Privacy & Cybersecurity #78
EU AI Act Simplification | EU-US DPF at Risk | EDPB OSS Case Digest | NIS2 Security Measures | GDPR Guidance for Video Games | Ireland on AI Deployment | Estonia AI Agent Identities | G7 Communiqué
July 5, 2026
🇪🇺 EU Gives Final Approval to AI Act Simplification Regulation
On 29 June 2026, the Council of the EU gave final approval to the Digital Omnibus on AI, a regulation amending the EU AI Act and related product-safety legislation. The measure is part of the EU’s wider simplification agenda and is intended to reduce implementation burden, clarify overlaps with sectoral legislation, and adjust several AI Act timelines. The regulation will enter into force on the third day after publication in the Official Journal.
The application of Chapter III, Sections 1 to 3, will be delayed. For high-risk AI systems listed in Annex III, the rules will apply from 2 December 2027. For high-risk AI systems embedded in products or themselves constituting products covered by Annex I harmonized product legislation, the rules will apply from 2 August 2028. This replaces the previous 2 August 2026 application date for these obligations.
The prohibited AI practices regime remains in place, and the amending regulation adds new prohibitions targeting AI systems that generate or manipulate non-consensual intimate material and AI-generated child sexual abuse material. These new prohibitions will apply from 2 December 2026. The text distinguishes provider obligations from deployer conduct: placing on the market or putting into service is prohibited where the prohibited generation is the system’s intended purpose, or where it is a reasonably foreseeable and reproducible outcome and the system lacks reasonable and adequate safeguards. Deployer use is prohibited where the deployer uses the system for that purpose.
The regulation also revises the AI literacy obligation. Providers and deployers will be required to take measures to support the development of AI literacy among staff and other persons operating or using AI systems on their behalf. The amended text expressly states that this does not require providers or deployers to guarantee any specific level of AI literacy for any individual.
A further privacy-relevant change is the new Article 4a on special-category personal data processing for bias detection and correction. Providers of high-risk AI systems may process special categories of personal data where strictly necessary for bias detection and correction, subject to safeguards such as use of anonymized or synthetic data where possible, pseudonymization, access controls, limits on onward access, deletion once the bias is corrected or the retention period ends, and documentation in records of processing. The same exceptional legal basis is also extended, in narrower terms, to deployers of high-risk AI systems and to providers and deployers of other AI systems and models where bias may affect health and safety, fundamental rights, or lead to discrimination under EU law.
For product manufacturers, the regulation addresses overlap between the AI Act and sectoral product legislation. It introduces a mechanism allowing the Commission to limit specific AI Act requirements where Union harmonization legislation already provides an equivalent or higher level of protection. It also clarifies the conformity assessment route for high-risk AI systems covered by Annex I product legislation and states that inclusion of a high-risk AI safety component does not, by itself, force the manufacturer into a third-party conformity assessment route where the underlying sectoral legislation allows reliance on harmonized standards.
The machinery sector receives separate treatment. Machinery Regulation (EU) 2023/1230 is moved from Section A to Section B of Annex I to the AI Act framework. The result is that AI-enabled machinery will not be subject to the AI Act’s high-risk requirements directly in the same way as Section A products. Instead, the Commission must adopt delegated acts under the Machinery Regulation to add health and safety requirements reflecting the relevant AI Act high-risk requirements, with those acts applying by 2 August 2028.
The regulation gives the AI Office exclusive supervisory and enforcement competence for certain AI systems based on general-purpose AI models where the model and system are developed by the same provider or within the same undertaking, subject to specified exceptions. It also gives the Commission market surveillance authority powers where an AI system qualifies as, or is integrated into, a very large online platform or very large online search engine under the Digital Services Act.
🇪🇺 EDPB Updates OSS Case Digest on GDPR Rights to Object and Erasure
The European Data Protection Board has published an updated One-Stop-Shop thematic case digest on the GDPR right to object under Article 21 and right to erasure under Article 17. The digest reviews final One-Stop-Shop decisions available in the EDPB public register, including decisions adopted up to January 2026.
The updated digest covers 551 final decisions relating to Article 17 and 80 decisions relating to Article 21. The EDPB notes that many cases were not severe breaches, but they reveal recurring operational failures in how organizations receive, classify, authenticate, process, and record data subject requests. Article 17 cases peaked in 2022 and 2023, with Irish-led cases having a significant effect on the overall volume. Article 21 cases showed a more consistent trend across several lead supervisory authorities.
Many failures are not legal interpretation problems but process-design problems. Controllers often failed because of poor internal routing, unmonitored contact addresses, unsynchronized databases, customer-service backlogs, technical errors, or unclear division of tasks between controllers and processors. The digest also stresses that the controller remains responsible for employee mistakes when handling rights requests; internal human error does not excuse non-compliance.
For the right to object, the digest focuses on direct marketing. It confirms that a data subject does not need to use formal legal wording. A general request not to receive further marketing can amount to an Article 21 objection. Controllers must make the right easy to exercise, provide clear information about it, avoid unnecessary steps, and ensure that unsubscribe or objection mechanisms work for all affected recipients, including prospects who do not have customer accounts. No-reply marketing emails may be used, but the message should clearly explain that replies are not monitored and provide an effective alternative route to object.
For the right to erasure, the digest gives particular attention to identity verification. Controllers may ask for additional information where there is reasonable doubt about the requester’s identity, but systematic requests for copies of national identity documents are not acceptable. The EDPB digest treats this as a data minimization issue as well as a rights-handling issue. Authentication must be relevant, appropriate, and proportionate to the data, request, context, and risk. In many cases, less intrusive methods may be sufficient, such as authenticated account areas, service-specific identifiers, account-related questions, or other proportionate verification steps.
The digest also distinguishes between cases where erasure must be carried out and cases where retention may still be justified. Legal obligations, defense of claims, public-interest grounds, fraud prevention, debt-related obligations, PNR retention, public registers, and freedom of expression may justify continued processing in some cases. However, controllers cannot rely on retention obligations too broadly. Where only part of the data must be retained, unnecessary data should still be deleted or moved into appropriate restricted or intermediate storage.
Most cases resulted in amicable settlement, reprimands, dismissal, no violation, or compliance orders rather than fines. The EDPB observes that many controllers remedied issues once supervisory authority involvement began. The digest also points to procedural inefficiency in the One-Stop-Shop mechanism, especially where minor complaints took months or years to close. The new EU procedural rules for GDPR enforcement may reduce some of these delays, including through early resolution and simpler cooperation procedures.
🇪🇺 NIS Cooperation Group Publishes Security Measures Reference Document for NIS2 Entities
In June 2026, the NIS Cooperation Group published Version 1.0 of its Reference document on security measures for entities under NIS2, together with a mapping table linking the document’s high-level cybersecurity objectives to national frameworks and international standards. The document is addressed to entities subject to Directive (EU) 2022/2555, especially organizations operating across more than one Member State and non-EU organizations seeking to understand the EU approach to NIS2 cybersecurity risk-management measures.
The reference document does not replace national implementing laws, supervisory guidance, or sector-specific requirements. Entities must still determine which Member State regime applies to them and follow the guidance of the relevant competent authority. NIS2 is a minimum-harmonization directive: Member States may adopt stricter or more detailed cybersecurity requirements, and national approaches already differ in structure, terminology, assurance levels, audit expectations, and treatment of essential and important entities.
The document focuses on Articles 20 and 21 of NIS2. Article 20 concerns governance and management-body accountability. Article 21 requires essential and important entities to take appropriate and proportionate technical, operational, and organizational measures to manage risks to the security of network and information systems. The reference document translates those obligations into 14 thematic areas, including management commitment, security policy, risk management, incident handling, business continuity, supply chain security, secure acquisition and development, effectiveness testing, cyber hygiene and training, cryptography, human resources security, access control, asset management, and physical and environmental security.
A key point is that the document treats NIS2 compliance as a governance and risk-management exercise, not as a narrow technical checklist. It repeatedly relies on a risk-based approach: measures should reflect the entity’s exposure to risk, size, likelihood and severity of incidents, and potential societal and economic impact. It also follows an all-hazards approach, meaning that security planning should address not only cyberattacks but also system failures, human error, physical access, utilities failures, fire, flood, and other environmental events that may affect availability, authenticity, integrity, or confidentiality.
The accompanying mapping table correlates the high-level objectives with horizontal standards and frameworks, including ISO/IEC 27001:2022, ISO/IEC 27002:2022, IEC 62443, and NIST Cybersecurity Framework 2.0, as well as selected national frameworks. The table warns that the mapping is not an equivalence assessment. It identifies relevant relationships between frameworks but does not conclude that compliance with one standard automatically satisfies another. This is a sensible caveat: organizations may use existing ISO, NIST, IEC, or national framework work to support NIS2 implementation, but they still need a jurisdiction-specific gap assessment.
The reference document also distinguishes its role from Commission Implementing Regulation (EU) 2024/2690. Entities covered by that Implementing Regulation, including certain digital infrastructure and digital service providers, must comply with the Regulation’s technical and methodological requirements.
The document gives a common vocabulary for discussing NIS2 security measures across Member States, even where national laws use different structures. This may help legal, compliance, and security teams organize internal control libraries, map existing security programs to national NIS2 requirements, and prepare evidence for supervisory engagement. It may also reduce duplication where entities already maintain an ISMS or use frameworks such as ISO/IEC 27001, NIST CSF 2.0, or IEC 62443 for OT environments.
🇪🇸🇧🇪Spanish and Belgian DPAs Issue GDPR Guidance for Video Game Industry
In June 2026, the Spanish Data Protection Agency and the Belgian Data Protection Authority published Recommendations and best practices for data protection in video games, a detailed GDPR guidance document for organizations involved in the video game ecosystem. The guidance is aimed at hardware suppliers, creators, designers and developers, development technology providers, publishers, and storefronts. It addresses privacy risks across the full lifecycle of a game: pre-production and production, release, post-production, and end-of-life.
The document treats video games as data-intensive digital services. It notes that modern games process direct identifiers, pseudo-identifiers, metadata, telemetry, communications data, payment data, biometric data, location data, and behavioral inferences. The DPAs emphasise that GDPR protections apply not only where a player’s real name or email address is processed, but also where a player can be singled out through identifiers, persistent IDs, device data, behavioral patterns, or gameplay profiles.
A central concern is gameplay telemetry. The guidance describes telemetry as continuous monitoring of player behavior and performance, often capturing actions, decisions, communications, movement, timing, progression, purchases, device data, and, in some environments, biometric or sensor-derived data. The DPAs warn that this data can support behavioral inference, including predictions about skills, emotions, personality traits, financial status, consumption habits, age, health, or vulnerability to particular game mechanics. These inferences can be used for personalization, monetization, fraud prevention, content moderation, or engagement optimization.
The guidance is particularly important for free-to-play, freemium, cloud, online, AR/VR, and AI-driven games, where data collection may be continuous and where monetization often depends on profiling, targeted offers, behavioral segmentation, advertising, or microtransactions. The DPAs warn against vague purposes such as “improving the player experience” and expect controllers to identify concrete purposes, such as bug detection, difficulty balancing, matchmaking, fraud prevention, or specific forms of personalization.
GDPR roles (controller and processor) must be assessed per processing activity, not by industry label. A publisher may be a controller for publisher-wide accounts and behavioral profiles, while a studio may be a processor for telemetry collected only under the publisher’s instructions. A development technology provider may be a processor for hosted analytics, but a controller where it reuses telemetry or profiling data across clients. Storefronts and hardware suppliers may be controllers for platform accounts, launcher telemetry, recommendations, cross-title profiling, and joint campaigns.
Unless a game is clearly and demonstrably adult-only, the DPAs expect actors to assume that children may be present and design accordingly. This includes age-appropriate interfaces, parental consent mechanisms where consent is relied upon, default restrictions on social features, safeguards for voice and chat, controls on friend requests, spending limits, guardian dashboards, and restrictions on monetization-oriented profiling. The document also flags loot boxes, time-limited offers, social pressure, cosmetics, scarcity mechanics, and addictive design patterns as areas requiring careful GDPR and fairness analysis.
The DPAs encourage local-first processing, minimized telemetry schemas, strict separation between safety or functional profiles and monetization profiles, default-off settings for optional analytics and profiling, short retention windows, and clear data dictionaries. They also recommend telemetry catalogues, privacy labels, player-facing privacy centres, granular consent flows, and in-game rights-management interfaces.
The guidance warns against purpose creep as games evolve through patches, seasonal events, new analytics, anti-cheat tools, monetization experiments, and new third-party integrations. Controllers are expected to review whether telemetry fields and behavioral models remain necessary, update records of processing, reassess DPIAs, monitor vendors and sub-processors, and refresh consent where processing materially changes. The guidance also addresses end-of-life duties, including advance notice to players, deletion or anonymization of account data, telemetry and behavioral profiles, and clear rights-exercise options before shutdown.
🇮🇪 Ireland NCSC Publishes AI Cyber Security Risk Assessment and Public Sector Deployment Guidelines
Ireland’s National Cyber Security Center has published two documents for organizations adopting AI: the 2026 NCSC AI Cyber Security Risk Assessment: Public Sector Deployment and Securing AI Adoption in the Public Sector: Cyber Security Guidelines for AI Deployments. The documents are aimed mainly at Irish public sector bodies, but the NCSC notes that they may also be useful for other sectors deploying AI.
The risk assessment sets out the threat landscape. The guidelines translate that assessment into a lifecycle-based control framework covering design, development, deployment, maintenance, and end-of-life. The NCSC frames both documents as part of Ireland’s wider public sector AI adoption package, alongside the Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalization’s responsible AI guidance, the EU AI Act, GDPR, NIS2, the Data Protection Commission’s AI and data protection guidance, and the Cyber Fundamentals Framework.
The NCSC identifies increased data movement, a wider attack surface, changing model behavior, supply chain exposure, and the possibility that vulnerabilities may emerge after deployment. This is a marked departure from traditional software assurance: AI security is treated as a continuing lifecycle obligation rather than a one-off pre-launch review.
The risk assessment identifies several assets requiring specific attention: citizen and classified data, identity and access management systems, ICT and cyber security infrastructure, AI models and artefacts, AI agents, operational processes, and vendors. Agentic AI receives particular attention because agents may hold elevated credentials, connect to databases or APIs, execute actions at scale, and create lateral movement or data exfiltration risks if compromised.
The NCSC also lists the main AI-specific threat types that public sector bodies should consider. These include direct and indirect prompt injection, data poisoning, model poisoning, model inversion, model extraction, supply chain compromise, excessive agency, system prompt leakage, and unbounded consumption. These risks are then mapped across the AI lifecycle: missing threat models and unclear governance in design; unvetted components, insecure training environments, and weak provenance in development; exposed APIs and weak IAM in deployment; poor monitoring and slow patching in maintenance; and orphaned datasets, logs, model weights, or other AI artefacts at end-of-life.
The accompanying guidelines provide seven operational principles. Public sector bodies are expected to build trust and security into the design phase, maintain traceability of AI assets, address supply chain assurance, conduct rigorous testing and validation, support accountable and explainable operation, maintain continuous monitoring and incident response, and safely retire AI artefacts when systems are decommissioned. The document expressly recommends reading the guidelines together with the risk assessment and implementing them within an overarching cyber security governance system such as CyFun.
The NCSC links AI deployment to EU AI Act cyber security and robustness requirements, GDPR obligations for personal data, and NIS2 risk management and incident reporting duties.
Two practical scenarios are included. The first concerns a browser-based AI productivity assistant used by staff for user-initiated document work. The recommended controls include acceptable use rules, SSO and MFA, vendor due diligence, training before access, audit logging, shadow AI monitoring, and confirmation that submitted content is not used for model training. The second scenario concerns a public-facing AI chatbot and internal caseworker assistant built by a department. The controls are more extensive: separated security zones, public and internal data scopes, threat modelling, hardened infrastructure, ingestion controls, red teaming, role-based access, kill switches, vulnerability disclosure, monitoring for jailbreak attempts, and formal decommissioning.
RIPD Paper Calls for Specific Rules on Neurodata and Non-Medical Neurotechnology
The Ibero-American Data Protection Network has adopted a June 2026 reference document on the regulatory challenges raised by neurodata and neurotechnologies outside the medical field. The paper focuses on consumer, workplace, education, entertainment, advertising and other non-clinical uses, where neurotechnology may collect, infer or act upon information linked to brain activity and the nervous system.
Neurodata may already be personal data where it relates to an identified or identifiable person, but the paper argues that this is not enough. Because neurodata can reveal or support inferences about cognitive states, emotions, behavior, health, identity and autonomy, the document proposes treating neurodata as a special category of personal data, with protections comparable to health, genetic, biometric, religious or philosophical-belief data.
The document proposes prohibitions on certain types of neuroprocessing, such as manipulative or deceptive neuroprocessing, exploitation of vulnerable groups, emotion inference in employment or education, neuroprocessing aimed at predicting criminal conduct, and non-medical neuroprocessing involving children or other vulnerable persons. It also proposes limits on legal bases: legitimate interests should not support commercial, advertising or personalization uses; contract necessity should not be used to make neurodata processing a condition of access to wellness, entertainment or productivity services; and consent should not be valid where neuroprocessing can stimulate, modulate, alter or manipulate the individual’s behavior.
The paper treats consent as structurally fragile where there is information asymmetry, imbalance of power, uncertainty about future inferences, or technical capacity to influence the individual’s behavior. This is particularly relevant for employers, schools, gaming platforms, wellness-device providers, neuromarketing companies and AI developers using biosignals or neural signals to infer attention, fatigue, emotion, stress or intent.
The paper also links neurodata regulation to AI governance. Where AI systems are used to decode or infer meaning from neurodata, the document calls for explainability at several levels: data acquisition and preprocessing, feature extraction and model operation, and the final inference or result. It warns against categorical statements such as “you are anxious” or “you lied” unless supported by rigorous scientific evidence, and instead calls for confidence intervals, uncertainty explanations, limitations notices and mechanisms to record which model, dataset and parameters produced a particular inference.
The proposed approach would also strengthen data protection impact assessment obligations. The paper suggests that neuroprocessing, neurodata processing, and systems that enable neurodata inference should generally be treated as high-risk processing. Controllers would need to justify necessity, suitability and proportionality, assess risks to fundamental rights, apply privacy-enhancing technologies where appropriate, and avoid creating large, identifiable neurodata repositories unless strictly justified.
The paper treats neurotechnology security as a matter of integrity, availability and physical or mental safety. For brain-computer interfaces and neuromodulation systems, interference with data or device function may affect the user directly, not merely expose information. The document therefore calls for robust security protocols, limits on connectivity and interoperability, and attention to attack scenarios involving neurostimulation or neural inhibition.
🇪🇪 Estonia Plans Digital Identities for AI Agents
Estonia’s government announced on 17 June 2026 that it will move forward with creating official digital identities for AI agents, described as “AI ID codes.” The proposal was agreed by the Eesti.ai advisory board, established on the initiative of Prime Minister Kristen Michal, and backed by the Prime Minister. The stated objective is to allow AI agents to act on behalf of individuals, companies, or organizations within defined, controllable, verifiable, and auditable limits.
If an AI assistant is used to prepare a declaration, compile a report, interact with an information system, or initiate a transaction, the system must be able to distinguish the agent from the person or organization it represents. It must also record the scope of the authority granted to the agent and preserve accountability for the underlying action.
An AI agent could be authorized to perform only specific functions, such as viewing data, preparing a document, drafting a payment, or acting within a set financial limit.
The announcement does not yet set out legislative text, implementation deadlines, or a detailed technical standard.
🇪🇺🇺🇸 U.S. Supreme Court Ruling Adds New Risk to EU–U.S. Data Privacy Framework
On 29 June 2026, the U.S. Supreme Court decided Trump v. Slaughter, holding that the Federal Trade Commission’s statutory for-cause removal protection is unconstitutional. The Court ruled that the FTC exercises executive power, including rulemaking, investigations, administrative enforcement, and litigation, and that Commissioners performing those functions must be removable by the President at will. The decision overrules, at least as applied to the modern FTC, the protection previously recognized in Humphrey’s Executor.
The judgment does not concern privacy law, the GDPR, or international transfers directly. Its significance lies in the role the FTC plays under Commission Implementing Decision (EU) 2023/1795, the adequacy decision for the EU–U.S. Data Privacy Framework. The Commission’s decision states that an “independent supervisory authority” with powers to monitor and enforce data protection rules should be in place, and then describes the FTC as an independent authority whose Commissioners serve seven-year terms and may be removed by the President only for inefficiency, neglect of duty, or malfeasance in office. That removal protection is the precise statutory feature the Supreme Court has now held unconstitutional.
noyb, the Vienna-based European privacy rights organization founded by Max Schrems, has been central to the litigation that invalidated both the Safe Harbor and Privacy Shield transfer frameworks. In its 30 June 2026 letter to the European Commission, noyb argues that the FTC cannot continue to serve as the independent public enforcement authority on which the adequacy decision relies. It also argues that private dispute resolution bodies and sectoral bodies such as the Department of Transportation cannot replace the FTC’s broad horizontal role, and that the same logic may affect other executive oversight bodies relevant to the framework.
The 2023 adequacy decision was adopted after Schrems II and relies not only on the DPF Principles for certified companies, but also on Executive Order 14086 and the Data Protection Review Court mechanism for U.S. signals intelligence redress. The Commission treated these arrangements as part of the answer to the CJEU’s concerns about necessity, proportionality, and effective redress. noyb now argues that a redress body established inside the executive branch by executive order cannot provide independence if U.S. constitutional law gives the President ultimate control over executive bodies.
🇺🇸 NIST Updates Guidance on Security, Privacy and Supply Chain Risk Management Plans
On 26 May 2026, NIST approved Special Publication 800-18r2, Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems, published in June 2026. The document supersedes NIST SP 800-18r1 from February 2006 and updates federal guidance on system planning for the modern risk environment.
The publication is primarily relevant to U.S. federal agencies, which must develop and maintain system plans under OMB Circular A-130. Private businesses may use the guidance voluntarily to structure their own security, privacy and supply chain risk management documentation.
NIST now treats three planning documents as a connected set of “system plans”: the system security plan, the system privacy plan, and the cybersecurity supply chain risk management plan. These plans are intended to describe the system’s purpose, operational status, selected controls, control implementation details, responsible personnel, system components, data flows and risks arising from information sharing outside the system boundary.
NIST encourages organizations to consider automated collection methods, central repositories, dashboards and machine-readable plan data instead of relying only on traditional document-based system plans. Static plans often fail to keep pace with modern development, cloud services, continuous monitoring, external integrations and changing supplier risk.
The guidance also gives privacy a more operational role. A system privacy plan is not limited to confidentiality controls. It should address privacy risks from data processing itself, including risks linked to predictability, manageability and disassociability. This is important because a system may be secure in the traditional CIA sense while still creating privacy risks through excessive collection, opaque data use, profiling, unnecessary sharing or weak individual-rights processes.
The Cybersecurity Supply Chain Risk Management (C-SCRM) element is equally significant. NIST expects system-level supply chain planning to address risks from COTS (Commercial off the Shef) products, vendor-managed services, cloud services, open-source dependencies, component provenance, supplier monitoring, SBOMs and supplier-related incidents.
G7 Privacy Authorities Set Common Priorities on Age Assurance, Connected Devices, Smart Glasses, and Agentic AI
The G7 Data Protection and Privacy Authorities met in Paris on 25–26 June 2026 under the CNIL presidency and adopted a communiqué addressing several technology issues now moving from policy discussion into regulatory supervision: children’s online protection and age assurance, connected home devices, smart glasses, agentic AI, enforcement cooperation, and cross-border data flows. The meeting also included representatives from the Global Privacy Assembly, GPEN, APPA, AFAPDP, Korea’s PIPC, the Council of Europe Convention 108 Committee, and the OECD, reflecting a broader effort to align privacy regulators beyond the G7 framework.
The G7 statement on privacy-preserving age assurance accepts that age assurance may be appropriate where risks to children cannot be addressed by less intrusive measures, or where laws impose minimum-age rules for services or restrict children’s access to certain content. But the statement rejects indiscriminate age checks. Age assurance should be limited to specific contexts, should not become a general-purpose identification layer, and should not be used to track, profile, or monitor users.
Regulators are drawing a line between proportionate, risk-based age assurance and systems that collect more identity data than necessary. The G7 principles emphasize purpose limitation, collection and retention limitation, effectiveness, transparency, privacy by design, and security. Providers using third-party age assurance vendors will need to assess what data is collected, whether the result is reused, how long data is retained, and whether children receive clear explanations.
The joint paper on connected home devices and children’s privacy applies similar principles to smart TVs, voice assistants, connected toys, and other internet-enabled devices used in the home. The authorities focus on online tracking technologies, including cookies, tracking pixels, ETags, device fingerprinting, and automated content recognition. The concern is that these devices operate in the home, where privacy expectations are high, and may monitor the behavior of children, household members, and visitors without adequate awareness.
The paper sets out practical expectations for manufacturers, software providers, and actors in the online tracking ecosystem. Geolocation and behavioral advertising should be off by default. Privacy notices should be clear, age-appropriate, and adapted to devices without screens. Consent mechanisms should avoid deceptive design patterns. Children and parents should have meaningful controls over collection and use. Devices that listen or record should provide conspicuous notice when data collection occurs.
The smart glasses compendium identifies the shift from visible, experimental devices toward discreet glasses that can look like ordinary eyewear while embedding cameras, microphones, sensors, and AI capabilities. The privacy risks are not limited to the wearer. Bystanders may be recorded without knowing it; images, voices, location data, biometric signals, and behavioral inferences may be collected; and recordings may be reused to improve AI systems.
The compendium also highlights unresolved questions around transparency and consent. Traditional cues for recording, such as holding up a phone, may be absent. LED indicators may not provide meaningful notice. In public or semi-public spaces, it may be practically impossible to obtain valid consent from everyone captured. In the EU and UK context, the document also notes that household-use exemptions may fall away where recordings are shared publicly, and that smart glasses may trigger ePrivacy or PECR rules as terminal equipment.
***
Direct your questions to groundcontrol@kepler.consulting.
Until the next transmission, stay secure and steady on course. Ground Control, out.

