The full story

Do Smart Glasses Collect Children's Data?

The law built to protect a child's face and voice covers exactly that, and then stops at the one question the glasses make hardest

Back to the summary

A 1998 bargain, dropped onto a 2026 sensor

The confusion in this subject is a category error, and it is worth naming before anything else. People hear "children's data law" and "camera glasses that capture children" and assume the first must govern the second. It governs a slice of it, and the slice is not the one most people are worried about.

The Children's Online Privacy Protection Act of 1998 is not a law about photographing children. It is a law about the deal a commercial online service has to strike before it takes a child's information. Its definitions are exact where it matters: a "child," the statute says, is "an individual under the age of 13" — not a teenager, not every minor, under 13. And the operative prohibition, in the statute itself, is aimed at a specific actor: it is unlawful for "an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child," to collect that information "in a manner that violates the regulations." Everything COPPA does hangs off that one sentence, and off the two triggers inside it.

When the triggers are met, the obligations are real. The statute requires the FTC's rule to make an operator "provide notice on the website of what information is collected from children," and to "obtain verifiable parental consent for the collection, use, or disclosure of personal information from children." The Rule that carries this out, 16 CFR Part 312, spells it out: an operator "is required to obtain verifiable parental consent before any collection, use, or disclosure of personal information from children." Not consent after the fact, not a notice buried in a policy — consent first, confirmed to be a parent's.

What the 2025 update actually changed, and what it pointedly did not

For most of COPPA's life, "personal information" was the stuff of a signup form: a name, an address, an email, a phone number. The category has grown, and in 2025 it grew in the direction of the sensor.

The FTC's amended COPPA Rule is not a proposal or a plan; it is in force. Its own dates line reads that the amended Rule "is effective June 23, 2025," and that, with a narrow exception for some safe-harbour provisions, "regulated entities have until April 22, 2026 to comply." The change that matters here is the addition of a "biometric identifier" to the list of personal information: one "that can be used for the automated or semi-automated recognition of an individual," the codified text says, "such as fingerprints; handprints; retina patterns; iris patterns; genetic data, including a DNA sequence; voiceprints; gait patterns; facial templates; or faceprints."

Voiceprints. Facial templates. Faceprints. Those are not incidental to a pair of AI glasses; they are the thing the device is built to produce when it recognises what it is looking at or listening to. And they now sit beside a category the Rule already had, one added in an earlier era of the law: "a photograph, video, or audio file where such file contains a child's image or voice." A child in frame, a child's voice on the audio track — the Rule has named both for years, and the 2025 update added the machine-readable print underneath them.

It is worth being precise about the limit of that change, because the roundups blurred it. In finalising the Rule the Commission declined to adopt a broader catch-all that the 2024 proposal had floated: language reaching "data derived from voice data, gait data, or facial data." What is in the codified Rule is the enumerated list above, not that wider derived-data phrase. The distinction is real: the Rule covers a faceprint, not every downstream inference a system might build from a face. For a device whose whole business is inference, that line will matter.

The two triggers, and why the glasses fall between them

Now the part that decides almost every real case. A child's face being sensitive is not what makes COPPA apply. Two things do, and only two: the service is directed to children, or the operator has actual knowledge it is collecting a child's personal information.

Take them in turn against a pair of Meta's glasses. "Directed to children" means, in the Rule's words, "a commercial website or online service, or portion thereof, that is targeted to children." AI glasses sold as a general-audience consumer product, marketed to and bought by adults, are not that. So the first trigger is off. That leaves actual knowledge, and this is where the subject splits cleanly in two.

There is the child who is the wearer, or who uses the glasses' AI assistant: a known user of an online service. If that service is collecting a recognisable child's personal information and the operator knows it, the machinery above is in play, and the operator owes notice, verifiable parental consent, and the rest. That is the case COPPA was built for, merely wearing new hardware.

Then there is the child who is a bystander: a stranger's kid on the pavement, caught in the frame of an adult's glasses. This is the case the whole cluster keeps returning to, and it is the one COPPA fits worst. For the rule to bite, an operator has to be "collecting" that child's information and have "actual knowledge" that it is a child. A wearer photographing a stranger is not an "operator" running a service. And whether an incidental capture routed anywhere gives a company "actual knowledge of a specific child" is not a settled question; it is barely a litigated one. The federal regime that reads, on paper, as if it were written for this sensor turns out to have a door the bystander case does not walk through.

What Meta says its glasses do, and the silence that matters

The device facts cut against the easy assumption too. Meta's own explainer says the capture light "has no off switch" and "blinks to let people know you're capturing content": the disclosure signal, such as it is. On storage, it says photos and videos "you capture with your AI glasses for your gallery are stored privately on your glasses," and that "you choose when to import them to your phone."

Stored on the glasses. Not, on that page, uploaded, retained in a cloud, or fed to a model. What Meta's FAQ does not address is as important as what it does: whether the AI-assistant queries, the microphone audio or the camera captures that go to Meta's servers are stored there, kept, or used to train systems is simply absent from the page. So the honest statement is narrow. The on-device gallery stays on the device by Meta's own account; whether anything a child said or whose face a child showed becomes something an online service "collects," in COPPA's sense, is exactly the question the public documents leave open. This piece will not put a claim in Meta's mouth that Meta's page does not make, and the broader picture of what happens to what these glasses capture is its own unfinished story.

Where the filmed child's remedy actually lives

If COPPA mostly does not reach the bystander child, the reasonable next question is what does, and the answer is not a single clean statute. It is a patchwork, and its sharpest pieces are at the state level rather than the federal one.

The place a filmed person, child or adult, has actually been given a lever is the state biometric-privacy laws. Illinois, Texas and Washington attach real consequences to capturing a face or voiceprint without consent, and Illinois in particular pairs that with statutory damages a claimant does not have to prove a loss to recover. That is the route this cluster has traced before, in the state statutes that put a price on a captured face, and it is a different mechanism from COPPA entirely: it does not care whether the operator was "directed to children," only whether a biometric identifier was captured without the consent the state demands.

COPPA, by contrast, is doing something narrower and more specific than the worry it gets attached to. It is the rule that says a service which knows it is dealing with children under 13 cannot quietly harvest their names, faces and voiceprints without a parent's verified yes; that it must say what it takes and why; and, under the amended Rule's retention section, that it may not sit on that data forever. Personal information collected from a child, 16 CFR 312.10 now provides, may be retained "only as long as is reasonably necessary" for the purpose it was collected for, and "may not be retained indefinitely." Those are strong protections for the child the service knows about. They do almost nothing for the child in the corner of a stranger's photo.

The through-line, stated plainly

Two facts, and they point in opposite directions. First: a child's face, a child's voice and the biometric prints made from them are, as of 2025, squarely inside what federal children's-privacy law protects — the update closed the gap between what the old signup-box rule imagined and what a modern sensor grabs. Second: that protection reaches an operator only through a service aimed at children or one that knows it has a child in front of it, and a pair of adult glasses catching a stranger's kid on the street clears neither bar.

The tidy headline — smart glasses collect children's data, and there's a law for that: is half right in a way that misleads. The data is covered. The everyday capture that frightens parents mostly is not, because the law is about a service's relationship with its child users, and the bystander was never a user of anything. Closing that gap would take a rule aimed at the wearer or the capture, not at the operator, and no such rule is on the table. Until one is, the strongest answer for the person whose child was filmed is not COPPA at all: it is the state statute that puts a price on a face, and even that only bites where it has been enacted.

Sources and verification

Note on access and limits: every statute and rule above was read first-hand at Cornell LII; the FTC final rule at govinfo, because federalregister.gov and ecfr.gov redirect to an access wall from this server; Meta's page at about.fb.com. Meta's FAQ does not address whether AI-assistant queries, microphone audio or camera captures are sent to, stored by, or used to train models in Meta's cloud, so this report makes no claim that it does. No FTC enforcement action naming smart-glasses makers was read, and none is asserted. This is a report on what the statute and Rule say; it is not legal advice, and it does not tell any reader whether a particular capture is covered or lawful.