Smart glasses are increasingly evolving from a technological novelty into a serious professional tool. Cameras, microphones, displays and artificial intelligence can now be integrated into eyewear that may look increasingly similar to ordinary glasses.
For security companies, this technology opens up interesting possibilities. Security personnel could receive operational information directly in their field of vision, check admission tickets, communicate with a control centre or be alerted to individuals who are being sought or are not authorised to enter an event.
However, what is technically possible is not automatically legally permissible. In Germany, the Telecommunications-Digital Services Data Protection Act (TDDDG), the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) impose important restrictions. AI-based systems may additionally fall within the scope of the European AI Act.
From Google Glass to AI Glasses
Google Glass demonstrated more than a decade ago the social and privacy questions raised by placing a camera directly in front of a user’s eyes. Since then, cameras and electronic components have become considerably smaller and more powerful.
Modern smart glasses can, for example:
- take photographs and record video,
- transmit images to a control centre,
- scan QR codes and tickets,
- recognise objects using AI,
- display information directly in the user’s field of vision,
- communicate with other security personnel,
- analyse faces, and
- potentially identify individuals automatically.
The last two functions in particular fundamentally change the legal assessment.
There is a significant difference between glasses that display a site map to a security officer and a system that continuously analyses the faces of everyone attending an event.
Section 8 TDDDG: When Do Camera Glasses Become a Problem?
A particular feature of German law can be found in Section 8 TDDDG – Misuse of Telecommunications Equipment.
Under certain conditions, the provision prohibits telecommunications equipment that disguises itself as another object or is concealed within objects of everyday use and, because of these circumstances or because of its functionality, is particularly suitable and intended for secretly intercepting non-publicly spoken words or recording images of other persons.
Section 8(2) TDDDG is particularly relevant to smart glasses. According to this provision, equipment is considered to be intended for secret interception or recording in particular where its interception or recording function is not clearly recognisable to the person concerned during the intended use of the object.
For modern camera glasses, the relevant question is therefore not simply:
Is the camera visible somewhere on the device?
The more important question may be:
Can the person concerned clearly recognise that a recording function is present or active?
This can become particularly problematic with glasses that externally resemble ordinary prescription glasses or sunglasses.
Section 8 TDDDG should therefore be considered at the hardware selection stage. Under the conditions laid down in the provision, it does not merely concern the misuse of a recording device. It also covers activities including possession, manufacture, making such equipment available on the market and importing it.
A private security company does not benefit from a general exemption simply because the technology is being used for security purposes.
A Visible Camera Is the Better Design
If smart glasses are to be used professionally by security personnel, they should therefore deliberately not be designed as hidden cameras.
Appropriate features could include:
- a clearly recognisable camera,
- an externally visible recording or transmission indicator,
- a status indicator protected against manipulation,
- clear identification of the glasses as electronic security equipment, and
- transparent information for visitors to the event.
However, the mere existence of a tiny status LED is not automatically a universal legal solution. The relevant question is not only whether the indicator technically exists, but also whether the person concerned can actually and clearly recognise the relevant function.
The final assessment under Section 8 TDDDG therefore depends on the particular device and how it operates.
Smart Glasses as a Tool for Security Personnel
From a data protection perspective, a considerably less problematic architecture would use the glasses primarily as a digital assistance system.
For example, a security officer could see the following information directly in their field of vision:
Access control
Ticket → QR code → Verification → ACCESS GRANTED
Operational information
Control centre → Alert → Location → Information displayed
Search for a person
Control centre → Photograph of person → Display in glasses → Human identification
The final decision remains with the security officer.
Such an architecture is fundamentally different from a system that automatically processes the biometric data of everyone attending an event.
Video Surveillance Remains Video Surveillance
As soon as the camera in the glasses captures people and the images are processed, transmitted or stored, data protection law must also be considered.
For video surveillance of publicly accessible areas in Germany, Section 4 BDSG is particularly relevant. Under certain conditions, video surveillance may be permissible, for example, to exercise the right to determine who may enter or remain on premises, or to protect legitimate interests pursued for specifically defined purposes.
An event organiser undoubtedly has a legitimate interest in preventing unauthorised persons from entering an event and in maintaining security.
However, this does not mean that every technically possible surveillance measure is necessary or proportionate.
Smart glasses also have a particular characteristic: their cameras are mobile. Unlike a permanently installed camera, they move with the security officer and generally follow the direction in which that person is looking.
As a result, people and areas may be captured that would never have been covered by conventional stationary video surveillance.
Avoid Continuous Recording Wherever Possible
A privacy-friendly implementation should therefore follow the principle of data minimisation.
A sensible technical architecture could look like this:
Camera
↓
Local processing
↓
QR code / object / event detected
↓
Result displayed
↓
Camera data discarded
Rather than:
Camera
↓
Continuous video stream
↓
Cloud
↓
Permanent storage
↓
AI analysis
↓
Profiling
Not every camera image needs to be stored simply because it is technically available.
In particular, continuously recording an entire eight- or twelve-hour shift would be considerably more difficult to justify than narrowly defined and purpose-specific processing.
The Critical Boundary: Automatic Facial Recognition
The use of smart glasses becomes particularly sensitive when the system is intended not only to record people, but to identify them automatically.
Technically, such a system could operate as follows:
Camera
↓
Detect face
↓
Extract biometric characteristics
↓
Biometric template
↓
Compare with watchlist
↓
MATCH
↓
Alert security officer
For example, an event organiser might maintain a list of individuals who are subject to a valid ban from the premises.
At first glance, it may seem logical to allow the smart glasses worn by security personnel to search automatically for these individuals.
From a data protection perspective, however, this creates a considerably greater intrusion.
The System Does Not Analyse Only the Person Being Sought
To identify one particular individual in a crowd, a facial recognition system must first analyse numerous other people.
At an event with 2,000 visitors, the processing cannot simply be described as:
“We process the data of the one person who is banned from the premises.”
Instead, the system may capture and analyse the faces of large numbers of visitors in order to determine that they are not the person being sought.
It is precisely this broad impact on uninvolved individuals that makes biometric remote identification particularly problematic.
Data protection authorities also point out that facial recognition systems make probability-based assessments. A supposed match does not necessarily mean that the correct individual has been identified.
For a security service, this also has an important practical consequence: an AI-generated match should never automatically be treated as definitive identification.
Biometric Data Receive Special Protection
Where facial characteristics are processed using specific technical means for the purpose of uniquely identifying a natural person, they constitute biometric data within the meaning of the GDPR.
When biometric data are processed for the purpose of uniquely identifying a person, they fall within the special categories of personal data governed by Article 9 GDPR.
Processing such data is generally prohibited unless one of the exceptions expressly provided for in Article 9(2) applies.
A general argument such as
“We have a legitimate interest in ensuring the security of the event”
is therefore not automatically sufficient to justify biometric identification.
Automatic facial recognition is legally of an entirely different magnitude from conventional video surveillance.
A Warning Sign Alone Is Not Enough
Transparency is an important element of lawful video surveillance. Visitors must be informed about the processing in accordance with the applicable legal requirements.
For example, a notice may indicate that video surveillance is taking place in particular areas and identify the controller responsible for the processing.
However, such a notice does not create a legal basis.
The same applies to facial recognition.
A sign stating
“Automated facial recognition is used at this event.”
does not make an otherwise unlawful biometric processing operation lawful.
Transparency and legal permissibility are two separate requirements.
The EU AI Act Must Also Be Considered
In addition to the GDPR and BDSG, AI-based biometric identification must now also be assessed under the European Artificial Intelligence Act (AI Act).
The AI Act contains extensive provisions relating to biometric systems and biometric remote identification. Its particularly strict provisions concerning real-time remote biometric identification in publicly accessible spaces are especially relevant to use for law enforcement purposes.
However, a private security company cannot draw the opposite conclusion:
“We are not the police, so we are allowed to use facial recognition.”
The GDPR, BDSG and the other applicable requirements of the AI Act continue to apply independently.
It is also notable that German data protection authorities impose very high requirements regarding a sufficiently specific legal basis even where automated facial recognition is used by public security authorities.
Private security companies should therefore approach such systems with particular caution.
Person Subject to an Entry Ban: What Could a More Privacy-Friendly Solution Look Like?
Suppose an event organiser informs the security service that a particular individual is not permitted to enter the venue because that person is subject to a valid entry ban.
Instead of biometrically analysing everyone attending the event, the control centre could provide security personnel with an existing photograph of that person.
Control centre
↓
Photo + relevant operational information
↓
Smart glasses
↓
Displayed to security officer
↓
Officer compares the person manually
↓
Further identity verification if necessary
The glasses assist the human operator rather than replacing human identification with continuous biometric surveillance.
For many practical applications, this approach could already provide substantial operational benefits.
Useful Functions for Security Companies
Smart glasses could perform numerous tasks for private security services without requiring facial recognition.
Access Control
QR codes, tickets or other forms of authorisation could be checked directly using the glasses.
The security officer could see, for example:
TICKET VALID
Area: VIP
Access: North
Operational Control
The control centre could send information directly to security personnel:
ALERT
Area B – West Entrance
Assistance required
This would reduce the need for security personnel to handle a smartphone or radio whenever information is received.
Navigation
At large events, industrial sites or extensive premises, maps and deployment locations could be displayed directly in the user’s field of vision.
Documentation
In the event of a specific incident, time-limited documentation could be technically possible where an appropriate legal basis exists and the data protection concept provides for such processing.
Object Recognition
Artificial intelligence does not necessarily have to identify people.
Possible applications could include recognising particular objects, open doors, restricted areas or other security-relevant situations.
However, each individual AI function must be assessed to determine which data it actually processes.
Audio Recording Is Particularly Sensitive
The microphone built into smart glasses must not be overlooked.
Video recording and audio recording are not legally equivalent.
In particular, Section 201 of the German Criminal Code (StGB) protects non-publicly spoken words. Secret audio recordings may have criminal consequences.
A security company should therefore follow a basic principle:
No continuous audio recording merely because the hardware includes a microphone.
A microphone used for radio or voice communication should be technically and organisationally separated from any recording of conversations taking place in the surrounding environment.
Data Protection Should Be Built Into the Technology
A professional system should be developed according to the principles of privacy by design and privacy by default.
This includes, for example:
- processing data locally wherever possible,
- avoiding unnecessary storage,
- defining short retention and deletion periods,
- encrypting communications,
- implementing clearly defined user roles and permissions,
- logging administrative access,
- preventing unrestricted export of video archives,
- separating different processing purposes,
- disabling functions unless they are required,
- avoiding continuous audio recording,
- clearly indicating active camera functions, and
- maintaining human oversight of security-relevant decisions.
Purpose limitation is particularly important.
A camera originally introduced solely for ticket verification should not subsequently be used for employee monitoring, behavioural analysis or facial recognition without a new legal and data protection assessment.
Data Protection Impact Assessment
Particularly high-risk processing operations must also be assessed under Article 35 GDPR.
German data protection authorities expressly point out in their guidance on video surveillance that processing biometric data using facial recognition software – for example, for access control or for observing and monitoring individuals – may require a Data Protection Impact Assessment before the processing begins.
A Data Protection Impact Assessment (DPIA) should not be treated merely as an administrative formality.
It should examine, in particular:
- What data are processed?
- Which individuals are affected?
- What specific purpose is being pursued?
- Why is the processing necessary?
- Are less intrusive alternatives available?
- What risks arise for the individuals concerned?
- Which technical and organisational measures reduce those risks?
The question of less intrusive alternatives is particularly important for smart glasses.
If a QR code can provide the same access-control decision, for example, there would need to be a convincing justification for additionally introducing biometric facial recognition.
Three Levels of Practical Deployment
For private security companies, the technology can broadly be divided into three levels of risk.
Level 1 – Assistance System
Suitable as a starting point
Smart glasses
├── Operational information
├── Navigation
├── QR / ticket verification
├── Alerts
├── Communication
└── Display of watchlist / entry-ban photographs
No automated biometric identification.
Level 2 – Mobile Video Surveillance
Only with a specific data protection and deployment concept
Smart glasses
├── Camera
├── Live transmission
└── Event-related recording where necessary
In particular, the legal basis, purpose limitation, transparency, necessity, retention periods, access controls and deletion procedures must be assessed.
Level 3 – Biometric Remote Identification
Legally particularly sensitive
Smart glasses
↓
Continuous facial capture
↓
Biometric analysis
↓
Database comparison
↓
Automated identification
A private security company should not treat such a system as a simple extension of ordinary video surveillance or deploy it without specialised legal assessment.
Technology Should Assist Security Personnel – Not Replace Them
Smart glasses could become an important professional tool for private security services.
Their greatest practical benefit does not necessarily lie in continuous facial recognition.
Glasses that provide security personnel with the right information at the right moment could already offer substantial security benefits:
Security officer
↕
Smart glasses
↕
Encrypted communication
↕
Control centre
↕
Operational and access-control system
The security officer remains responsible for assessing the situation and making decisions.
This is not only more favourable from a data protection perspective; it can also make operational sense. An algorithm does not automatically understand the complete context of a security situation.
Conclusion
Smart glasses could significantly change the way private security services operate. Information, access control, navigation, communication and certain AI assistance functions can be integrated directly into a security officer’s field of vision.
However, the more the technology moves from assistance towards surveillance, the greater the legal requirements become.
Facial recognition demonstrates this particularly clearly. There is a major legal difference between displaying a photograph of a person being sought and continuously comparing the biometric characteristics of everyone attending an event against a database.
A responsible deployment should therefore follow a simple principle:
As much technological assistance as is useful – but only as much personal surveillance as is actually necessary and legally permissible.
A future-proof smart glasses system for private security services should therefore incorporate data protection, IT security and transparency into its technical architecture from the outset.
The decisive question is not simply:
What can modern camera glasses do?
It is:
How can we use this technology to improve security without unnecessarily sacrificing people’s privacy?
Disclaimer: This article provides general information on technical and legal issues and does not constitute legal advice.
Further Reading
- German Federal Ministry of Justice / Gesetze im Internet: Section 8 TDDDG – Misuse of Telecommunications Equipment
- German Federal Ministry of Justice / Gesetze im Internet: Section 4 BDSG – Video Surveillance of Publicly Accessible Areas
- General Data Protection Regulation: in particular Articles 4, 9 and 35 GDPR
- Regulation (EU) 2024/1689 – Artificial Intelligence Act
- German Federal Commissioner for Data Protection and Freedom of Information (BfDI): Information on video surveillance and biometrics
- German Data Protection Conference (DSK): Guidance on video surveillance and publications concerning biometric facial recognition
This article was created and refined in dialogue with AI. The subject matter and content originate from human authorship.