
Issue 17 • Wednesday, July 15, 2026
A concise weekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.
At a Glance
- LAPD’s audit findings and continuing Flock contract dispute show why surveillance-vendor assurances must be converted into configurations, logs, and contract terms that an independent reviewer can test.
- The Seventh Circuit rejected Clearview AI’s unusual biometric settlement because differently situated class members did not have adequate representation.
- New Jersey prohibited sales of sensitive data, while new research shows why privacy rights still fail when each data broker controls its own opt-out and deletion process.
- Redmond’s $410,762.16 Axon award includes six Skydio drones, 38 vehicle fleet-camera upgrades, and DroneSense livestreaming—and the department already operates fixed Axon plate readers—showing why bundled technology contracts need a complete capability and data-flow inventory.
Flock’s trust problem is now a governance problem
The American Civil Liberties Union has assembled a national record of instances in which it says Flock Safety gave police departments, elected officials, or the public inaccurate or misleading accounts of how its automated license plate reader network operates. The July 2 analysis points to disputes involving federal access, national searches, product capabilities, camera status, sharing settings, and vendor control.
The document is advocacy, not an adjudication. Its most serious examples should therefore be read alongside underlying records and the affected jurisdiction’s response. But the pattern matters even before every disagreement is resolved. A surveillance vendor is not selling an ordinary office product. Its descriptions can determine whether officials approve deployment, what a policy prohibits, what the public believes is possible, and whether a later audit is designed to detect the right risks.
Issue 16 described how Woodburn learned that its cameras had appeared in broad outside-agency searches through a pilot architecture city officials said they had not knowingly approved. The broader warning is that officials cannot assume contract language, dashboard labels, or a verbal assurance fully describe the live system.
That problem is especially serious in a networked platform. A local agency may control its own users while the vendor controls hosting, software updates, administrator privileges, integrations, federation rules, default settings, and the practical meaning of a feature name. A city may prohibit national sharing yet remain exposed through a pilot, external search path, inherited configuration, support account, or later product update.
The clearest example arrived in Los Angeles. In a review of two months of LAPD automated-license-plate-reader activity, the Los Angeles Police Commission’s Office of Inspector General found that ALPR activity contributed to recovery of 337 stolen vehicles. It also identified 161 alerts that officers initially treated as matches to stolen vehicles but that later proved inaccurate. That is not a general error rate across every plate scanned, and the public report does not establish that every inaccurate alert resulted in a vehicle stop.
The review covered LAPD’s larger, multi-vendor ALPR environment rather than Flock cameras alone. Flock operated 138 pole-mounted cameras within a department-wide network of roughly 2,000 readers. The governance lesson is not that one percentage fully measures one vendor. It is that an independent reviewer could reconstruct alert handling, identify inaccurate matches, and examine data-sharing and contract risks across the system.
LAPD then allowed its three-year Flock agreement to expire and suspended ordinary access while negotiating stronger terms involving privacy, security, data ownership, and sharing. The Los Angeles Times reported on July 14 that negotiations continue, so the lapse should not be treated as a final decision to abandon Flock. The Police Commission separately supported suspending new Flock deployments and contracts pending additional oversight and public input.
This is why public bodies should treat material vendor representations as testable contract requirements. Before approval, officials should require a live demonstration of every sharing and administrator screen, a diagram of all local, outside-agency, vendor, and subprocessor access paths, and an export showing the exact audit fields generated by each action.
The contract should attach the approved configuration, prohibit silent changes, and require written notice and affirmative approval before a pilot, integration, network expansion, administrator role, or new search mode touches local data. It should require preservation of evidence when a disputed representation arises and permit independent technical review. A vendor’s failure to produce the agreed audit evidence should itself be a material breach.
Why it matters for public officials: Oversight cannot depend on asking the same company that designed the system whether the system complies. The agency needs technical controls and records that allow someone else to reconstruct what happened.
A practical verification test: Can the agency independently identify every person and organization that searched, viewed, exported, shared, administered, or changed the system—including vendor staff—and can it prove that prohibited access was technically blocked rather than merely discouraged by policy?
Clearview settlement fails on who represented the class
The U.S. Court of Appeals for the Seventh Circuit has vacated approval of an unusual nationwide settlement involving Clearview AI. Instead of conventional cash relief, the agreement would have given class members a financial interest tied to about 23 percent of the facial-recognition company’s future value.
The court did not hold that an equity-like remedy is inherently improper, and it did not decide the underlying biometric-privacy claims. It also did not require additional injunctive relief. The decisive problem was procedural: the settlement created much larger potential benefits for favored state-law subclasses, but the nationwide class lacked representatives who could adequately protect the interests of people in those different groups.
The case now returns to the district court. The policy conflict remains important. A privacy remedy should compensate affected people and constrain unlawful conduct without making their recovery depend on the future commercial success of the very surveillance practice being challenged.
For public officials, the lesson is not limited to class actions. Remedies should be evaluated operationally: What conduct stops? What data are deleted? What future collection is restricted? Who receives compensation? Who can enforce the agreement? A settlement can be creative without being accountable.
“We cannot get past a key procedural problem in the settlement process.”
— U.S. Court of Appeals for the Seventh Circuit, In re Clearview AI, Inc. Consumer Privacy Litigation (2026)
New Jersey moves upstream—but privacy rights still need a working compliance system
New Jersey enacted A5328 on June 30 as P.L. 2026, c.25. The law prohibits selling, offering to sell, or licensing sensitive data and directs the state to create a public registry for data brokers and a newly defined category of data collectors.
The sensitive-data sales prohibition took effect immediately. The registry provisions are delayed for 270 days and are scheduled to become operative on March 27, 2027. That timing distinction matters: New Jersey has already made the upstream policy choice that covered sensitive information cannot be sold, even though the registration system is not yet operational.
The prohibition is structurally important because it applies regardless of how many consumers’ records an entity controls or processes and regardless of whether the seller would otherwise fall within the New Jersey Data Privacy Act’s usual thresholds. That avoids a common weakness in privacy statutes: numerical thresholds that leave smaller but highly sensitive datasets outside the rule.
The law’s definition of sensitive information reaches categories that can expose a person’s body, beliefs, associations, movements, and vulnerability. The precise exceptions, registration disclosures, fees, and enforcement provisions will matter in implementation, but the central policy choice is clear: some data should not become a commercial product merely because a company can collect or infer it.
This advances the data-broker discussion from Issue 16. A warrant requirement or procurement restriction controls the government buyer. A sales prohibition controls the market that supplies the buyer. Neither approach is complete by itself.
If government cannot compel sensitive location information without judicial process but can buy a commercially assembled substitute, constitutional protection becomes dependent on the acquisition route. If a state prohibits government purchases but permits unrestricted commercial sale, the same information remains available to private investigators, employers, insurers, landlords, political operatives, abusive partners, and intermediaries that may later sell to government.
An upstream rule also reduces the burden placed on individuals. A person should not have to identify hundreds of hidden companies, submit separate requests, disclose more identity data, and repeatedly opt out of a market they never knowingly joined.
Rights on paper still fail at the doorway
A July UC Irvine study using synthetic identities found that opt-out and deletion processes among California-registered data brokers remained inconsistent, burdensome, and sometimes ineffective. Researchers reported nonresponses, intrusive verification demands, and substantial variation in how requests had to be submitted. These are research findings rather than enforcement judgments, but they test what consumers actually encounter when trying to use rights that exist on paper.
A separate large-scale study of registered brokers found that only 9 percent of 522 brokers were fully compliant with transparency requirements. In an audit of 250 consumer-request processes, 43 percent made it impossible to exercise all privacy rights and 64 percent introduced at least one feature that created substantial friction.
Together, the studies illustrate a recurring design failure: the regulated company controls the doorway through which a person must pass to invoke the right against that company.
The consumer may not know the broker exists. The broker may demand identity documents that create new risk. Names, addresses, emails, and phone numbers may not match the records the broker bought. A deletion request may remove one profile while another affiliate, source, or later purchase recreates it.
The better model is centralized and testable. California’s Delete Request and Opt-Out Platform provides a developing example: one verifiable request can direct registered brokers to delete covered information, with broker processing requirements beginning August 1, 2026. A state can also prohibit unnecessary identity collection, publish response rates, conduct regulator-run test requests, and impose consequences when firms do not respond or reacquire deleted data.
Officials should distinguish deletion from suppression. A company may stop displaying a profile while retaining data, hashes, linkage keys, derived attributes, or source relationships that allow the profile to reappear. A meaningful deletion standard should specify what must be erased, what may be retained for legal compliance, how downstream recipients are notified, and how completion is certified.
A registry should make the market inspectable
A useful registry should identify each broker’s legal and trade names, parent and affiliates, categories of data collected, original sources, customer categories, sensitive-data practices, government clients, opt-out and deletion methods, retention periods, security incidents, and whether the company honors universal opt-out signals.
Registration alone is not validation. Regulators should compare claims against sample transactions, consumer requests, website behavior, contracts, and technical data flows. Repeated failure should lead to escalating penalties, suspension from the market, and notice to downstream customers.
Public agencies should consult the registry before purchasing or accepting commercially sourced data. Procurement files should identify the original collector and every intermediary, not merely the company that signed the government contract.
The combined safeguard: Restrict collection and sale of sensitive data upstream; require a warrant or equivalent judicial process for government acquisition downstream; and prohibit contractors or partner agencies from doing indirectly what the public body may not do directly.
The larger risk is what happens when separate databases become one system
A July 9 Brennan Center report warns that federal agencies are increasingly linking government records with commercially acquired location, biometric, financial, social-media, and other personal information. The report describes the Department of Homeland Security as an emerging hub for this consolidation and says AI-assisted analysis can turn records collected for unrelated purposes into searchable profiles of people’s movements, relationships, beliefs, and activities.
The warning reaches state and local government. Driver’s-license, benefits, voter-registration, law-enforcement, and other records may be requested or shared for purposes far removed from the reason they were originally collected. Protecting one local database is not enough if its contents can become an input to a much larger federal or commercial system.
Why it matters for public officials: Data-sharing agreements should state the permitted purpose, prohibit onward transfer and unrelated reuse, require notice and audit records for outside requests, and allow access to be suspended when the receiving agency changes how the information will be used.
Flock shows why officials need visibility into a vendor’s network and administrator actions. Clearview shows why a remedy must fairly represent differently situated people. Data-broker regulation shows why the original collector and every intermediary matter. Data consolidation shows why risk grows again when once-separate records become one searchable system.
In each case, accountability fails when review stops at the nearest interface: the local dashboard, the named defendant, the final seller, or the written policy. The safeguard must follow the system from collection through processing, sharing, decision, remedy, and deletion.
Data minimization includes separation: Before linking systems, document the original purpose and legal authority for every dataset, the people and agencies receiving access, the risks of inaccurate matches, and the conditions for ending the connection.
Local Watch
A closer look at how a bundled local purchase connects drones, vehicle cameras, license-plate readers, and livestreaming.
Redmond adds drones and fleet cameras to an existing Axon surveillance ecosystem
On June 23, the Redmond City Council approved a five-year, $410,762.16 award to Axon Enterprises and Skydio. The official council packet, pages 76–77, describes two Skydio R10 indoor drones, four Skydio X10 outdoor drones, software for livestreaming and integration with patrol and SWAT operations, and 38 Axon vehicle fleet cameras. The vehicle cameras will expand patrol-car coverage from two views—front-facing and rear-seat—to three by adding a rear-facing camera.
The agreement also provides for six new drones at the 30-month mark while allowing Redmond Police to retain and use the original six. If the first group remains operational, the department could have as many as 12 Skydio aircraft after the refresh rather than simply exchanging old equipment for new.
The staff report identifies $100,000 in General Operating Fund reserves for implementation. The remaining payments are scheduled unevenly: $70,256.02 in fiscal year 2026–27, $8,265.41 in 2027–28, and $110,746.91 in each of the following three fiscal years. Because the public packet contains the police staff report rather than the executed agreement and itemized vendor quote, it does not disclose every software license, storage term, administrator role, or data-control provision included in the award.
The purchase sits inside a larger Axon environment
Redmond Police already uses Axon body-worn cameras, vehicle cameras, interview-room cameras, Evidence.com, and fixed license-plate-reader cameras, according to the staff report. The new award therefore adds drones and expanded vehicle-camera coverage to an existing evidence and plate-reader environment rather than creating a stand-alone UAS program.
That distinction matters because surveillance capabilities can be shaped by how separate tools work together. A fixed plate reader may identify a vehicle and location; dispatchers or officers may then use patrol cameras or a drone to follow the response. The staff report does not say that Redmond currently connects fixed-LPR alerts to drone deployments, but both systems are now part of the department’s technology environment and should be governed as a combined workflow when they interact.
Skydio says the X10’s VT300-Z telephoto package can resolve a license plate from approximately 800 feet under suitable conditions. That is an optical capability: the camera may capture an image in which a plate is legible. It is not, by itself, automated plate recognition, optical-character recognition, or a database search.
Skydio separately describes drone-response systems that can receive alerts from third-party ALPR platforms. In that type of workflow, the fixed reader produces the plate match and the drone supplies aerial observation. Public records should make clear whether Redmond has enabled such a connection, what legal and policy rules apply, who may authorize a deployment, and what audit trail links the original plate alert to the drone mission.
DroneSense carries the livestream
The staff report names DroneSense as the livestreaming platform used by Redmond Police and SWAT during critical incidents and investigations. Redmond’s published UAS information says the department does not store data obtained by a UAS in third-party storage and has no UAS data-sharing agreements with outside agencies.
Livestreaming through a third-party platform does not necessarily mean that the provider permanently stores the video. It does mean the department should publicly document how the stream is secured and handled: whether DroneSense buffers or retains video or metadata; who can receive a stream; whether recipients can record it; how viewers are authenticated; whether access expires automatically; what viewer logs are created; and where flight telemetry, operator identity, and incident metadata are stored.
The same records should show whether completed drone recordings enter Evidence.com, whether live feeds can be viewed through an Axon command interface, which company controls administrator settings, and how access is revoked when an incident ends.
San Francisco shows the risk of weak sharing controls
A recent San Francisco incident demonstrates why those details matter even when a department has a written security policy. WIRED reported that live feeds from five San Francisco Police Department drones were reachable through a public Skydio ReadyLink without a password or authentication code. The feeds included color and thermal video, real-time location information, and the names and email addresses of drone pilots.
Researchers archived about 48 hours of activity: 60 videos from 20 flights showing detentions, searches, apartment windows, rooftops, streets, courtyards, unhoused people, and many bystanders who did not appear to be subjects of an investigation. The link had been set to remain active for a year and may have exposed the feeds for roughly six months.
ReadyLink is not the platform named in Redmond’s staff report; Redmond identifies DroneSense. The control lesson nevertheless applies to any livestreaming system. Authentication, named recipients, short expiration periods, complete viewer logs, and automatic revocation should be mandatory defaults rather than options left to the person creating a link.
The federal transition should be described precisely
Redmond’s existing drone fleet includes foreign-manufactured Autel and DJI aircraft. The staff report cites the American Security Drone Act and related National Defense Authorization Act provisions as the reason for moving to U.S.-manufactured Skydio equipment.
The federal restrictions are narrower than a general ban on commercial sales of all foreign-manufactured drones. Federal acquisition rules restrict federal agencies from procuring or operating covered systems and, beginning December 22, 2025, restrict the use of federal funds to procure or operate prohibited systems, subject to exceptions and waivers. Moving away from Autel and DJI may preserve federal-funding eligibility and reduce the risk that existing aircraft become harder to support, but the legal rule should not be described as a universal sales ban.
Why it matters locally: Redmond’s award adds indoor and outdoor drones and 38 vehicle cameras to an environment that already includes fixed Axon plate readers, Evidence.com, and DroneSense livestreaming. Oversight should focus on the combined data flows and operational workflows, not only on the label attached to each product.
Before fixed-LPR alerts are connected to drone response, live-feed access is expanded, storage or retention changes, remote or docked operations begin, or automated analysis is added, Redmond should require public notice, documented legal review, and approval proportionate to the new capability.
Local verification test: Can Redmond produce the executed agreement, complete product and license inventory, data-flow diagram, fixed-LPR integration map, livestreaming settings, retention rules, viewer logs, and approval history needed to show that the combined system matches its published UAS commitments?
“There’s a certain trust given to the police to use these things correctly.”
— Security researcher Sam Curry, quoted by WIRED (2026)

Warning Signals
Early indicators of how connected systems, software transitions, and delayed maintenance can expand risk before policy catches up.
Axon Watch: July 31 transition brings AI oversight questions
Axon says that on July 31 the legacy Axon Evidence experience will be deprecated and the redesigned interface will become the only version available. The deadline does not establish that any AI product will automatically be licensed or enabled for Bend. Availability may depend on licensing, configuration, rollout status, and agency activation.
But a mandatory interface change is still an oversight point. Officials should request a current feature inventory showing every AI-assisted capability available, licensed, enabled, or planned; the evidence it can analyze; the output it creates; retention and sharing; model providers and subprocessors; audit fields; human-review requirements; and whether activation requires notice, legal review, or Council approval.
Council question: Which Axon capabilities will be available to Bend after July 31, which are enabled, and what record will show when a new analytical or AI-assisted function is activated?
A federal information-sharing network was breached after warnings were twice dismissed
According to Nextgov’s account of an internal Department of Homeland Security incident readout, intruders accessed the Homeland Security Information Network, a platform used to share sensitive but unclassified records with federal, state, local, and international partners, after analysts twice concluded that suspicious activity was a false positive. By the time officials declared a breach, the intruders had installed hidden backdoors and stolen credential files. Public reporting has not established exactly what information was obtained from HSIN.
The same architecture that lets many agencies exchange information also lets one successful intrusion reach every connected partner. Any agency using a federal or regional sharing network should know who can close an alert, what independent verification occurs before suspicious activity is dismissed, and how partners are notified when the network may be compromised.
Active exploitation turns maintenance into an emergency
CISA warned on July 14 about active exploitation of Microsoft SharePoint vulnerabilities and urged organizations to harden affected systems. A vulnerability bulletin becomes a safeguard only when someone knows which systems are affected, has authority to act immediately, verifies that mitigation was completed, and checks whether attackers gained access before the patch.

Safeguards
The strongest protections this week turn assurances into evidence, keep connected systems visible, and establish what happens when technology does not perform as promised.
Turn vendor promises into enforceable specifications
Attach the approved configuration, architecture diagram, sharing settings, administrator roles, audit fields, feature inventory, and data-retention schedule to the contract. Require a live demonstration before deployment and after material updates. A statement such as “national sharing is off” should identify every technical pathway the phrase covers, including pilots, federated searches, vendor support accounts, integrations, and inherited defaults.
Require written notice and affirmative approval before a pilot, integration, new administrator role, subprocessor, network expansion, or policy-changing default touches local data. Preserve both the old and new configuration so reviewers can identify exactly what changed, who approved it, and when the change took effect. Contract remedies should include suspension, corrective work, fee recovery, and termination when a material representation proves false.
Give the agency independent evidence
The agency should be able to export complete, tamper-evident logs without vendor assistance. Logs should identify the user and organization, date and time, case number, purpose, legal authority, search terms, datasets, result count, exports, sharing, denied attempts, vendor access, administrator changes, and final disposition.
The log format and required fields should be contract deliverables rather than whatever a dashboard happens to display. Assign someone outside day-to-day use of the system to review records on a fixed schedule, investigate anomalies, and document corrective action. Contract for independent technical testing, incident preservation, audit cooperation, and meaningful remedies. A vendor’s failure to produce required evidence should itself be a material breach.
Govern integrations and live links before activation
Maintain a current diagram of local users, outside agencies, vendor administrators, subprocessors, federated networks, application-programming interfaces, evidence systems, exports, backups, and legal-process pathways. For each route, specify who can authorize access, what purpose is allowed, what data leave the system, how long the connection lasts, and what evidence the action creates.
Require authentication, short expiration periods, named recipients, viewer logs, and automatic revocation for every live video or data-sharing link. Prohibit public or reusable URLs for police-surveillance feeds and regularly test access from outside the government network. Limit recording and retention to the documented mission; a secure link can still expose unnecessary footage of homes, bystanders, and private spaces.
Control sensitive data throughout the chain
Prohibit the sale of sensitive location, biometric, health, communications, and association data upstream. Require a warrant or equivalent judicial authorization when government seeks the same information downstream, regardless of whether it comes from a carrier, platform, advertiser, broker, contractor, or partner agency. Ban indirect acquisition: a public body should not ask another agency or vendor to obtain information it could not lawfully obtain itself.
Provide one state-run mechanism for access, correction, opt-out, and deletion requests. Define deletion precisely: address source data, derived attributes, linkage keys, backups, downstream recipients, later reacquisition, and certification. A profile that silently reappears was not meaningfully deleted. Before combining datasets, document each source’s original purpose, legal authority for reuse, receiving agencies, matching risks, and the conditions for ending the connection.
Review software capabilities before deadlines and updates
A mandatory interface transition should trigger a feature and policy review. Identify every analytical or AI-assisted tool available, licensed, enabled, or planned; the data it can ingest; the output it creates; retention and sharing; model providers and subprocessors; auditability; and the human decision that remains accountable.
Do not treat interface availability as authorization. New summarization, search, identification, prediction, streaming, remote-operation, or automated-dispatch capabilities should require documented legal review and approval proportionate to their effect. The system should record who activated each feature, the governing policy, the effective date, and whether the feature can be disabled without losing access to unrelated functions.
Patch, investigate, and plan for failure
Maintain a current inventory of internet-facing services and unsupported equipment. Assign emergency patch authority, restrict management access, enforce strong authentication, preserve logs, and review for indicators of compromise after active exploitation is announced. Installing an update does not establish that attackers were not already present; agencies should document what was exposed, how far investigators looked back, and why they concluded the environment is safe to return to service.
For every sensitive system, name who can suspend use, preserve evidence, notify affected people, correct records, commission an independent review, and terminate the contract. Define what must be reported to elected officials and the public after unauthorized access, inaccurate matches, vendor nonperformance, or a policy-changing software update. The morning after an incident is too late to decide who has authority to stop the system.
Bottom line
Trust is not an audit. A safeguard exists when an independent reviewer can test the representation, reconstruct the action, identify the responsible person, correct the error, and impose a consequence.
The common question for Issue 17 is simple: What evidence would prove that the system did what officials were told it would do?



