---
title: Hamburg Data Authority Raises Privacy Concerns Over Meta AI Glasses
url: https://www.elseif.net/hamburg-data-authority-raises-privacy-concerns-over-meta-ai-glasses
published: 2026-10-04T16:04:00+00:00
language: en
section: Models
source: https://www.cybersecurity360.it/legal/privacy-dati-personali/meta-ai-glasses-tanti-i-rischi-privacy-ecco-perche/
organizations: Meta, Hamburg Data Protection Authority, Ray-Ban, AI training, GDPR, smart glasses
publisher: elseif
---

# Hamburg Data Authority Raises Privacy Concerns Over Meta AI Glasses

Hamburg data authority has subjected Ray-Ban Meta AI Glasses to a technical and legal analysis that raises doubts about the lawfulness of third‑party recordings, transparency and use of data for AI training. The Hamburg Data Protection Authority examined the glasses in a laboratory, dissected the application down to database tables, intercepted network traffic and checked how data are collected, stored and used. The outcome is a very strict reading of privacy: outside a close circle of friends and family, recording other people with these devices is unlikely to be considered consequence‑free under GDPR. The final report was published by the Hamburg Commissioner for Data Protection and Freedom of Information on 10 September 2026. The authority states that obtaining genuinely informed consent in most everyday situations is hardly practicable, while the use of third‑party data for Meta’s AI training normally lacks an adequate legal basis. The issue concerns not only Meta but also anyone who wears the glasses: from private users to content creators and companies that decide to employ them as a work tool. The Hamburg report tries to clarify roles, responsibilities and privacy obligations along a technological chain where it becomes increasingly complex to distinguish who collects data from who decides how they are used.

The document makes clear that it is not a sanctioning decision and warns that it is not complete technically or legally and does not evaluate Meta’s processing. It represents an important reading by a European authority on a product sold throughout the Union and its technical accuracy is unlikely to go unnoticed by counterpart authorities. The Hamburg authority is a regional data protection body, not the lead supervisor for Meta in the Union; the lead supervisor is the Irish Data Protection Commission because of the one‑stop‑shop rule. The investigation focused on the first‑generation Ray‑Ban Meta Wayfarer (2023) together with app version 229.0.0.29. An interdisciplinary team with expertise in social networks, data protection and legal profiles of AI applications carried out the work. The study also compared the first generation with the second generation, which the report identifies as the best‑selling smart glass in the world. In April 2025 Meta announced that it would train its models with public content of adult European users and with interactions with Meta AI, starting 27 May 2025, using an opposition mechanism that applies only to the future and does not cancel previous training. Opponents, people appearing in photos taken by others or included in questions asked to Meta AI through the glasses, have opposition tools that the report judges considerably more cumbersome.

The state of the training, active or inactive, is the pivot on which the entire legal analysis turns. The hardware examined includes a 12‑megapixel wide‑angle camera, five microphones, two speakers, 32 GB flash memory, Wi‑Fi, Bluetooth, touch panel and sensors such as a gyroscope. All functions can be commanded by voice with “Hey Meta” or “OK Meta”. The Meta AI app on the smartphone acts as a bridge between glasses, phone and social network. The authority tested the hardware, the network traffic and the storage possibilities. Network traffic intercepted with HTTP Toolkit on a Pixel 7 running Android 13 was encrypted toward all endpoints except b‑www.facebook.com, where the app repeatedly sends diagnostic data: device model, operating system and kernel version, a device identifier and a build identifier. The authority notes that such information could serve not only diagnostics but also device fingerprinting.
