Mayor Kebler and Members of the Bend City Council,
On behalf of Bend Privacy Alliance, I am writing to request that consent-agenda items 4D and 4F on the July 15, 2026 agenda be pulled for brief public discussion.
We are not asking the Council to reject either item. We are asking for basic public clarification about the security and privacy protections associated with two systems that will hold or generate potentially sensitive information.
Item 4F concerns the purchase of Aclara water-meter transmission units. The supporting materials indicate that these devices can generate hourly, time-stamped household water-use readings and support on-demand readings. Data at that level of detail can reveal occupancy and household activity patterns.
Before authorizing a five-year purchase, we ask the City to publicly explain:
- How long hourly household readings are retained.
- Who may access individual household histories.
- Whether the transmissions and stored data are encrypted.
- Whether access is logged and periodically audited.
- Under what circumstances the data may be shared with law enforcement, contractors, landlords, insurers, researchers, or other agencies.
- Whether the information may be used for purposes beyond billing, system maintenance, leak detection, and customer-requested services.
- Whether Aclara or its subcontractors have remote access to Bend customer data.
Item 4D concerns the ProjectTeam cloud platform for capital-project documents, workflows, financial records, contractor collaboration, and integrations with other City systems.
The proposed data-protection addendum contains several encouraging provisions, including City ownership of its data, restrictions on sale and unrelated data mining, domestic data-storage requirements, incident-reporting obligations, and post-contract data destruction.
However, the public packet does not clearly state whether:
- Multifactor authentication will be mandatory for every City, contractor, and vendor account.
- City data and backups will be encrypted in transit and at rest.
- The City has reviewed an independent security assessment, such as a SOC 2 report or comparable audit.
- External contributors will be governed by least-privilege access controls and complete access logging.
- The hosting providers and subprocessors that may possess City data have been disclosed and reviewed.
- The vendor maintains appropriate cyber-liability insurance.
These may already be addressed through the City’s internal security-review process. A brief explanation during the meeting would give the public confidence that the privacy and cybersecurity implications were considered before approval.
As more public services rely on connected devices and cloud platforms, procurement is one of the most important points at which the City can establish meaningful safeguards. Addressing these questions before approval is easier and less costly than trying to add protections after deployment.
Thank you for your consideration and for making these issues part of the public record.
Sincerely,
Jonathan Westmoreland
Bend Privacy Alliance
Protecting privacy, transparency, and civil rights in Bend
Leave a Reply