Meta Promised "Designed for Privacy" on Its AI Glasses. Contractors in Kenya Were Watching.
Key Takeaways:
- A class action lawsuit filed March 4, 2026 in the US District Court for the Northern District of California accuses Meta of false advertising and privacy violations tied to its Ray-Ban AI smart glasses
- Plaintiffs allege that footage from the glasses, including intimate footage from bedrooms and bathrooms, was routed to a subcontractor in Kenya without adequate consumer disclosure
- Meta marketed the glasses with the phrase "designed for privacy, controlled by you" while burying the existence of human review in supplemental terms
- Over 7 million pairs were sold in 2025, making this a potential class of millions of affected consumers
- The UK's Information Commissioner's Office has opened a formal inquiry into the same practices
- For Indian businesses building or deploying AI hardware or wearable devices, this case illustrates the compliance floor the DPDP Act 2023 is setting around consent, disclosure, and data pipelines
Somewhere in Nairobi, a contract worker opened a queue of video clips and started labeling objects.
One of the clips showed a woman undressing in a bedroom. The footage had been captured by her partner's smart glasses, transmitted to Meta's servers, and routed to a subcontractor for AI training purposes. The partner had no idea this was happening. Neither did she. Nobody had told either of them.
That sequence of events, first reported by Swedish newspaper Svenska Dagbladet, is now at the center of a class action lawsuit filed against Meta Platforms and eyewear manufacturer Luxottica of America on March 4, 2026 in the US District Court for the Northern District of California. The case is Bartone v. Meta Platforms Inc., No. 3:26-cv-01897.
The lawsuit does not just allege a privacy violation. It alleges that Meta built its entire marketing strategy around a promise it knew it could not keep.
What Meta Said vs. What Was Actually Happening
Meta advertised its Ray-Ban AI glasses with language that was unambiguous to any reasonable consumer. The phrases included "designed for privacy, controlled by you" and "built for your privacy." Both plaintiffs, Gina Bartone of New Jersey and Mateo Canu of California, say they relied on those representations and would not have purchased the glasses had they known the truth.
The truth, according to the complaint filed by Clarkson Law Firm, is this:
When users engage the glasses' multimodal AI features, including the Live AI function that lets the glasses answer questions about the surrounding environment, the footage captured is not stored locally. It is transmitted to Meta's servers. From there, it enters a review pipeline staffed by human contractors at a subcontractor facility in Kenya. Those contractors view and label the footage to train Meta's AI models.
Meta's position, stated through spokesperson Christopher Sgro, is that this process only applies when users actively share content with Meta AI, and that footage otherwise stays on the device. The complaint disputes this characterization. As Engadget noted, there is no way to use the glasses' multimodal features without sharing the captures of your surroundings with Meta. The opt-out is functionally opt-out of the product's core AI capabilities entirely.
Where was the disclosure? A version existed, buried in Meta's UK AI terms of service. The US version of Meta's policy stated only that "Meta will review your interactions with AIs, including the content of your conversations with or messages to AIs, and this review may be automated or manual (human)." No mention of human contractors. No mention of cross-border data transfer to Kenya. No mention that intimate footage from inside users' homes could end up in a labeling queue.
"No reasonable consumer would understand the slogan 'designed for privacy, controlled by you' to mean deeply personal footage from inside their homes would be viewed and catalogued by human workers overseas," the complaint stated.
The Scale of the Problem
More than 7 million pairs of Meta Ray-Ban AI glasses were sold in 2025 alone. That figure appears in the complaint not as a statistic but as a measure of potential harm. Every person who used the Live AI features while sharing content with Meta AI had footage enter that review pipeline. The vast majority had no idea.
The complaint describes the categories of footage reviewed by contractors: financial information, sexual activity, bathroom use, and other content captured in private settings. One Swedish news report described a specific case in which bedroom footage of a woman undressing ended up in a Nairobi data center review queue, footage the couple did not know was being processed externally.
The complaint also raises a broader concern about bystanders. Smart glasses record the world from the wearer's perspective. Every person who appeared in that footage, in hallways, in shared spaces, in family settings, had no opportunity to consent to being captured, transmitted across borders, and reviewed by contractors working for a company they had never interacted with.
This is what the lawsuit describes as transforming a personal device into a "surveillance conduit."
The Legal Framework: What the Complaint Actually Charges
The complaint charges Meta and Luxottica with violations of consumer protection laws across multiple counts.
False Advertising: The core allegation is that Meta's privacy marketing claims were affirmatively false. This is not a case of a company failing to disclose something minor. The complaint argues that the product's central marketing message, privacy and user control, directly contradicted the product's actual data practices.
Privacy Law Violations: The complaint implicates state consumer privacy frameworks, including the California Consumer Privacy Act as amended by the CPRA, which requires clear notice and honoring of user rights around personal data collection and use. If biometric data processing is involved, additional state laws in Illinois and Texas could also be triggered.
Failure to Disclose: The complaint specifically targets the burial of human review disclosures in supplemental legal terms that no ordinary consumer would locate or read before purchase.
Dignitary Harm: The filing argues that the undisclosed pipeline exposes consumers to "unreasonable risks of dignitary harm, emotional distress, stalking, extortion, identity theft, and reputational injury."
The UK's Information Commissioner's Office responded to the Swedish newspaper investigation by opening a formal inquiry, stating: "The claims in this article are concerning. We will be writing to Meta to request information on how it is meeting its obligations under UK data protection law." That inquiry runs parallel to the US litigation.
What This Means for AI Wearables and the Consent Problem
The Meta glasses lawsuit is not the first time this product category attracted legal and regulatory attention. In 2024, Harvard researchers demonstrated that the device's built-in camera could be used to identify strangers in real time through facial recognition. That demonstration preceded any commercial AI glasses review pipeline controversy by more than a year.
The pattern is consistent: AI wearables create a category of ambient, continuous data collection that consumer expectations, legal frameworks, and product disclosures have not caught up with. People understand that their phone camera records when they open the camera app. They do not intuitively understand that wearing a pair of glasses and asking an AI a question about what they are looking at transmits footage of their home to contractors on another continent.
This is the consent architecture problem at the core of this litigation. The product's privacy marketing actively displaced the consumer's ability to seek out the real answer. When a product says "designed for privacy," a reasonable person stops looking for the fine print because they believe the headline.
That is the legal exposure. It is also the design choice Meta made.
Implications Under Indian Law and the DPDP Act 2023
India does not yet have a commercially significant AI wearables market at the scale of the US or Europe, but the DPDP Act 2023 creates a compliance framework that applies to any company processing personal data of Indian citizens, including foreign companies operating consumer technology products in India.
Several provisions of the DPDP Act are directly implicated by the fact pattern in the Meta case.
Notice and Consent: Under Section 5 of the DPDP Act, a Data Fiduciary must give the Data Principal a clear and plain-language notice before or at the time of collecting personal data, specifying what data is collected, the purpose of processing, and the identity of any Data Processors involved. Burying the existence of human contractor review in supplemental AI terms would not satisfy this standard. The DPDP Act requires notice that is "itemised" and written in clear language.
Purpose Limitation: The DPDP Act requires that personal data only be processed for the purpose for which consent was obtained. A consumer who activates an AI feature to ask the glasses a question about the world around them has not consented to their footage being used for AI model training by a third-party subcontractor. These are different purposes. The distinction matters legally.
Cross-Border Data Transfer: The DPDP Act includes provisions governing cross-border transfer of personal data. Transfer of footage to a subcontractor in Kenya without adequate contractual safeguards or user awareness would trigger scrutiny under these provisions once the government notifies the applicable rules.
Bystander Rights: This is the most legally untested dimension. People who appear in footage captured by AI glasses worn by someone else in India are also Data Principals whose data is being processed. The DPDP Act's consent requirements technically apply to their data too, and an ambient recording device that captures bystanders without their knowledge raises real compliance questions that no Indian company building AI hardware should ignore.
For Indian AI hardware developers, the Meta lawsuit serves as a case study in what happens when the marketing layer and the data practices layer do not align. The DPDP Act's penalty framework reaches up to Rs 250 crore for serious violations. The reputational cost of a "surveillance conduit" headline reaching Indian media before a product launch would be measured differently, but no less seriously.
Frequently Asked Questions
Q: What exactly is the Bartone v. Meta lawsuit about?
A: The lawsuit, filed March 4, 2026 in the US District Court for the Northern District of California, alleges that Meta engaged in false advertising by marketing its Ray-Ban AI glasses with privacy promises like "designed for privacy, controlled by you" while operating a data pipeline that routed user footage, including intimate footage from inside homes, to human reviewers at a subcontractor in Kenya. The complaint also names eyewear manufacturer Luxottica of America as a defendant.
Q: Can Indian users of Meta Ray-Ban glasses take legal action?
A: Indian users currently face a different legal landscape than US plaintiffs. The DPDP Act 2023 does not yet have a fully notified enforcement framework and the Data Protection Board has not been constituted as of early 2026. However, depending on the nature of data collected and processed, complaints may also lie under the Information Technology Act 2000 and its rules relating to sensitive personal data. Consulting a qualified cyber law advocate is advisable.
Q: Does the DPDP Act 2023 apply to foreign AI product companies operating in India?
A: Yes. The DPDP Act applies to processing of personal data of individuals in India, regardless of where the Data Fiduciary is located. A foreign company selling AI glasses in India and processing footage from Indian users' surroundings falls within the Act's scope.
Q: What should Indian businesses building AI wearables or similar products do right now?
A: Three immediate steps are advisable. First, audit every data collection event in your product and map it to a consent touchpoint that is visible to the user before or at the time of collection, not buried in supplemental terms. Second, document every Data Processor and subcontractor that touches personal data in your pipeline, and ensure your privacy notice names them or describes them with sufficient specificity. Third, assess whether your product captures data about bystanders who are not users, and determine how you will meet consent obligations for that category of data principal.
Q: What is the UK ICO's role in this matter?
A: The UK's Information Commissioner's Office has opened a formal inquiry into Meta's data handling practices for the Ray-Ban AI glasses following the Swedish newspaper investigation. The ICO has stated it will write to Meta to request information on how it is meeting its obligations under UK data protection law. This is a separate regulatory proceeding from the US class action litigation.
Q: How does this case affect how Indian courts or regulators might view similar AI product cases in future?
A: Indian regulators and courts increasingly look to US and EU case law when interpreting technology-related legal questions. A finding in Bartone v. Meta that ambient AI data collection paired with false advertising is actionable under consumer protection law would build a body of precedent that Indian regulators evaluating the same fact pattern under the DPDP Act and Consumer Protection Act 2019 could draw on. The legal principles around consent, notice, and dignitary harm are consistent across jurisdictions, even if the specific statutes differ.
If your organization is developing AI-powered hardware, wearable devices, or products that collect ambient data in Indian homes or public spaces, understanding your obligations under the DPDP Act 2023 before launch is not optional. The LLM Advocates team advises clients across India on data privacy compliance, AI governance, and digital consumer protection law. Contact us at contact@llmadvocates.com or call +91-8572022292.