Australia's Office of the Australian Information Commissioner has opened a formal investigation into Shenzhen Qingcheng, the Chinese software company behind the HeyCyan app powering Kmart's $89 Anko-branded smartglasses. Privacy Commissioner Carly Kind announced the probe after the company failed to respond to inquiries, compounding concerns about third-party analysis of the technology and its privacy policy. Meta and Google, which make or plan competing smartglasses, were contacted but will not be investigated. The investigation follows months of public backlash. Guardian Australia reported in August that Kmart had sold out of the discount glasses — essentially a cheap clone of Meta's Ray-Ban smartglasses capable of capturing images and recording high-definition video without any visible indicator to bystanders. A GetUp petition gathered more than 55,000 signatures calling for restrictions. Councils in Canterbury-Bankstown, Sydney City, Brisbane, and Yarra (Melbourne) have banned the glasses from venues like swimming pools. The federal government is considering restricting their use in government workplaces. The structural problem Commissioner Kind identified is precise and alarming: Australia's Privacy Act applies to companies and Commonwealth agencies, not to individuals. If you walk into a public pool wearing covert recording glasses, the Privacy Act has almost nothing to say about it. The entity collecting personal information is not the retailer or manufacturer but the software provider — in this case, a Shenzhen-based company that apparently feels no obligation to respond to Australia's privacy regulator. Researchers at the University of Sydney analysed 350 publicly available Instagram videos shot on smartglasses between 2023 and 2026, finding a clear shift toward discreet, point-of-view recording that bystanders cannot detect. In a subset of those videos, approximately 60% of interactions could be classified as potential harassment, with subjects visibly uneasy or attempting to disengage. These are not theoretical privacy harms — they are documented behavioral patterns at scale. Kind flagged proposed reforms to the Privacy Act that would replace the current 'reasonably necessary for an entity's functions and activities' test with a 'fair and reasonable' test. The new framework would require companies to consider whether individuals had genuine choice in the collection of their personal information and would impose heightened protections for children. Kind framed these reforms as increasingly necessary given the trajectory of surveillance wearables — from smartglasses to personal assistant gadgets to ambient recording badges. The deeper structural issue is jurisdictional asymmetry. A Chinese software company can power a mass-market surveillance device sold in Australian discount stores and simply decline to engage with the country's privacy regulator. Kmart sells the hardware; Shenzhen Qingcheng controls the data pipeline. Neither the retailer nor the individual user is clearly accountable under current law. The investigation may clarify what obligations exist, but it cannot manufacture jurisdiction over a company that does not answer its letters. What emerges is a regulatory framework designed for an era when data collection required infrastructure and intent, now confronting a world where an $89 pair of glasses turns every wearer into a surveillance node. The proposed Privacy Act reforms may raise the bar for software providers, but enforcement against offshore entities remains the load-bearing weakness. The regulator is moving; the question is whether it can move fast enough to matter.