Meta pitched its AI glasses as the next leap in personal technology, the device that was meant to be the next smartphone. They resemble ordinary everyday eyewear while housing a camera, microphones and an AI assistant that can photograph, record, and translate in real time amongst many other features.
The response however has been much colder than Meta anticipated. For instance, in the United States, Immigration and Customs Enforcement (ICE) has prohibited employees from wearing them on duty; courts in England and Wales require visitors to surrender them at the door; and venues such as Soho House and Wetherspoons have barred them from their premises. Public discourse has even given it a unique nickname – "pervert glasses."
Two Indian episodes frame the legal question. In March 2026, a content creator wearing the glasses recorded a transgender protester at a Delhi demonstration without consent; the footage circulated widely and drew a wave of targeted harassment. In July 2026, Delhi Police personnel were photographed wearing the glasses while monitoring student demonstrators at the Cockroach Janta Party protests. India has enacted no specific statute for wearable recording devices, so the governing framework is essentially the Constitution and the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
Indian law is not otherwise silent on non-consensual recording. Two criminal provisions come closest. Section 66E of the Information Technology Act, 2000 penalizes capturing or transmitting the image of a person’s ‘private area’ without consent, and the offence of ‘voyeurism’ punishes watching or capturing the image of a woman engaged in a ‘private act’ in circumstances where she would expect privacy. Neither, however, fits the conduct these glasses enable. Both are confined to intimate capture in a setting where the subject expected privacy: the first to a ‘private area,’ the second to a woman in a ‘private act.’ They say nothing about the ordinary recording of a face or a voice in a public place.
The Principal, the Data, and the Fiduciary
The DPDP Act is based on a consent-first model, as its preamble makes clear. It protects the ‘Data Principal’, defined under the DPDP Act as the individual to whom the personal data relates. In the situation these glasses create, the Data Principal is not the wearer but the bystander – the passer-by, or the person across the table, whose face and voice are captured as they walk into frame. ‘Personal data,’ in turn, is defined as any data about an identifiable individual, so a captured image or recorded voice falls squarely within the DPDP Act’s ambit.
The DPDP Act imposes duties on the ‘Data Fiduciary’, defined as the person who determines the purpose and means of processing that personal data. In this scenario, there are two primary candidates for Data Fiduciary.:
- The first is the wearer, who directs the camera and decides what to record;
- the second is Meta, which determines the purpose and means ofwhat happens to a recording once made, including storing the footage on its servers, and determining what is done with it there
Each raises a distinct problem. The wearer has an exemption of “personal use: that may remove their obligations entirely. Meta’s problem is whether it can satisfy the consent the Act demands, as discussed in the next section.
Consent the Bystander Cannot Give
Irrespective of who the Data Fiduciary is, the DPDP Act renders the processing of personal data lawful only if it is with the Data Principal’s ‘consent’ or one of the ‘legitimate uses’ specified under the Act- medical emergency, an employment purpose, a function of the State. None of these apply to filming a passer-by in public. Consent would therefore appear to be the relevant basis for processing. Consent, under the Act, must first be sought with a notice, that is clear, itemised, and in plain-language, stating the purpose of collecting data, means of withdrawing consent, as well as the process of raising a complaint.
This is where Meta’s position as a fiduciary unravels. Such notice-and-consent mechanism of the Act presumes that the fiduciary can approach the data principal before processing their data, but Meta has no means of doing so. It does not know who the bystander is, has no means of reaching a stranger captured in passing, and receives the footage only after the recording has already occurred. Hence, the very person whose consent the Act requires is someone Meta can neither identify in advance nor contact at all. The obligation is not merely unmet; for a fiduciary in Meta’s position, it is impossible to meet. And the bystander, for their part, receives no notice, gives no consent, and ordinarily never learns a recording occurred, so never has occasion to withdraw consent or to complain. The Act’s central mechanism is therefore structurally unavailable to the very person it exists to protect.
Meta’s answer to this concern was a hardware signal: a small LED on the frame that illuminates while the camera records, intended to alert those nearby that they are being captured. But a light is not a ‘notice.’ Under the Act, valid ‘consent’ must be preceded by a notice that gives the Data Principal enough to make an informed choice about the identity of the person collecting the data, the purpose of collection, and the means of withdrawing consent or raising a complaint. The indicator supplies none of these. It identifies no Data Fiduciary, states no purpose, and offers no mechanism to object or withdraw; at most it signals that a recording is occurring, never by whom, for what purpose, or to what end. Its practical value is lower still: the LED is small and easily missed on a busy street. A Data Principal can neither agree to nor refuse a signal they may never perceive, still less consent to processing whose purpose was never disclosed to them. Whatever the light achieves as a courtesy, it is not the notice the Act requires, and it cannot supply the ‘consent’ that notice exists to enable.
The Right to Erasure That Cannot Erase
Even the rights the Act does confer on the bystander prove difficult to exercise in practice. The right to erasure under Section 12 entitles the data principal to have their personal data deleted, and the purpose-limitation duty under Section 8 confines a fiduciary to using data only for the purpose for which it was collected. Yet the glasses route captured voices, images and the inferences drawn from them to Meta’s servers, where they may be used to train AI systems and, by some accounts, are reviewed by sub-contractors in Kenya. Once a data principal’s face has been absorbed into a model’s parameters, or copied to a reviewer halfway across the world, deleting the original file neither reverses what the model has learned nor undoes what has already travelled downstream. The right exists on paper, while the remedy has essentially dissolved in practice.
The Vulnerable Data Principal
The problem gets worse when the person filmed is a child or someone with a disability. The processing of a child’s data under the DPDP Act requires the verifiable consent of a parent or lawful guardian, and the provision prohibits tracking, behavioural monitoring and advertising directed at children. These safeguards are structurally unavailable in the setting these glasses create. A child who wanders into frame on a footpath is no less a data principal, yet verifiable parental consent cannot be obtained for a child a stranger happens to film. The same holds for the other class, that is, a person with a disability, in which case the verifiable consent of a lawful guardian is mandated. Hence, the class the legislature sought hardest to protect is thus left the least protected in fact.
The Accountability Vacuum
This returns us to the question left open earlier: where a bystander is harmed, who answers for it under the Act? The answer turns on two exemptions, and the two Indian incidents fall neatly upon one each.
The wearer is usually exempt: The Act takes an individual who processes personal data for a purely personal or domestic purpose outside the scope of the Act. A creator who films strangers in order to publish for commercial purposes may fall outside this exemption, but a wearer who records and simply keeps the footage or uses for personal purposes is exempted.
State instrumentalities may be exempted: The Act empowers the Central Government to exempt certain instrumentalities of the State from the Act. Should it do so, the student demonstrators, equally data principals, fall outside the Act’s protection.
As for Meta it turns from data-protection law to tort. Unlike the wearer, Meta cannot claim personal-use exemption; unlike the State, it is not a public instrumentality. But as shown above, the DPDP Act’s ‘consent’ duties are, for a manufacturer in Meta’s position, impossible to perform against an unidentifiable bystander, so the Act reaches it only weakly. The emerging route runs outside the Act altogether. In August 2026, in a matter in which the Internet Freedom Foundation provided pro bono assistance, a bystander who had been covertly filmed through Ray-Ban Meta glasses at a Delhi café, and whose footage was then circulated widely as a ‘cringe’ reel, issued a legal notice against Meta. The notice alleges that Meta is liable in negligence for designing and marketing eyewear deliberately styled to be indistinguishable from ordinary spectacles, with only an inadequate capture light as a safeguard. The claim is framed as product liability: a duty of care owed to the bystander that arises from Meta’s own design and marketing choices, is independent of its role as an intermediary, and therefore falls outside the safe harbour that Section 79 of the IT Act extends to intermediaries.
For now, though, that route is untested. Under the statute meant to protect personal data, the bystander filmed by a private wearer, and the protester filmed by an exempted State, are each left without a remedy.
Since the statute does not provide any remedy, the aggrieved might turn to the Constitution. In Justice KS Puttaswamy (Retd) v Union of India the Supreme Court held privacy, including informational privacy, to be a fundamental right under Article 21, and subjected any State intrusion upon it to a test of legality, legitimate aim, proportionality, and procedural safeguards. State’s use of always-on glasses to capture personal data, would have to be justified against that standard. However, the constitutional right offers the bystander little against the private wearer; Article 21 binds the State, not a stranger with a camera.
What the Gap Demands
It would be unfair to predict failure of DPDP Act. The Act drafted for circumstances in which consent can be sought with a tick against an “I agree” box, and for those circumstances it works well. Its silence falls where the collection is invisible, and already uploaded before the data principal is aware that a stranger was recording.
Closing that gap does not require a new statute, at least not first. Three things would do most of the work, and they are set out below in the order of how quickly they can happen:
- Privacy by design, directed at Meta. There is broad agreement across regulators and researchers that the capture light does not work as a safeguard. As early as 2021, the Irish Data Protection Commission and the Italian Garante questioned whether the indicator on the device could effectively put bystanders on notice, and peer-reviewed studies through 2026 have found that bystanders and even wearers regard the signal as ineffective. A design obligation fixed on the device and the platform; a conspicuous, non-defeatable recording signal, together with default limits on retention and downstream use would place responsibility on the party that builds the product, rather than on a ‘consent’ that no bystander can give.
- Clarification of the scope of ‘personal use.’ The personal-or-domestic exemption was written for private, household processing, not for footage published to lakhs of strangers for creator payouts. European law offers a reference point: in Ryneš, the Court of Justice held that a home CCTV camera covering even part of a public space fell outside the household exemption and squarely within data-protection law. A similar reading that capture reaching the public sphere, or published for gain, is not ‘personal use’ would stop the exemption from swallowing the very conduct these glasses enable.
- Clarification of the scope of the State exemption. The exemption should be read down to sit with the proportionality standard laid down in Puttaswamy, so that a single blanket notification cannot place always-on surveillance of protesters beyond both statutory and constitutional reach at once.

Leave a Reply