Do Smart Glasses Collect Children's Data?

The law built to protect a child's face and voice covers exactly that, and then stops at the one question the glasses make hardest
A child's face, voice and the biometric prints drawn from them are exactly the "personal information" the federal children's-privacy rule protects, and a 2025 update added biometrics to the list. But the rule binds only a service aimed at children, or one that knows it is collecting a child's data, which is where a stranger's glasses fall outside it.
How it started
Congress wrote COPPA in 1998 for a website asking a child to type a name
The Children's Online Privacy Protection Act was passed in 1998, when collecting a child's data meant a signup box on a web page. It fixes the age precisely: a "child" is "an individual under the age of 13."
Its rule is a bargain, not a ban. It is unlawful for "an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child," to collect that information without giving notice and obtaining verifiable parental consent. The whole scheme was built around a service and its child users: not around a stranger with a camera.
What changed since
a 2025 rule update pulled a child's captured face and voice, and the biometric prints taken from them, inside "personal information"
The Federal Trade Commission's amended COPPA Rule took effect on 23 June 2025, and regulated firms have until 22 April 2026 to comply. It added a category the 1998 web could not have needed: a "biometric identifier," listed to include "voiceprints" and "facial templates; or faceprints."
That sits alongside a category the Rule already carried: "a photograph, video, or audio file where such file contains a child's image or voice." Read the two together and the point is uncomfortable. A camera and a microphone worn on a face produce, by default, the exact material the children's-data rule now names twice.
Where it stands now
the data is squarely covered; the trigger that makes anyone responsible is not
The sentence worth being wrong about, if it turns out wrong, is this one: the output of these glasses is textbook COPPA personal information, and yet in most street encounters COPPA reaches none of it. The rule does not switch on because sensitive data exists. It binds an operator whose service is directed to children, or one with actual knowledge it is collecting from a child.
Meta's Ray-Ban glasses are a general-audience product sold to adults. So the clean case is a child who is the wearer, using the AI features as a known user; the stranger's child caught on the pavement is the case the statute was not built to close, because nobody has established that an incidental capture gives an operator "actual knowledge" of a child. This is a different question from the widely believed myth that there is a general law against photographing children in public — that is criminal and privacy law; this is the federal data regime, and it has its own seam.
What happens next
one date is on the calendar, and it does not touch the bystander
The dated step is the compliance deadline: 22 April 2026, written into the FTC's own order, by which regulated operators must meet the amended Rule. That is real and it is coming.
Nothing else is scheduled. No FTC action naming smart-glasses makers can be pointed to here, and no rule addresses the incidental-bystander capture that the whole subject keeps arriving at. On the question of the stranger's child, nothing is on a calendar and the Commission has not said it will return to it.
Sources and verification
- 15 U.S.C. 6501 (Cornell LII): "child" means "an individual under the age of 13"; defines "operator" and "website or online service directed to children."
- 15 U.S.C. 6502 (Cornell LII): the prohibition on "an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child," and the notice and "verifiable parental consent" requirements.
- 16 CFR 312.2 — Definitions (Cornell LII): "personal information" includes "a photograph, video, or audio file where such file contains a child's image or voice" and a "biometric identifier ... such as fingerprints; handprints; retina patterns; iris patterns; genetic data, including a DNA sequence; voiceprints; gait patterns; facial templates; or faceprints"; defines "operator" and a service "directed to children."
- 16 CFR 312.3 — General requirements (Cornell LII): notice, verifiable parental consent, parental review, and the limit on conditioning a child's participation on excess data — owed by an operator directed to children or one with actual knowledge it collects a child's information.
- 16 CFR 312.5 — Parental consent (Cornell LII): an operator "is required to obtain verifiable parental consent before any collection, use, or disclosure of personal information from children," and the approved methods for confirming a parent.
- 16 CFR 312.10 — Data retention and deletion (Cornell LII): a child's personal information may be retained "only as long as is reasonably necessary," "may not be retained indefinitely," and must then be deleted.
- FTC, final amended COPPA Rule — Federal Register, 22 April 2025 (govinfo, doc. 2025-05904): the amended Rule "is effective June 23, 2025," with compliance required "until April 22, 2026," and adds "biometric identifier" to personal information while declining the broader "data derived from voice data, gait data, or facial data" language proposed in 2024.
- Meta — "Meta's AI Glasses: Your Questions Answered" (about.fb.com): the capture LED "has no off switch" and "blinks to let people know you're capturing content"; photos and videos "are stored privately on your glasses."
Note on access and limits: every statute and rule above was read first-hand at Cornell LII; the FTC final rule at govinfo, because federalregister.gov and ecfr.gov redirect to an access wall from this server; Meta's page at about.fb.com. Meta's FAQ does not address whether AI-assistant queries, microphone audio or camera captures are sent to, stored by, or used to train models in Meta's cloud, so this report makes no claim that it does. No FTC enforcement action naming smart-glasses makers was read, and none is asserted. This is a report on what the statute and Rule say; it is not legal advice, and it does not tell any reader whether a particular capture is covered or lawful.