7 min read

Adonis’s Smart Glasses and GDPR: What the Law Actually Says About Ray-Ban Meta

A balanced and fact-checked look at the case that brought smart glasses into the Greek Parliament — and why the issue affects every business, not just government ministers.

Adonis’s Smart Glasses and GDPR: What the Law Actually Says About Ray-Ban Meta

The Timeline: What Happened with the Smart Glasses Controversy

During visits to hospitals on the islands of Leros and Lemnos, Health Minister Adonis Georgiadis was photographed wearing glasses fitted with a built-in camera, microphone, and AI assistant. Photos quickly circulated on social media, prompting an immediate question: were they recording video and audio?

The matter was raised in Parliament by PASOK MP Panagiotis Doudonis, who voiced concerns regarding data privacy and GDPR compliance. The Minister responded that the device was a pair of second-generation Ray-Ban Meta smart glasses, which he had purchased himself and used solely as a Bluetooth headset without recording anyone. However, he added that he intended to wear them during future public appearances to document any potential illegal acts or altercations.

Although no recorded footage was ever published, the debate opened up a broader conversation: What is the legal framework governing smart glasses in Europe, and what does it mean for privacy?

Artificial Intelligence and Smart Glasses: What Are Ray-Ban Metas?

To understand the legal implications, it helps to distinguish between the different types of technology available. Smart glasses generally fall into three categories:

  1. Camera and AI Glasses (Without a Display): This is the category the Ray-Ban Meta belongs to. They feature a 12 MP camera (1080p video), a multi-microphone array, open-ear speakers, Wi-Fi/Bluetooth connectivity, and a voice-activated AI assistant. The wearer does not see a digital display through the lenses.
  2. Heads-Up Display Glasses: These project basic information (such as notifications or turn-by-turn navigation) directly into the wearer’s field of view.
  3. Augmented Reality (AR) Glasses: These overlay digital objects onto the physical world, requiring real-time 3D spatial mapping of the surroundings.

What Matters to GDPR?

Under European and UK data protection law, the distinction between these categories is largely irrelevant. What matters to a bystander standing opposite the wearer is the presence of a camera and microphone at eye level. Data protection legislation does not focus on whether the glasses have an internal display, but on whether personal data is being collected and how.

The Four Arguments — The Legal Reality

The Minister’s defence rested on four main arguments. Here is how the law applies to each:

1. "The LED indicates recording, so the device is GDPR-compliant"

The Reality: The GDPR (and the UK GDPR) does not certify hardware. There is no such thing as a "GDPR-compliant camera". The regulation governs data processing activities and places obligations on the person or organisation collecting the data (the Data Controller).

While the recording LED is a privacy-by-design feature (Article 25 GDPR), it does not automatically make recording lawful. Data Protection Authorities across Europe have noted that a small LED light on a pair of glasses does not provide the same clear notice as someone visibly holding up a smartphone to record.

2. "I was in a public space with other media cameras present"

The Reality: Data protection law evaluates every processing activity independently. The fact that a news crew is legally recording a public visit does not automatically give anyone else the right to record for their own separate purposes. Furthermore, journalists operate under specific statutory exemptions (Article 85 GDPR) designed to balance privacy with freedom of expression — exemptions that do not extend to individual recordings made for personal or security reasons.

3. "I am recording for security and to gather evidence of offences"

The Reality: To rely on "legitimate interests" (Article 6(1)(f) GDPR), the processing must be strictly necessary, and the controller's interests must not override the rights and freedoms of the individuals being recorded. Continuous, indiscriminate recording in public places "just in case" something happens rarely meets the strict necessity test required by data protection regulators.

4. "The recording took place in a hospital setting"

The Reality: Recording within a medical facility significantly increases legal risks:

  • Special Category Health Data (Article 9 GDPR): Capturing images of patients, visitors, or individuals receiving treatment constitutes the processing of health data, which is strictly prohibited without explicit consent or a specific statutory legal basis.
  • Employee Privacy: Recording staff in their workplace is subject to tight restrictions, as the inherent power imbalance between employers/executives and employees means consent cannot usually be considered freely given.

What Do Smart Glasses Mean for Your Business?

This debate extends far beyond politics. Owners of hotels, restaurants, retail shops, and service businesses are increasingly encountering the use of wearable tech by both employees and customers.

If a staff member wears smart glasses at a reception desk, or a customer records inside your venue, your business bears responsibility for protecting personal data on its premises.

4 Compliance Steps for Businesses:

  1. Establish a Wearables Policy: Set clear guidelines regarding the use of smart glasses, bodycams, and smartwatches equipped with cameras by staff during working hours.
  2. Protect Private Areas: Explicitly prohibit recording devices in sensitive spaces such as changing rooms, restrooms, or private guest rooms.
  3. Install Proper Signage: If you operate CCTV or video monitoring, your signage must clearly state the purpose of recording, the identity of the Data Controller, and individual rights — a basic "CCTV in Operation" sticker is insufficient.
  4. Audit Your Digital Presence: Data compliance extends to your online platforms. Ensure your website’s cookie banner blocks tracking scripts prior to user consent and that contact forms include proper privacy disclosures.

Conclusion

The controversy surrounding smart glasses highlights a modern reality: technology often evolves faster than social norms. While owning wearable tech is entirely legal, using it in public or commercial spaces carries responsibilities that protect everyone's right to privacy.

This article is provided for informational purposes only and does not constitute formal legal advice. For specific compliance enquiries, consult a certified Data Protection Officer (DPO) or qualified legal professional.

🛡️ Need a Website That Is Fully GDPR-Compliant by Design?

At agénor.BI, we build bespoke websites, booking engines, and data analytics systems for hotels, hospitality venues, and SMEs — with privacy and GDPR compliance built in from day one (Privacy by Design).

  • ✅ Fully compliant cookie consent banners with no unlawful pre-loading of tracking scripts.
  • ✅ Secure data handling across all booking and contact forms.
  • ✅ Privacy-focused analytics that deliver valuable insights without compromising user data.

👉 Contact us today for a privacy audit of your website.