Part of the AI Regulation News hub.
Hamburg's data protection authority has published a final report stating that recording people outside a wearer's close circle of friends and family will generally not be permissible under data protection law, and that there will typically be no legal basis for Meta's AI training
The report is not about what Meta does with your data. It is about what you become the moment you point the glasses at someone else.
Bottom line: Not binding. This is a supervisory authority's own review report, published 10 September 2026. It states the HmbBfDI's assessment. It imposes no fine, issues no order and, on its face, opens no proceedings against anyone.
Who this affects: Data protection officers and privacy counsel advising on wearable devices and device policy, employers and operators of hospitals, schools, retail sites and venues deciding whether to allow AI glasses on their premises, smart glasses vendors selling into the EU, and individual wearers.
Issue date: 10 September 2026, published simultaneously in German and English. No deadline attaches to it and it sets no compliance date.
What changed: A German supervisory authority put a technical teardown of the Ray-Ban Meta Wayfarer (Gen 1) and a full legal assessment on the public record, and said what it thinks the law permits.
Analysis: The report's declared subject is the responsibility of the person wearing the glasses for third parties' data. Meta's processing of its own users' data is expressly excluded from the analysis.
Primary sources: HmbBfDI announcement, Ray-Ban Meta AI Glasses · Abschlussbericht (German, 53 pages) · Final report (English, 53 pages)
- Instrument (EN)
- Final Report on the Technical and Data Protection Review of the Ray-Ban Meta AI Glasses
- Authority
- Hamburgischer Beauftragter fuer Datenschutz und Informationsfreiheit (HmbBfDI)
- Jurisdiction
- Germany, Free and Hanseatic City of Hamburg. The authority writes that much of its reasoning generalises to smart glasses as a product category
- Status
- Published. A supervisory authority's review report, not a decision, order or fine
- Bindingness
- Not binding. It states the authority's own assessment of how the GDPR applies. The GDPR provisions it interprets are of course binding in their own right
- Issue date / next deadline
- 10 September 2026. No deadline is set and no compliance date is named
- Legal basis
- Assessment carried out against Regulation (EU) 2016/679, in particular Articles 2(2)(c), 4(7), 5(1)(a), 6(1)(a) and (f), 9, 12, 13, 21 and 26
- Document
- 53 pages, published in German and English. The English file carries a creation stamp of 10 September 2026
- Primary source
- https://datenschutz-hamburg.de/news/ray-ban-meta-ai-glasses-hmbbfdi-legt-technischen-und-datenschutzrechtlichen-pruefbericht-vor
What the report concludes about recording other people
This is a published review report and it binds nobody, so read the following as the authority's stated position rather than as a rule anyone is now obliged to follow. In the findings paragraph of its own announcement the HmbBfDI writes: "Die Pruefung kommt zu dem Ergebnis, dass die Aufnahme von Personen, die nicht zum engen Freundes- und Familienkreis gehoeren, datenschutzrechtlich bis auf seltene Konstellationen des berechtigten Interesses nicht zulaessig sein wird, da die informierte Einwilligung in der Realitaet bereits mangels Transparenz nicht eingeholt werden kann." The diacritics are folded here for typesetting; the unaltered German sits in the quote field and on the authority's page.
The authority published its own English rendering on the same page, and it reads: "The review concludes that, from a data protection perspective, recording individuals who are not part of a person's close circle of friends and family will generally not be permissible - except in rare cases involving legitimate interest - since informed consent cannot realistically be obtained due to a lack of transparency." We read the German as the source of record and checked the authority's English against it.
Two hedges in that sentence do real work and survive into the report itself. The conclusion is expressed in the future tense rather than as a finding of past unlawfulness, and it carves out rare legitimate-interest constellations. Section IV.3 of the report gives the clearest worked example of that carve-out: a visually impaired user relying on the AI function as a daily aid, whose interest in social participation and mobility may prevail, though the report adds that this cannot be stated as a general rule and has to be assessed case by case.
The wearer is the controller, and a joint controller once AI training is on
The report's declared subject is the wearer, not the manufacturer. Section IV.1 opens by saying the assessment covers exclusively the processing of third-party personal data when using the glasses, and that Meta's processing of its own users' personal data is not the subject of the analysis. Anyone reading this as a general verdict on Meta's data practices is reading something the document says it is not doing.
On the household exemption the report is split by scenario. Used without AI training, the report says the Article 2(2)(c) exemption is not automatically ruled out where a natural person uses the glasses in a private or family context, does not specifically capture unrelated third parties, pursues no commercial purpose and does not make the data accessible beyond that circle.
With AI training enabled the assessment changes. The report states that the household exemption then does not apply, because the third party's data is transferred into a training context determined by Meta and so serves an independent, non-private purpose. Its reasoning is that the adverse effect lies less in the initial capture than in the loss of controllability and the potential permanence of the processing, citing EDPB Opinion 28/2024 for the proposition that personal training data remains embedded in model parameters and may under certain circumstances be extracted.
From there the report reaches joint controllership under Article 26. Without training, it treats users as separate controllers under Article 4(7). With training on, it reads Wirtschaftsakademie, Jehovan todistajat and Fashion ID together and concludes that the wearer and Meta jointly determine purposes and means for the collection and transmission. It also applies the Fashion ID limit: that joint responsibility does not extend to downstream steps Meta determines alone.
What the teardown found, and what it could not settle
The technical half is unusually concrete for a supervisory publication. The authority traced the Meta AI companion app's structure, recorded its data transmissions and then disassembled the glasses to analyse the components, including the 32 GB flash memory chip.
The facial recognition finding is the one most likely to be misquoted, so here it is with its own hedges intact. The authority found database tables whose names point to facial recognition. Those tables contained no entries, and the report says it can therefore be assumed that so far no facial recognition is taking place, while noting that the basic structures for adding such a feature later are already present in the software. The report separately records that a June 2026 EFF and WIRED account described facial recognition software already present, that manual interaction reportedly made identification possible, and that Meta shortly afterwards modified the software so the behaviour could no longer be reproduced. We are repeating the report's account of those press reports, not verifying them.
A second technical question came back unresolved, and the report says so. Asked whether faces are masked before images go to Meta, it found masked images in app storage carrying a timestamp two seconds after processing by Meta, and concluded that the point could not be settled because the transmission is encrypted. The report is careful that this masking is object recognition of the face type, not identifying facial recognition.
The recording indicator gets the harshest treatment. The report says the outward-facing LED lights only for photos, video, live streaming and video calls; that when Meta AI is used it glows very dimly on Gen 1 and not at all on Gen 2; that the light has a limited beam angle and is hard to see outdoors or in sunlight; that stickers, paint or caps can suppress the visible light while still letting ambient light reach the sensor meant to detect covering; and that for video the cover check runs only at the moment recording starts, so covering the LED afterwards leaves the recording running with no indicator at all.
Three usage scenarios, and why the training toggle is the hinge
The report separates photo and video capture, use of Meta AI, and publication to Facebook or Instagram, and assesses each on its own facts.
Simple camera use can rest on consent or legitimate interests, with the ordinary rules for photography applying. Use of Meta AI without AI training can rest on consent, and the report accepts navigation, translation, information gathering and, for visually impaired users, social participation as interests capable of prevailing case by case. Its stated gradient: the more that uninvolved third parties are specifically collected, analysed or processed in sensitive contexts, the more likely their rights and freedoms prevail.
Publication to social networks can rest on consent, which the report says would have to refer expressly to the publication, or within narrow limits on legitimate interests, with the Kunsturhebergesetz and its case law used as the benchmark for balancing.
Behind all three sits a default the report flags in its introduction: AI training is activated by default using Meta AI interaction data, on an opt-out basis, and an objection filed later operates only prospectively. On that footing the report states that AI training using third-party data is generally impermissible, because the prerequisites, including timely information and a valid legal basis, are usually not met, and because the affected third party's Article 15, 16 and 17 rights are practically unenforceable.
What to do with a report that binds nobody
Nothing in this document orders anyone to change anything. Its practical weight is evidentiary and reputational: it is a supervisory authority's stated reading, backed by a teardown, published in English so it can be cited outside Germany.
For anyone writing device policy, the operative fact is which party the report puts in the frame. It treats the individual wearer as a controller for third-party data, and as a joint controller with Meta once the training toggle is left on. That is a materially different risk allocation from the one most workplace device policies assume, which is that the vendor carries the data protection exposure.
The report also says, in Section IV.1, that many of its considerations apply to smart glasses generally rather than only to this product, and it flags where it is using the term in that generalised sense. It tested the Gen 1 model. Its Gen 2 observations, particularly on the LED, are comparative remarks made in the course of that testing and are identified as such.
What we did not verify
What we opened: the authority's own announcement page in German and English, and the full 53 page English final report, downloaded directly from the authority and read as extracted text, including the summary, the introduction, the technical findings at Section III.6 and the legal assessment at Section IV.
What we did not open: the German-language final report PDF. We read the German only as it appears in the authority's announcement, which is where our verbatim quotation comes from, and we took the substantive detail from the authority's own English report. We also did not open the EFF or WIRED reports the document cites, EDPB Opinion 28/2024, EDPB Guidelines 1/2024 or 7/2020, or any of the CJEU judgments, so we describe all of those only as this report describes them.
What we refuse to claim: we do not say Meta has been found to have broken the law, because this is a review report and not a decision, a fine or a finding in any proceeding. We do not say wearing the glasses is illegal. We do not say facial recognition is running on the device, because the report found the relevant tables empty and framed its conclusion as an assumption. We do not say the masking question was resolved, because the report says it could not be. We give no enforcement step, deadline or next procedural stage, because the document names none. Quotations from the German are reproduced with folded diacritics in the running text as a house typesetting convention, with the unaltered text preserved in the quotation field; no word has been changed.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
If your organisation is writing a policy on AI glasses, the allocation in this report is the part to plan around. The authority treats the person wearing the glasses as a controller for everyone else's data, and as a joint controller with Meta for as long as the AI training setting stays on. Decide whether that setting is something you leave to the individual wearer, and decide what you tell people on your premises, because the report's own testing says the recording light will often not tell them anything.
Source File
Open the English report and check four things for yourself: the recording conclusion in the summary on page 2, the household exemption analysis under Section IV.3.b, the joint controllership reasoning under Section IV.3.c, and the LED findings at Section III.6.f, including the point that the cover check for video runs only when recording starts.
Die Prüfung kommt zu dem Ergebnis, dass die Aufnahme von Personen, die nicht zum engen Freundes- und Familienkreis gehören, datenschutzrechtlich bis auf seltene Konstellationen des berechtigten Interesses nicht zulässig sein wird, da die informierte Einwilligung in der Realität bereits mangels Transparenz nicht eingeholt werden kann. Zudem wird es regelmäßig an einer Rechtsgrundlage für das KI-Training durch Meta fehlen. · HmbBfDI, announcement accompanying the Abschlussbericht on the Ray-Ban Meta AI Glasses, findings paragraph, 10 September 2026
FAQ
Has the Hamburg authority banned the Ray-Ban Meta glasses?
No. The document is a review report. It states the authority's assessment of how the GDPR applies, and it contains no prohibition, no order, no fine and no deadline.
Does the report say Meta broke the law?
It says that there will typically be no legal basis for Meta's AI training, and that AI training using third-party data is generally impermissible. That is the authority's stated assessment in a published report, not a finding in any proceeding, and the report expressly excludes Meta's processing of its own users' data from its analysis.
Am I personally responsible if I wear the glasses?
The report treats the wearer as a controller under Article 4(7) for third parties' personal data, and as a joint controller with Meta under Article 26 once AI training is enabled. Without AI training the report says the household exemption is not automatically ruled out; once AI training is on, it says the exemption does not apply at all.
Did the authority find facial recognition on the device?
It found database tables whose names point to facial recognition, but those tables held no entries, so the report assumes none is taking place so far while noting that the structures for adding it later already exist in the software. A separate question, whether faces are masked before transmission, could not be resolved because the transmissions are encrypted.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.