The full story
Can Your Employer Make You Wear Recording Glasses at Work?

There is no law against the device — only one that decides how much it is allowed to see
A camera on every shop floor, pointed the wrong way to notice
Walk into a large supermarket and there is a fair chance the person scanning the aisle is wearing a small camera on their chest. Tesco offered body-worn cameras to staff as part of a security programme it put at £44m over four years, the cameras alongside door-access systems, protection screens and digital radios, after its chief executive, Ken Murphy, said physical assaults on staff had risen by around a third in a single year. Usdaw, the shopworkers' union, supported the move. Its general secretary, Paddy Lillis, said there was "no doubt that body-worn cameras do have a deterrent effect," and set out the term that turns out to be the legal heart of the matter: "the public must be fully aware they are in use."
That is the quiet fact under the whole debate. Employer-issued recording has already arrived, and it arrived facing outward. A camera worn to protect a worker still films every customer who steps up to complain, every child in a trolley seat, every passer-by who happens through the frame. The worker wears it; other people are recorded by it. When the device was a chunky vest-mounted box, at least everyone could see it. The direction the technology is now travelling erases even that: the recording capability is migrating into eyewear that is hard to tell from a normal pair of glasses, and the same warehouse or field-service employer that handed out a barcode scanner a decade ago can now hand out a lens. The question employees are starting to type, can our boss make me wear this, is the natural next one. The answer is more interesting than a yes or a no.
There is no smart-glasses law, and that is the whole answer
There is no statute in the UK or Ireland about recording glasses at work. No law names the device, bans it, or licenses it. That absence is not a loophole; it is the answer. Recording staff and the public with a worn camera is governed by the same data-protection law that governs every other kind of workplace monitoring: the UK GDPR and the Data Protection Act 2018, as interpreted by the ICO's guidance on monitoring workers, and, across the EU, the GDPR as applied by national regulators such as Ireland's Data Protection Commission.
That reframing cuts both ways, and it is worth being precise about the direction. It does not mean an employer is free to do as it likes because no rule mentions glasses. It means the demanding general rules apply in full. The ICO's own guidance already folds the hardware in, listing "camera surveillance including wearable cameras" and "body worn devices" among the monitoring methods it covers. The mirror of this question — whether an employer can stop a worker wearing their own smart glasses — runs on the same track from the other side. Both come down to the same test: not "is there a glasses law," but "can the employer satisfy data-protection law for what these glasses actually do."
Six boxes before the first frame
The first requirement is a lawful basis. Article 6 of the UK GDPR states that processing "shall be lawful only if and to the extent that at least one" of six bases applies: consent, performance of a contract, a legal obligation, vital interests, a public task, or the employer's legitimate interests. In the workplace the ICO is blunt that consent rarely works, because the imbalance of power between employer and worker means it cannot be freely given; legitimate interests is the usual candidate, and it has to survive a balancing test against the rights of everyone recorded.
Choosing a basis is not a formality to be waved through. The ICO tells employers they "must be clear about" their purpose and "select the least intrusive means to achieve it," and warns against monitoring workers "just in case." Its worked example is pointed: an employer that reacted to a few late log-ins by rolling out webcam snapshots of remote staff was, in the regulator's words, likely acting unlawfully, "because it is disproportionate, and there are less intrusive ways to check start times." Read across to eyewear that records continuously, and the same logic bites harder. A device that films everything, all shift, to solve a problem that a narrower tool would solve is the textbook case of the disproportionate means the guidance tells employers to reject.
The assessment that has to happen first
For anything higher-risk, the law front-loads the scrutiny. Article 35 of the UK GDPR requires a Data Protection Impact Assessment before processing that "is likely to result in a high risk to the rights and freedoms of natural persons," and singles out, among the cases that trigger it, "a systematic monitoring of a publicly accessible area on a large scale." A worn camera sweeping a shop floor or a public street is close to a definition of that phrase. The assessment itself, the statute says, must set out "an assessment of the necessity and proportionality of the processing operations" and the measures to reduce the risk.
The ICO makes the same demand in plainer words for cameras specifically: an employer considering video or audio monitoring "must" complete a DPIA, and must "consider why this monitoring is necessary." If that assessment turns up a high risk the employer cannot reduce, Article 35 requires it to consult the ICO before going ahead at all. This is the step most likely to be skipped in a hurried rollout, and it is the one the law treats as non-negotiable for exactly the kind of always-on wearable recording the question is about.
The people who never agreed to wear anything
The sharpest point is the one the "can my boss make me" framing misses entirely. An outward-facing worn camera records the public far more than it records the worker, and those people never signed a contract, never sat through an induction, and often never see the lens. Data-protection law does not forget them. The ICO tells employers that if they use video or audio monitoring they must make "anyone else caught by the monitoring, such as visitors or customers, aware of its operation," and explain why they are doing it. It goes further: if a customer or worker later asks for the footage of themselves, a subject access request, the employer "may need to be able to redact third parties from the footage," which for a camera that films crowds is a genuine, ongoing burden.
Ireland's Data Protection Commission draws the same line and names the reason wearables are worse than fixed cameras. Unlike CCTV, which "can be carefully positioned to minimise the risk of inadvertent data collection," a body-worn camera "can effectively turn the wearer into a mobile surveillance system that is likely to capture the personal data of passers-by." The ICO's parallel in its own guidance is the dashcam: an outward-facing camera, it notes, "can capture recordings of other motorists or pedestrians outside of the vehicle," and that spillover is treated as a data-protection risk in its own right, not an incidental detail. A pair of recording glasses is a dashcam that walks.
Audio is the line, and faces are a second one
Not all recording is equal in the eyes of the law, and the gradient is instructive. The ICO says audio is treated as markedly more intrusive than video. It tells employers to "switch off by default any capability to record audio" and to use it "only in exceptional circumstances," and warns that continuous audio-and-video recording "can be highly intrusive," a combination an employer is "unlikely to be able to justify... in most circumstances." That single instruction rules out the most obvious way an employer might use recording glasses — leaving them running with the microphone live — in most settings.
Faces are the other threshold. The moment glasses are used to identify people rather than merely film them, the footage stops being ordinary video. Article 9 of the UK GDPR treats "biometric data for the purpose of uniquely identifying a natural person" as special-category data, whose processing is prohibited unless a further, narrow condition is met on top of the lawful basis. The ICO adds that facial recognition "presents a high risk," so a DPIA is mandatory, and flags a practical hazard: there are "concerns about the accuracy of facial recognition technologies, particularly for people from ethnic minority groups." That is not a hypothetical. It is the same technology, and the same failure mode, that saw a shopper wrongly flagged as a shoplifter by a supermarket's facial-recognition system — a live demonstration of what happens when a machine's match is trusted over the person in front of it, and a reminder that what these systems can actually identify is a narrower and messier thing than the marketing implies.
Covert recording is almost always out
One route an employer might imagine, issue the glasses quietly, watch what staff do, is the one the law shuts hardest. The ICO says it is "unlikely" that an employer "will be able to justify covert monitoring in most usual circumstances." Where it is contemplated at all, it is confined to exceptional cases such as suspected criminal activity or gross misconduct, "should only be authorised by senior management," must be "strictly" targeted and time-limited to "the shortest time possible," and must stop the moment the investigation ends. A standing arrangement in which workers wear recording devices without being told, as a matter of routine, is not the exception the guidance contemplates; it is the thing it rules out.
The rulebook is being rewritten as you read this
The reason none of this is quite settled is that the law it rests on is mid-revision. The Data (Use and Access) Act 2025 became law on 19 June 2025 and its data-protection provisions have been switching on in stages, some on 20 August 2025, a further tranche on 5 February 2026, reshaping parts of the UK GDPR, including a new "recognised legitimate interest" basis inserted at Article 6(1)(ea). That is why the ICO's monitoring-workers guidance now carries its "under review" banner: the regulator is rewriting the detail to match the amended statute. The principles above, lawful basis, transparency, an impact assessment for high-risk monitoring, the duty to the public in the frame, are the durable core, and none of them is going away. What may shift is the fine print an employer relies on to clear the bar. For the worker asking whether the glasses can be forced on them, the useful thing to know is that the answer was never a wearable rule waiting to be found. It was, and remains, whether the employer can honestly satisfy a general law that is, right now, being changed around the exact question they are asking.
Related coverage
You Own the Video Your Smart Glasses Shoot, Not Meta — when the employer, not the wearer, is the recorder and so the copyright owner
Sources and verification
- ICO, Employment practices and data protection: monitoring workers — data protection and monitoring workers: lists wearable cameras and body-worn devices as monitoring technologies; lawful basis, least-intrusive duty, DPIA for high-risk, transparency and covert-monitoring limits, and the "under review" notice following the DUA Act.
- ICO, Monitoring workers — specific considerations for different methods of monitoring: the "must" list for video and audio monitoring, audio switched off by default, informing customers and visitors, redaction on a subject access request, the dashcam parallel, and facial recognition as biometric special-category data.
- ICO, Monitoring workers — using biometric data for time and access control and monitoring: biometric data as special category when used to identify a worker, the DPIA requirement, and the need for a genuine alternative.
- UK GDPR, Article 35 (Data protection impact assessment), legislation.gov.uk: DPIA required before high-risk processing; "systematic monitoring of a publicly accessible area on a large scale"; the necessity-and-proportionality requirement; consulting the Commissioner where high risk cannot be reduced.
- UK GDPR, Article 6 (Lawfulness of processing), legislation.gov.uk: the six lawful bases and the "at least one" requirement, and the new recognised-legitimate-interest basis at 6(1)(ea) inserted by the DUA Act.
- UK GDPR, Article 9 (Special categories of personal data), legislation.gov.uk: "biometric data for the purpose of uniquely identifying a natural person" as prohibited special-category data absent an Article 9(2) condition.
- Data Protection Commission (Ireland), Guidance on Body Worn Cameras or Action Cameras: a body-worn camera "can effectively turn the wearer into a mobile surveillance system that is likely to capture the personal data of passers-by," with heightened concern where microphones or facial recognition are added.
- ICO, Data (Use and Access) Act 2025: Royal Assent on 19 June 2025 and the data-protection provisions now in force under staged commencement.
- Retail Insight Network, Tesco offers body-worn cameras to staff amid rising assaults: the £44m security investment over four years, the reported one-third annual rise in assaults per Ken Murphy, and Usdaw general secretary Paddy Lillis on deterrence and the public being "fully aware" the cameras are in use.