Smart glasses expose holes in India’s privacy law.
In June, Kylie Jenner posted her latest collaboration - a new design for Meta’s AI-powered “smart glasses”. Images of her wearing them filled social media, as did videos of her teenage self lamenting the lack of privacy she was afforded because of her fame. The irony was unmissable: Ms. Jenner, once so worried about privacy, now promoting a device that enables surveillance.
That contradiction, writes Sonikka Loganathan, is the core of wearable tech’s privacy crisis. Smart glasses are marketed as “normal-looking eyewear with discreetly integrated technology.” Hidden from the naked eye, they contain “tiny speakers, microphones, a lightweight camera.” Meta isn’t shying away from how inconspicuous these features are; rather, it is flaunting it.
According to Meta, these glasses allow you to see and answer calls, messages, and notifications via voice command. Built-in speakers help listen to music and an integrated camera enables you to capture photos or videos through the lenses. In India, they retail at around Rs 25,000. Stickers that claim to completely cover the LED recording indicator are also widely available.
Meta says if the LED is covered, the glasses will block recording until the sticker is removed. Yet workarounds are just a Google search away. The glasses also make a shutter sound, but that is not a strong indicator you are being recorded.
Meta argues the glasses are “designed for privacy, controlled by you.” But this control is limited to the wearer, not the recorded. And Meta’s website adds, “Meta collects data needed to help ensure that your glasses and app are reliable, secure and operating normally.” A Swedish investigation found that Meta’s contracted workers, who sometimes review data to track user experience, were able to view sensitive content filmed on the smart glasses, including wearers using the toilet.
The risks compound when seen through India’s data. NCRB showed that in 2023, before these glasses entered the market, there were 3,678 cases of women-centred cybercrimes. Of these, 2,767 involved transmission or publication of sexually explicit material. In 2023, NCRB recorded over 698 cases related to use or storage of child sexual abuse material. If adults cannot often recognise when the glasses are recording, a child certainly cannot.
Legally, India has little to protect people from this surveillance. The Digital Personal Data Protection Act, 2023 is technologically agnostic, making purpose of data collection the key consideration. In public space, people can neither grant consent nor monitor how their information is used.
Following K.S. Puttaswamy vs. Union of India 2017, reasonable expectation of privacy was recognised as a fundamental right under Article 21. This means people, even in public spaces, don’t generally expect to be captured in detail. But DPDP excludes information that is made publicly available. Hence reasonable expectation of privacy is not met because Act does not regulate how someone is being recorded in public. Its scope is diluted further since there are minimal indicators you could be in someone’s frame.
Banning such devices isn’t practical. Meta might be biggest player today, but Google and Reliance are entering the market. As wearable tech becomes more advanced, banning will become increasingly difficult. Instead, laws should be framed with an understanding of how AI is changing the landscape. The need is for assessments on how technology will evolve, the risks that may accompany it, and government’s responsibility in ensuring citizens are adequately protected.