H.R. 2853 — the Combating Organized Retail Crime Act of 2025
Federal Legislation · Now Before the U.S. Senate · Updated May 27, 2026
Where the bill standsThe House passed H.R. 2853 on May 12, 2026, by a vote of 348–60. It is now engrossed and headed to the Senate, where it must clear committee and a floor vote before it can become law. That makes this the moment Oregonians can still weigh in — by contacting Senator Ron Wyden and Senator Jeff Merkley.[1]
This guide explains, in plain language, what H.R. 2853 would do and lays out the key privacy and civil-liberties talking points you can raise when you email Oregon’s two U.S. senators or their staff. It is educational and informational. Use the points that matter most to you, in your own words — personal letters carry more weight than form letters.
01What the Bill Does
H.R. 2853 does two main things. The first is a set of criminal-law changes. The second — and the focus of most privacy concern — is the creation of a new federal coordination center.
It strengthens federal criminal tools for retail and cargo theft.
The bill expands criminal forfeiture, adds theft and stolen-goods offenses (18 U.S.C. §§ 659, 2314, 2315) as money-laundering predicates, treats gift cards and prepaid cards as “monetary instruments,” and lets prosecutors meet the $5,000 federal threshold by adding up thefts over a 12-month period rather than needing a single large theft.[2]
It creates a retail-crime coordination center inside ICE.
The bill directs the Secretary of Homeland Security to establish an Organized Retail and Supply Chain Crime Coordination Center, with its director appointed by the head of U.S. Immigration and Customs Enforcement. The Center would coordinate federal investigations, assist state and local police, build relationships with private companies, run an information-sharing system using existing DHS and DOJ databases, and enter agreements with private-sector entities. Its authority sunsets after seven years.[3]
Worth stating plainly Organized retail and cargo theft are real problems, and the bill drew broad bipartisan support in the House. The question this guide raises is not whether the problem exists — it does — but whether a data-sharing center housed inside ICE should be built without the privacy guardrails that normally accompany this kind of information-sharing infrastructure.
02Key Talking Points
These are the points to raise with Oregon’s senators. You don’t need all of them — pick two or three that resonate and explain why they matter to you.
Point 01
A retail-theft problem is being handed to an immigration agency.
The Center is placed inside Homeland Security Investigations, with its director appointed by ICE — not a consumer-protection body like the FTC or the Commerce Department. That structural choice means information gathered for retail-crime purposes sits inside the same agency that conducts immigration enforcement.
You might sayI’m concerned that H.R. 2853 places a retail-crime data center inside ICE, and that the bill contains no limits preventing information from being used for immigration enforcement unrelated to the underlying case.
Point 02
It builds a fusion-center-style hub spanning many agencies.
The Center can be staffed by detailees from CBP, the Secret Service, Postal Inspection, ATF, DEA, FBI, and state and local police, and can share resources with other DHS interagency centers. That lets data collected about retail theft move across unrelated enforcement domains — drugs, weapons, immigration, financial crimes — with no clear firewall between them.
You might sayPlease ask what prevents retail-crime data in this Center from being repurposed for unrelated investigations across the many agencies that would have access.
Point 03
It opens direct data pipelines from private companies, with no rules on what flows through them.
The Center is directed to build relationships with retailers and transportation companies and to receive investigative information from them. That could include security-camera footage, license-plate data, facial-recognition leads, loyalty-card and payment records, return histories, and proprietary “organized retail crime” databases — yet the bill never specifies what categories of data can or cannot be shared.
You might sayThe bill should specify what private-sector data the Center may receive, and it should prohibit bulk transfers of customer, shopper, vehicle, or location data.
Point 04
It carves out an exception to a federal confidentiality law.
The bill lets the Center’s director personally authorize disclosure of information otherwise protected under 18 U.S.C. § 1905 whenever it is deemed “operationally necessary” — an undefined term. While the approval cannot be delegated, there is no definition of the standard, no after-the-fact review, no notice to affected parties, and no limit on redisclosure.
You might sayThe term “operationally necessary” is undefined and should be narrowed, with logging and after-the-fact review required for any disclosure of otherwise-protected information.
Point 05
The scope language invites mission creep.
The covered-crime definition includes “other crimes related to” the core offenses — open-ended phrasing that could let the Center’s reach expand well beyond retail and cargo theft over time.
You might sayPlease ask for a tighter definition of covered crimes, with a clear connection to organized retail or supply-chain theft.
Point 06
The basic privacy guardrails are simply missing.
The bill does not require warrants before sensitive data is shared, data minimization, retention or deletion limits, audit logs of every search, independent civil-liberties audits, redress for people wrongly flagged, public posting of agreements with private companies, or limits on facial recognition, license-plate readers, and location data. A center this broad should carry those protections in the text.
You might sayBefore the Senate advances this bill, it should add data minimization, retention limits, audit logging, independent civil-liberties audits, and a redress process for people wrongly identified.
Point 07
Strengthen what’s already good in the bill.
The bill does include a seven-year sunset, a non-delegable approval requirement for confidential disclosures, and annual public trend reports — all worth keeping. But seven years is long enough for a surveillance system to become permanent in practice, and the required reports cover enforcement results rather than civil-liberties impacts.
You might sayI’d urge a shorter reauthorization window — three years instead of seven — with a public civil-liberties audit before any renewal, and reporting that includes the number of U.S. persons affected and any immigration referrals.
03Who to Contact
Oregon is represented in the U.S. Senate by two senators. Both will vote on whether this bill advances. Contacting either or both — by email, phone, or their web contact form — puts your concerns on the record.[4]
Contact details confirmed against each senator’s official Senate website on May 27, 2026. Both senators maintain field offices in Bend’s Jamison Building. The web contact forms route your message to the staff who track this issue and are the most reliable channel.
04How to Write an Effective Message
Identify yourself as an Oregon constituent and give your city. Staff sort mail by whether you live in the state.
Name the bill by number: H.R. 2853, the Combating Organized Retail Crime Act of 2025.
Lead with one specific ask — for example, “Please push for privacy amendments before this bill advances,” or “Please vote no unless these safeguards are added.”
Pick two or three talking points from Section 02 and put them in your own words. Specific and personal beats long and comprehensive.
Be brief and respectful. A few clear paragraphs is plenty. Staff log the position and the ask.
Ask for a response on where the senator stands. That prompts a substantive reply rather than a form acknowledgment.
Subject
Privacy concerns with H.R. 2853 — please seek amendments
Message
Dear Senator [Wyden / Merkley],
I’m a constituent writing from [your city], Oregon. I’m contacting you about H.R. 2853, the Combating Organized Retail Crime Act of 2025, which the House passed on May 12 and which is now before the Senate.
I understand organized retail and cargo theft are real problems. My concern is the new coordination center the bill creates inside ICE. As written, the bill places a data-sharing hub inside an immigration-enforcement agency, opens direct data pipelines from private retailers without specifying what data can be shared, and leaves out basic safeguards like data minimization, retention limits, audit logs, and a way for wrongly flagged people to seek correction.
Before this bill advances, I’d ask you to push for those privacy protections to be written into the text, to narrow the undefined “operationally necessary” disclosure standard, and to support a shorter reauthorization window with a public civil-liberties audit before any renewal.
Could you let me know where you stand on adding these safeguards? Thank you for your time.
Sincerely, [Your name] [Your city], Oregon
Sources
[1] H.R. 2853 status and House vote (348–60, May 12, 2026): Congress.gov; engrossed-in-House text: GovInfo. [2] Criminal-law provisions (forfeiture, money-laundering predicates, gift-card coverage, 12-month aggregation): bill text via GovTrack and CBO cost estimate, cbo.gov. [3] Coordination Center, ICE placement, duties, and seven-year sunset: bill text; CBO estimate. [4] Oregon’s U.S. senators and office contact details confirmed via each senator’s official site: wyden.senate.gov and merkley.senate.gov.
Bend Privacy Alliance
Share freely · No copyright claimed · Verify before you act
Investigation · Retail surveillance · Public-private camera networks
When store cameras become police infrastructure.
Six retailers operate in Bend, Oregon. Their privacy policies describe facial recognition, license plate readers, and behavioral analytics. The city has quietly built the bridge that connects them to law enforcement. Here is what is public, what is alleged, and what is still unknown.
Is your trip to a Bend grocery store or hardware store also a data point in a law-enforcement system?
What’s verified
Across the six retailers, public policies disclose combinations of video surveillance, biometrics, license-plate capture, location and device tracking, behavioral or session analytics, and consumer profiling — though not every retailer discloses every capability at the same level of detail. Three retailers have dedicated ALPR policies; Albertsons has a California-specific ALPR policy; Fred Meyer/Kroger’s general policy discloses license-plate capture by some cameras. Three retailers disclose facial recognition explicitly.
The Bend bridge
Bend Police has funded FususCore bundles for up to 10 local retailers, linking private cameras to the Bend Connect system.
What you can do
Under the Oregon Consumer Privacy Act, you can require each retailer to tell you who they have shared your data with. Templates are in the Action Toolkit.
In February 2025, the Bend Police Department launched Connect Bend — a community camera registry powered by Fusus, the public-private surveillance platform Axon acquired in 2024. By March 2026, 618 cameras were registered across the city. 174 of those had been upgraded with FususCORE devices, giving the Bend Police Department conditional access to live and recorded feeds. The platform costs the department approximately $75,000 per year and is the same Axon/Fusus infrastructure used for body cameras and digital evidence storage. (Source: The Bulletin, May 15, 2025 and March 4, 2026.)
In November 2025, the Bend Police Department and the Deschutes County District Attorney’s Office added a grant program on top of the registry. Up to ten Bend retailers could receive a FususCORE Device Bundle — the hardware that converts a private camera into an integrated feed — through the Oregon Criminal Justice Commission’s Organized Retail Theft Grant Program. Applications were due August 3, 2025; after the one-year grant term, businesses pay $150/year to remain integrated. The headline framed it as a fight against shoplifting. (Source: The Source Weekly; Central Oregon Daily.)
The contract that governs each retailer’s participation is published at bendconnect.org/terms-conditions/ as a Data Share and License Agreement between the camera owner and the City of Bend. Section 5 makes a contractual promise to camera owners: “City will not share access to Owner’s camera views with members of the public, or outside of City, without the prior written consent of Owner.” Section 6 requires the camera owner to provide Bend “camera make, model, IP address, and camera and/or associated DVR/NVR login information.” Section 7 confirms that Bend, not Axon, is the physical custodian of the FūsusCORE hardware on each property.
The contract is between the camera owner and the City. It does not bind Axon. Axon operates the platform that processes, stores, and routes the data. Axon’s contractual relationships with other agencies, its retention policies, its use of the data to train artificial intelligence models, and its own audit logs are not addressed by the agreement that the retailer signed. Customers in the parking lot are not party to the agreement at all.
This is the bridge. Retail surveillance and police surveillance are not separate categories when the cameras are wired into the same platform. Whether the store calls it “asset protection” or the city calls it “Organized Retail Theft Grant,” the practical effect is the same: a private camera operating in a place of public accommodation becomes part of a public surveillance network, and the platform that operates it is a multi-billion-dollar publicly traded surveillance vendor headquartered in Scottsdale, Arizona.
Bend residents have not voted on this. They are unlikely to have been notified by any retailer that has joined. The list of participating retailers, the policy governing access escalation, the retention period for the footage, the conditions under which it can be shared with federal agencies — none of that is yet in the public record. The Bend Privacy Alliance toolkit and templates published alongside this piece are designed, in part, to surface it.
Two specific findings worth knowing
First: the bendconnect.org footer links to a Privacy Policy at https://bendconnect.org/privacy-policy/. The page returns the “Axon Fusus Community Connect and Axon Fusus Registry Website Privacy Notice,” last updated February 21, 2025. The notice is Axon’s own corporate privacy notice for its Community Connect and Registry products — not a Bend-specific notice drafted for Bend residents or approved by the City. It describes how Axon collects, uses, discloses, transfers, and stores the personal data of users of the platform. Whether a national vendor’s standard privacy notice meets the disclosure requirements of ORS 646A.578 for a program branded as a City-of-Bend public safety program is a question the City has not addressed publicly.
Second: the Connect Bend Privacy FAQ states that “Fūsus does not employ facial recognition technology” — but in the next answer it discloses that “Fūsus utilizes artificial intelligence to rapidly search video. All AI use cases exclude facial recognition, but may be utilized to automatically recognize weapons, vehicles of interest, etc.” “Vehicles of interest” describes automatic license plate recognition functionality and vehicle attribute identification by AI — activities that the Oregon Consumer Privacy Act treats as processing of personal data, and that the January 2026 geolocation amendments (HB 2008) treat as sensitive data when they identify a person to a radius of 1,750 feet or less.
Why this matters now
In January 2026, Bend’s City Council voted to suspend its Flock Safety automated license plate reader cameras after public outcry over Flock’s national track record of immigration sharing and personal misuse by police. That decision was real and the public made it happen. The retail-camera integration program is a parallel pathway that has not received the same scrutiny. It deserves the same scrutiny.
§02
What the policies actually say
What the policies actually say
This section sticks to one type of evidence: language pulled from each company’s own current, public privacy policy. These are statements the companies have committed to in writing, dated, and posted on their corporate websites between April 2025 and February 2026. They are not allegations.
A privacy policy describes what a company reserves the right to do. It does not prove that any particular store is doing it. That is a separate question, addressed in section 5.
The six retailers, in their own words
Capability
What the policies actually say
Video cameras in stores and parking lots
All six Every one of the six companies discloses CCTV and parking-lot camera operation as standard practice. This is the floor, not the ceiling.
Facial recognition / biometric capture
Home Depot Explicit: “Biometric Information — Facial recognition” is listed as a collected category in the Home Depot Privacy and Security Statement. Home Depot’s FY2023 Annual Report (SEC Form 10-K, filed March 2024) discloses that its “Computer Vision” technology has been deployed across all U.S. stores. Third-party reporting indicates the technology was expanded to self-checkout areas for loss prevention by May 2024; that specific application has not been independently confirmed from primary corporate sources.
Walmart The Walmart Customer Privacy Notice lists collection of “voice prints, imagery of the iris or retina, face geometry, and palm prints or fingerprints.” Three-year biometric retention from last interaction.
Fred Meyer / Kroger The Fred Meyer Privacy Policy states biometric collection including facial recognition data may occur in “select locations” with point-of-entry notice.
Safeway / Albertsons The Albertsons Privacy Policy states: “In some states, our cameras may capture biometrics (e.g., facial recognition technology).” Entry signage required where deployed.
Lowe’s The current Lowe’s U.S. Privacy Statement (April 2025) uses “image matching and analysis technology” on images from recorded footage in some states, applied after incidents by Asset Protection. Lowe’s does not label this as facial recognition in the current policy.
Automated License Plate Recognition (ALPR)
Lowe’s Dedicated ALPR section in the U.S. Privacy Statement. 90-day retention. Home Depot Dedicated ALPR section in the Privacy and Security Statement. No fixed retention period stated. Walmart Dedicated ALPR Privacy Notice, updated February 2026. Led by VP, Chief Safety Officer. 60-day retention. Safeway / Albertsons California ALPR Policy. 60-day default; 12-month retention at “high-crime” stores. Director of Corporate Asset Protection as custodian. Fred Meyer / Kroger Kroger has an ALPR policy applying to “select retail locations in California” (Ralphs confirmed). Fred Meyer / Oregon deployment unverified.
In-store Wi-Fi and Bluetooth tracking
All six disclose some form of in-store device or signal tracking. Albertsons is the most explicit: for loyalty members, the policy says they collect MAC address, IP address, device identifier, and real-time device location through in-store Wi-Fi. Bluetooth tracking and motion sensors are disclosed for in-store navigation. Beacons in baskets and carts measure dwell time in front of advertising displays.
Lowe’s “keystroke activity and rhythms, mouse movements, scrolling and clicks.” Home Depot “Session replay software may be used to record and replay your interaction.” Fred Meyer / Kroger “keystrokes, cursor movements, scrolling activity, and click-related activity.” Walmart, Albertsons, Safeway Not disclosed at this granularity in their current policies.
Inferences and profiling
All six disclose inferences-from-personal-data as a category. Albertsons goes furthest: their policy lists inferences about your “purchase preferences, interests, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.”
AI / ML model training on shopper data
Albertsons / Safeway only one of the six explicitly states data is used to “train our artificial intelligence or machine learning algorithms or models (or those provided by our service providers).” The others may do so but do not disclose it in this language.
Smart shopping carts with cameras and sensors
Albertsons / Safeway In some locations: “You may also see smart carts in our stores, which use cameras and sensors to tally items as you grab them off the shelf and place them in your cart. As an added bonus, you can pay through the cart and skip the checkout lines.” Bend deployment of smart carts is unverified.
Estimated per-shopper data value
Albertsons / Safeway The December 2025 privacy policy states: “We estimate the value of consumers’ data to be, on average, approximately $4.13 per consumer in 2024.” That figure was $1.33 in the 2022 policy version — a tripling in two years.
Inter-retailer sharing
Albertsons / Safeway California ALPR Policy: “We may also work with other retailers to keep track of organized retail crime groups… we typically share public data such as vehicle details (make, model, and color) and license plate information.” This is unusually transparent about retailer-to-retailer surveillance coordination. The other five companies do not discuss this explicitly.
How to read this table
The clearest pattern: facial recognition, ALPR, in-store device tracking, and inferences are now standard disclosures in major-retailer privacy policies. The companies are not hiding it. They are simply describing it in the place fewest people read.
What the policies do not tell you is which specific Bend, Oregon stores have any of these systems deployed today. That is the next chapter of work, and it is what Oregon’s privacy law was designed to support.
The companies are not hiding it. They are describing it in the place fewest people read.
§03
A short history of how Bend got here
A short history of how Bend got here
Three threads converge in 2025–2026: a city-government experiment with automated license plate readers, a retail-theft grant pipeline, and a national pattern of surveillance vendors quietly accumulating local footholds. The Bend story is the local edition of a story playing out in many small American cities.
May 2025
Bend signs a $19,900 contract with Flock Safety
Four Flock Falcon cameras are deployed at two intersections on Highway 97. The contract is amended in July 2025 to swap them for Falcon Long Range units, adding $4,100. Total spend: $24,000, non-refundable. (See The Source, December 9, 2025.)
November 2025
Bend Police and Deschutes County DA open the FususCore retail grant
Up to ten Bend retailers are invited to apply for a FususCore Device Bundle — up to four cameras, onboard storage, one-year subscription, warranty — that connects existing store security cameras to the Bend Connect platform. Funded by the Oregon Criminal Justice Commission Organized Retail Theft Grant Program. (See Central Oregon Daily, November 12, 2025; The Source Weekly, July 10, 2025.)
January 7, 2026
Bend City Council votes to suspend the Flock cameras
The decision follows public concern about Flock’s national use by federal immigration agents and reports of police misuse to track romantic partners and abortion seekers in other states. Senator Wyden publicly criticizes Flock. Other Oregon cities (Woodburn, Talent) have already pulled their Flock contracts. (See OPB, January 8, 2026; The Source, January 8, 2026.)
March 2026
Connect Bend reaches 618 registered cameras, 174 integrated
A year after the program’s February 2025 launch, 618 cameras are mapped in the Connect Bend registry, with 174 fully integrated via FūsusCORE devices. Over the prior year, BPD has sent 14 community-request emails through the system. The police spokesperson confirms she is “not aware of any suspect video footage related to those requests.” (See The Bulletin, March 4, 2026.)
May 6, 2026
Federal immigration queries on Bend’s Flock data become public
The Source reports that federal immigration authorities made 279 queries into Bend’s Flock Safety data during the first three weeks of June 2025, due to a BPD configuration error that left the “National Lookup” reciprocal-sharing feature on by default. The audit was prompted by an Oregon Law Center FOIA request. The data sharing happened without Oregon sanctuary-law authorization. (See The Source, May 6, 2026.)
May 20, 2026
Bend pivots to Axon stationary ALPR
Rather than re-up with Flock, Bend Police propose adding stationary ALPR cameras as an amendment to the existing Axon contract (in place since 2022 for body cameras, tasers, and in-vehicle ALPR). Public comment at the May 20 City Council meeting questions why a $19,000 grant would justify a quarter-million-dollar surveillance expansion without a council vote. The Council commits to a vote and public input before the add-on is finalized. (See The Source, May 20, 2026; The Source, May 21, 2026.)
The pattern that emerges: Bend has been responsive when residents engage on a specific surveillance vendor or contract. The Flock suspension is the proof. But the retail-camera integration pathway has not been the subject of the same public scrutiny because it operates through a different door — a grant program framed as anti-theft assistance, not surveillance procurement.
§04
Where the data can go once it leaves the store
Where the data can go once it leaves the store
Imagine you push a cart through a Bend Albertsons or Fred Meyer or Lowe’s. By the time you reach the parking lot, a series of systems may have captured signals about you. Each of those signals can travel through more than one downstream pipeline.
Here is what corporate policies disclose as possible destinations for the data each retailer collects.
First-party use
The retailer itself
Asset protection, loss prevention, marketing, inferences about your preferences, AI/ML model training (Albertsons explicitly).
First-party transfer
Affiliates and subsidiaries
Kroger’s 84.51° subsidiary aggregates and analyzes shopper data across all Kroger banners, including Fred Meyer. Albertsons Media Collective monetizes shopper data across 2,200+ stores in 35 states.
Third party
Advertising and data partners
All six retailers disclose sharing inferences, online activity, location data, and commercial information with advertising and marketing partners. Most categorize this as a “sale” or “sharing” under California and Oregon law.
Third party
Other retailers
Albertsons’ California ALPR Policy explicitly discloses inter-retailer ALPR sharing for “organized retail crime groups.” Auror and similar industry platforms enable the same kind of sharing.
Government
Local police
All six retailers disclose discretionary sharing with law enforcement. Where a Bend retailer has joined the FususCore / Bend Connect program, that sharing happens through an integration, not a one-off request.
Government
Federal agencies
Most retailers reserve the right to share when “we believe disclosure is appropriate or necessary.” The Flock controversy demonstrated that ALPR data already feeds into systems used by ICE and other federal agencies. A FususCore / Bend Connect retailer integration could create the same pathway from inside private store networks.
An Oregon shopper’s data has a long route
To make the data flow concrete, here is a plausible (not hypothetical) sequence based on what each step’s company says in writing:
You park outside a Bend Lowe’s. The parking-lot ALPR camera records your license plate, the make, model, and color of your vehicle, and a timestamp. Retention per Lowe’s policy: 90 days, longer if necessary.
You walk in. A ceiling camera captures your image. Lowe’s U.S. Privacy Statement says that in some states, recorded footage may be analyzed using “image matching and analysis technology” by Asset Protection following an incident.
You connect to the free in-store Wi-Fi to look up a product price. Lowe’s collects your device usage information.
You use the mobile app. Lowe’s app collects your “keystroke activity and rhythms, mouse movements, scrolling and clicks.”
You buy something with a stored credit card linked to your Lowe’s account. Inferences about your project, your home, and your buying patterns join your account profile. Lowe’s reserves the right to enrich this with public-records data including property size, year built, and number of rooms.
That profile is shared, for marketing purposes, with advertising partners. Under Oregon and California law, this is generally a “sale” or “sharing.”
Separately, the ALPR record may be shared with law enforcement “upon appropriate request and solely in connection with criminal investigations” — per Lowe’s own ALPR Privacy Policy. If your Bend Lowe’s is one of the retailers connected to Bend Connect through a FususCore bundle, the camera footage itself becomes accessible to Bend Police through the city’s platform.
Every one of those steps is described, in writing, in a corporate policy. None of them require malicious intent on the part of the retailer. They are the standard architecture of modern retail surveillance.
§05
A risk map for residents
A risk map for residents
Not every form of in-store data collection is equally consequential. Privacy advocacy that treats them as equivalent loses credibility quickly. Here is a rough ordering, from least to most consequential for individual rights, based on what current corporate policies disclose and what current civil-liberties literature documents about each practice.
Lower concern
Aggregate camera analytics
Counting foot traffic, measuring wait times in checkout lines, detecting spills on the floor. If actually de-identified and aggregated, this is the form of in-store analytics with the smallest civil-liberties footprint.
Lower concern
Loyalty program purchase history
The trade is explicit: you give up purchase data, the retailer gives you discounts. The consent is real. The risk is concentration: 84.51° and Albertsons Media Collective aggregate this across millions of households.
Higher concern
Mobile app precise geolocation
Tracks where you are with the app open, sometimes also in the background. Builds a location history. Salable to data brokers in most current privacy frameworks.
Higher concern
Inferences and profiling
The data is processed to predict your interests, household composition, life-event status, and propensity to buy specific categories. Used for ad targeting, but also for differential pricing.
Higher concern
Automated License Plate Recognition
Builds a record of every vehicle visit to the lot, when, and how often. When shared with police, becomes a movement-tracking system for everyone, not just suspects.
Highest concern
Facial recognition
Identifies you against a watchlist or database. Once your face data is captured, you cannot change it. False-positive rates are documented to be higher for Black and Asian faces. Misidentification has already led to wrongful arrests in other jurisdictions.
Highest concern
Retail-to-police camera integration
Combines all of the above into a system that operates under private-actor rules (the retailer can deploy whatever it wants) but with public-actor reach (police can pull footage through the integration). Constitutional protections that constrain government cameras do not constrain private cameras that police access.
Why the integration is the linchpin
Each individual surveillance practice has known harms. The harms are not new, and most of them have been the subject of state-level legislative attention. What makes the Bend Connect / FususCore arrangement different is structural: it lowers the legal and procedural friction between two systems that used to be separate.
A private retailer’s camera is bound by the retailer’s own policy. A police camera is bound by Fourth Amendment doctrine and (where applicable) state surveillance laws. When the two are merged, the retailer’s permissive rules govern the front end and the police’s broad access governs the back end. The privacy gap appears in the middle, where neither rulebook fully applies.
The privacy gap appears in the middle, where neither rulebook fully applies.The structural problem the Bend Privacy Alliance is describing
§06
Oregon law is more powerful than most people realize
Oregon law is more powerful than most people realize
The Oregon Consumer Privacy Act took effect on July 1, 2024. It is enforceable only by the Oregon Attorney General — consumers cannot file private lawsuits under it — but the rights it grants Oregon residents are unusually strong, and most residents have not exercised them.
The Oregon-distinctive right
Oregon law gives you a right that no other US state currently gives. Under ORS 646A.574(1)(a)(B), you can require a company that processes your data to tell you, at the company’s option, either (i) the specific third parties to which it has disclosed your personal data, or (ii) the specific third parties to which it has disclosed any personal data. The company has the option of which list to provide. The right itself is not optional.
What this means in practice: if you file an OCPA Right to Know request with a Bend Home Depot, Lowe’s, Walmart, Fred Meyer, Safeway, or Albertsons, the company must tell you who it has shared customer data with. Not just the categories. The specific names. This is the lever that turns “advertising partners” from a vague policy phrase into a concrete list you can examine.
The four core OCPA rights
Right to know and access Confirmation that the company processes your data, the categories it processes, and a copy of the data in a portable format. ORS 646A.574(1)(a). Right to specific third parties The Oregon-distinctive right described above. At the controller’s option, but not optional in principle. ORS 646A.574(1)(a)(B). Right to correct and delete Correction of inaccuracies, and deletion of personal data (including derived data and data obtained from other sources). ORS 646A.574(1)(b) and (c). Right to opt out Opt out of the sale of personal data, targeted advertising processing, and profiling that produces legal or similarly significant effects. ORS 646A.574(1)(d). The company must honor Global Privacy Control browser signals.
The 45-day clock
Under ORS 646A.576, the company has 45 days to respond. They can take a 45-day extension if they tell you why within the first 45 days. If they go silent, you can file with the Oregon AG, which has exclusive enforcement authority under ORS 646A.583.
What sensitive data covers
OCPA’s definition of sensitive personal data is broader than most other state laws. It includes, in addition to the usual categories (race, ethnicity, religious beliefs, health condition, sex life, citizenship, immigration status, genetic data, biometric data, precise geolocation, child data), status as transgender or non-binary and status as a crime victim. Sensitive data has heightened protections, including opt-in consent requirements.
What it means for retail: the inference category in Albertsons’ policy — “psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes” — could, if it includes data that touches sensitive categories, trigger heightened OCPA protections. Whether it does is a question worth pressing through a Right to Know request.
A note on what the OCPA does not do
OCPA does not give you the right to sue the company directly. You cannot collect damages under the statute. Enforcement is by the Oregon Attorney General. This is one reason individual right-to-know responses matter so much: they create a documentary record that, if the AG eventually takes interest, can support an investigation.
The Portland comparison
The City of Portland prohibits private entities from using face recognition technology in places of public accommodation within city limits (Portland City Code Chapter 34.10). Bend has no equivalent. A Surveillance Technology Accountability Ordinance for Bend would be the local mechanism for closing this gap — not relying on OCPA alone, which provides individual rights but does not ban any specific technology.
§07
What a real surveillance accountability ordinance would do
What a real surveillance accountability ordinance would do
The structural argument of the Bend Privacy Alliance is that retail surveillance and public surveillance become a single accountability problem the moment they are integrated. The Surveillance Technology Accountability Ordinance and Procurement Framework already in front of the Bend City Council and Procurement Committee is one model for what such a rule could look like. The principles below are not the ordinance text; they are the policy logic the ordinance applies to all surveillance technology operated by, contracted by, or funded by the City of Bend — including FususCore integrations and retail-camera partnerships.
Ten principles for retail-to-police camera integration
Public notice before deployment. No new private camera integration into a city-managed platform without a published notice and a comment period.
Council approval. City access to private camera networks requires a Council vote on the record, not an administrative grant decision.
Public inventory. The City maintains and updates a public list of every retailer, business, or facility integrated into Bend Connect, FususCore, or any successor system.
Retention limits. Maximum retention for any data ingested from private cameras must be defined in writing and enforced by audit.
Audit logs. Every law-enforcement query against the integrated camera network is logged with a queryer ID, timestamp, and investigative justification.
Named custodian. A named senior city officer is accountable for the operation of the integration, with that role published.
Access controls. Training, role-based access, and removal procedures are documented and audited annually.
Prohibition on face recognition. Face recognition is not deployed against integrated camera feeds without separate Council authorization following a formal procurement review.
ALPR sharing limits. ALPR data is not shared with federal agencies, out-of-state agencies, or non-investigative third parties absent specific legal process.
Annual transparency report. The City publishes an annual report on usage, queries, sharing events, and audit findings.
These are the same principles that govern responsible municipal surveillance procurement in cities that have already adopted Surveillance Technology Ordinances — Oakland, Seattle, Cambridge, Nashville, San Francisco, and others. Bend has the opportunity to be the first Oregon city outside Portland to apply them comprehensively. The work in front of the Bend City Council and Procurement Committee is the vehicle.
§08
What you can do this week
What you can do this week
Most of what this piece describes can be tested by any Bend resident with a thirty-minute time investment and a willingness to wait 45 days. Here are four things that are within reach.
Action 01
File an OCPA Right to Know request
Use the templates in the companion Action Toolkit to ask each of the six retailers what data they hold on you and who they have shared it with. The 45-day clock starts when they receive it. Send through their privacy portal and screenshot the confirmation.
Action 02
Photograph store entry signage
Visit a Bend Home Depot, Lowe’s, Walmart, Fred Meyer, Safeway, or Albertsons. Photograph any signage at the door describing biometric capture, video surveillance, or ALPR. Note camera positions and self-checkout indicator boxes. Time and date the photos. Absence of required signage is itself a disclosure violation. Send photos to westmoreland.jonathan@gmail.com.
Action 03
File a Bend Police records request
The template in the Action Toolkit asks the City of Bend for all FususCore / Bend Connect contracts, ORT grant records, retailer applications, training materials, audit logs, and communications with the six named retailers. Submit through the City’s public records portal. Request a fee waiver under ORS 192.324(5).
Action 04
Show up at City Council
The next public-input opportunity on Bend’s surveillance contracts will arrive when the Axon ALPR add-on comes back for a vote. Council meetings are at City Hall, 710 NW Wall Street, typically 6 p.m. Public comment is two minutes. Written submissions in the council packet are also read.
The toolkit and the Evidence Matrix that accompany this piece contain the legal citations, contact channels, escalation procedures, and confidence ratings for every claim made above. Use them. Verify them. Improve them. Send corrections to westmoreland.jonathan@gmail.com.
§09
Sources and how to verify everything in this piece
Sources, and how to verify
Every factual claim in this piece is traceable to a primary source: a corporate privacy policy current as of May 24, 2026, an Oregon statute or DOJ guidance page, a court docket, or local Bend reporting from named outlets. The full source ledger, with version dates, archive recommendations, and confidence ratings, is in section 9 of the companion Action Toolkit document.
Headline citations for the claims in this piece:
Lowe’s:Lowe’s U.S. Privacy Statement, effective April 21, 2025 (current corporate privacy notice; uses “image matching and analysis technology” language). An older Lowe’s mobile-app help page cited by the ACLU in 2018 used “facial recognition technologies” language; the current language on that page has not been independently confirmed for this piece and is not relied on here.
Home Depot:The Home Depot Privacy and Security Statement (last revised December 29, 2025), including the explicit Biometric Information / Facial Recognition category and the dedicated ALPR Usage and Privacy Policy. The Home Depot FY2023 Annual Report (SEC Form 10-K) discloses Computer Vision deployment across all U.S. stores; available via the SEC EDGAR system at sec.gov.
Fred Meyer / Kroger:Fred Meyer / Kroger Privacy Policy, including the explicit keystroke/cursor/scroll behavioral analytics disclosure and the 84.51° subsidiary description.
Reporting:Central Oregon Daily, “Bend retailers offered theft tech from police through grant,” November 12, 2025 (FususCore / Bend Connect / ORT grant program); The Source Weekly, “Ten Businesses can Apply to Connect Security Cameras with Bend Police,” July 10, 2025; The Bulletin, “Bend Police: More than 500 cameras registered,” May 15, 2025; The Bulletin, “Bend Police program now includes hundreds of private security cameras,” March 4, 2026.
Bend Flock suspension reporting:The Source (Bend, Oregon) coverage by Peter Madsen, January through May 2026, on the Flock suspension and Axon transition (see bendsource.com).
Litigation references (allegations only):Jankowski v. The Home Depot, Inc., No. 1:25-cv-09144 (N.D. Ill., filed Aug 1, 2025, voluntarily dismissed without prejudice Oct 31, 2025) — allegations of BIPA violations re: Computer Vision at self-checkout. The allegations were not adjudicated. Schmierer v. Home Depot U.S.A. (Sacramento Superior Court, April 2026) and the related N.D. Cal. action — pending California ALPR Privacy Act class actions. Allegations only. Milberg BIPA class action against Walmart in Illinois — pending. Allegations only.
If you find an error, send a correction to the Bend Privacy Alliance at westmoreland.jonathan@gmail.com. This piece will be revised. The companion Evidence Matrix and Action Toolkit will be revised alongside it. The goal is a record that can be verified by anyone with the same documents, not an argument that depends on trust.
6
Retailers studied
10
FususCore bundles offered to Bend retailers
45
Days for an OCPA response
$4.13
Albertsons’ estimate of one consumer’s annual data value (2024)
0
Bend retailers publicly named as FususCore participants, to date
The goal is a record that can be verified by anyone with the same documents, not an argument that depends on trust.
Bend Privacy Alliance
Civic policy and advocacy work on surveillance technology governance, consumer privacy, and civil rights in Bend, Oregon. The Alliance publishes working research, action toolkits, and investigative pieces designed to be verified by readers and improved through corrections.
This piece is one of three companion documents on retail surveillance in Bend. The Evidence Matrix is the internal research file with confidence ratings on every claim. The Action Toolkit contains the OCPA right-to-know templates, the Bend Police public records request template, escalation language, and a full source ledger.
Compiled May 24, 2026 · Version 1.0 · Bend, Oregon
Verify before citing · Save sources at time of access
Thank you for the thoughtful reply, and for offering to talk individually. I understand the public-meeting-law concern and appreciate you moving Council to BCC.
I agree on the core points: Council does not directly manage the Police Chief or department staff, police policies are generally administrative documents, and state law applies whether or not Policy 428 restates it.
The distinction I am trying to draw turns on a word in your own reply. You wrote that Council does not “typically” review administrative police policies. I agree — and that is the distinction. Policy 428 is not a typical administrative policy. Most department policies govern internal officer conduct. Policy 428 governs a public-facing surveillance system: the collection, retention, sharing, auditing, and oversight of automated license plate reader data associated with members of the public, most of whom are not suspected of anything. A policy that determines how the City collects, stores, shares, and may search time-and-location data associated with ordinary residents’ vehicles feels like a matter of public governance and civil liberties, not only day-to-day administration.
In looking at how the Charter and Code address this kind of question, a few provisions seemed relevant and I wanted to flag them for the conversation. Charter Section 6 vests all powers of the City in the Council except as the Charter provides otherwise, and Section 5 directs that the Charter be liberally construed so the City may exercise its powers fully. Bend Code 1.30.005(E) requires the City Manager’s regulations, policies, and guidelines to be consistent with the Charter, the Bend Code, and Council ordinances, and 1.30.005(C) provides a mechanism for Council review of a City Manager regulation, either on its own motion or on petition of any person within 30 days of first public posting. I’m not assuming Policy 428 falls within (C) — the Code doesn’t define “regulation,” and I’d genuinely value the City’s view on that. But it does seem like the kind of question worth understanding the answer to, given the public-facing nature of what 428 governs.
A couple of things I’d appreciate your thoughts on whenever we talk: how the City thinks about whether a public-facing surveillance policy like 428 falls within 1.30.005(C), and whether there’s a sense of when Council might see the Policy 428 framework — and any related safeguards — in a public setting. I appreciate your clarification that any new fixed-ALPR use will require a contract that comes before Council with public comment, and that’s helpful. My remaining concern is sequencing: by the time a contract reaches Council, the governing framework may already be largely set by the department policy and the vendor’s terms. Seeing the policy framework publicly before or alongside any such contract would let the community weigh in while the rules can still be shaped.
That same reasoning is why I raised the surveillance-technology procurement and oversight ordinance in my original letter. Adopting an ordinance is legislation, squarely Council’s role, and it would set clear public rules up front rather than handling each issue ad hoc after it becomes a controversy. I’d love to discuss that on the call as well, if you have time.
My schedule is pretty flexible for the next week or so — if you can send a couple of times that work for you, I can accommodate. Thank you again for engaging with this so seriously.
Most people don’t think much about how the City buys technology. But some of the tools cities now use — cameras, license plate readers, drones, data dashboards — can quietly record where you go, who you’re with, and what you do, long before anyone suspects you of anything. Once a city owns a system like that, what it can do tends to grow over time through software updates and new features, often without anyone outside the vendor noticing.
I’ve submitted two documents to the Bend City Council that are meant to put residents back in control of that process: a Surveillance Technology Accountability, Privacy, and Civil Rights Ordinance and a companion Surveillance Procurement and Contracting Framework. Here’s what they would actually do for the people who live here.
You get a say before the City buys surveillance tools
Under the proposed ordinance, no City department could acquire, borrow, pilot, subscribe to, or deploy surveillance technology without prior City Council approval at a public hearing — with the required reports released at least 30 days in advance so residents can read them and weigh in. That approval has to be specific: approving one tool doesn’t automatically approve another, approving hardware doesn’t approve hidden software features, and any ambiguity is resolved in favor of requiring public approval. The decision about whether Bend adopts a surveillance tool belongs to the community and its elected representatives — not to a vendor’s sales pitch or a quiet administrative purchase.
Surveillance can’t quietly expand after it’s approved
One of the biggest real-world risks is “mission creep” — a system bought for one narrow purpose gradually gaining new powers through updates, add-on analytics, or AI modules. The ordinance treats any meaningful expansion as a “material change” that requires fresh public approval, and it specifically says automatic, vendor-pushed, or bundled updates can’t switch on capabilities the public never approved. A camera approved as a camera doesn’t silently become a facial-recognition system.
Protected and private activities are shielded
The ordinance bars using surveillance to monitor or map constitutionally protected activity — protest, worship, journalism, labor organizing, political activity, legal advocacy — absent a warrant. It also protects “sensitive locations”: medical and reproductive care facilities, addiction-treatment centers, domestic-violence shelters, immigration legal-aid offices, libraries, newsrooms, polling places, and places unhoused residents rely on for shelter and survival. The City couldn’t build registries, heat maps, or profiles tracking unhoused people or anyone’s visits to these places.
Your data can’t be sold or fed to corporate AI
The rules prohibit the City — and its vendors — from selling, renting, or commercially exploiting surveillance data, and from using residents’ data to train or improve a vendor’s products or algorithms. They also bar using City surveillance for civil immigration enforcement except where the law specifically requires it. Data collected about Bend residents stays in service of Bend residents.
The City — not a private company — holds the keys
A system being “encrypted” doesn’t mean it’s secure if the vendor can still read the data. The ordinance requires that sensitive stored police data use “Exclusive Agency Key Control,” meaning no vendor, cloud host, or subcontractor can unilaterally decrypt it. License plate data that isn’t a hit gets automatically deleted within 72 hours, hot-list entries expire quickly, and bulk databases can’t be kept around for speculative future use.
Real accountability you can check
Every access to sensitive surveillance data has to be logged. High-risk programs get independent annual audits, and the City must publish an annual public report covering how often tools were used, how many searches were run, any misuse or breaches, and any expansions proposed or discovered. There’s a public complaint process, automatic suspension when something goes seriously wrong, and a hard rule that no existing contract is grandfathered in forever — legacy systems have to be brought into compliance or discontinued.
The companion framework makes the promises stick
Strong policy can still be undermined by weak contract language buried in vendor agreements. The Procurement and Contracting Framework translates these principles into the actual contracts: baseline terms requiring City ownership of data, no secondary vendor use, no silent feature activation, audit rights, deletion certification, and renewal conditioned on compliance — with even stronger terms for high-risk technologies. It also gives the City practical tools to review the contracts it already has, so the protections aren’t just aspirational.
The bottom line
None of this stops Bend from using technology that genuinely serves public safety. What it does is make sure that when surveillance tools are used, the public knew about it, approved it, can see how it’s working, and can shut it down if it’s misused. It puts residents — not vendors, and not default settings — in charge of decisions that affect everyone’s privacy and civil liberties.
The City Council does not typically review administrative polices of the police department, as we are not direct managers of the police department nor any other staff other than the City Manager. This is why I forwarded your feedback to the Chief. Also, it’s not possible to really engage in discussion and deliberation with you over email with all of us included as that would violate public meeting laws. I’m happy to give you a call to discuss more individually. I am moving Council to BCC to avoid further group emails at this point.
Some other clarifications:
Any new use of fixed ALPR will require a contract, that contract will come before Council at a public meeting at which public comment will be available, and discussion can be had at that time of whether Councilors want to support such a contract or not. Written comments from the public on items of general interest are received directly to us via email to Councilall@bendoregon.gov – unless it is a land use public hearing our staff typically do not compile comments for the agenda packet but we see them in our email.
On policy 428 – as is the case with many administrative or city policies that are governed by state law, it is not necessary to copy the exact, full language of the statute into our policy. The state law will always apply, even if our policy does not incorporate each and every word. Admin policies guide our departments and are operational documents – they do not replace or override state laws and statutes, which always apply.
Please let me know if you’d like to chat further and I can give you a call.
Bend’s next surveillance decision is no longer theoretical. After shutting down its Flock Safety cameras earlier this year, Bend officials are now considering stationary Axon automated license plate reader cameras.
The first important development came from The Source Weekly, which reported that Bend officials were looking at Axon as a possible new stationary ALPR vendor. According to the reporting, the proposal could be handled as an add-on to Bend’s existing Axon contract, and more than 70 Bend Police cruisers have already used Axon Fleet 3 camera systems with ALPR capabilities since July 2023. (Source Weekly, May 20)
That matters because a stationary ALPR system is not just another camera. It creates a searchable record of vehicle movements. It can connect to vendor systems, agency workflows, evidence platforms, audit logs, retention settings, and future software features. If the rules are weak at the start, the public may not understand what was approved until the system is already in place.
The second important development is better news for public oversight. A follow-up Source Weekly story reported that, after public interest, City Manager Eric King would bring the stationary ALPR decision to Council for a vote and allow public input before the decision moves forward. The same article reported that Axon and Bend Police would evaluate two demonstration ALPR units and begin phased installation of cameras at Bend entry and exit points in the coming year, according to King’s report. (Source Weekly, May 22)
That process matters. Bend residents should not have to learn about surveillance expansion only after contract language, demo units, or vendor workflows are already in motion. Public input is strongest before a system becomes normal, before data starts flowing, and before future upgrades are treated as minor technical changes.
Why it matters for Bend: Bend has already learned that ALPR oversight cannot stop at vendor selection. The public needs clear answers before any stationary ALPR system returns: who can search the data, whether outside agencies can access it, whether federal immigration searches are technically blocked, how long plate data is retained, what audit logs show, whether vendor staff can access the system, and whether future features can be activated without a new public process.
Bend’s decision does not happen in isolation. National reporting now shows why local ALPR rules need to account for federal access before the data exists.
404 Media reported that the FBI wants to buy nationwide access to automated license plate reader data, which could allow the agency to track vehicles, and by extension people, across the country without a warrant. WIRED framed the request as an effort to obtain “near real-time” access to U.S. license plate readers, and Ars Technica reported that the FBI wants U.S.-wide access to license plate cameras with data in near real time. (404 Media) (WIRED) (Ars Technica)
That is the national context for local ALPR decisions. A city may approve cameras for stolen vehicles, serious crimes, or public-safety emergencies. But once plate scans enter a vendor network, the data may become valuable to other agencies, other jurisdictions, and future search tools that were not central to the original local debate.
This does not require assuming bad faith by local officials. It simply recognizes how surveillance infrastructure works. The usefulness of a system grows when it connects to other systems. That is why access limits, retention limits, audit logs, purpose rules, vendor-access controls, and public reporting need to be built before deployment, not negotiated after the data becomes useful to others.
Why it matters for Bend: If Bend brings stationary ALPR back through Axon, the policy question should not be limited to whether the cameras help police solve crimes. Councilors and residents should also ask what network the cameras join, whether Bend data can be searched outside the city, whether outside access is disabled by default, and whether future sharing requires public notice and Council approval.
“A dependence on the people is, no doubt, the primary control on the government; but experience has taught mankind the necessity of auxiliary precautions.” — James Madison, The Federalist No. 51 (1788)
School-bus cameras could become mobile ALPR infrastructure
ALPR expansion is not limited to fixed cameras on poles or cameras mounted on police vehicles.
404 Media reported that BusPatrol has installed AI cameras on tens of thousands of school buses and now wants to let law enforcement search the license-plate data those buses collect while driving. The original purpose is school-bus safety and stop-arm enforcement. The warning signal is what happens when that safety system becomes a mobile plate-reader network. (404 Media)
That shift matters because public approval for one purpose does not automatically justify another. Residents may support camera enforcement to protect children at bus stops while still objecting to broad police searches of location data collected across neighborhoods.
The safeguard lesson is direct: purpose limits need to be written before deployment. A school-bus safety system should not become general law-enforcement infrastructure without public notice, public debate, retention limits, access restrictions, and audit logs.
New Hampshire offers one of the clearest examples of strict ALPR regulation. Under New Hampshire RSA 261:75-b, number-plate scanning devices are limited to law-enforcement use and may be used only for specific purposes, such as identifying stolen vehicles, wanted or missing persons, suspended or revoked registrations, outstanding warrants, or vehicles connected to certain criminal investigations. (NH RSA 261:75-b)
The law also says an ALPR alert alone does not create reasonable suspicion for a stop; an officer must visually confirm the plate or develop independent reasonable suspicion. Routine scanned-plate data may not be recorded or transmitted and must be purged within three minutes, unless the alert leads to a citation, arrest, protective custody, or another specified documented action. HB 1059 removed the scheduled repeal of the law, making that framework permanent. (BillTrack50 HB 1059)
That model matters because it shows ALPR safeguards do not have to be vague. A law or policy can define who may use the system, what purposes are allowed, how quickly data must disappear, what confirmation is required before action, and what cannot be shared.
Shared pattern: ALPR is becoming network infrastructure
The strongest stories this week point in one direction: ALPR is no longer only a local camera purchase. Fixed city cameras, police vehicle cameras, state pilots, vendor platforms, retail parking lots, and school-bus systems can all generate searchable vehicle-location data.
A tool introduced for one purpose can later become useful for another: stolen-car recovery, traffic enforcement, immigration enforcement, retail security, school-bus safety, federal investigations, or broad movement tracking.
That is why Bend’s next step matters. The central question is no longer only, “Should this camera be installed?” It is, “What network does this camera join, who can search it, what vendors or subcontractors can access it, how long the data remains useful, and whether the public can verify the answers?”
Surveillance oversight works best before the system becomes infrastructure.
“Experience should teach us to be most on our guard to protect liberty when the government’s purposes are beneficent.” — Justice Louis Brandeis, dissenting in Olmstead v. United States (1928)
Warning Signals
These items point toward where surveillance systems, vendor platforms, identity infrastructure, and data governance may be heading next.
This week’s Axon Watch is not only about new features. It is about how public-safety technology is becoming a connected platform: cameras, evidence storage, records, AI report drafting, case review, partner sharing, retention rules, and audit trails.
Axon’s May 2026 release notes show several changes officials should watch closely. In Axon Evidence, the May DEMS update includes Case Agent, an AI tool that can reason over selected case evidence and provide citation-backed responses; Advanced Case Sharing, which gives partner organizations controlled access to shared cases and evidence; more human-readable audit-trail exports; configurable media-view permissions; evidence-search API rate-limit changes; and retention categories that can be configured from one day up to 99 years. (Axon DEMS May 2026 release notes)
Axon Records also received May updates affecting report writing, report search, audit-log sorting, and DataStore access controls. Axon’s cameras and sensors release notes show the continuing deployment cadence for the device side of the same ecosystem. (Axon RMS May 2026 release notes) (Axon Cameras and Sensors May 2026 release notes)
Draft One deserves special attention. Axon’s own product guide says Draft One can be used on “any playable audio/video files supported by Axon Evidence,” not just body-worn camera footage. That means the oversight question is broader than “Can AI draft a police report from body-camera audio?” It is: what evidence types can feed AI-generated narratives, who can run the tool, how drafts are reviewed, whether edits are auditable, and whether the final report clearly reflects what came from the officer rather than the system. (Axon Draft One product guide)
This matters because Axon’s AI business is not a side experiment. Investor-facing reporting says Axon’s AI revenue grew sharply in Q1 2026, alongside broader growth in software, connected devices, records, and real-time operations. (Axon Q1 2026 AI revenue item)
For public officials, the key point is simple: when a vendor platform expands, oversight has to expand with it. ALPR, body cameras, evidence storage, AI report drafting, records systems, case sharing, and retention settings should not be reviewed as isolated tools if they operate inside the same ecosystem.
Cleveland appears to be another warning about the gap between policy promises and system behavior. Reporting mirrored by MSN says records showed Cleveland’s Flock network was used for immigration-related searches, with the city blaming Flock and drones after logs showed searches that raised concerns. (MSN mirror)
If a city says ALPR will not be used for immigration enforcement, that promise has to be reflected in technical controls. Are outside agencies blocked by default? Are search purposes required? Are federal queries technically prevented? Are vendor settings independently reviewed? Are audit logs public enough for elected officials and residents to verify compliance?
Vehicle privacy now includes apps, stores, accounts, and purchase histories
Vehicle surveillance is no longer only about cameras reading plates. Forbes reported that federal prosecutors demanded identifying information from Apple, Google, and Amazon connected to users of the EZ Lynk vehicle-tuning app. The reporting says the demand sought information including names, addresses, IP addresses, and purchase histories, and that the demand to Google alone could cover more than 100,000 users. (Forbes)
Cars and vehicle-related behavior can now be connected through license plates, app stores, cloud accounts, connected-car services, purchase histories, repair tools, insurance systems, location data, and payment records. The safeguard question is not only whether a camera can see a car. It is whether vehicle-related data can be used to identify large groups of people after the fact.
Age verification is becoming identity infrastructure
Child safety online is a legitimate public goal. But the design of age-verification rules matters. Georgia Tech researchers reported that online age checks can create privacy risk when verification systems collect and share sensitive data such as face images and device fingerprints. EFF also warned that lawmakers are moving toward broad youth social-media restrictions while the evidence base remains contested. (Newswise / Georgia Tech) (EFF)
The trend is broader than ID upload. Colorado’s OS-level age-data proposal, Meta’s AI-based age enforcement, and similar proposals point toward systems where apps, operating systems, platforms, or AI models infer or verify age before people can access ordinary online spaces. (Reclaim the Net) (TechNewsWorld)
Direction of travel
This week’s signals point in the same direction: data collected for one purpose is becoming useful for another. ALPR systems can become federal search tools. Evidence platforms can become AI report-writing systems. Age checks can become identity infrastructure. Vehicle apps can become investigative datasets. The safeguard challenge is to define access before the system becomes too widespread to limit.
Safeguards
A safeguards page works best when it gives officials practical models: shorter retention, narrower access, public review, usable audit logs, and clear limits before systems become infrastructure.
Look to Connecticut and Troy for access and immigration-use guardrails
New Hampshire is not the only model. Connecticut’s SB 397 offers another strong example because it connects ALPR limits with immigration-enforcement protections. The details should be reviewed carefully before copying the language, but the policy lesson is clear: ALPR rules can address civil-rights concerns directly, including whether local data can be used to support federal immigration enforcement.
Troy, New York, offers a city-level example. After public conflict over Flock cameras, the mayor and council agreed on new rules that included stronger limits on data sharing, annual audits, restrictions on immigration-enforcement use, limits involving public demonstrations, and controls around nationwide lookup features. (Times Union)
For Bend, the lesson is not to copy any one jurisdiction word for word. The lesson is that guardrails can be written before approval. A city can require narrow purpose limits, outside-agency restrictions, immigration-use rules, audit access, public reporting, and Council review before cameras are installed.
Surveillance oversight should not end at the purchase date. Cambridge, Massachusetts, recently voted to end its ShotSpotter contract after public debate and a close Council vote. The decision shows that cities can reassess surveillance tools after deployment and decide that a system no longer meets local standards for trust, accuracy, cost, civil rights, or public accountability. (Cambridge Day)
That matters for ALPR because approval should not be treated as permanent. Any new Bend policy should include renewal dates, public reporting, independent review of audit logs, complaint pathways, and a real off-ramp if the system fails to meet the community’s standards.
Treat procurement ethics as a privacy safeguard
Surveillance procurement is not just about price and features. It is also about public trust. Bend already has a procurement ethics and reporting page that describes ethics commitments, reporting options, and a confidential third-party reporting tool for concerns involving fraud, misconduct, policy violations, or ethics issues. Oregon law also limits gifts from sources with legislative or administrative interests, and Oregon ethics rules help define when a source has an interest in public decisions, contracts, or use of public funds. (City of Bend procurement ethics) (ORS 244.025) (Oregon ethics rules)
Those rules matter in surveillance procurement because vendor relationships can shape public infrastructure for years. Demo units, pilots, add-ons, contract amendments, software subscriptions, AI upgrades, and support access should all be documented clearly.
When the product is surveillance infrastructure, procurement ethics become privacy safeguards. Public officials should know what vendor contacts occurred, what features were demonstrated, what contract pathway is being used, whether subcontractors or support staff can access data, and whether future add-ons will return to Council before activation.
Do not let cybersecurity become the forgotten access-control layer
Reuters reported that vulnerability exploitation surpassed stolen credentials as an initial breach vector in Verizon’s 2026 breach report, while AI is helping attackers move faster. Separately, Axios reported that a senator requested a classified briefing after CISA and DHS credentials were exposed through a contractor’s GitHub repository, and WIRED reported on a software-supply-chain attack spree that compromised developer tools and open-source ecosystems. (Reuters) (Axios) (WIRED)
The practical lesson is simple: access controls are only as strong as the systems behind them. Public agencies should require MFA, least-privilege access, credential rotation, secrets scanning, vendor incident reporting, software dependency review, patch timelines, and logs that show when vendors, subcontractors, or contractors accessed sensitive systems.
Bottom line
The best safeguards this week are practical: require public review before expansion, narrow the purpose, shorten retention, block outside access by default, prohibit immigration-use unless clearly authorized by law, require visual confirmation before enforcement action, log every search, audit the logs, disclose vendor and subcontractor access, and make shutdown or nonrenewal a real option.
Public input is the primary control. But public input works best when it is backed by auxiliary precautions: enforceable rules, technical limits, audit trails, and consequences before surveillance systems become too widespread to limit.
“If men were angels, no government would be necessary.” — James Madison, The Federalist No. 51 (1788)
Thank you for confirming receipt, and for ensuring the comments reach Chief Krantz. I appreciate it.
I do want to clarify that several of my asks are Council-level governance questions rather than only Department policy edits. Specifically, I am asking whether Council will require public review before treating Policy 428 as sufficient ALPR governance, and whether Council will direct that no new ALPR system, renewal, expansion, or feature activation move forward until the policy is amended.
Since Councilors are copied on this thread, I want to be clear that the three asks in my letter are addressed to Council as a body. They concern public oversight and governance, not only edits to Department policy, and I would welcome any response from Councilors.
I would also appreciate understanding the City’s process for written public comment on Policy 428 or future ALPR use. Will written comments be included in the Council packet for the meeting where this comes up, or distributed to Councilors individually?
I have not seen Policy 428 on a published agenda yet, and I would like to be there in person for public comment if and when it comes up.
Dear Chair Chang, Vice Chair DeBone, and Commissioner Adair:
I am writing on behalf of Bend Privacy Alliance regarding Action Item #6 on the May 27, 2026 Board agenda: authorization of Contract No. 2026-0327, a five-year, $2,412,669 agreement with Axon for body-worn cameras, Tasers, and fleet cameras for the Deschutes County Sheriff’s Office.
I understand that body-worn cameras and fleet cameras can serve legitimate public-safety, evidence, and accountability purposes. My concern is not with cameras in the abstract.
My concern is that this procurement is not simply an equipment replacement. It is a five-year commitment to a digital-evidence and cloud technology platform that may include, enable, or allow later activation of ALPR, AI tools, analytics, data-sharing functions, and vendor-controlled system settings.
The Board should not be asked to approve that kind of system without a clear public record of what is included, what is excluded, and what cannot be enabled later without separate public approval.
The December 2025 audit should be treated as a prerequisite document
The December 2025 Deschutes County Internal Audit should be treated as a prerequisite document for this vote.
The audit found that DCSO’s existing body-worn and in-car camera program had a solid foundation, but needed improved oversight and reporting. It found that camera reporting was not published, replicable, or evaluative; supervisors were not consistently reviewing footage according to policy; public-records tracking was incomplete; and information-security controls fell short.
Most importantly, auditors could not independently verify whether deputies consistently recorded and categorized footage because DCSO did not provide access to footage for audit review.
The County should not approve a more complex Axon cloud ecosystem unless the contract and implementation plan directly address those audit findings.
The ALPR question should be answered before approval
The most urgent issue is ALPR.
DCSO spokesperson Jason Carr recently told The Source Weekly that the Sheriff’s Office does not currently use ALPR. However, the staff report refers generally to “fleet cameras” and does not identify the specific Axon fleet-camera model, software modules, or activation rights included in the contract.
Axon’s Fleet 3 system is publicly described as having ALPR capability, and Axon states that Fleet 3 ALPR can be activated as a subscription through Axon Evidence without additional equipment.
That matters because SB 1516 took effect in Oregon on March 31, 2026.
If this contract includes ALPR-capable hardware, ALPR software, or the ability to enable ALPR later, the County should demonstrate before approval how the contract complies with SB 1516’s requirements for captured license plate data, vendor restrictions, retention, sharing limits, audits, public reporting, and end-to-end encryption.
Encryption and vendor access need clarification
This is not theoretical.
Oregon’s Chief Information Security Officer testified that under Axon’s cloud architecture, “each law enforcement agency service subscriber does not retain encryption keys to their own data.”
SB 1516 requires ALPR data to be encrypted using, at minimum, end-to-end encryption, but the practical meaning of that requirement is still developing.
Before entering a new five-year Axon agreement with any ALPR capability or activation rights, the County should clarify who controls encryption keys, who can decrypt ALPR data, and whether Axon or any subcontractor retains technical access.
Other jurisdictions show why technical compliance should not be assumed
Other jurisdictions have already faced this problem.
In March 2026, the Pierce County, Washington Sheriff’s Office reportedly deactivated approximately 200 Axon Fleet 3 ALPR cameras after concluding that its system could not be operated in compliance with Washington’s new ALPR privacy law.
Oregon’s law is different, but the lesson is directly relevant: technical compliance with ALPR privacy laws should not be assumed. It should be demonstrated before approval or activation.
Recent Oregon examples show why defaults and sharing settings matter
Recent events in Oregon also show why this matters.
Federal immigration authorities reportedly queried Bend PD’s Flock Safety ALPR database 279 times in three weeks after a vendor default setting was not disabled.
The Rural Organizing Project has also filed litigation alleging that federal immigration authorities were able to query Oregon State Police systems through LEDS/NLETS; OSP denies the allegations, and the litigation is pending.
These examples show why vendor defaults, interagency access, and data-sharing settings need to be addressed before surveillance technology is deployed.
Existing policies do not appear to answer the ALPR question
DCSO’s existing policies are helpful, but they do not appear to answer the ALPR question.
Policy 8.21 governs body-worn and in-vehicle incident recording, not bulk license plate scanning of uninvolved drivers.
Policy 4.30 governs LEDS, NCIC, and CCH access, but does not appear to govern automated plate scans or hotlist matching.
Policy 4.35 governs generative AI, but does not appear to govern ALPR, vehicle classification, or computer-vision analytics.
Policy 4.15 governs digital media as evidence, but does not appear designed for continuous or bulk vehicle-location collection.
Questions the Board should require answers to before voting
Before voting, I respectfully ask the Board to require clear answers to five questions:
What specific Axon products, fleet-camera model, software modules, cloud services, and activation rights are included in Contract No. 2026-0327?
Does the contract include ALPR-capable hardware, ALPR software, hotlist matching, vehicle analytics, searchable vehicle-location data, or any ability to activate those functions later?
If ALPR capability is included or can be enabled later, how does the contract comply with SB 1516, including encryption, retention, search logs, vendor restrictions, audits, public reporting, and data-sharing limits?
Are any Axon AI tools included, licensed, enabled, or available through this contract, including Draft One, Policy Chat, AI transcription, AI redaction, summarization, report writing, predictive analytics, or any tool that analyzes body-camera, fleet-camera, audio, video, report, or evidence data?
What limits will apply to interagency sharing, federal access, out-of-state access, vendor access, subcontractor access, and default settings that could allow data to be shared beyond DCSO?
Requested Board action
I respectfully ask the Board to take one of three actions:
First
Defer authorization until these questions are answered, any ALPR-specific policy is developed if ALPR is included or available, and the internal audit referenced in the staff report is made available or publicly summarized.
Second
Sever the fleet-camera portion from the body-worn camera and Taser portions and authorize only the latter two while the County resolves the ALPR, AI, SB 1516, and sharing questions.
Third
At minimum, condition approval with clear motion language stating that:
No ALPR, license-plate recognition, hotlist matching, vehicle analytics, or searchable vehicle-location data may be enabled without separate public notice, policy review, SB 1516 compliance analysis, and Board approval.
No Axon AI, AI-assisted report writing, AI transcription, predictive analytics, biometric analytics, facial recognition, or new cloud analytics module may be enabled without separate public notice, policy review, and Board approval.
All access, searches, exports, downloads, sharing, retention changes, deletion activity, and vendor-support access must be logged and auditable.
Vendor default settings allowing federal, out-of-state, or third-party sharing must be disabled at the contract or administrator level unless separately approved by the Board.
The County must publish a plain-language privacy impact summary before deployment and provide annual public reporting on system use, access audits, sharing activity, retention/deletion compliance, complaints, policy violations, and any AI, ALPR, or analytics tools enabled.
Conclusion
Body-worn and fleet cameras may improve accountability, but only if the surrounding data system is governed by clear limits, public transparency, enforceable retention rules, strong audit logs, and meaningful restrictions on secondary use.
The Board should not authorize privacy-sensitive capabilities that have not been clearly disclosed, governed by policy, and shown to comply with Oregon law.
Thank you for your consideration. I plan to attend the May 27 meeting and am available to discuss any of the above at the Board’s convenience.
Attached are my detailed comments on Bend Police Department Policy 428, dated May 15, 2026, along with a one-page summary of requested amendments and Exhibit A, a section-by-section comparison of SB 1516 and Policy 428.
My central concern is that Policy 428 has two separate problems.
First, the policy contains specific operational and textual gaps that should be closed before adoption — places where the policy authorizes uses broader than the statute permits, omits required vendor contract terms, or fails to require audit and logging fields the statute requires the operative documents to contain.
Second, even where the policy fits within SB 1516, it adopts the broadest uses state law still allows rather than a narrower local standard appropriate for Bend.
SB 1516 is the statutory floor for ALPR use in Oregon — it is not the ceiling for local privacy protection.
The clearest example is the parking-use authorization. SB 1516 §4(2)(g) permits ALPR use for “regulating the use of parking facilities” — one bounded purpose. Policy 428.3 expands this to “parking regulation and the management of parking facilities” — two distinct authorizations joined by “and.”
That is the operative permission on the face of the document and cannot be cured by deference to state law.
The attached letter identifies similar operational gaps in the policy’s required vendor contract terms, including missing CJIS Security Addendum execution and security-incident notification language; the monthly vendor audit fields, including missing the per-search detail SB 1516 §6(1)(i) requires; and the outside-agency search log, including the missing cameras-accessed field SB 1516 §5(2)(b)(C) requires.
It also addresses SB 1516 §5(2)(b)’s substantive scope limits on outside-agency sharing — “limited to data relevant” and “no unrestricted or ongoing access” — which are independent of the prohibited-purpose list in Policy 428.6.3 and worth operationalizing through the written request-certification process described in Part II.
The letter also describes eighteen local strengthenings grouped into seven categories:
administrative-use limits,
sensitive-location and occupant protections,
outside-agency controls,
retention and historical-search limits,
vendor and cybersecurity controls,
public accountability and complaint redress, and
Council-approval requirements.
Each is consistent with SB 1516; none asks the City to use ALPRs in a way state law prohibits.
I respectfully ask Council not to treat Policy 428 as final until Bend PD closes the operational and textual gaps identified in the letter and Exhibit A, and until Council considers stronger local safeguards.
I would also encourage Council to advance the broader Bend Surveillance Technology Accountability, Privacy, and Civil Rights Ordinance so future surveillance technologies are not added in piecemeal department-policy form without public notice and Council approval.
I am happy to answer questions, provide further clarification, or discuss any of the items in the attached materials at the Council’s convenience. I can be reached at
Thank you for your time and consideration.
Sincerely,
Jonathan
Attachments
The documents attached to my email to Council are available below: