Key Facts
- Legal Framework: Article 21 (K.S. Puttaswamy), DPDP Act 2023, Section 66E IT Act, Section 77 BNSS
- Enforcement Challenge: Consent is meaningless if the data subject doesn’t know they are being recorded
- Legal Gap: Section 66E only protects “private areas”; DPDP excludes “publicly available” data; Section 77 requires a “private act”
- Global Context: Germany discussing complete ban; EU GDPR transparency obligations; US state laws on biometric capture
- Delhi Cafe Case: Victim seeks ₹2.05 crore damages from Meta for covert recording
- Regulatory Roadmap: Tamper-proof indicators, on-device processing, bystander blurring, short retention, fast takedown
Direct Answer
AI smart glasses have exposed a critical enforcement gap in Indian privacy law. While the legal framework exists on paper—Article 21 (privacy as a fundamental right under K.S. Puttaswamy), the DPDP Act (consent, purpose limitation, security safeguards), and criminal provisions like Section 66E IT Act and Section 77 BNSS—none of these address the core problem: How do you enforce consent when the device records without the bystander’s knowledge? Section 66E IT Act only protects images of “private areas”—a public street does not qualify. Section 77 BNSS requires a “woman’s private act”—a casual recording of a crowd does not meet that threshold. The DPDP Act excludes “publicly available” information, leaving ambient public recordings unregulated.
Germany is discussing a complete ban on Meta smart glasses because recording devices hidden in everyday objects are illegal under German law. The Delhi cafe case—where a man was covertly recorded at Khan Market and the video received 4.19 lakh views—is testing whether Meta can be held liable for product design that enables privacy violations. In the absence of legislation, organisations must adopt practical compliance frameworks.
In this article:
- The Enforcement Gap
- The Legal Framework
- Global Regulatory Context
- The Delhi Cafe Case
- The Regulatory Roadmap
- The Practical Compliance Framework
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police since 1996.
The Enforcement Gap
AI smart glasses have exposed a critical enforcement gap in Indian privacy law. The technology enables covert, continuous recording in public spaces without the knowledge or consent of bystanders.
The Core Problem
How do you enforce consent when the device records without the bystander’s knowledge?
The DPDP Act’s consent requirement is meaningless if the data subject doesn’t know they are being recorded. The technology fundamentally alters the way information flows in everyday life. As Helen Nissenbaum argues, “privacy is not breached merely because information is observed in public spaces, it is compromised when information is collected, processed or shared in ways that are inconsistent with the norms of the context in which they were generated”.
The Invisible Bystander
In the absence of any visible camera or a recording indicator, determining whether recording is taking place becomes exceedingly difficult, which, by extension, means that raising objections or even making inquiries is a far-fetched act. One could use the glasses to continuously record, analyse, process and transcribe people’s activities, without them having any idea of being recorded.
What Makes Smart Glasses Different
Recording on phones or cameras in public is overt and generally identifiable. If one has an objection, they may bring it up with the person recording. What makes smart glasses different is not merely what they record, but how they do it.
AI wearables breach contextual expectations by transforming ordinary, everyday interaction into continuous surveillance, often without the knowledge of those affected.
The Legal Framework
Article 21 and K.S. Puttaswamy
The Supreme Court’s landmark judgment in K.S. Puttaswamy v. Union of India (2017) established privacy as a fundamental right under Article 21. However, this is a judicial decision that primarily operates against the State and does not create any private law remedy whenever an individual records another.
Section 66E of the Information Technology Act
Section 66E penalises capturing, publishing or transmitting images of a person’s “private area” without consent. This narrow threshold does not cover general public surveillance or everyday recording in public spaces.
Section 77 of the Bharatiya Nyaya Sanhita (BNS)
Section 77 protects women against observation or recording when engaged in private acts. A casual recording of a crowd does not meet this threshold.
Section 78 of the BNS
Section 78 criminalises stalking, including repeated monitoring through electronic means.
The Digital Personal Data Protection Act, 2023
The DPDP Act is technologically agnostic and does not specifically address covert recording in public spaces. The DPDP Act excludes information that is “publicly available”, creating a loophole for devices that capture data without explicit consent. Personal and domestic use is exempted from the DPDP Act’s scope.
Global Regulatory Context
Germany
Germany is discussing a complete ban on Meta smart glasses. The Hamburg data protection authority has classified the glasses as a concealed recording device. German law prohibits recording devices hidden in everyday objects. The difficulty of distinguishing the smart glasses in everyday life and of identifying when the camera is active could justify a complete prohibition. Germany’s Federal Network Agency has previously said smart glasses may be prohibited when their recording functions are not sufficiently recognizable.
European Union
The GDPR requires explicit consent for data collection under Article 6(1)(a). However, enforcing those rights is difficult when the device owner is unknown.
United States
Several US states have laws on biometric capture. Texas is investigating Meta glasses over whether they unlawfully record people, monitor bystanders, or collect biometric information without adequate notice or consent. A class action lawsuit filed in March 2026 in the US alleges false advertising and privacy violations tied to Meta’s Ray-Ban AI smart glasses.
The Delhi Cafe Case
A Delhi man has sent a legal notice to Meta and an Instagram creator, seeking ₹2.05 crore in damages for covertly recording him using Ray-Ban smart glasses.
What Happened
The creator filmed the video using Ray-Ban Meta smart glasses and posted it as an Instagram reel on July 26. The video garnered more than 4.19 lakh views over 10 days and attracted ridiculing comments.
The Response
The man attempted to report the video. Instagram lacked a specific privacy-violation category and Meta’s grievance officer for India did not acknowledge his complaint. Instagram eventually informed him that the video did not violate community standards.
The Legal Argument
The Internet Freedom Foundation (IFF), which assisted the man pro bono, stated that Meta is liable for a device “deliberately styled to be indistinguishable” from regular spectacles. The legal notice asserted that Meta “owed and breached a duty of care to [the man] as a victim, and is liable in negligence for its contribution to the intrusion upon his privacy”. It also argued that the “recording indicator on the said devices is inadequate and easily overlooked”, despite the small light on the right temple that turns on when a video is being recorded and flashes when a photo is being taken.
The Significance
This case is among the first legal actions in India seeking to hold a smart glasses manufacturer liable for product design harm.
The Regulatory Roadmap
The post identifies a sensible set of principles that could guide regulation:
Tamper-Proof Indicators
Recording indicators that cannot be concealed, disabled, or covered by stickers. Meta has stated that if wearers tried to tamper with the light indicator, it would be disabled.
On-Device Processing
Processing data locally on the device rather than transmitting it to the cloud.
Bystander Blurring
On-device AI that automatically blurs faces not actively engaged with the wearer.
No Default AI Training
Images and audio should not be used for AI training by default. Meta’s privacy policies state that they save all audio transcriptions on the glasses to train AI models but there is a way for users to opt out.
Short Retention
Automatic deletion of recordings within 24 hours unless flagged for a specific purpose.
Independent Audits
Regular third-party audits of compliance with privacy safeguards.
Fast Takedown
Clear mechanisms for victims to have recordings removed from platforms.
The Gap
Without legislation, these are voluntary guidelines that manufacturers can ignore.
The Practical Compliance Framework
For organisations deploying or banning these devices, the question is not what the law should be, but what can be enforced today.
Banning Devices in Sensitive Zones
- Toilets and changing rooms
- Clinics and hospitals
- Confidential meetings
- Courtrooms and police stations
- Government offices
Requiring Visible Indicators
- A recording light that cannot be disabled
- Visible indicators that cannot be concealed
- Distinguishable from regular spectacles
Implementing Bystander Blurring
- On-device AI that automatically blurs faces not actively engaged with the wearer
- Consent mechanisms for bystanders
Short Retention
- Automatic deletion of recordings within 24 hours unless flagged for a specific purpose
Organisational Policies
- Ban on smart glasses in the workplace
- Clear signage indicating recording may be prohibited
- Training on privacy and consent
The Maharashtra Initiative
The Maharashtra government is constituting an expert committee to formulate standard operating procedures (SOPs) for the use of AI-powered smart glasses and similar wearable devices. It will also train security agencies and law enforcement personnel to regulate and respond to the use of such devices in public spaces.
FAQ
What is the enforcement gap in Indian privacy law regarding AI smart glasses?
The enforcement gap is the inability to enforce consent when the device records without the bystander’s knowledge. The DPDP Act’s consent requirement is meaningless if the data subject doesn’t know they are being recorded.
What does Section 66E of the IT Act cover?
Section 66E penalises capturing, publishing or transmitting images of a person’s “private area” without consent. This narrow threshold does not cover general public surveillance.
What does Section 77 of the BNS cover?
Section 77 protects women against observation or recording when engaged in private acts. A casual recording of a crowd does not meet this threshold.
Why doesn’t the DPDP Act regulate smart glasses effectively?
The DPDP Act excludes “publicly available” information, leaving ambient public recordings unregulated. Personal and domestic use is exempted.
What is the Delhi cafe case?
A Delhi man sent a legal notice to Meta and an Instagram creator, seeking ₹2.05 crore in damages for covertly recording him using Ray-Ban smart glasses at a Khan Market cafe.
What is Germany doing about smart glasses?
Germany is discussing a complete ban on Meta smart glasses because recording devices hidden in everyday objects are illegal under German law.
What is a “tamper-proof indicator”?
A recording indicator that cannot be concealed, disabled, or covered by stickers, making it visible to bystanders when recording is taking place.
What is “bystander blurring”?
On-device AI that automatically blurs faces not actively engaged with the wearer, protecting the privacy of bystanders.
What is the Maharashtra government doing?
The Maharashtra government is constituting an expert committee to formulate SOPs for the use of AI-powered smart glasses and similar wearable devices.
What can organisations do today?
Ban devices in sensitive zones, require visible indicators, implement bystander blurring, adopt short retention policies, and establish clear organisational policies.
Explore More:
Read my blog: Shoeb Hakim Blog
Book Now: Book a Consultation
Contact: Contact Adv. Shoeb Hakim
Careers: Careers at Shoeb Hakim
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police since 1996.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
#AdvShoebHakim #SmartGlasses #PrivacyLaw #DPDPAct #CyberSecurity #DigitalForensics #WhiteCollarCrime #LegalDefense #Compliance #WearableTech



Leave a Reply