Can You Film Strangers in Europe With Smart Glasses?

A flat illustration split into a warm home and a cool street. On the left, inside a cream-and-terracotta room with an orange
AI-generated editorial illustration. Not a documentary image.

The GDPR exemption everyone leans on was written for a camera that stays home

A pair of Ray-Ban Meta glasses has been on sale across the European Union for the better part of two years: Meta switched its assistant on in France, Italy, Ireland and Spain in November 2024, then Germany, Austria, Belgium, Denmark, Sweden and Finland the following April. So a shopper in Lyon or Cork can buy, today, a camera that lives on their face in the jurisdiction with the strictest data-protection law on earth. The obvious question is whether that law lets them walk down a busy street with it running. The obvious answer, the one every consumer guide gives, is that private use is exempt: GDPR does not reach what an ordinary person does for their own enjoyment.

That answer is not wrong. It is just built on a foundation the European Court of Justice already inspected, and found does not hold where these glasses actually get worn.

The exemption people are reaching for is real and it is short. Article 2(2)(c) of the GDPR says the Regulation "does not apply to the processing of personal data ... by a natural person in the course of a purely personal or household activity." Recital 18, which explains it, adds the crucial qualifier: the activity must have "no connection to a professional or commercial activity," and it names the kind of thing it means — "correspondence and the holding of addresses, or social networking." Keep a holiday clip on your phone, show it to friends, and you are exactly the person this clause was written to leave alone.

The word doing all the work is 'purely'

The guides skip what comes next. The exemption is not a status you have; it is a description of an activity, and the Court reads it narrowly. In 2014 it decided a case called Ryneš, and the facts are worth holding onto because everything downstream turns on them. A man in the Czech Republic, after repeated attacks on his home, fixed a camera under the eaves that recorded the entrance to his house, and, unavoidably, a slice of the public footpath and the house across the street. He argued this was a purely personal or household activity and so outside data-protection law entirely.

The Court said no. Its ruling is precise: a home camera "which also monitors a public space" does "not amount to the processing of data in the course of a purely personal or household activity." The reasoning, quoted later by Europe's own regulators, is the sentence that matters here. Once a recording covers "even partially, a public space and is accordingly directed outwards from the private setting of the person processing the data," it "cannot be regarded as an activity which is a purely 'personal or household' activity."

Ryneš is not about smart glasses. It is about a fixed box screwed to a wall, and it was decided under the old Data Protection Directive, the law GDPR replaced. No court has taken it and applied it to a face-worn camera. But the European Data Protection Board, the body that coordinates every national privacy regulator in the bloc, did the work of carrying it forward. Its 2019 guidelines on video devices state the principle flatly: the household exemption "must be narrowly construed," and it reproduces the Ryneš test as the current rule for anyone pointing a lens at the public.

Read that test back with the product in mind. A camera "directed outwards from the private setting" is not an edge case for smart glasses. It is the entire feature. Nobody buys them to film the inside of their own home; the whole proposition is that they capture the world in front of you, on the street, in the shop, across the café table. The device is the thing the exemption bends away from, worn on purpose.

The two examples that draw the line

The EDPB does not leave this abstract. Its guidelines carry small worked examples, and set side by side they show precisely where a wearer crosses over.

On the inside of the line: "A tourist is recording videos both through his mobile phone and through a camcorder to document his holidays. He shows the footage to friends and family but does not make it accessible for an indefinite number of people. This would fall under the household exemption." A second example puts a mountain biker recording her own descent on an action cam in a remote area, for her own entertainment — also inside, "even if to some extent personal data is processed."

On the outside: a homeowner monitoring his own garden stays exempt only "provided that the video surveillance does not extend even partially to a public space or neighbouring property." The moment it does, he is out.

Two things decide it, then, and neither is the one the guides fixate on. Not whether you recorded, but where it pointed and who ends up able to see it. The tourist is safe because the camcorder documents his holiday and the footage stops with people he knows. Change one fact — he uploads the clip publicly, and a separate CJEU ruling the EDPB cites, Lindqvist, closes the door: the exemption covers "private or family life," not processing that makes data "accessible to an indefinite number of people." Posting to an open account is the far side of that sentence.

The word nobody puts on the label: controller

If the exemption falls away, something has to replace it, and this is the part that will surprise a wearer who thinks of themselves as a consumer, not an institution. GDPR does not have a light setting for private individuals who step outside the household exemption. It has one status for anyone who "determines the purposes and means of the processing of personal data," and Article 4(7) gives it a name: controller. The bank is a controller. The hospital is a controller. And a person who walks through a crowd capturing identifiable faces, "any information relating to an identified or identifiable natural person," in the Regulation's own definition of personal data, for a purpose that is no longer purely personal, is standing, at least on the face of the text, in the same box.

Being a controller is not a crime; it is a set of duties. It means there has to be a lawful basis for the processing, and it means the people being recorded are owed transparency about it. That is the quiet weight of the Ryneš line. The reader who assumed "it's just personal use" was not making up the exemption: they were making up the certainty that they still qualify for it while doing the one thing the device is built to do.

We will put the claim plainly, because hedging it would waste the whole piece: the household exemption is not a shield the wearer carries, it is a description of an activity the wearer keeps leaving. The EDPB is careful to say the assessment is an overall one: it weighs whether there is a personal relationship with the people recorded, the scale and frequency of the recording, and the harm it risks, so a single stray face in a single clip is not the point. A habit of walking public space with a running camera is.

Plenty of readers arrive at this question through the American frame, because the American writing on it is louder. In the United States the whole argument runs on wiretap statutes and a patchwork of one-party and two-party consent states; the number of "all-party" states is the thing everyone tries to memorise. It is tempting to ask which kind of country Germany or Spain is.

It is the wrong map. The EU has no register of consent states and no statute that turns a bystander's lack of permission, by itself, into the offence. Britain, just outside the bloc now, has no such rule either, and its limits come from harassment and image offences instead. The European mechanism is not consent at the moment of pressing record; it is the data-protection question of whether you are processing other people's personal data outside the household exemption, and if so, on what basis. That is a genuinely different question, and importing the consent count answers none of it. It can even mislead in the reassuring direction — "nobody's consent is legally required, so it's fine" skips straight past the controller duties that attach the instant the exemption lapses.

Enforcement still waits on the same broken assumption

There is a catch under all of this, and it is the same one that haunts every jurisdiction this desk has looked at. The entire structure — the exemption, the Ryneš boundary, the controller's transparency duty: assumes the recorded person has some way of knowing there is a recording to object to. GDPR's answer to "how does the public know" has always leaned on visibility: the CCTV sign on the wall, the camera you can see.

Meta's answer is a light. The company describes it in its own words: "There's a light on the front of every pair of our AI glasses that we call a capture LED ... this white light blinks to let people know you're capturing content" — briefly for a photo, continuously through a video. It is a real disclosure, and it is a small one, aimed at a passer-by who has to notice a blinking LED on a stranger's frames in daylight and know what it means. Every published method for telling whether a pair of glasses is actually recording comes with its own footnote admitting how easily it fails. A data-protection regime built on the recorded person being able to know is pointed, here, at the one device engineered so that they may not.

So Europe arrives at a settlement that is stricter than the American one on paper and just as hard to enforce in the street. The law does not need a consent count, because it already has a deeper principle: point a camera outward at the public and you are no longer doing a purely private thing, and the duties of someone who processes other people's data land on you. The device makes crossing that line effortless and invisible in the same motion. Whether a regulator ever reaches an individual wearer over it is a different question, and an honest one to leave open, but the boundary is not vague, and it is not new. The Court drew it over a camera bolted to a house eleven years before these glasses reached a European shelf.

Is It Legal to Record People With Smart Glasses in the UK? — the British answer, which drops the EU's data-protection frame and turns on harassment and image offences instead

Is It Legal to Record Strangers With Smart Glasses? (United States) — the consent-state map Europe conspicuously does not use

Are Kmart's $89 Camera Glasses Legal in Australia? — the same question in a third legal system, where recording law is set state by state

Can You Actually Tell When Smart Glasses Are Recording? — the missing fact every one of these regimes, GDPR included, quietly depends on

Is It Legal to Record Someone With Smart Glasses in Ireland? — Ireland is the member-state overlay to the bloc-wide GDPR household-exemption answer, with a criminal layer the EU piece does not carry

Smart Glasses Can Livestream You to an Audience in Real Time — going live strains the personal/household shelter this piece maps even harder than a saved recording does

Filming Children in Public With Smart Glasses — the Ryneš household-exemption line that decides when filming a child in public becomes regulated processing

Can I Make Someone Delete a Video of Me Filmed on Smart Glasses? — the same household exemption, read from the filmed person's side — it removes the erasure right against a private wearer

Sources and verification

This piece reports what the GDPR text, a CJEU judgment and the EDPB's guidance say, and what Meta publishes about its own device. It is not legal advice, and no court has ruled on recording strangers in public with smart glasses under EU data-protection law.