What is Australia investigating about smart glasses?
Australia's privacy regulator has opened a formal investigation into the Chinese company behind the HeyCyan app used by several low-cost smart glasses. The inquiry follows an unanswered information request; it is not a finding that a breach or Privacy Act violation occurred.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
At a glance
- 1The OAIC has opened a formal investigation into Shenzhen Qingcheng Future Technology, whose HeyCyan app supports multiple low-cost smart-glasses products sold through Australian retail channels.
- 2The trigger was the company's failure to answer preliminary inquiries about what the glasses record, who can access the information and where it is stored; that silence is not evidence that a breach occurred.
- 3The regulator has not found facial-recognition capability in Australian-market smart glasses and has not concluded that Meta, Google, Kmart or BDI Technology breached privacy law.
Research topic
How Australian privacy law applies to personal information collected through software supporting consumer smart glasses

The regulator is investigating the software provider, not announcing a proven breach
Australia's Office of the Australian Information Commissioner has begun a commissioner-initiated investigation into Shenzhen Qingcheng Future Technology, the China-based company behind the HeyCyan phone application. The app supplies software used with several lower-cost smart-glasses products, including Kmart's Anko-branded glasses and products offered through Big W Marketplace, Amazon and other retailers. The regulator says the app is required for functions including calls, music and a voice assistant, with information gathered through the glasses collected by the app for processing.
The announcement does not say that the company suffered a data breach, unlawfully recorded anyone or violated the Privacy Act. It establishes an inquiry into practices, procedures and systems. That distinction matters for users, bystanders and retailers: a formal investigation gives the regulator compulsory information-gathering powers, but evidence still has to be collected and tested before any determination, remedy or penalty application could follow.[1][2]
Five organisations were asked how recording, access and storage work
The OAIC says it had monitored smart-glasses deployment since early 2026. After correspondence from Australia's Attorney-General in August, it issued preliminary inquiries from 12 August to entities involved in hardware, retail and software. The regulator's account identifies Kmart and BDI Technology as retailers, Shenzhen Qingcheng as a software provider, Meta as a manufacturer and software provider, and Google as a company planning glasses and underlying software. The questions covered what the devices record, who has access to the resulting information and where it is stored.
Shenzhen Qingcheng did not respond, according to the regulator. Privacy Commissioner Carly Kind said that left her without assurance that Australians' personal data was being protected as the Privacy Act requires. The investigation was opened so the OAIC could use its full powers, including compulsory notices. That rationale is procedural: non-response and third-party concerns justify closer scrutiny, but they do not establish what data was collected, whether it left Australia, whether security failed or whether any individual suffered harm.[1][2]
The legal responsibility may sit with the entity holding the information
The Commissioner's accompanying analysis explains why a product's supply chain complicates accountability. Selling or manufacturing a recording-capable device does not automatically mean an organisation holds the personal information captured through it. The entity running the software or storage service may be the party collecting and holding the information, and therefore the party subject to relevant Australian Privacy Principles. Retailers may still face reputational expectations and should conduct due diligence, but the regulator has not treated every company in the chain as legally equivalent.
The OAIC wrote separately to retailers of devices using HeyCyan and urged them to consider whether continued sale was appropriate. It also contacted the Australian Retailers Council about privacy risks in connected and surveillance products. Those steps may alter what consumers see on shelves before the investigation ends. They are not product bans or recall orders. Retailers, marketplaces and consumers should distinguish a regulator's risk warning from a concluded enforcement action.[2]
Not every recording is automatically personal or sensitive information
Australian law currently turns partly on whether information is about a reasonably identifiable person. Images or voices may meet that test when names, uniforms, location data or other context allow someone to be singled out. The Commissioner's analysis says the answer can depend on the capabilities and other data held by the entity receiving the recording. That means the same-looking clip might have different privacy implications depending on whether it is processed only on a device, linked to an account or combined with identification data.
Consent is not mandatory for every collection of ordinary personal information under the current Act; collection generally must be reasonably necessary for the entity's functions or activities. Sensitive information faces a higher bar. Facial recognition could involve biometric information and normally require consent, but the Commissioner explicitly says the preliminary work had not identified facial-recognition capability in smart glasses then available in Australia. It would therefore be misleading to present this investigation as proof of covert facial recognition.[2]
For people nearby, visibility and security are the immediate practical issues
Smart glasses change the social conditions of recording because a camera, microphone or assistant can be worn continuously and may be less noticeable than a phone held up for a photograph. Bystanders may not know that their image or voice has been captured, which makes it difficult to exercise access, correction or complaint rights. The OAIC notes that community concern has already prompted restrictions in some local public facilities and a petition, but it also recognises that phones, action cameras, dashcams and doorbells create overlapping problems.
Security becomes more important when a software provider can receive large volumes of information that people did not realise was being collected. A weak account system, unclear retention policy or insecure transfer could expose recordings and associated metadata. The current sources do not demonstrate that any of those failures occurred in HeyCyan. The public-interest case for investigation is that users and bystanders cannot independently verify the app's handling practices while the provider has not answered the regulator's questions.[1][2]
What would change the assessment
The assessment should change when the investigation produces verified facts: a response from the company, compulsory-notice records, technical findings about data flows, locations and retention, or a determination identifying compliant or non-compliant conduct. Independent testing should document which models use HeyCyan, what permissions are requested, whether processing is local or remote, what is transmitted when the assistant is used, and whether people can delete or retrieve their data. Testing must avoid inventing evidence of a successful breach.
A final regulatory decision could require specified corrective steps or redress, and serious or repeated interference with privacy could lead the Commissioner to seek civil penalties in court. Conversely, evidence of data minimisation, transparent notices, secure storage and effective user controls could reduce concern. Until that record exists, the accurate conclusion is limited but consequential: Australia's privacy regulator has escalated unanswered questions about a widely distributed smart-glasses software layer into a formal investigation.[1][2]
What this means for people
- Owners need clear information about what leaves the glasses or phone when calls, music and voice-assistant functions are used.
- Bystanders may be recorded without recognising the device as a camera or microphone, limiting their practical control over personal information.
- Retail workers and marketplaces may be asked to assess software and privacy risk, not only the safety of the physical product.
Global context
The investigated company is based in China, while the devices and marketplaces named by the OAIC operate in Australia and often across borders. The case illustrates how inexpensive connected hardware can depend on a less-visible software provider in another jurisdiction. Comparable regulators will face the same allocation problem: identifying who actually collects and controls recordings, and ensuring that overseas providers can be reached when local residents' data is involved.
What the evidence does not yet show
- The OAIC has opened an investigation but has not made a determination, established a breach or alleged that any identified person suffered harm.
- The regulator says Shenzhen Qingcheng did not answer preliminary inquiries, so key facts about data flows, access, storage, retention and security remain unverified publicly.
- The OAIC has not identified facial-recognition capability in smart glasses then available on the Australian market.
- Kmart, BDI Technology, Meta and Google were part of preliminary inquiries, but the OAIC has not opened the same formal investigation into those entities or concluded that they were non-compliant.
- Retail listings can change; the regulator's named sales channels establish distribution observed during its inquiries, not current stock at every seller.
What to watch next
- Whether Shenzhen Qingcheng responds to compulsory notices and discloses its data architecture and retention practices.
- Any verified technical assessment of the HeyCyan app's permissions, transfers, storage locations and deletion controls.
- Retailer decisions on continuing sales, withdrawals, warnings or software changes.
- A published OAIC determination, enforceable undertaking, court proceeding or closure without a breach finding.
Living evidence record
Impact record IAI-1TKKZXE
Evidence stage
Observed
Confidence
Supported
Reporting basis
Source analysis
Independent or research support
Not yet
Record status
Monitoring
Last checked
7 October 2026
Source trail
2 direct sources across 2 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Related-source reporting disclosure
This record analyses 2 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.
Evidence trail
Sources used for this report
Links checked 7 October 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Government & Policy
Will EU text watermarks prove AI authorship?
No. OpenAI's new textGrain signal can indicate that eligible text passed through a supported system, but its own tests show detection falls sharply after editing and cannot establish who wrote, owns or verified a passage.
8 min · 3 sources
Government & Policy
What will the new US AI task force actually decide?
President Donald Trump has publicly announced a federal AI task force led by intelligence chief Jay Clayton. The announcement confirms its four-person leadership and stakeholder remit, but the charter, evidence process, enforcement power and final policy test remain unpublished.
9 min · 6 sources
Government & Policy
Who sets the rules for genomic AI?
A peer-reviewed review mapped 90 publicly documented national genomics initiatives across 70 countries and territories. Thirty-two reported current or planned AI use, but the researchers found public AI-specific governance in only three programmes.
8 min · 4 sources
The Impact Brief
Keep the evidence trail, not the noise.
Get the most consequential AI developments with direct sources and clear limits.
Reader commentary
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Explore commentary across the portal →Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.