The Office of the Australian Information Commissioner (OAIC) issued preliminary inquiries to various manufacturers and distributors of smart glasses from 12 August, including Meta Platforms, Kmart, Google and Shenzhen Qingcheng, based in China.
Although the OAIC received responses from most of them, Shenzhen Qingcheng did not respond. The privacy commissioner has therefore opened an investigation into the company's privacy practices.
In a blog post announcing this, Australian Privacy Commissioner Carly Kind said: “In the absence of any response from Shenzhen Qingcheng to the OAIC’s preliminary inquiries, I have no assurance that it is protecting personal data of Australians as required by the Privacy Act.”
Veronica Scott, an expert in privacy, cyber and data at Pinsent Masons, said: “While the commissioner highlighted privacy obligations and public concerns about the data collected by smart glasses, the most significant message was about accountability and potential liability across the supply chain.”
“It acknowledges the fragmented legal framework that currently applies to smart glasses and that Privacy Act obligations won’t apply directly to manufacturers and retailers who do not collect or hold personal information from these devices.”
“The OAIC also says businesses should conduct their own due diligence on privacy risks of connected surveillance devices they sell, expressly flagging accessorial liability for privacy breaches found in section 92 of the Regulatory Powers Act 2014 that applies to the Privacy Act’s civil penalty regime the OAIC enforces.”
In this case, users are required to connect to an app called HeyCyan for certain features, including calls, voice assistant and music. The smart glasses came under public scrutiny when a pair purchased by the Australian Broadcasting Corporation (ABC) were found to still have footage filmed in a Chinese factory saved to the device.
Scott said: “This is an important warning of the potential consequences for ancillary contraventions.”
“This could conceivably include retailers, technology providers and others who develop, distribute or deploy connected devices and are knowingly involved in civil penalty contraventions. These are not just limited to serious privacy breaches,” she said.
“These devices may also be subject to the cyber security standards for smart devices made under the Cyber Security Act 2024 and Australian state and territory surveillance laws, which are not necessarily keeping up with the development and widespread sale and use of these types of smart devices.”
Following the review of the OAIC’s decision on Bunnings’ use of facial recognition technology, businesses and organisations have specific requirements to undertake privacy impact assessments, ensure transparency and obtain consent or other authorisation to use devices enabled with facial recognition technology, according to Scott.
“Businesses are on notice that these requirements will also apply to smart devices,” Scott said.
“Employers should also take note and assess whether these devices are being used by staff or visitors anywhere in the workplace, with or without their knowledge, and ensure they have been assessed. They too could face potential liability.”