
Issue 19 • Wednesday, August 26, 2026
A concise biweekly scan of surveillance, privacy, cybersecurity, and the safeguards public officials should keep in view.
The most important privacy decision often happens after collection
A record may begin as a plate read, body-camera frame, licensing file, or router signal. Its consequences change when systems fuse it with other data, infer new relationships, convert it into evidence, or open it to outside searches.
At a Glance
- Data fusion can create knowledge no agency collected directly.
- Software updates can change a system’s real capability without new hardware.
- Retention, access, and audit rules must follow the data wherever it moves.
The decision point keeps moving downstream: routine records (plates, files, dispatch) get pulled into one searchable layer through fusion, that layer supports new inference (identity, association, pattern), and inference drives action (an alert, a retention decision, a sharing decision). Most rules still attach to the original collection — how long a plate read is kept, who may view a case file. Fusion weakens those boundaries unless purpose, access, retention, and audit rules follow the information into the combined system.
Flock’s new AI layer turns separate records into investigative prompts
WIRED reconstructed Flock’s OS Investigate interface from code the company’s own login pages served to anyone who loaded them. Reporters Dhruv Mehrotra and Dell Cameron found 69 prewritten prompts and 45 tools designed to reach plate scans, camera metadata, case files, dispatch logs, arrest records, commercial identity records, and other sources. The prompts include finding frequent visitors to a neighborhood, identifying vehicles that travel together, and turning plates into names or addresses. Flock says the product remains in development and may change before broader release.
The policy issue is no longer only whether a plate camera should exist. Once separately governed datasets sit behind one interface, a query can reconstruct movement and association at a scale that raises Fourth Amendment and modern-general-warrant concerns.
The governance gap: Most rules attach to the original collection — how long an ALPR read is kept, who may view a case file, or why a dispatch record exists. Fusion weakens those boundaries unless purpose, access, retention, and audit rules follow the information into the combined system. Before deployment, ask: Which datasets can be joined? Which fields become searchable? Can prompts infer associates or routines? Who can export results? Which audit record survives?
A licensing database becomes a federal target
Oregon and other states are challenging federal demands for personal information concerning approximately 17 million commercial drivers — including names, dates of birth, Social Security numbers, license numbers, and issuing states.
What happened
The Commercial Driver’s License Information System (CDLIS) exists so states can determine whether an applicant is already licensed elsewhere. The states supply and own the records; the American Association of Motor Vehicle Administrators (AAMVA) operates the system on their behalf.
According to Oregon’s complaint, the Federal Motor Carrier Safety Administration demanded five years of records for every driver and threatened federal funding when AAMVA resisted. A related Department of Homeland Security subpoena sought the same data. The states argue that federal agencies are attempting to build a separate copy without public notice or clear limits on later use or sharing.
On August 20, a federal judge issued a temporary restraining order barring transfer of the plaintiff states’ records while the court considers a preliminary injunction. The order is temporary, but it is an important early recognition that bulk access cannot be treated as an ordinary administrative request.
Why it matters beyond driver licensing
The dispute is a purpose-limitation case in unusually clear form. A record may be accurate, useful, and lawfully collected for one program. None of those facts establishes that a different agency should receive the entire database for a different mission.
Centralized public systems are attractive precisely because they eliminate the cost of collecting information again. Driver, voter, benefits, education, health, and law-enforcement records can become inputs to unrelated investigations when the requesting agency treats availability as permission.
The safeguards should travel with the information
Purpose limitation should bind the original agency, every recipient, and every contractor. A data-sharing agreement should identify the permitted use, legal authority, fields disclosed, users, retention period, onward-transfer rules, and the event that ends access.
Bulk transfer deserves heightened scrutiny because it reverses the ordinary investigative sequence. Instead of identifying a person and seeking information tied to a factual basis, government first acquires a population-scale database and decides later which records may become useful. That architecture can produce the functional equivalent of a modern general warrant: collect the records first, preserve the ability to search them, and supply the justification only after a person becomes interesting.
The transfer test: What was the original statutory purpose? Which exact fields are necessary now? Why would targeted legal process be insufficient? Who may search, export, or combine the records? Does the recipient face the same retention and disclosure rules? Can access be suspended and every copy deleted? What public report will show how the data were used?
Legislative principle: Information collected under one authority should not become a general-purpose investigative asset merely because a centralized copy is technically convenient. Require necessity, minimization, notice, auditability, and a defined end point before secondary access begins.
Make privacy rights usable — without building another identity trail
California DROP moves the burden from individuals to brokers
California’s Delete Request and Opt-out Platform (DROP) allows a resident to send one request to more than 600 registered data brokers. Brokers must retrieve requests on a recurring schedule, delete eligible information, and direct service providers and contractors to do the same.
By August 25, the state reported more than 500,000 registrations. Approximately one quarter of registered brokers had already reported processing requests; 99.9 percent of participating consumers had a profile deleted by at least one broker, and the typical user had information removed by more than 40.
The institutional design matters. Traditional privacy rights often require people to identify hundreds of companies they have never heard of, locate separate forms, verify themselves repeatedly, and return later to see whether the request was honored. Centralization makes the right practical and gives the regulator a common compliance surface to inspect.
Deletion still needs a technical definition. A broker can stop displaying a profile while retaining source data, linkage keys, derived attributes, backups, or relationships that allow the profile to reappear. A meaningful standard should address inferences, downstream recipients, later reacquisition, legal exceptions, and certification of completion. The most valuable feature may be the regulator’s ability to compare claims across the market — running test requests, comparing broker response rates, and imposing escalating consequences when a company ignores the platform or reacquires information it was required to erase.
Meta settlement: safer defaults meet the age-assurance problem
A proposed multistate settlement would require major changes for teenage users of Instagram and Facebook, including default daily limits, overnight blocks, school-hour notification controls, safer content settings, stronger parental tools, age assurance, and independent auditing.
The design provisions offer a useful alternative to rules that place all responsibility on children or parents. A protective default changes the environment before harm occurs. An independent auditor creates a record outside the platform’s own public assurances.
Age assurance remains the privacy fault line. A system intended to protect minors can require every user to prove or estimate age, creating pressure to collect government identification, facial images, device signals, or behavioral information. The protective rule can become a population-wide identity system if minimization is not built in.
A privacy-preserving standard should prove only the necessary threshold and then forget the evidence used to reach it: do not retain government ID when a less intrusive method works; separate age confirmation from browsing and account history; prohibit advertising, profiling, product development, and law-enforcement reuse; publish error rates and independently test demographic performance; provide correction and appeal when a person is classified incorrectly; and require short retention and deletion that includes vendors and subprocessors.
Shared lesson: Centralization can make a right easier to exercise and make a database more attractive to misuse. Pair usability with minimization, strict purpose limits, short retention, strong security, public reporting, and independent verification.

Warning Signals: new sensors hide inside familiar objects and familiar workflows
Smart glasses make ambient recording harder to see
VICE reports that teen boys are using camera-equipped smart glasses to record and harass girls in schools and other everyday settings. The form factor matters because ordinary social cues no longer reveal that recording is occurring. A person may notice a raised phone; glasses can remain pointed at someone throughout an interaction.
Brisbane supplied a concrete institutional response. The city prohibited nonconsensual recording with phones, action cameras, smart glasses, and other camera-enabled devices at all 21 council pools. Staff can enforce the condition of entry even where general public-space law would otherwise permit recording.
The safeguard follows capability rather than shape. A policy limited to phones will fail when the same recording function moves into glasses, earbuds, jewelry, vehicles, or another object.
Routers can become motion sensors through software
Comcast’s Wi-Fi Motion capability illustrates a different expansion path. Network equipment installed to provide connectivity can use changes in radio signals to infer movement in a home. The device does not need a conventional camera to acquire a sensing function. This is why procurement inventories should record latent and update-enabled capabilities. Officials need notice when an ordinary device begins collecting a new data type, making a new inference, or sending information to a new service.
SignalTrace connects vehicles, devices, and association
Ars Technica reports that Leonardo’s SignalTrace pairs automated license plate reader observations with Bluetooth or radio-frequency device signals. That combination can associate a vehicle with a device and infer which devices — and potentially which people — travel together.
The shift is qualitative. A plate reader traditionally produces a time-and-location record about a vehicle. Device detection adds a second identifier. Repeated co-location can then become social-network evidence even when neither person was originally the subject of an investigation. Association is not guilt. Family members, coworkers, rideshare passengers, neighbors, protesters, journalists, and bystanders can move together for innocent reasons. A system that ranks associates should not silently convert proximity into suspicion.
The common pattern: Glasses become concealed cameras. Routers become motion sensors. Plate readers become device-and-association systems. The governance trigger should be the new capability, not the purchase date of the original hardware. Require renewed notice and approval when a system adds a data type, inference, matching method, real-time alert, sharing pathway, or automated decision.
Procurement question: What can this device become after a software update, and what record will show that the new function was reviewed before activation?
Axon Watch: one ecosystem can move from capture to identity to evidence
Edmonton tests body-camera facial recognition
Edmonton police are testing an Axon-supported workflow (Associated Press) that compares faces captured by body-worn cameras against police watch lists. During the pilot, officers do not receive identifications in the field; results are reviewed afterward. That boundary matters because after-the-fact analysis can become real-time officer alerting through a later product or policy change.
Before any expansion, officials should know who enters a person on the watch list, what evidence is required, how long the entry remains, which model and threshold are used, how demographic performance was tested, and how a person corrects a false association.
Fleet 3 turns a plate record into evidence
Axon’s August release notes say agencies can enable officers to convert an ALPR read or hit directly into evidence from the Fleet 3 Dashboard. Users may add or edit the owner, title, ID, category, and tags before the record uploads, and the conversion receives priority over video uploads.
This is a retention decision disguised as workflow convenience. A short-retention surveillance record should not become longer-term evidence merely because someone clicks “convert.” Require an existing case, individualized relevance, a named decision-maker, and an audit record that preserves the original capture and every later change.
Fusus exposes configuration — preserve it: the same August release notes add diagnostic visibility into the ALPR alert pipeline. Agencies should preserve configuration snapshots before and after material changes so a later reviewer can reconstruct what sources, routes, filters, and alert settings were actually enabled.
Long contracts consolidate capabilities and leverage
Baton Rouge approved a long-term Axon agreement reported at more than $31 million. The package brings multiple functions under one vendor relationship, including records and AI-assisted report writing, Fusus, and other Axon services. (Note: I could not independently verify the specific dollar figure or procurement record for this item before publishing — flagging for your review rather than linking to an unconfirmed source.) Consolidation can reduce administrative friction while increasing switching costs and integration risk. Oversight should follow the combined data flows: which product can read another product’s records, which administrator spans systems, which retention rule controls a copy, and what remains exportable if the contract ends.
Apex pauses a DroneSense amendment for review
Apex, North Carolina pulled an Axon contract amendment from its consent agenda and sent it for committee review after residents raised concerns. The city already had drones; the proposed change concerned DroneSense software and related capability. That distinction is exactly why review was appropriate.
Public oversight should not depend on whether a proposal includes a new physical sensor. Software can add remote operation, livestream distribution, alert integration, mapping, evidence transfer, automated analysis, or new administrator access to equipment already in service.
Vendor switching is not capability reform
National reporting from NPR shows Axon, Motorola, Verkada, and other vendors positioning themselves to inherit business from jurisdictions leaving Flock. A different logo does not answer what is collected, how long it is retained, who can search it, or what integrations remain.
Axon Watch test: Ask which capabilities are available, licensed, enabled, or planned; what activates each one; which data cross product boundaries; and whether the agency can disable one feature without losing unrelated functions.

Safeguards: put approval, evidence, and limits at every expansion point
1. Require approval for material new capabilities
Treat a software update, integration, new model, search field, livestream route, or outside database as a governance event when it changes what the system can reveal or do.
2. Require a warrant or bind access to a real investigation
Use judicial authorization for retrospective movement searches where constitutionally required. At minimum require a case or CAD number, qualifying offense, factual basis, named user, and purpose before access.
3. Justify every move into longer-term evidence
Identify each retained record individually. Preserve the original capture, reason for retention, linked case, decision-maker, later edits, exports, and the date the longer retention ends.
4. Make logs usable outside the vendor dashboard
Agencies should export complete, tamper-evident records showing users, organizations, searches, results, denied attempts, vendor access, configuration changes, sharing, and corrective action.
5. Make the contract follow every copy
Apply retention, deletion, sanctuary-law, public-record, incident, and audit requirements to vendors, subprocessors, integrations, backups, downstream recipients, and contract closeout.
Oversight is becoming concrete
Congress. Sen. Josh Hawley opened a Judiciary subcommittee investigation into Flock’s collection, retention, access, and dissemination practices, with documents requested by September 8.
Pflugerville. The city ended its Flock agreement after records reportedly showed that 459 outside organizations conducted nearly 1.6 million searches that included the city’s network over six months.
Salt Lake City. Officials have considered requiring an active case number before officers access ALPR information — a more enforceable rule than a generic free-text investigative purpose.
The closing principle: procurement is policy
A system’s real rules are determined by configuration, integrations, contract terms, administrator roles, and access pathways — not merely the purpose stated when it was purchased.
The goal is not to block every tool. It is to restore checks and balances before collection, fusion, retention, and outside access become permanent infrastructure.
Signals & Safeguards is the newsletter of Jonathan Westmoreland, founder of Bend Privacy Alliance · jonathanwestmoreland.com · Published August 26, 2026.
Leave a Reply