Australia and New Zealand · Connected products
Smart glasses: see the compliance risks before you sell or deploy
Smart glasses can be a camera, microphone, AI assistant, biometric system and connected consumer product all at once. A single model may trigger consumer, privacy, cyber, product safety, radio and workplace rules.

The practical lesson
Smart glasses should not be approved as a single piece of consumer electronics.
They need a joined-up review covering the glasses, lenses, battery, charger, radio functions, app, cloud platform, AI processing, privacy settings, customer claims and intended use.
Finding these gaps after a launch can mean disabled listings, consumer remedies, privacy complaints, product recalls, unusable stock or urgent changes to a workplace deployment.
If your business is considering importing, selling, private-labelling or deploying smart glasses, review the complete compliance pathway before stock is committed or the product goes live.
Start with the complete feature map
The compliance position depends on what the exact model can do.
Two products that look similar may create very different obligations. Before approving a model, record whether it has or supports:
- cameras, microphones, speakers, recording indicators or livestreaming;
- automatic uploads, remote access, location tracking or cloud storage;
- facial, voice, eye, gait or other biometric processing;
- AI recognition, translation, scene description or decision support;
- Bluetooth, Wi-Fi, mobile or other radio functions;
- an app, user account, subscription, advertising or paid features;
- local, Australian, New Zealand or overseas data storage and processing;
- tinted, prescription, protective, corrective or health-related lenses; and
- firmware or software that can materially change the product after launch.
The review should cover the product as sold and its reasonably foreseeable use, not just the functions highlighted in the launch campaign.
Consumer law and customer claims
The hardware, digital services and headline claims need to work together.
In Australia, the Australian Consumer Law applies to representations, consumer guarantees, product safety and unfair contract terms. In New Zealand, the Fair Trading Act and Consumer Guarantees Act create similar controls over claims, product quality and consumer rights.
Evidence may be needed for claims about recording time, battery life, AI accuracy, translation, object recognition, compatibility, water or dust resistance, impact performance, lens category, UV protection, privacy indicators and security support.
Make material dependencies prominent. Customers should be able to understand if a function needs a compatible phone, account, subscription, internet connection, particular operating system, supported language, cloud service or region. Do not hide a significant limitation in technical specifications or terms.
Terms governing subscriptions, cloud storage, AI services, feature removal, account suspension, warranties and cancellation should also be checked for transparency and unfairness. A later software change can affect the product's performance, claims and continuing compliance.
Privacy, recording and bystanders
A recording light does not resolve the privacy questions.
Smart glasses may collect information about the wearer and people nearby, including images, voices, location, behavioural information and sensitive or biometric data. The business should identify what is collected, why it is necessary, who receives it, where it is processed, how long it is kept and whether it is used to train or improve an AI system.
In Australia, the Privacy Act applies to covered organisations, while state and territory surveillance, listening-device and workplace laws may impose additional requirements. The federal statutory tort for serious invasions of privacy also makes intrusive recording and misuse an important risk even where a particular Privacy Act obligation does not apply.
In New Zealand, the Privacy Act and its information privacy principles can apply to collection, notice, use, disclosure, overseas transfer, security, access and retention. The Privacy Commissioner has said organisations remain responsible for how smart glasses are configured and used. A visible recording indicator can help with transparency, but it is not a substitute for assessing necessity, lawfulness, fairness and potential harm.
Consumer privacy information should explain the actual system, not simply repeat a manufacturer's general statement. Workplace and enterprise deployments also need rules for prohibited locations, confidential information, children, patients, customers and people who cannot reasonably avoid being recorded.
Biometric processing
Facial or other biometric functions require a separate decision.
In Australia, the OAIC treats facial recognition technology as privacy intrusive. A business should assess whether biometric processing is necessary and proportionate, whether valid consent or another lawful basis exists, how accuracy and bias are managed, and how templates and matching results are secured. General signage or a broad privacy policy may not be enough.
New Zealand's Biometric Processing Privacy Code is now fully in force, including for existing systems after the transition period ended on 3 August 2026. It adds specific requirements around purpose, necessity, proportionality, transparency, safeguards, accuracy, access and the use of biometric information.
Do not assume a feature is outside biometric regulation because recognition occurs in the glasses, because only a template is stored or because a third-party cloud provider performs the matching.
Cybersecurity and software support
Connected glasses need a support plan, not just a launch date.
Australia's mandatory security standards apply to many consumer-grade smart devices manufactured on or after 4 March 2026. Depending on the product and exclusions, the supplier may need to address unique passwords, vulnerability reporting, a stated security-update period and a statement of compliance.
Across both countries, the security review should address secure pairing, authentication, account recovery, permissions, encryption, signed updates, cloud and API access, third-party software, AI providers, vulnerability handling, security monitoring, factory reset, resale and the end of support.
New Zealand's Privacy Act requires reasonable security safeguards for personal information. The NCSC also recommends choosing secure and verifiable technologies, including checking supplier practices, update commitments, assurance and lifecycle support.
If a core feature depends on a cloud service or app that will no longer be supported, the business should understand the effect on functionality, consumer guarantees, privacy, security and any existing customer commitment.
Radio, electrical, optical and product safety
The physical product and every supplied component need the right evidence.
In Australia, suppliers should check ACMA requirements for radio communications, electromagnetic compatibility and electromagnetic energy. Applicable products may need testing, records and the Regulatory Compliance Mark. Chargers, power supplies and batteries can create separate electrical, transport and product-safety obligations.
If the product includes non-prescription tinted lenses for sun protection, Australia's mandatory standard for sunglasses and fashion spectacles may apply. Prescription, protective or specialised products need to be classified and assessed under the rules relevant to their intended purpose.
New Zealand suppliers should check the Radio Spectrum Management requirements, applicable standards, testing, supplier documentation and labelling. General product-safety, consumer guarantee and fair-trading obligations still apply even when there is no product-specific mandatory standard.
Both markets require a process for complaints, safety incidents, corrective action and recalls. In Australia, a supplier may also have to report a consumer product associated with a death or serious injury or illness within two days of becoming aware of it.
Workplace use
Deploying smart glasses changes the workplace risk assessment.
Employers and other persons conducting a business or undertaking should assess distraction, visibility, ergonomics, battery heat, radio use, fatigue, situational awareness, manual tasks, vehicles, machinery and emergency procedures. A useful function does not remove the need to eliminate or minimise health and safety risks.
A deployment plan should also cover who may record, where recording is prohibited, when audio may be captured, how workers and visitors are notified, whether personal devices are allowed, who can access recordings, retention, overseas processing, security incidents and disciplinary use.
Australian state and territory surveillance and workplace-monitoring laws differ. New Zealand employers should also address privacy, consultation, fair policy implementation and worker health and safety before deployment.
Health and medical claims
The intended purpose can change the regulatory pathway.
Claims about diagnosis, treatment, monitoring, correction, prevention or clinical performance may bring the product or related software within medical-device rules. In Australia, assess the Therapeutic Goods Administration requirements. In New Zealand, assess the Medicines Act framework and Medsafe's medical-device guidance.
Do not add a health claim to a general consumer product without confirming that the product, software, evidence, listing and advertising can support it.
Before stock is committed or the product goes live
Answer these questions for the exact model and intended use.
- What can the product record, infer, transmit and store?
- Which organisations, apps, cloud services, AI providers and overseas recipients receive data?
- Is each collection and use necessary, lawful, fair and explained to wearers and bystanders?
- Does the product perform facial, voice, eye or other biometric processing?
- Can every product, privacy, security, AI, optical and performance claim be substantiated?
- Are subscriptions, compatible devices, regions, support periods and removed features disclosed?
- Do the Australian smart-device security standards apply, and is the required statement ready?
- Are radio, EMC, electrical, battery, optical and product-safety requirements supported by exact-model evidence?
- Are customer terms, guarantees, returns, repairs, refunds and cancellation arrangements compliant?
- Does a workplace deployment meet recording, consultation, privacy and health and safety requirements?
- Could a claim or intended purpose make the glasses or software a medical device?
- Can the business respond to vulnerabilities, privacy incidents, complaints, serious injuries, corrective action and recalls?
Official sources
Review the current Australian and New Zealand requirements.
Privacy, biometrics and recording
- New Zealand Privacy Commissioner: expectations about smart glasses
- New Zealand Biometric Processing Privacy Code
- OAIC: surveillance wearables and privacy
- OAIC: assessing facial recognition privacy risks
- Australian electronic surveillance framework
Consumer, cyber and product requirements
- ACCC: consumer rights and guarantees
- ACCC: false or misleading claims
- Australian security standards for smart devices
- ACMA: supplier compliance rules
- Australian mandatory standard for sunglasses and fashion spectacles
- New Zealand Radio Spectrum Management: supplier compliance
- New Zealand product-safety requirements for businesses
Workplace and medical-device guidance
Planning to sell or deploy smart glasses?
Review the complete compliance pathway before launch.
Watchdog Compliance can review your product, app, privacy, cybersecurity, consumer claims and market-entry obligations for Australia and New Zealand before stock is committed or the product goes live.
Tell us about the model, intended customers or workplace use, connected services and proposed markets. We can identify the relevant requirements, evidence gaps and actions to address before launch.
Important information
Check the exact product, intended use and current rules.
This update is general information, not legal advice. The applicable obligations depend on the product features, claims, supply chain, users, data flows and place of use. Laws, standards and official guidance can change. Check the current requirements and obtain advice for your circumstances before acting.
