NewsTradingSentimentEventsCommunityBriefing
Tech

Smart Glasses Pose Data Risks for SA Employers Under PoPIA

By Tech Desk · · 2 min read
A pair of sleek, modern smart glasses resting on a wooden desk next to a pair of wireless earbuds
Illustration: Tradingbird, based on a photo published by Bizcommunity

Employers face compliance challenges as smart wearables collect biometric data in South African offices.

Key points

  • Biometric data from smart glasses and earbuds is protected under PoPIA, requiring explicit consent for processing.
  • Bystander rights are compromised because current device notifications are deemed inadequate by regulators and studies.
  • Transparency obligations are at risk due to default AI settings and cross-border data transfers to contractors.

Smart glasses and earbuds are increasingly entering South African workplaces, creating significant legal risks under the Protection of Personal Information Act. These devices function as continuous data collection tools, capturing biometric and health information that falls into a protected category under local law. As adoption grows, employers must navigate strict regulations regarding consent and data handling to avoid liability.

The issue is not merely about employee privacy but also the rights of bystanders who may be recorded without their knowledge. Regulators in Europe have already flagged these devices as surveillance tools, with France warning of normalized invisibility and Germany reviewing sales bans. South African companies cannot assume they are insulated from these global trends, as PoPIA requirements apply to any processing of personal information within the jurisdiction.

Biometric data triggers strict legal protections

Under PoPIA, biometric information is classified as special personal information, meaning its processing is generally prohibited without explicit consent or a specific statutory exception. Devices like Meta’s Ray-Ban smart glasses capture facial features and voiceprints, while Apple’s AirPods Pro 3 collect heart rate and motion data. This classification places a heavy burden on employers, who must demonstrate a lawful basis for any such data collection.

The practical implication is that even incidental collection of this data can be a violation. If an employee uses these devices in a shared office space, the company may be responsible for the processing of third-party data. The law requires that data subjects have the right to know when their information is being collected, a right that is often compromised by the silent nature of these wearables.

Bystander rights are difficult to enforce

A core challenge is the lack of effective notification for people who are not the device owners. A peer-reviewed study concluded that the small LED indicator on current smart glasses is inadequate as a safeguard for bystanders. This creates a conflict with Section 11 of PoPIA, which requires a responsible party to demonstrate a lawful basis for processing, a standard that is nearly impossible to meet when individuals do not know they are being recorded.

Regulators in France, Germany, and the Netherlands have reached similar conclusions, viewing these devices as tools of covert surveillance. For South African employers, this means that allowing such devices in open-plan offices or meetings without clear policies and technical controls poses a direct compliance risk. The legal difficulty lies in proving that consent was obtained or that the processing was necessary, given the opacity of the data collection.

Transparency gaps and data transfer issues

Section 18 of PoPIA mandates that data subjects be informed about what is collected, why, and who is responsible. Recent updates to privacy policies by major tech companies have removed options to disable certain recording features, defaulting to AI-enabled processing. Additionally, investigations have revealed that footage may be reviewed by human contractors in other countries, such as Kenya, without adequate disclosure to users.

This opacity conflicts with the transparency mandate of South African law. Furthermore, the transborder transfer of this data is restricted unless the recipient country provides adequate protection or specific consent is given. As reported by Bizcommunity, these global practices sit uncomfortably with local obligations, requiring employers to scrutinize how their employees' data is handled by third-party vendors to ensure full compliance.

Based on reporting by Bizcommunity, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories