Hamburg Report: Ray-Ban Meta Glasses and the Wearer's Risk
Independently fact-checked against primary sources (last audited October 6, 2026). · 7 primary sources cited on this page. How we verify our legal content

Hamburg Regulator Says Ray-Ban Meta Wearers Carry the GDPR Risk
Hamburg's data protection authority published its final report on the Ray-Ban Meta AI Glasses on 10 September 2026. Its subject is not mainly Meta. It is the person wearing the glasses, and what German and EU data protection law lets that person record.
Information last verified on September 16, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article covers German and EU data protection law as applied by one German state supervisory authority. It does not state US recording law, and nothing here describes a one-party or two-party consent rule in any US state. For the standing position on consent to recording in Germany, see our overview of German recording consent rules.
What the Hamburg Authority Published
On 10 September 2026 the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, HmbBfDI) published the final report of its technical and data protection review of the Ray-Ban Meta AI Glasses. The authority released the document in German, as a 55-page Abschlussbericht, and in an official English translation running to 53 pages. The review combines a technical teardown of what the device stores and transmits with a legal assessment of who may lawfully use it and on what basis.
The report names its own centre of gravity in a single sentence: "Im Mittelpunkt der Untersuchung steht die datenschutzrechtliche Verantwortung der Brillennutzenden in Bezug auf die personenbezogenen Daten Dritter." The authority's own English version puts it as: "The investigation focuses on the data protection responsibilities of the glasses users with regard to the personal data of third parties." That framing is unusual for a regulator examining a consumer device from a very large platform, and it is the reason this document matters to readers who simply want to know what they may film in public.
The scope limit is stated just as plainly. The report says that the processing operations carried out by Meta are not evaluated, and that professional use, beyond content creators and influencers, was not examined in detail. It is a study of what a wearer does, not an audit of a platform. The general question of which German data protection authority is competent for a given controller sits behind why a single Land authority produced a review of a device sold across the EU.
What the Report Found About the Recording Light
The authority tested the outward-facing LED that is meant to signal to bystanders that the glasses are capturing. Its conclusion is carefully conditioned, and the conditions are the finding:
"Zwar ist eine nach außen gerichtete LED-Leuchte eingebaut, die auf Foto- oder Videoaufnahmen hinweisen soll, jedoch ist diese abhängig von Entfernung, Blickwinkel und Lichtverhältnissen nur eingeschränkt wahrnehmbar."
HmbBfDI, Final Report on the Ray-Ban Meta AI Glasses, 10 September 2026, Summary
The authority's own English version of that passage reads: "Although an outward-facing LED light is built in to indicate that photos or videos are being taken, it is only visible to a limited extent, depending on distance, viewing angle, and lighting conditions." It continues: "The mere illumination of the LED alone is not sufficient to adequately inform data subjects about the data processing." The report's answer to that gap is not a hardware demand but a duty on the wearer, who it says would need to take additional measures, such as notices in the form of pictograms or verbal communication.
Two distinctions matter here.
First, this is not a finding that the LED is invisible or absent. It is a finding that its visibility is contingent on three named physical variables, and that even when a bystander does see it, a glowing light does not by itself convey the information that the GDPR's transparency duties require. The report does add one unconditioned observation: regardless of generation, the LED is not easily visible in many environments, particularly outdoors and in direct sunlight.
Second, the behaviour differs by mode and by generation. When the wearer uses the Meta AI assistant to ask a question about what is in front of them, the report observed that the outward-facing LED glows very dimly on the first-generation glasses and does not glow at all on the second generation, with the consequence that people in frame often cannot recognise that they are being captured. That is a separate observation from ordinary photo capture, where the LED does still flash briefly, for roughly a second, on both generations, and where the report noted the Gen 2 LED is in fact slightly brighter than the Gen 1 LED in photo and video mode. Collapsing those two scenarios into a single claim that the light does not come on would misstate the report.
Why the Wearer Is the One With the Legal Problem
The report's central legal conclusion is directed at the consumer, not the manufacturer. Assessing the usage scenarios it considered practically relevant, the authority concluded that the recognisable depiction of individuals who do not belong to the wearer's close circle of friends and family will generally not be permissible under data protection law, except in rare cases involving legitimate interests, because informed consent cannot realistically be obtained in the real world.
The reasoning tracks the GDPR's lawful-basis architecture. Consent under Article 6(1)(a) is the obvious candidate for filming an identifiable stranger, and it is the one that fails first in practice: a wearer walking through a station concourse cannot inform every person in frame of the controller, the purposes and their rights, and cannot take a freely given and revocable agreement from them. Legitimate interests under Article 6(1)(f) then become the fallback, and the report does not close that door. It states that for use of the AI function, Article 6(1)(f) is not excluded from the outset ("nicht von vornherein ausgeschlossen"), but that it comes into consideration only in narrowly limited situations that must be assessed case by case. A residual, fact-specific exception is not a general permission.
Article 9 adds a further hurdle that is easy to miss. Where a recording reveals health, political opinions, religious belief or sexual orientation, the special-category rules apply on top of Article 6. The report finds that Article 9(2)(e), the exemption for data manifestly made public by the data subject, is generally unavailable for third parties, because only the data subject can make their own special-category data manifestly public. A wearer cannot make that determination for the person they filmed.
For publication, as opposed to capture, the report reaches for German image-rights law as an interpretive benchmark inside the Article 6(1)(f) balancing test. The Kunsturhebergesetz § 22 provides that images of a person may only be distributed or publicly displayed with the consent of the person depicted, and § 23(1)(3) carves out images of assemblies, processions and similar events in which the depicted persons took part, subject to the § 23(2) limit where a legitimate interest of the person depicted is infringed. The statute itself sets no focal-point test; that condition comes from the report's application of the provision, which states that at public events such as concerts, sporting events and city festivals there may be a legitimate interest in publishing overview photos or videos where individual persons are not the focus of attention. The report pairs that with Article 21: data subjects should be able to object, and where an objection is raised during the event itself, the images generally may not be used unless the individuals are made unrecognisable. That body of law is used to inform the balancing exercise when smart-glasses footage of third parties is posted to a social network, not to govern the act of recording itself. Readers looking for the standing rules on photographing someone without consent in Germany will find that framework set out in full there.
One clarification cuts against the assumption many readers bring to a German recording story: the report does not rest on the criminal provisions. Germany's Strafgesetzbuch § 201 punishes the unauthorised recording of the non-publicly spoken word of another, and § 201a addresses violations of the most intimate personal sphere and of personality rights through image recordings. Those provisions remain the standing criminal backdrop to how German law treats recording generally, and they are where audio capture is usually analysed; see the rules on recording conversations in Germany for that separate track. But the Hamburg report builds its analysis on the GDPR and on the Kunsturhebergesetz, and it does not invoke § 201 or § 201a. Anyone describing the report as a criminal-law finding is describing a different document.
AI Training and the Loss of the Household Exemption
The GDPR does not apply to a natural person's purely personal or household activity. Article 2(2)(c) is what allows an ordinary person to photograph their own family at a birthday party without becoming a data controller, and the report accepts that it can cover ordinary photo and video use of the glasses among close friends and family.
The exemption has two limits the report draws sharply. The first is that it never protects the manufacturer. In the report's words, the providers of such services, here Meta, remain bound by the GDPR themselves regardless, because "die Haushaltsausnahme privilegiert ausschließlich natürliche Personen", the household exemption privileges natural persons exclusively. The second limit is the one with practical consequences for wearers, and it turns on a default rather than a choice. The report records that the use of this data for AI training is structured as an opt-out process, in which content is generally used for training unless users object. Where training is not objected to, the authority finds the legal assessment changes significantly: the activity leaves the household sphere, and the wearer becomes a joint controller with Meta in respect of the training data. A consumer who assumed they sat outside the GDPR's scope is inside it, with controller obligations, without having switched anything on.
The report is pointed about what that leaves the filmed third party. Objections do not operate retroactively, and it notes that the objection routes Meta offers to third parties, people who appear in a wearer's Meta AI interactions rather than holding an account themselves, are significantly more cumbersome to file.
On the lawfulness of that training, the report is direct:
"Im Ergebnis kann die Nutzung personenbezogener Daten Dritter durch Ray-Ban Meta AI Glasses zu KI-Trainingszwecken regelmäßig weder auf eine wirksame Einwilligung noch auf berechtigte Interessen gestützt werden."
HmbBfDI, Final Report on the Ray-Ban Meta AI Glasses, 10 September 2026, Section IV.3.b.bb
The official English version renders that as: "As a result, the use of third-party personal data by Ray-Ban Meta AI Glasses for AI training purposes generally cannot be based on either valid consent or legitimate interests." The report explains that consent usually fails for lack of information and because the third party has no effective means of withdrawing it, and that the Article 6(1)(f) balancing test typically fails because uninvolved third parties are drawn into a global AI training context without sufficient transparency, without effective control, and without reasonable foreseeability. The qualifiers "generally" and "typically" are the report's own; it is not stating an absolute prohibition.
The Database Tables That Are Not Facial Recognition
During the technical examination the authority found database tables named "face", "face_group", "face_low_confidence_pair" and "face_to_face_group". They sit in the Meta AI companion app's SQLite database on the paired phone, which matters to the scope of the finding: the report states that the glasses' own memory chip lacked any standard ports that would allow data to be read out, so it was the app's application storage that could be examined. The table names plainly point to the possibility of facial recognition, and the report says so before setting out what the testing actually showed.
The obvious assumption that these tables are used for facial recognition could not be confirmed through testing. The tables in question contained no entries. On that basis the report states that it can be assumed that, at least so far, no facial recognition is taking place. It records that no evidence of facial recognition being performed could be found, while noting that the basic structures for adding such a feature in the future are already in place within the software.
The report therefore does not find facial recognition in the Ray-Ban Meta AI Glasses. It finds empty tables with suggestive names, an affirmative conclusion that the feature is not running, and a latent schema capability that a future software change could populate. The report draws one further distinction worth keeping straight: the face masking it examined, in which faces are detected before transmission to Meta AI, is object recognition rather than facial recognition, because facial recognition in the strict sense means matching captured faces against a database of already known faces.
The authority separately recounts a June 2026 account by the Electronic Frontier Foundation and WIRED, according to which facial-recognition software was already present on the glasses and in the app, and manual interaction with it could make the glasses match and identify faces against a database of known faces. Two things about that passage are easy to get wrong. The report attributes the account to those outlets rather than to its own testing, and it does not claim to have refuted it. What it records is that shortly afterwards Meta changed the software so the behaviour could no longer be reproduced, a statement the report dates to 26 June 2026. Its own examination, separately, found no evidence of facial recognition being performed.
The legal consequence is stated conditionally. The report notes that facial recognition, where used to identify a person uniquely, would process biometric data and so engage Article 9, whose special-category processing is prohibited unless an Article 9(2) exception applies. It then records that the facial recognition feature is currently not enabled, and that if it were, the associated processing by users and by Meta would face those stricter requirements.
What Legal Weight This Report Carries
A report is not an order. What HmbBfDI published is an investigatory assessment (a Prüfbericht, issued as an Abschlussbericht). It is not a fine, not a prohibition, not a binding EU-wide ruling, and not a decision of a court or of the European Data Protection Board. It creates no new obligation by itself: it states how one German supervisory authority reads existing GDPR obligations as they apply to a specific consumer device.
The report also limits its own reach in terms. It states that the investigation claims no completeness, in either technical or legal respects ("Die Untersuchung erhebt keinen Anspruch auf Vollständigkeit, weder in technischer noch rechtlicher Hinsicht"). Its detailed hardware and software testing was carried out on the first-generation Ray-Ban Meta Wayfarer, examined as a representative example; the second-generation observations are narrower secondary findings, which is why the Gen 2 LED behaviour appears as a specific comparison rather than a full parallel assessment.
Two further points should be stated as absences rather than facts. Nothing in the report says that an enforcement proceeding against Meta has been opened, and no evidence either way was located for this article. The report also does not address lead-supervisory-authority or one-stop-shop questions, which would determine which authority could take formal action against Meta's European establishment in the first place.
Finally, one thing this report is not is a response to any other German regulator. Neither language version mentions the Bundesnetzagentur anywhere. Where secondary coverage sets this report against a position attributed to that agency, the comparison is supplied by the coverage rather than by the document, which says nothing on the subject.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The durable point in this report is not about Meta. It is that a European regulator has looked at a mass-market consumer camera and concluded that, in most of the situations people actually buy it for, the lawful basis a wearer would need is not obtainable. Consent fails because you cannot brief a crowd. Legitimate interests survives only as a narrow, case-by-case exception the report declines to generalise. The gap that opens between what a product makes effortless and what the law permits is the whole story, and it does not depend on anything unique to Germany.
That gap widens because of the second structural finding: the transparency mechanism built into the hardware is, on the authority's assessment, too contingent to do the legal work assigned to it. A signal whose visibility depends on distance, angle and light is not a substitute for information about who is processing what and why, and the remedy the report reaches for is telling. It does not ask for a better light. It asks the wearer to add pictograms or say something out loud, which is a duty most buyers will not know they have.
The AI-training finding is the one most likely to surprise ordinary users, because of where the default sits. A consumer who takes a photograph of a friend is, under Article 2(2)(c), outside the GDPR entirely. The same consumer who has simply not objected to AI training is, on this reading, a joint controller of third-party personal data alongside a multinational platform. A legal status that changes through inaction rather than through a deliberate choice is a hard thing for any product to disclose well, and the report treats the third party's position as worse still: their route to object is neither retroactive nor easy to use.
One caution belongs in any honest reading. This is an assessment that limits its own completeness, from one Land authority, and it tells wearers how a regulator reads the law rather than changing it. We make no prediction about whether enforcement follows. Readers in occupational settings should also note that the same capture questions arrive with a different legal frame at work, where employer duties and works-council involvement sit on top of everything above.
This is general legal information, not legal advice. It covers German and EU data protection law and reflects sources verified on September 16, 2026. Laws change and this story is developing; consult a lawyer qualified to practise in Germany about your specific situation.
Related articles
- how German law treats recording generally
- photographing someone without consent in Germany
- the rules on recording conversations in Germany
- which German data protection authority is competent
- our overview of German recording consent rules
- wearable recording devices in the workplace
Last updated: 2026-09-16. This is a developing story; details verified as of 2026-09-16.
Frequently Asked Questions
Is it legal to record people with smart glasses in Germany?
The Hamburg data protection authority concluded on 10 September 2026 that, across the usage scenarios it treated as practically relevant, recognisable recording of people outside the wearer's close circle of friends and family will generally not be permissible under data protection law, apart from rare legitimate-interest cases, because informed consent cannot realistically be obtained. That is a regulator's assessment of existing GDPR obligations, not a new rule or a ban.
Do Ray-Ban Meta glasses show when they are recording?
There is an outward-facing LED, and the Hamburg authority did not find it invisible. It found the light only visible to a limited extent, depending on distance, viewing angle and lighting conditions, and concluded that the LED lighting up alone does not adequately inform bystanders about the data processing. The report also observed that during Meta AI queries the LED glows very dimly on the first generation and not at all on the second, while ordinary photo capture still produces a brief flash of about one second on both. It adds that regardless of generation the LED is not easily visible in many environments, particularly outdoors and in direct sunlight.
Did the Hamburg authority find facial recognition in the Ray-Ban Meta glasses?
No. It found database tables with facial-recognition-suggestive names, including 'face' and 'face_group', but those tables contained no entries and testing could not confirm the assumption that they are used for facial recognition. The report states that it can be assumed no facial recognition is taking place, while noting that the software structures for adding such a feature later are already present.
Does the Hamburg report ban Ray-Ban Meta glasses in Germany?
No. The document is an investigatory assessment report published on 10 September 2026, not an order, a fine, a prohibition or a court ruling. It expressly states that the investigation claims no completeness in technical or legal respects, and nothing in it says an enforcement proceeding was opened.
Can I take photos of friends and family with smart glasses under the household exemption?
The report accepts that Article 2(2)(c) of the GDPR, the personal or household activity exemption, can cover ordinary photo and video use among a close circle of friends and family. It stresses that the exemption privileges natural persons only and never relieves the provider, here Meta, of its own GDPR obligations.
What happens with AI training when wearing smart glasses in Germany?
The report records that Meta's AI training is structured as an opt-out process, so content is generally used for training unless the user objects. On the Hamburg authority's analysis, where AI training is not objected to, the activity falls outside the household exemption and the wearer acts as a joint controller with Meta for that data. The report also finds that using third-party personal data for AI training generally cannot be based on valid consent or on legitimate interests, because consent usually fails for lack of information and effective withdrawal, and the balancing test typically fails for want of transparency, control and foreseeability.
Does German criminal law apply to recording with smart glasses?
Germany's Strafgesetzbuch § 201 covers unauthorised recording of the non-publicly spoken word, and § 201a addresses image recordings that violate the most intimate personal sphere and personality rights. Those provisions are the standing criminal backdrop to recording in Germany, but the Hamburg report does not rely on them. Its analysis rests on the GDPR and on the Kunsturhebergesetz.
Can I post smart glasses photos of strangers on social media in Germany?
Publication is analysed separately from capture. The report uses the Kunsturhebergesetz as an interpretive benchmark inside the Article 6(1)(f) balancing test, under which § 22 requires the consent of the person depicted for distribution or public display, subject to exceptions in § 23 such as images of assemblies and processions in which the depicted persons took part. The focal-point condition often quoted alongside that exception is not in the statute; it comes from how the report applies the provision, saying there may be a legitimate interest in overview photos or videos of public events where individual persons are not the focus of attention.
Why did a Hamburg authority review a product sold across the EU?
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit is the data protection supervisory authority for the German state of Hamburg, and it carried out the technical and legal review published on 10 September 2026. The report does not address lead-supervisory-authority or one-stop-shop questions, which would govern which authority could take formal action against Meta's European establishment.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- HmbBfDI news page announcing the final report on the technical and data protection review of the Ray-Ban Meta AI Glasses, 10 September 2026, linking both language versions(datenschutz-hamburg.de).gov
- HmbBfDI, Final Report on the Technical and Data Protection Review of the Ray-Ban Meta AI Glasses, official English version, 10 September 2026, 53 pages(datenschutz-hamburg.de).gov
- HmbBfDI, Abschlussbericht zur technischen und datenschutzrechtlichen Untersuchung der Ray-Ban Meta AI Glasses, German version, 10 September 2026, 55 pages(datenschutz-hamburg.de).gov
- Strafgesetzbuch section 201, Verletzung der Vertraulichkeit des Wortes, official consolidated text(gesetze-im-internet.de).gov
- Strafgesetzbuch section 201a, Verletzung des höchstpersönlichen Lebensbereichs und von Persönlichkeitsrechten durch Bildaufnahmen, official consolidated text(gesetze-im-internet.de).gov
- Kunsturhebergesetz section 22, Recht am eigenen Bild, official consolidated text(gesetze-im-internet.de).gov
- Kunsturhebergesetz section 23, exceptions to the consent requirement including the assemblies and processions exception, official consolidated text(gesetze-im-internet.de).gov