficulty, you can agree to it and record the meeting yourself so that both sides hold the same version.
So far the government has relied on the existing law, and there is certainly a strong case for that as opposed to creating yet more legislation. The UK GDPR, the Data Protection Act 2018, the tort of misuse of private information, the Protection from Harassment Act 1997 and the voyeurism offences in the Sexual Offences Act 2003 already cover most of the harm that smart glasses can do. A recent analysis from Doughty Street Chambers made the point that the gap is not in the substantive law. The gap lies in the speed, cost and reach of the remedies. A person filmed in the street and posted online may have a good claim, but by the time they find out the footage has spread and the uploader is anonymous and abroad.
Several things would help. The ICO should issue specific guidance on wearable cameras, setting out when the household exemption ends and what a controller must do when staff or visitors record on its premises. Manufacturers should be required to fit a recording indicator that cannot be switched off, and the device should stop recording if the indicator is covered. Platforms should be obliged to provide a fast route for people to have non-consensual wearable footage removed and to preserve the uploader's account data pending a court order. Australia introduced a statutory tort of serious invasion of privacy in June 2025 and there is an argument for a similar clear cause of action here, with a streamlined procedure for identifying anonymous uploaders. Facial recognition in consumer glasses should be addressed before it arrives rather than after. The Online Safety Act 2023 reaches illegal content but not most privacy intrusions, and that gap is worth closing.
So how should solicitors and law firms be addressing this issue? Most of the practical steps are within the firm’s control and most of them cost very little.
Start with policy. Your existing policies on confidentiality, IT use, personal devices, social media and data protection were almost certainly written with phones and laptops in mind. Add wearable technology to the provisions. Decide whether smart glasses are permitted in the office at all and, if they are, where recording is allowed and where it is prohibited. Most firms will want a clear rule that recording is not permitted anywhere in the office, in client meetings or at court, and that smart glasses must be removed in meeting rooms and in any area where client information is visible. Make it clear that a breach will be treated as misconduct.
Deal with reasonable adjustments openly. A member of staff who relies on the glasses for captions or audio description has a right to ask for them, and a blanket ban may be discriminatory. The answer is a written arrangement covering where the glasses can be used, with recording and cloud upload disabled, rather than a refusal.
Extend the rule to visitors. Add a line to your client care letter and terms of business, put a notice at reception and brief reception staff on what the glasses look like and what to say to visitors who wish to wear them. Have a provision in place for difficult visitors that refuse to remove them – for example a senior staff member that reception can call upon in difficulty.
Consider the premises and the extent to which it would defeat potential attempts to breach confidence. Recording is only a danger where there is something to record. Screens facing public areas, files left on desks, whiteboards in glass walled meeting rooms and conversations in corridors are long standing risks that smart glasses make worse. A clear desk rule and privacy filters on screens go a long way.
Train people. A short briefing on what smart glasses are, why they matter to a law firm and what the firm expects is enough for most staff. Include the court position so that no one is caught out at security. Make sure staff know what they look like. The current models are hard to spot but not impossible. Small lenses in the corners of the frames and thicker than usual arms are the giveaways.
Plan for the breach as well. If you discover that a meeting has been recorded or that footage from your office has been posted online, you will need to assess whether personal data has been compromised, whether the ICO must be notified within 72 hours and whether clients need to be told. Having that thought through in advance makes all the difference between a managed incident and a crisis.
Smart glasses are not going away. Within a few years they may be as common as earbuds. The firms that handle them well will be the ones that decided what they expected before the first incident rather than after it.