Widespread Wearables: what the $89 Kmart smart glasses mean for your organisation

Sam Fiddian, Anna Casellas, Molly Smith
14 Aug 2026
6 minutes

The $89 Anko Smart Glasses sold out nationally in under one week, bringing discreet recording capability to the mass market. With the Attorney-General calling for an urgent privacy investigation and the Privacy Commissioner questioning whether current law is fit for purpose, we look at the risks this development might pose to organisations and the steps in-house teams should consider taking in response.

The Anko Smart Glasses represent a step change in consumer surveillance technology: discreet, affordable, and designed to be indistinguishable from ordinary eyewear.

Every workplace, client site, and corporate premises now faces a realistic prospect that individuals (employees, contractors, visitors) may be passively recording their surroundings without any visible indicator that a camera is active.

Key takeaways

The Privacy Act 1988 (Cth) (Privacy Act) regulates organisations, not individuals. The practical consequence is that in-house teams must focus on what the organisation can control: its policies, its premises, and its compliance frameworks. With that framing in mind, in-house teams should consider the following actions:

  1. Audit existing policies: Review workplace surveillance, acceptable use, BYOD, and information security policies. Assess whether they adequately address wearable recording devices. Update definitions and prohibitions where necessary.

  2. Implement premises-based controls: Deploy signage, update visitor protocols, and designate restricted zones. Consider whether smart glasses should be treated analogously to smartphones in secure areas.

  3. Revisit APP compliance: Assess whether current privacy collection notices and consent mechanisms are adequate for a world in which recording devices are invisible. Update privacy policies and collection statements where gaps exist.

  4. Monitor legislative reforms: Monitor the progress of legislative reforms and regulatory guidance in this area and assess their impact on your organisation. The fair and reasonable test and enhanced consent standards expected in the Tranche 2 Privacy Act reforms will require changes to existing practices.

  5. Prepare for incident response: Develop or update your data breach and privacy incident response plan to address scenarios involving covert wearable recording. Ensure staff know how to report suspected recording and that escalation pathways are clear.

  6. Consider complementary legal frameworks: Remember that the Privacy Act is not the only source of obligation. State and territory surveillance legislation, workplace health and safety duties, confidentiality obligations, and contractual restrictions all provide additional levers to manage recording risks on your premises.

The rise of consumer surveillance wearables

On 28 July 2026, Kmart released its Anko Smart Glasses: black-rimmed, clear-lens glasses capable of recording high definition video and photographs, which are transferred to a paired smartphone via the HeyCyan app. At $89, the product offers discreet surveillance capability to the mass market at a fraction of the cost of Meta’s Ray-Ban smart glasses, which retail for several hundred dollars.

The product sold out across Australia in under one week.

Within days of their release, Attorney-General Michelle Rowland had formally requested that the Office of the Australian Information Commissioner (OAIC) investigate the privacy implications of smart glasses, citing serious safety concerns for women and children. Rowland noted that “unlike other forms of technology, smart glasses may be used more discreetly, making it harder to know when you are being recorded.”

This coincided with the release by Privacy Commissioner Carly Kind of a detailed blog post on the OAIC website, indicating that the OAIC is “giving serious consideration to the issues raised by surveillance wearables and monitoring their market presence to understand if scrutiny and intervention is required or warranted.”

In the United Kingdom, pub chain Wetherspoons has already banned smart glasses with cameras in its venues, an early signal of how commercial premises operators are responding to the technology.

Why this matters for commercial organisations

While public commentary has focused on consumer safety risks, the privacy concerns raised by the Attorney-General and Privacy Commissioner have direct implications for commercial organisations. While individuals acting in a personal capacity are generally not subject to the Privacy Act or the Australian Privacy Principles (APPs), the Privacy Act and the APPs regulate the privacy practices of organisations, including the activities of their employees in the course of their employment.

This distinction is critical: an employee who covertly records colleagues using smart glasses for purely personal reasons is unlikely, by that act alone, breaching the APPs, because the APPs do not impose obligations on individuals. However, the organisation that controls the premises and the employment relationship does bear obligations under the APPs in respect of the personal information environment it manages.

In-house teams cannot treat this as someone else's problem. Where personal information is collected in the course of your organisation's functions or activities, or where your organisation holds personal information that may be exposed by recording on your premises, the APPs impose obligations on your organisation.

How smart glasses collect and store data

The Anko Smart Glasses present privacy risks typical of consumer wearables with recording capabilities.

They feature an integrated micro camera that captures high-definition video and photos from the wearer’s perspective, including faces, documents, screens, and credentials, without any visible recording indicator such as an LED light. Recorded media is transferred to the wearer’s smartphone via the HeyCyan companion app, typically over Bluetooth, using a persistent connection that enables near real-time transfer. The HeyCyan app offers a range of features, including music playback, call management, AI assistant integration, and seamless photo and video sharing directly from the device.

Once transferred, recordings are stored locally on the smartphone and accessed through the HeyCyan app. These recordings can be copied, shared, uploaded to cloud services, or transmitted to third parties without the knowledge of those recorded. While recordings are primarily stored locally, users can upload them to cloud platforms, social media, or messaging services, making it difficult for organisations to control further disclosure.

From a compliance perspective, several critical concerns arise. The 8-megapixel camera and 1080p video capability of these devices can record faces, surroundings, private conversations, and confidential material, often without the knowledge or consent of those being recorded. Key concerns include the absence of a visible recording indicator, the ease with which footage can be disseminated, and the volume of personal and sensitive information that can be collected covertly.

The privacy challenge

APP 3 mandates that personal information must be collected by lawful and fair means. For sensitive information, such as biometric data (including facial images), APP 3.3 requires that collection only occur with consent. Organisations must also ensure that the collection of personal information is reasonably necessary for their functions or activities.

APP 5 requires organisations to notify individuals, at or before the time of collection, about the purposes of the collection, who will receive the information, and the consequences of non-collection. However, smart glasses present a significant compliance challenge: how can individuals be notified that they are being recorded when the recording device is indistinguishable from ordinary eyewear?

Privacy Commissioner Kind has highlighted this issue, stating: “There are real questions as to whether [technology companies] will be able to [comply with privacy law]: how will they notify individuals that their images or voice has been recorded?”

We would take it one step further. If the personal information is being collected by employees in the course of their employment, or stored on employer-issued devices, how will employers ensure that this does not represent a privacy compliance risk.

For organisations permitting the use of smart glasses, achieving APP 5 compliance may require measures such as:

  • prominent signage at entry points, clearly disclosing the potential for recording;

  • express terms in visitor and contractor agreements addressing recording on premises;

  • real-time notification mechanisms, where practicable; and

  • policies restricting or prohibiting the use of recording-capable wearables in defined areas.

And the privacy risks do not stop at the point of collection. Employers could be held responsible for the unlawful use of the information by employees. And merely holding the data in its systems or on its devices represents a significant risk in the event that the data is the subject of a data breach.

Beyond privacy

Of course, potential privacy implications are not the only risk created by mass adoption of surveillance wearables such as the Anko Smart Glasses. Developments in this technology have the capacity to amplify insider threats across the spectrum, from presenting further challenges for an organisation's cyber defences, to increasing the ease with which insiders can exfiltrate confidential information or valuable intellectual property.

And this is quite aside from the potential impact on workplace claims and investigations, which can often involve allegations of covert recordings of disciplinary or performance management activities or which might themselves be the subject of bullying or harassment claims by those recorded, all against the background of the increased recognition of the risks associated with psychosocial hazards.

The removal and surrender question

Whether an organisation can require visitors or employees to remove or surrender smart glasses raises practical and legal questions. Employers generally have broad authority to set conditions of entry to their premises, including restrictions on devices. However, any removal or surrender policy would need to:

  • be clearly communicated in advance;

  • apply consistently and not discriminatorily;

  • account for prescription smart glasses (where the recording device is integrated into corrective lenses);

  • provide secure storage for surrendered devices; and

  • be documented in employment contracts, workplace policies, and visitor terms of entry.

Where organisations determine to permit the use of these devices, clear policies and practices around that use would be required to seek to mitigate the risks posed.

Looking ahead

The Anko Smart Glasses are a $89 harbinger of a broader trend. As wearable recording technology becomes cheaper, more accessible and more discreet, the gap between what the law requires and what individuals can do will only widen. A potential OAIC investigation and the Tranche 2 reforms all signal that the regulatory framework is shifting, but it has not yet matured.

In the interim, the burden falls on organisations to manage the risk through policy, premises controls, and proactive compliance. In-house teams that act now will be materially better positioned when the regulatory landscape crystallises.

Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.