Enforcement & Fines

OAIC Opens Investigation into the HeyCyan Smart Glasses App

OAIC Opens Investigation into the HeyCyan Smart Glasses App

On 7 October 2026, the Office of the Australian Information Commissioner (OAIC) announced that it had opened a formal investigation into Shenzhen Qingcheng Future Technology Co. Ltd. The company developed HeyCyan, the companion mobile app used by a number of lower-cost smart glasses, including Anko smart glasses sold by Kmart in Australia and products offered through Big W Marketplace, Amazon and other retailers.

Shenzhen Qingcheng did not respond to the OAIC’s preliminary inquiries. The OAIC said that the absence of a response, together with concerns raised by third-party technical analysis and the company’s privacy policy, prompted the formal investigation. The OAIC can now use compulsory information-gathering notices to examine how the devices record information, which entities can access it and where it is stored. At this stage, the OAIC has not found that Shenzhen Qingcheng or HeyCyan breached Australia’s Privacy Act 1988.

The investigation concerns the provider of the companion software. Photos, video and sound recorded by smart glasses may remain on the glasses or the wearer’s phone, or may pass through the app to a company backend or third-party service. Those different processing arrangements affect which entities collect or hold personal information and how the Australian Privacy Principles (APPs) apply.

HeyCyan’s Functions and the Scope of the OAIC Investigation

The OAIC has monitored smart glasses since early 2026. In August 2026, the Australian Attorney-General asked the Privacy Commissioner to examine the privacy implications of these devices. The OAIC then made preliminary inquiries of entities involved in the hardware, software and retail chain, including Meta, Google, Kmart, BDI Technology and Shenzhen Qingcheng. It asked them to explain how the devices record information, who can access the data and where it is stored.

According to the investigation announcement, connecting HeyCyan to smart glasses enables functions such as playing music, answering calls and using HeyCyan’s voice assistant. Some functions involve information gathered by the glasses being collected through HeyCyan for processing. The Google Play listing also describes photo and video import, voice control, calling, messaging and music-service connections. HeyCyan’s privacy policy describes voice translation, AI question answering, image understanding and real-time conversation functions.

These functions suggest three broad processing arrangements:

Processing arrangementProduct activityFacts to verify
Processing on the glasses or phoneImages and recordings remain on the glasses or are imported to the wearer’s phoneWhether the companion software provider can access or control the recordings; whether the information remains held by an individual for private affairs
App processingThe app imports media, binds an account, configures the device, checks firmware or receives diagnosticsWhether the app receives or caches media; whether it creates account, device or usage records; which entity controls those records
Backend and third-party processingSpeech recognition, translation, image understanding, AI question answering or real-time conversationsWhich backends, cloud services or SDKs receive the content; each party’s purpose, retention period, access rights and processing location

The APP 3 guidelines take a broad approach to “collection”. An entity may collect personal information when it acquires the information for inclusion in a record, even if it holds the information for only milliseconds. The actual processing arrangement must also be examined where an entity functions as a router or hub. Two entities may collect the same personal information. A review of the software provider should therefore cover local files, transient transmission, backend records and third-party services. Persistent storage on the software provider’s own servers is only one relevant fact.

Responsibilities of Software Providers, Hardware Companies and Retailers

In its regulatory blog, the OAIC explained that the Privacy Act 1988 applies to entities that handle personal information. A company does not automatically become subject to the Act merely because it sells or manufactures hardware with a camera. A retailer that only sells a device, or a manufacturer that does not collect or hold information generated by the device, may not have the same APP obligations as the software provider.

Whether the companion software provider has APP obligations depends on whether the software receives, holds or controls information collected by the device. Where those conditions are met, the provider must comply with the applicable requirements for collection, use, disclosure and security. Outsourcing storage or processing to a cloud provider does not necessarily prevent the company from “holding” the information. Under the OAIC guidelines, a company may still hold a record that it does not physically possess if it has the right or power to access, amend or otherwise control it. Depending on the access and control rights established by contract, multiple entities may be regarded as collecting or holding the same personal information.

A retailer’s obligations under the Privacy Act 1988 likewise depend on whether it collects or holds the relevant personal information. The Privacy Commissioner has written to retailers selling HeyCyan-enabled devices and asked them to consider whether it remains appropriate to offer those products. The OAIC also noted that consumers and shareholders may expect retailers to conduct privacy due diligence on connected and surveillance devices. Businesses may face reputational harm, and regulatory powers legislation also provides for accessorial liability where the relevant conditions are met. Retailers sourcing private-label products should review the companion app and its backend services as part of the hardware procurement process.

Collection of and Notice to Bystanders

Wearers choose to buy the glasses, install the app and accept its terms. Bystanders, children, colleagues and customers do not use the product, but their images, voices and location information may be recorded by the device and processed by the companion software or third-party services. Companies therefore need to assess information about wearers separately from information about people who are recorded.

Whether an image or recording is personal information depends on whether an individual is reasonably identifiable. Name badges, school or work uniforms, companions, a name spoken in a recording and precise location can all connect a recording to a particular person. A platform that already holds account data, social connections or location history may also use that information to identify someone in an image or recording. In recent determinations, the OAIC explained that “reasonably identifiable” is not limited to knowing a person’s legal name. Information may meet the threshold if it can single out or distinguish someone in a way that affects the person’s rights or interests.

For ordinary personal information, the Privacy Act 1988 does not make consent a universal precondition for collection. APP 3 requires an organisation to collect only information that is reasonably necessary for its functions or activities and to collect it by lawful and fair means. The OAIC’s updated 2026 guidance explains that proportionality is implicit in reasonable necessity and requires a data-minimisation approach.

Biometric information is subject to a higher standard. If smart glasses extract facial features for automated identification or verification, the processing may involve sensitive information for which consent is required. The OAIC has also expressly stated that it has not yet identified facial-recognition functions in smart glasses available in the Australian market. Recording an image of a face and generating or using a biometric template are distinct processing activities.

APP 5 requires an APP entity that collects personal information to take reasonable steps to notify the individual of matters including the fact and purpose of collection, the entity’s usual disclosures and likely overseas disclosures. A wearer can receive information through the app interface, but a bystander will not ordinarily interact with the app. A recording indicator may show that the glasses are recording, but it does not by itself explain who operates the backend, why the information is processed or whether it is disclosed overseas. The OAIC did not prescribe a single form of notice in its regulatory blog and said that the obligation must be assessed in the circumstances of collection.

The wearer’s acceptance of the terms creates an arrangement between the wearer and the product provider. It does not contain an authorisation given by a bystander. The software provider must still assess whether collecting bystander information is reasonably necessary, whether the means of collection are fair and what notification steps are required.

HeyCyan’s App Store Label and Privacy Policy

As of 8 October 2026, the “Data safety” section of HeyCyan’s Google Play listing stated “No data collected” while also stating that the app may share app information and performance data with third parties. Google notes that the developer supplied this information.

The HeyCyan privacy policy linked from Google Play lists account information, audio recordings and transcripts, location, IP address, device information, usage records and fault logs. It also states that some AI, speech-translation and real-time conversation functions involve Microsoft, AWS, Alibaba Cloud and Agora. Depending on the function, processing may be local, transient or involve persistent storage. HeyCyan states that its backend does not persistently store some AI requests and responses.

The app-store label and privacy policy organise information differently. Their wording alone does not establish what the app actually collects, and it is not sufficient to establish a breach. Product configuration, network traffic, backend logs and supplier contracts should clarify:

  • which versions, functions and data categories are covered by Google Play’s “No data collected” statement;
  • which media, voice, location and device information remains local and which passes through HeyCyan’s backend;
  • which information Microsoft, Agora and other providers receive, and what processing role each performs;
  • whether transient processing creates security, operational or diagnostic logs, and how long those logs are retained; and
  • which data is affected by account deletion, device unbinding and deletion of local files.

These materials should also be consistent with in-app notices and retail product pages. A privacy policy records the processing practices that a company publicly describes. Network traffic, backend configuration and contracts help verify how the product actually operates. Comparing them allows a company to assess whether its privacy disclosures are complete and accurate.

Compliance Review for Smart Glasses Products

Different smart-glasses functions may use different data paths. Photo import, voice assistants, translation, real-time conversations, firmware updates and fault diagnostics should be reviewed separately. The review should:

  1. record the content, account, device, location and log information processed by each function;
  2. distinguish information about wearers from information about bystanders, and assess whether the individuals are identifiable;
  3. determine the access rights, control rights and contractual roles of the app provider, hardware brand, cloud providers, AI providers and retailers; and
  4. compare local processing, transmission, caching, persistent storage, human access and deletion with the app-store label, in-app notices and privacy policy.

The resulting record can be used to determine the specific requirements of APP 1 on governance and transparency, APP 3 on collection, APP 5 on notification and APP 11 on information security. Security measures should cover access controls, logging scope, SDK permissions, retention periods, deletion mechanisms and the security-update cycle.

On 31 August 2026, the Australian Government released a consultation paper and draft legislation for the second tranche of Privacy Act reforms. The proposal would introduce a “fair and reasonable” test, strengthen consent requirements and provide additional protection for precise location data. These measures are not yet in force. If enacted in their present form, companies offering smart glasses would also need to assess whether processing is fair and reasonable by reference to its scope, genuine user choice, reasonable expectations and potential harm.

The OAIC’s HeyCyan investigation remains in progress. Companies that provide or sell similar products can begin with the three questions used by the OAIC: how the device records information, which entities can access it and where it is stored. Those facts support the next assessment: which entities collect or hold personal information and which existing APP obligations apply.

References

See the OAIC investigation announcement: https://www.oaic.gov.au/news/media-centre/oaic-opens-investigation-into-maker-of-heycyan-smart-glasses-phone-app; OAIC, “Smart glasses under the microscope”: https://www.oaic.gov.au/news/blog/smart-glasses-under-the-microscope; OAIC, “Surveillance wearables – are we through the looking glass(es)?”: https://www.oaic.gov.au/news/blog/surveillance-wearables-are-we-through-the-looking-glasses; OAIC guidance on APP 3, APP 5 and APP 11: https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-3-app-3-collection-of-solicited-personal-information, https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-5-app-5-notification-of-the-collection-of-personal-information, and https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information; the Australian Government’s second-tranche privacy reform announcement: https://ministers.ag.gov.au/media-centre/modernising-australias-privacy-laws-digital-age-31-08-2026; and the HeyCyan Google Play listing and linked privacy policy: https://play.google.com/store/apps/details?id=com.glasssutdio.wear, https://www.qlifesnap.com/heycyan.html.

Related reading