Smartwatches have long been part of everyday life in the office. Smartglasses now represent a new generation of wearables that carry cameras, microphones and AI functions directly on the body. This creates new risks for organisations: confidential conversations can be recorded, people can be filmed without their knowledge, and data can be transferred to external clouds. The FDPIC warns of the data protection risks posed by wearables. Organisations should therefore check whether their existing data protection and IT policies are still adequate.
From fitness tracker to workplace risk factor
Smartwatches and fitness trackers have become an integral part of everyday life. At the same time, smart glasses (such as the Ray-Ban Meta Wayfarer) are becoming more powerful and better suited to everyday use. The Federal Data Protection and Information Commissioner (FDPIC) therefore published new guidance on the use of wearables in March 2026. Wearables can do far more than just count steps. Depending on the device, they feature cameras, microphones, GPS, Bluetooth, heart rate monitors, mobile connections and other sensors. Smartwatches can display messages and business notifications. Smart glasses can capture images and sound and, in some cases, process or distribute content directly via the internet. This makes the issue relevant for businesses too.
Why smart glasses are reaching a new level
Not every wearable poses the same risks. From a business perspective, a smartwatch that merely displays the time and step count must be assessed differently from a connected pair of glasses with a camera, microphone and AI functions. Smart glasses are particularly problematic because it may not be immediately obvious to other people whether a recording is in progress. The FDPIC also expressly points this out. Modern connected glasses can record images and sound and, in some cases, transmit the content immediately. This increases the risk that employees, customers, business partners or other individuals may be recorded without being aware of it.
This is not merely a data protection issue. Covert video or audio recordings may, depending on the circumstances, also be relevant under criminal law. The EDÖB refers in particular to Articles 179bis, 179ter and 179quater of the Swiss Criminal Code. For businesses, there is an additional dimension to consider: what happens if smart glasses are worn during an internal meeting? If confidential customer information is visible on a screen? If employees have access to development departments, server rooms or other highly secure areas? Or if conversations with customers or business partners are recorded and potentially transmitted to an external cloud service?
In principle, a smartphone can offer the same functions. The difference, however, lies in the discreet nature and constant availability of the wearable device. It is precisely for this reason that companies should not automatically regard their existing rules as sufficient.
IT regulations should explicitly cover wearables
Many companies already have IT usage regulations, BYOD policies, information security guidelines or rules governing the use of personal mobile phones. Whether these regulations also cover wearables depends on their specific wording. A policy that refers only to ‘mobile phones’, ‘computers’ and ‘tablets’ may give rise to unnecessary questions of demarcation when it comes to smartwatches and smart glasses. A more sensible approach is a technology-neutral definition that also encompasses connected, body-worn devices with recording, communication, storage or sensor functions.
From a business perspective, the key question here is not whether employees are permitted to wear a smartwatch for personal use. Rather, it is necessary to assess which functions of a wearable device pose risks in which work environments, and whether existing internal policies already adequately address these risks. Not every company needs a separate ‘wearables policy’. In many cases, it should suffice to make targeted additions to existing IT, BYOD, data protection and information security policies. You can find more detailed information on BYOD in our article “Bring your own device (BYOD) from a legal perspective”.
Data protection: It is not just the wearer’s data that is relevant
When the term ‘wearables’ is mentioned, one’s first thought is usually of the data relating to the person wearing the device. Fitness trackers and smartwatches can record heart rate, sleep patterns, location or other physical information. Under the Swiss Data Protection Act, health data is classified as personal data requiring special protection. In day-to-day business, however, a different perspective is often more important: wearables can collect data about third parties. Smart glasses, for example, can film employees, record conversations or capture documents and screen content, as the FDPIC warns. Data processing that breaches the principle of transparency may constitute an unlawful infringement of personal rights.
Employers should therefore ensure that the impression is not created that wearing a personal device automatically gives employees the right to record other people or business operations. Particular caution is advised wherever sensitive information is regularly processed – for example, in human resources departments, during internal investigations, at management meetings or when processing health, customer or other confidential data.
Wearables used for employee monitoring may be unlawful
The other side of the issue arises when it is not employees using their own devices, but the employer providing wearables or analysing the data from them themselves. Examples might include smartwatches for recording specific work processes, GPS data for resource planning – for instance in the logistics sector – or other sensor information. In such cases, the responsibility under data protection law shifts significantly. Under Article 328b of the Swiss Code of Obligations (OR), an employer may process personal data relating to employees insofar as this concerns their suitability for the employment relationship or is necessary for the performance of the employment contract. In addition, Article 26 of ArGV 3 protects employees from surveillance and monitoring systems designed to monitor their behaviour in the workplace. The FDPIC also emphasises that technical surveillance must correspond to a genuine need on the part of the employer and must not serve the purpose of monitoring behaviour. In particular, a permissible measure must be proportionate, and the employees concerned must be informed in advance; further information on this can be found in the article ‘Data protection: Monitoring of employees’. This distinction is particularly relevant in the case of wearables, as they can enable particularly detailed data collection. Location, movement or health data can paint a detailed picture of an individual. Companies should therefore not fall into the trap of assuming that data which is technically available may also be used under employment law. Further information on data use can be found in the article “Data as currency – the compatibility of data protection and data use”.
Employee consent is no guarantee
Furthermore, caution is advised when introducing such systems if a company wishes to rely on the consent of its employees. In the context of employee monitoring, the FDPIC points out that consent in the employment relationship must be assessed with caution, as employees may feel pressured and consequently restricted in their freedom of choice. It is therefore always necessary to ask whether the specific data is relevant at all before obtaining the relevant consent. Only once the purpose, necessity and proportionality have been clarified should a decision be made on the specific data protection arrangements.
Taking IT security and trade secrets into account
Wearables are also additional connected devices. The FDPIC points out that many functions of such devices may require processing in a public cloud. AI functions, in particular, may require external computing power.
This therefore raises a practical question for businesses: Where does the information collected by a wearable during operation end up?
This is particularly relevant in the case of smart glasses. If image, audio or other data is transmitted to the manufacturer’s services or to third-party providers, a seemingly private device can become an additional interface between the company and an external infrastructure.
The protection of personal data may be compromised, particularly in the case of sensitive data such as health information. It follows that the more sensitive the activity or the business area concerned, the more likely it is that technical or organisational restrictions may be justified.
No blanket ban – but risk-based rules
However, these risks do not mean that companies should ban all wearables in the workplace. A standard smartwatch in the office typically presents a different risk profile to smart glasses with an activated camera during a confidential meeting. It should also be borne in mind that wearables can help to provide targeted support to people with disabilities in their day-to-day working lives. Internal company guidelines should take these differences into account. It is crucial that restrictions are justified in a comprehensible manner, are proportionate in their application, and are communicated transparently to employees.
What companies should do now
The new guidance from the FDPIC provides a good opportunity to review a company’s own wearable governance. Companies should first identify which internal regulations already exist and whether wearables are clearly covered by them. It is then advisable to carry out a function-based risk analysis. It is not the product name ‘smartwatch’ or ‘smartglasses’ that should be the deciding factor, but rather the technical capabilities: camera, microphone, location tracking, local storage, cloud connectivity, AI functions and access to business systems. Particular caution is required when dealing with data requiring special protection under Article 5(c)(2) of the Data Protection Act (DSG), such as health data. On this basis, existing IT or BYOD policies can be amended. Relevant guidelines for working from home are also important; for more on this, see the article “Data Protection and IT Security When Working from Home”. In particular, these should set out prohibitions on recording, permitted connections to company systems, rules for confidential areas and a procedure for security incidents. Raising staff awareness is at least as important. A policy is of little use if employees do not recognise why smart glasses in a meeting room pose different risks to a conventional wristwatch.
Conclusion: The next data protection issue is worn on the body
Wearables are no longer a topic for the future. Smartwatches have long been part of everyday life, and with increasingly powerful smart glasses, a new class of devices is making its way into offices and workplaces. Companies therefore do not necessarily need to create a new set of rules. However, they should check whether their existing IT, BYOD, data protection and information security policies are still up to date in terms of technology. Wearables with cameras, microphones, location tracking, cloud and AI functions deserve particular attention. The more discreetly such devices can collect and transmit information, the more important clear internal guidelines become. The correct answer is rarely either complete freedom or a blanket ban. What is needed instead is risk-based wearable governance: which devices are permitted to do what – and where? Companies that answer this question today will not have to revise their rules only when the first pair of smart glasses appears at a confidential executive meeting or when the technology evolves towards smart contact lenses or body chips.
Sources
- FDPIC, Wearables: Smartwatches, fitness trackers, smart glasses
- FDPIC; The new Data Protection Act from the FDPIC’s perspective
- Articles 5, 6 & 7 of the Federal Data Protection Act
- Art. 179bis et seq. Swiss Criminal Code
- Federal Office for Cyber Security (BACS), Measures to protect IoT devices
- FDPIC; Disclosure of patient data