Norway's consumer watchdog has urged retailers to halt sales of smart glasses equipped with facial recognition capabilities—devices the Norwegian press has bluntly dubbed "Pervert Glasses." The move signals a paradigm shift from regulating how these devices are used to whether they should be sold at all.
This isn't a minor compliance note. It's the opening salvo in what could become Northern Europe's first comprehensive ban on covert surveillance wearables. And for anyone tracking the intersection of consumer tech and regulatory enforcement, the Norwegian playbook is worth dissecting.
The Legal Labyrinth: GDPR, Criminal Code, and the EEA Factor
Norway operates within a dense legal matrix that makes this far more complex than a simple product recall. As an EEA member, the General Data Protection Regulation applies directly. Facial recognition falls under Article 9's special category provisions—biometric data processed for unique identification is presumptively prohibited unless explicit exceptions apply.
The Norwegian Personal Data Act (Personopplysningsloven) supplements GDPR domestically. But the more interesting legal weapon sits in the Criminal Code. Section 267a, effective since 2019, explicitly criminalizes secret photographing of individuals. Smart glasses that record without visible indicators arguably trigger this provision immediately.
Here's the hidden layer most coverage misses: retailers selling these devices could face criminal complicity arguments, not just administrative fines. The Norwegian consumer authority's urging creates a documented awareness trail—ignoring it while continuing sales undermines any "we didn't know" defense later.
This regulatory pivot also needs to be read against the EU Artificial Intelligence Act's trajectory. The AI Act classifies real-time remote biometric identification as "unacceptable risk"—effectively banning it. Norway, despite not being an EU member, will likely adopt the AI Act through EEA incorporation. The current smart glasses push may be domestic groundwork for that larger framework.
The Enforcement Architecture: Dual-Track Pressure
Norway's data protection authority (Datatilsynet) has been escalating enforcement. In 2021, it fined a retail company 100,000 NOK for facial recognition use, explicitly stating that the technology's intrusiveness makes it difficult to satisfy GDPR's legitimate basis requirements in most scenarios.
The current move represents an escalation: from punishing usage to blocking distribution channels. This is a structural shift worth understanding.
What's less visible is the inter-agency coordination. The consumer authority (Forbrukertilsynet) and Datatilsynet appear to be running a dual-track enforcement strategy—consumer protection law on one side, data protection law on the other. This coordinated approach is relatively novel in Norwegian regulatory practice and could become the template for future tech regulation.
The consumer authority lacks direct fining power. But it can petition the Market Council (Markedsrådet) for injunctions. Violating those injunctions triggers daily coercive fines (tvangsmulkt)—potentially hundreds of thousands of NOK per day. The accumulation effect is the real teeth here. Six months of non-compliance at 100,000 NOK daily equals 18 million NOK. For mid-sized retailers, that's existential.
The Compliance Risk Landscape: Who's Actually Exposed
Retailers face a multi-layered risk profile that most compliance frameworks haven't caught up with.
First, the Market Control Act: selling products that pose unreasonable consumer risk. Probability of enforcement here is high—the consumer authority's public urging has formalized regulatory attention.
Second, GDPR exposure: if devices ship with facial recognition enabled by default, retailers become complicit in processing special category data. The legal theory here is novel but plausible—facilitating the processing qualifies as assistance.
Third, criminal law exposure under Section 267a. Lower probability, but the reputational damage alone would be substantial.
The hidden vulnerability sits upstream. Importers, not retailers, bear the heaviest compliance burden as the "first entity placing products on the Norwegian market." Product safety regulations impose strict review obligations on importers, and "we didn't know" isn't a viable defense. Retailers who sourced through importers may have contractual recourse—but if the importer is based in China, cross-border enforcement becomes prohibitively expensive.
Strategic Implications: Compliance as Competitive Advantage
For retailers, the smart play isn't waiting for formal prohibition. It's preemptive removal combined with public compliance positioning.
The Norwegian consumer authority historically shows leniency toward first-time violators who cooperate. Retailers who proactively delist and issue public statements about waiting for regulatory clarity are building compliance credit. There's even a reputation play here: Forbrukerrådet may publicly acknowledge cooperative retailers, converting a compliance obligation into brand capital.
For manufacturers, this is a product design fork. The Norwegian move could cascade across the Nordics through established coordination mechanisms among consumer ombudsmen. Denmark, Iceland, and Finland may follow suit. Smart manufacturers should be designing "privacy-friendly" variants now—cameras with visible indicator lights, no facial recognition modules, or regional firmware that disables biometric features. Compliance becomes product differentiation in a tightening regulatory environment.
The gray market risk is real. Norwegian prohibition without EU-wide coordination creates arbitrage through cross-border e-commerce. This will likely push Norway toward customs enforcement—another layer of regulatory cost and consumer friction.
The Insurance Angle
One overlooked dimension is insurance. Product liability and cyber policies may add exclusions for covert surveillance devices. Retailers holding inventory without coverage face uninsured recall costs. Insurers will likely adjust premiums for consumer electronics categories with facial recognition components.
The DPIA Backdoor
Here's a technical insight most analyses miss: Norway could achieve comprehensive regulation without new legislation through GDPR's Data Protection Impact Assessment mechanism. Article 35 requires DPIAs for high-risk processing. Covert facial recognition clearly qualifies. If Datatilsynet issues guidance requiring DPIA certification before smart glasses can be sold, that's de facto pre-market approval—achieved through existing law, no parliamentary action needed.
This "DPIA as licensing" approach would be elegant and precedent-setting. It sidesteps EEA free movement challenges while achieving equivalent regulatory outcomes.
The Free Movement Tension
Norway's EEA obligations create friction. A unilateral ban on specific products could trigger safeguard measure challenges—other EEA states arguing unreasonable restrictions on goods movement under Article 11 of the EEA Agreement. Norway would need to justify the restriction under public morality or public order exceptions. That legal battle could take years.
This may explain why the consumer authority is using soft-law pressure first—urging retailers to act voluntarily—rather than pursuing immediate formal prohibition. It builds the evidentiary record for future justification while achieving near-term market effects.
The Verdict: A 12-18 Month Window
We're in the transition window between legal vacuum and clear rules. The next 12-18 months will likely produce either dedicated Norwegian regulations on covert surveillance devices or formal EEA incorporation of the AI Act's biometric restrictions.
Retailers should treat the consumer authority's urging as de facto interim compliance standards. The cost of waiting for formal prohibition—inventory write-offs, recall logistics, accumulated daily fines, reputational damage—far exceeds the cost of proactive compliance.
The bigger signal here: Northern Europe is building the template for consumer hardware regulation in the AI era. The "pervert glasses" narrative is culturally loaded, but the regulatory architecture being constructed is durable. Device-level restrictions, DPIA requirements, importer liability, insurance adjustments—this is the infrastructure of AI governance at the consumer level.
We didn't need a new law to start the crackdown. The existing toolkit was sufficient. And that's the real lesson for anyone building or selling connected hardware: the regulatory window is closing, and the instruments to close it already exist.