https://www.polity.org.za
Deepening Democracy through Access to Information
Home / Legal Briefs / Werksmans RSS ← Back
Apple|Meta|Werksmans Attorneys|WhatsApp – Company|France|Germany|Ghana|Kenya|South Africa|United Kingdom|Data Privacy|Data Protection|Surveillance|Information Commissioner's Office|Information Regulator|Ahmore Burger-Smidt|AirPods Pro|Ray-Ban Meta|Artificial Intelligence|Biometrics|Smart Glasses
||||||
apple|meta|werksmans-attorneys|whatsapp-company|france|germany|ghana|kenya|south-africa|united-kingdom|data-privacy|data-protection|surveillance|information-commissioners-office|information-regulator|ahmore-burger-smidt|airpods-pro|ray-ban-meta|artificial-intelligence|biometrics|smart-glasses
Close

Email this article

separate emails by commas, maximum limit of 4 addresses

Sponsored by

Close

Article Enquiry

Invisible data collection through a privacy lens


Close

Invisible data collection through a privacy lens

Should you have feedback on this article, please complete the fields below.

Please indicate if your feedback is in the form of a letter to the editor that you wish to have published. If so, please be aware that we require that you keep your feedback to below 300 words and we will consider its publication online or in Creamer Media’s print publications, at Creamer Media’s discretion.

We also welcome factual corrections and tip-offs and will protect the identity of our sources, please indicate if this is your wish in your feedback below.


Close

Embed Video

Invisible data collection through a privacy lens

Werksmans

17th September 2026

ARTICLE ENQUIRY      SAVE THIS ARTICLE      EMAIL THIS ARTICLE

Font size: -+

More than seven million pairs of Meta’s Ray-Ban smart glasses were sold worldwide in 2025. Apple’s AirPods Pro 3, launched in September 2025, now monitor heart rate and translate live conversations using artificial intelligence. A next-generation Apple AirPod with an embedded camera is in advanced testing. These are not consumer curiosities, they are data collection instruments that walk through office doors, and POPIA has something to say about every byte they capture.

The global regulatory response has been swift. France’s independent data protection authority warned in May 2026 that smart glasses risk normalising surveillance that is “almost invisible and omnipresent.” Germany’s Hamburg data protection commissioner concluded that covert filming with these devices violates data protection law, and a sales ban is under active review. The UK’s Information Commissioner's Office has formally written to Meta demanding compliance information, and a US class action alleges the glasses are a “surveillance nightmare disguised as fashion.” In East Africa, a Russian vlogger was identified in early 2026 recording intimate encounters with women in Kenya and Ghana using Meta smart glasses and posting the footage online for profit.

Advertisement

South Africa is not insulated from any of this. POPIA’s framework for special personal information, its transparency obligations, and its transborder transfer restrictions are all directly engaged. 

The POPIA exposure: five critical risk areas

Advertisement

Biometric and health data as special personal information 

Biometric information occupies a privileged category under POPIA. It is classified as “special personal information,” and processing it is generally prohibited unless a specific statutory exception applies, most commonly, explicit consent or a substantial public interest justification. The practical implications are significant. Meta’s smart glasses capture facial features, voiceprints, and video footage of identifiable individuals. Apple’s AirPods Pro 3 collect heart rate, motion, and calorie data via an in-ear optical sensor, transmitting this to Apple’s Health ecosystem and, with user permission, to third-party fitness applications. 

Bystander and third-party rights

Every data subject has the right to know when personal information about them is being collected. That right is effectively annihilated by a device designed to record people covertly. Smart glasses are, by their nature, silent observers. The sole notification mechanism on Meta’s Ray-Ban glasses is a small LED light, which a peer-reviewed CHI 2026 study concluded is “inadequate” as a bystander safeguard. Regulators across France, Germany, and the Netherlands have reached the same conclusion. The legal difficulty is plain: section 11 of POPIA requires a responsible party to demonstrate a lawful basis for processing, which becomes a near-impossibility when the data subject has no knowledge that processing is occurring at all.

Transparency and notice failures

Section 18 of POPIA requires reasonably practicable steps to ensure data subjects know what information is being collected, why it is being collected, and who is responsible. What the major technology companies have been doing sits uncomfortably with that obligation. Meta’s April 2025 privacy policy update removed the option for users to disable voice recording storage and enabled AI features by default. A Swedish investigation in early 2026 revealed that intimate footage, including nudity and financial information, was reviewed by human contractors in Kenya without adequate disclosure to users. That kind of murkiness can be said to be fundamentally inconsistent with POPIA’s transparency mandate.

Transborder data transfers 

Personal information may only leave South Africa where the recipient country provides an adequate level of protection, or where binding corporate rules or consent apply. This is not an abstract concern. Meta's routing of footage captured by South African users to contractor facilities in Nairobi for AI training annotation raises serious questions about compliance with section 72. Apple's transmission of aggregated health and activity data to its US-based servers engages the same provision. 

Security of processing 

Responsible parties must secure the integrity and confidentiality of personal information through appropriate technical and organisational measures. Section 19 demands nothing less. The revelation that Meta's AI training pipeline could not distinguish between mundane footage and deeply sensitive content, and that no adequate filtering existed, represents a failure that would be difficult to defend under any reasonable reading of the provision. 

What does this mean for South Africa?

The Information Regulator's 2025/26 Annual Performance Plan signals a firmer enforcement posture, including a new compliance monitoring programme, a Code of Conduct for data collection at controlled entry points (covering biometric systems and surveillance technologies at business premises), and mandatory e-portal breach reporting since April 2025. Against this backdrop, South African organisations should consider, amongst others, the following:

Consider whether to restrict smart glasses and AI-enabled earbuds in offices, boardrooms, client-facing areas, and controlled environments. Also, review workplace policies on wearable devices. 

Update privacy notices to address the possibility that employees, visitors, or clients may be recorded by wearable devices, and specify the organisation's position on such recording.

Conduct Personal Information Impact Assessments (PIIAs) as required by Regulation 4(b) of the POPIA Regulations, specifically for any deployment of wearable technology that captures biometric or health data.

South Africa has both the constitutional foundation and the legislative architecture through POPIA to shape the regulatory response to wearable AI across the continent. The Information Regulator has not yet issued specific guidance on smart wearables, but the trajectory is unmistakable: the draft Code of Conduct on controlled-entry-point data collection, the compliance monitoring programme, and the Regulator's enforcement action against WhatsApp for applying weaker privacy terms to South African users than to Europeans all signal a regulator that will not tolerate a two-tier approach to data protection.

Specific AI legislation is not imminent in 2026, but POPIA already provides a comprehensive framework for regulating wearable AI. 

Written by Ahmore Burger-Smidt, Director at Werksmans Attorneys

 

EMAIL THIS ARTICLE      SAVE THIS ARTICLE      ARTICLE ENQUIRY      FEEDBACK

To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here


About

Polity.org.za is a product of Creamer Media.
www.creamermedia.co.za

Other Creamer Media Products include:
Engineering News
Mining Weekly
Research Channel Africa

Read more

Subscriptions

We offer a variety of subscriptions to our Magazine, Website, PDF Reports and our photo library.

Subscriptions are available via the Creamer Media Store.

View store

Advertise

Advertising on Polity.org.za is an effective way to build and consolidate a company's profile among clients and prospective clients. Email advertising@creamermedia.co.za

View options

Email Registration Success

Thank you, you have successfully subscribed to one or more of Creamer Media’s email newsletters. You should start receiving the email newsletters in due course.

Our email newsletters may land in your junk or spam folder. To prevent this, kindly add newsletters@creamermedia.co.za to your address book or safe sender list. If you experience any issues with the receipt of our email newsletters, please email subscriptions@creamermedia.co.za