The 60-second summary
On 7 October 2026, the OAIC announced an investigation into Shenzhen Qingcheng, provider of the HeyCyan smart-glasses phone app, after unanswered preliminary enquiries. This is an investigation under existing law, not a finding of infringement or a product ban.
Timeline that matters
12 August 2026
Preliminary enquiries
OAIC began enquiries with smart-glasses manufacturers and distributors.
7 October 2026
Investigation announced
OAIC announced its HeyCyan investigation and published companion analysis.
Not announced
Outcome timetable
No final decision date or new general compliance deadline is stated.
What changed
The OAIC moved from preliminary enquiries to a formal investigation and wrote to retailers about its concerns. Its companion analysis distinguishes hardware sellers from entities holding recorded information. It discusses context-dependent identifiability, collection, notices and security. Proposed privacy reforms remain separate from current requirements.
Who should pay attention?
Privacy and legal
Assess entity roles and applicable duties.
Procurement
Require evidence of app data handling.
Security
Test capture, upload, storage and deletion.
What the guidance clarifies
- Investigation status
- No final infringement finding or penalty has been announced.
- Role-specific duties
- Selling hardware does not alone determine responsibility for recorded data.
- Consent
- Do not infer a universal consent rule from this case.
- Reforms
- The companion blog's proposed reforms are not current obligations.
Global relevance — follow the data beyond the device
Why this matters for global organisations.
Wearable procurement should cover the app and processing service as well as the hardware. Map incidental capture, vendor access, derived information and deletion before approving use.
- Determine responsibility from actual data handling.
- Require verifiable supplier evidence.
- Assess bystanders and sensitive environments.
- Maintain reliable regulator-response ownership.
14 actions to start now
- Inventory wearable devices and associated apps.
- Identify each entity collecting or holding recorded information.
- Map audio, images, location, uploads and derived data.
- Assess identifiability in context.
- Document necessity and alternatives for each use.
- Obtain specialist advice on sensitive data and consent.
- Review recording indicators and notices.
- Test app permissions and default capture settings.
- Require vendor evidence on access and storage.
- Review encryption, authentication and sharing controls.
- Test retention, deletion and device disposal.
- Define restrictions for sensitive spaces and workplace use.
- Assign an owner for regulator correspondence.
- Track findings and enacted reforms separately from proposals.
Suggested next steps
- Review for official investigation findings and enacted changes.
Evidence worth retaining
- Device and app inventory.
- Entity-role and data-flow map.
- Collection assessment.
- Impact assessment.
- Permission and configuration tests.
- Vendor responses and contracts.
- Access and storage evidence.
- Retention and deletion tests.
- Notices and staff instructions.
- Regulatory correspondence and source register.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Who holds recordings and derived information?
- Can bystanders be identified in context?
- Is sensitive information collected?
- Which legal duties apply to each entity?
- Can features operate with less data?
- Where are recordings processed?
- Can vendor assurances be independently checked?
- Which workplace restrictions are appropriate?
- How will data be deleted on exit?
Official sources
- OAIC — HeyCyan investigation announcement, 7 October 2026
- OAIC — Smart glasses under the microscope, 7 October 2026
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.