[HN Gopher] I wrote to Flock's privacy contact to opt out of the...
___________________________________________________________________
I wrote to Flock's privacy contact to opt out of their domestic
spying program
Author : speckx
Score : 424 points
Date : 2026-04-14 17:47 UTC (5 hours ago)
(HTM) web link (honeypot.net)
(TXT) w3m dump (honeypot.net)
| kstrauser wrote:
| I wrote this. I had/have absolutely no expectation that Flock
| would comply with my request, but figured I should try anyway For
| Science. Their reply rubbed me wrong, though. They seem to claim
| that there are no restrictions on their collection and processing
| of PII because other people pay them for it. They say:
|
| > Flock Safety's customers own the data and make all decisions
| around how such data is used and shared.
|
| which seems to directly oppose the CCPA. It's _my_ data, not
| their customers '.
|
| Again, I didn't really expect this to work. And yet, I'm still
| disappointed with the path by which it didn't work.
| carefree-bob wrote:
| They were saying "don't write to us, talk to the people who own
| the cameras and ask them to delete the data". A company that
| manufactures video cameras is not the one to talk to when
| someone records you, talk to the person who recorded you.
|
| But a reasonable person would say -- the data is stored on
| Flock servers, not with the camera owners. And Flock would say,
| just because we sell data storage functionality to camera
| owners doesn't mean we own the data, anymore than a storage
| service you rent a space from owns what you put in that space.
|
| But then an even more reasonable person would say: the
| infrastructure is designed in such a way as to create
| inadvertent sharing, and the system has vulnerabilities that
| compromise the data, so Flock has responsibility for setting up
| the system in such a way that it's basically designed to
| violate privacy.
|
| And _that_ is the main criticism of Flock. You need to have a
| more nuanced criticism. It would be really interesting to see
| this litigated.
| fudgy73 wrote:
| AFAIK Flock owns the cameras and leases them out [0].
|
| [0] https://www.flocksafety.com/blog/flock-safety-does-my-
| neighb...
| mminer237 wrote:
| If you go to Rent-A-Center and rent a DSLR, that doesn't
| make Rent-A-Center responsible for the pictures taken by
| their cameras.
| kstrauser wrote:
| If Rent-A-Center installed the camera in a bathroom, I'd
| contend that it does.
|
| Flock's cameras aren't in bathrooms. However, they're
| still recording people who haven't opted into it. ("But
| you have no expectation of privacy in a public place!"
| "You have the expectation that someone might
| inadvertently overhear you. You don't have the
| expectation that someone is actively recording you at all
| times.")
| danielsunsu wrote:
| I think if it were only offline storage it would not be
| as big of an issue. A more accurate analogy would be
| renting a DSLR that automatically transmits every picture
| to Rent-A-Center servers.
| yabutlivnWoods wrote:
| Your example is apples and oranges. Flock maintains
| private infrastructure that stores data.
|
| If the DSLR uploaded them to Rent-A-Center owned/leased
| servers it would in fact require Rent-A-Center to take
| the necessary steps.
|
| As Rent-A-Center would be the only group with proper
| access to data storage they would have inserted
| themselves into the chain of custody, and thereby have
| such obligation to ensure others data is wiped from
| systems they control.
| tptacek wrote:
| AWS also maintains private infrastructure that stores
| data. Go write them asking to purge data pertaining to
| you from S3 and see how that goes.
| itsdesmond wrote:
| Flock has knowledge/use of the data. Their system
| processes can relate the photos "owned" by two different
| entities. They're interacting with it and selling their
| access to it as a feature. That's obviously distinct from
| S3.
|
| But you knew that.
| tptacek wrote:
| I know quite a bit about Flock, having been intimately
| involved in the process of evicting it from our
| municipality, and I don't think the distinction you're
| trying to draw here is meaningful. Flock will say they
| provide a service, one avidly sought by the actual owners
| of the data, to generate analysis based on that data.
|
| They're contractually forbidden from "selling their
| access to it" to arbitrary parties; they can share data
| only with the consent of their customers, almost all of
| whom actively want that data shared --- this is a very
| rare case of a data collection product where that's
| actually the case.
| dureuill wrote:
| Except their customer's data isn't actually theirs: OP
| requested their private data to be deleted from the
| system. So OP expressed a clear intent for their data not
| to be used by Flock's customer. We could say that the
| data thus becomes abusively retained on these systems. As
| a result, IF Flock has the technical means of performing
| the requested data deletion, it should be compelled to
| perform it.
|
| This is the same situation as a web hosting provider: if
| it is communicated to them that one of their customers
| uses their service to host illegal content, then it
| becomes the web hosting provider's responsibility to
| remove that content.
|
| Reasonable technical feasibility for the service provider
| is key here, but it can be argued since the data can
| apparently be shared in ways that identify OP.
|
| Probably not how the law currently works (don't know, not
| a lawyer), but I guess it should, as otherwise it allows
| creating a platform that shares abusively retained data
| without any reasonable recourse for the subjects of this
| data to remove the data from the platform.
| tptacek wrote:
| I do not believe this is how the law works. Two _totally_
| different regimes.
| Mordisquitos wrote:
| Does AWS actively and by design parse and keep track of
| personally identifiable information of the data that AWS
| customers store on their S3 buckets? If that were the
| case they would absolutely be subject to CCPA (and GDPR)
| requests for deletion.
|
| However, I suspect that is not the case. AWS is agnostic
| as to the type of data stored on S3, and deletion of PII
| stored on S3 is the sole responsibility of the AWS
| customer that chooses to store it.
| danudey wrote:
| If AWS maintained private infrastructure that stored and
| indexed data associated with people's license plates and
| vehicles and then charged customers to do searches
| against that data then yes, you could write them to ask
| them to purge data pertaining to you.
|
| If Flock was just an opaque cloud storage service for law
| enforcement to back up their mass surveillance to then
| sure, your argument would have merit; it's not, it's a
| giant database of photos, locations, times, license plate
| information, and likely a lot more. They're not selling
| cloud storage, they're selling (leasing?) surveillance
| devices and tools.
| tptacek wrote:
| The argument you're making implicates way more than just
| Flock, and is in a practical sense novel. If you can cite
| jurisprudence (or even legal experts) backing it up, I'm
| interested in reading it. Otherwise, I'm happy to accept
| that we just have premises about the law that are too far
| apart for an argument to be productive.
|
| My experience on HN is that these kinds of discussions
| almost immediately devolve into debates about what people
| want the law to be, as opposed to what it actually is.
| Karrot_Kream wrote:
| Realistically speaking you're never going to get pro
| Flock people in any numbers on this site writing comments
| at all. The anti surveillance position's popularity when
| it comes to up votes, down votes, and flags on this site
| is such that pros will continue posting about what they
| want the law to be and antis will stay out. That's just
| how crowd voting dynamics shape out.
| yabutlivnWoods wrote:
| I don't live in a state with a law like California's so
| your "gotcha" isn't relevant.
|
| Californians would have standing under the law but need
| expensive lawyers to litigate.
|
| AWS has employed expensive lawyers to argue semantics;
| they host OS VMs and databases. This provides them legal
| cover for what AWS customers store.
|
| Amazon the retailer stores customer data. A non-customer
| would have standing under California law to litigate
| removal of PII should they decide to hire lawyers.
|
| Your reductionism is to law what a Linux beige box on a
| routable IP, no firewall, hosting a production health
| database with creds set to admin/pwd1234 is to software
| engineering.
|
| Coincidentally 1234 happens to be the code to my luggage.
| ldoughty wrote:
| But the data collected is property of the government and
| flock is not allowed to use that data for additional
| business gain (according to their statements)...
|
| So they can't sell the fact that you're at Target at 8:00
| p.m. on Thursday to anybody... Nor build profiles to sell
| to advertisers... And if that's the case that's very
| similar to cloud storage vendors.
|
| If I access hacker news, and the record of my visit is
| stored in an AWS S3 bucket, I can't submit to AWS to delete
| my visitor record, even though the server, network cards,
| wires, and storage medium are AWS property, it was hacker
| news' website that generated that record and their
| responsibility to take my request to delete it.. AWS'
| stance would rightly be "talk to the website operator for
| CCPA requests"
| tptacek wrote:
| This is also true according to their contracts (we were
| one of the first munis in the country to ostentatiously
| cancel our Flock contract, and the lead up to that was a
| bunch of progressive legal experts poring over that
| contract looking for holes.)
| fsckboy wrote:
| > _a bunch of progressive legal experts poring over that
| contract looking for holes_
|
| all attorneys represent their clients; your attorney does
| not have to share your opinion of the law or public
| policy, they can still interpret what the law means to
| you.
|
| if you are afraid your attorney might have a bias (they
| are human) you may get better advice from the
| "misaligned" POV: the flaws/holes in a privacy law found
| by a pro-business conservative attorney are more likely
| to find sympathy in the courts from both fellow
| conservatives and progressive judges.
| shermantanktop wrote:
| As a practical matter, this may be good advice. But it
| also places a demand on someone with a legitimate concern
| that they go find an ideological "beard" to make
| themselves more palatable and sympathetic.
|
| It's not hard to see how this enables an institution to
| gate itself from criticism.
| thaumaturgy wrote:
| Except that Flock very clearly benefits financially from
| having direct access to this data: owning (and in their
| own documentation, they very clearly _do_ own it) a
| network of 80,000 surveillance devices across the
| country, and owning every single transit point for the
| data they collect, is what gets them to a $7.5 billion
| valuation from investors.
|
| The fact of the matter is that Flock is playing two-step
| with the concept of "ownership" of data. They disclaim
| ownership as a way to leave local agencies holding the
| bag for liabilities, but they fight _tenaciously_ to
| retain complete and unfettered access to that data.
|
| (After organizing a community group that won Flock
| contract cancellations in multiple jurisdictions in
| Oregon, I went on to coauthor state legislation
| regulating ALPRs. I am very well familiar with all the
| dirty ball they play.)
|
| Also, Flock's cameras collect more data than is provided
| to police agencies. Who owns _that_ data, I wonder?
| necovek wrote:
| That makes them a data broker in my reading, and at least
| in California, Data Broker legislation should apply. CA
| Data Broker registry gives me access denied, but that
| could be because I am outside US.
| ScoobleDoodle wrote:
| I looked it up at
| https://cppa.ca.gov/data_broker_registry/ and didn't find
| Flock / Flock Safety in that list of the currently
| registered 566 data brokers.
| tptacek wrote:
| Because Flock isn't a data broker. Flock's customers own
| their data, not Flock, and they use Flock's platform
| voluntarily to share data with other customers.
| necovek wrote:
| I was referring to the claim that "Flock's cameras
| collect more data than is provided to police agencies" --
| that suggests that there is data not "owned" by the
| customers, which implies it's Flock's data, thus it might
| make them liable under Data Broker legislation.
| cwillu wrote:
| Equivocation. My stock broker doesn't own my stocks
| either, they merely hold my assets in a brokerage
| account.
| tptacek wrote:
| I encourage you to present that analogy to an actual
| court and see how far it gets you. It's very easy to find
| the statutory definition of a "data broker" under
| California law.
|
| This is what I mean by the fruitlessness of these kinds
| of legal discussions on HN. What do you want me to argue,
| that you're wrong to _want_ the law to work that way?
| jaredwiener wrote:
| And you would (rightfully) be angered if your stock
| broker sold your shares and pocketed the proceeds,
| because you own them.
| tadfisher wrote:
| Flock charges to access the data which is voluntarily
| shared by other customers. I am struggling to note a
| difference in this practice from any other data brokerage
| service in existence.
|
| Does Flock do some kind of P2P dance to avoid the data
| transiting their systems?
| close04 wrote:
| So... Flock uses their own platform and top to bottom
| tech stack to do everything technically? Your local PD
| doesn't use random cameras (like Reolink), doesn't run a
| custom software stack (like Frigate in a container on
| some random VM hosted with AWS), doesn't store the data
| wherever (like Backblaze)? The customers just have to
| install the Flock cameras and "order" the subsequent data
| from Flock? But you say they're not at all responsible or
| accountable for any it because despite doing everything
| at every step, they're "just a broker"?
| unethical_ban wrote:
| If Flock's customers, using Flock's infrastructure or
| tooling, can share data with each other, that would be
| bad.
|
| I'm not saying that's what's happening, but that's what I
| _thought_ was happening before reading this thread, and
| now I have to go and run through their policies.
|
| Either way ALPRs and AI-facial scanners in public are a
| huge violation of privacy and I loathe them, but I hope
| it's correct that Flock customers cannot easily share
| information with one another.
| unethical_ban wrote:
| This is worth validating independently, but to be clear:
|
| Are you saying Flock itself does not have access to any
| of the data, and that the data they store on behalf of
| local governments is not fed into any central datalake?
| That every organization's data is completely, unalterably
| separate from everyone else's?
|
| If so, that makes the panopticon _slightly_ less
| powerful.
| valeriozen wrote:
| The AWS analogy breaks down because AWS doesn't encourage
| customers to pool their S3 buckets into a nationwide
| searchable index.
|
| Flock operates a federated network. If you drive past an
| unmarked camera, you have absolutely no way of knowing
| which specific HOA or town leased it so how are you
| realistically supposed to know who the "data controller"
| is to send your ccpa or deletion request to?
| giancarlostoro wrote:
| Start standing in front of the cameras looking sketchy
| long enough till police are sent out to ya, then ask the
| cop who called.
| chaps wrote:
| Someone once dropped some fireworks not too far from me
| at 3am a few years back. They were loud and, yeah, cops
| were called. A few minutes later about five cars drive
| past me about 30mph over the limit. Not sure how they
| didn't see me or try to see me. But I know they didn't
| catch the BRIGHT orange and lifted care.
|
| Me being me, I submitted a FOIA request for the dashcam
| footage of the five cop cars and the dispatch logs.
|
| Instead of pulling over the easily identifiable car, they
| pulled over some random guy. They were behind him the
| whole time but five cop cars pulled behind him thinking
| that he fired a gun a few minutes back.
|
| He was let go without a citation, but the official
| reason, despite being paired with the dispatch for the
| firecracker, was a broken headlamp.
| jnovek wrote:
| I don't care. I don't care who owns the data. If I can't
| easily get private information like my movements removed
| from a database like this, the legislation does not
| sufficiently protect me.
|
| It should _absolutely_ be Flock's responsibility to
| remove my data and we should absolutely require it by
| law. Full stop.
| lazide wrote:
| A reasonably nuanced defense could likely claim that to
| be able to do what you want, would have much worse side
| effects on privacy.
|
| For example, would you want to be able to tell Public
| Storage (or some other storage unit place) to remove any
| naked photos of you stored anywhere in their storage
| units?
|
| For them to actually be able to do that would require
| they have nigh omniscience on everything stored by/for
| everyone in every one of their storage units. Even inside
| closed boxes.
|
| Now, it's not the same thing of course - but hopefully
| you understand what I'm referring to?
| LadyCailin wrote:
| Except that the analogy is that they already have, or can
| easily create, that list. If they couldn't, their value
| proposition would be lame. "We know you're looking for a
| specific license plate, here's a million hours of footage
| from all over the city, have at looking through it all."
| lazide wrote:
| Only for paying customers, which you aren't of course. If
| those customers paid public storage to inventory their
| stuff, then that inventory is their property. Surely it
| would be inappropriate to use their inventory data to
| find your naked photos. A violation of privacy even. (/s,
| kinda)
|
| I was enumerating the likely defense, not that it's
| valid.
| tptacek wrote:
| The law cares about lots of things we don't care about.
| eagleinparadise wrote:
| If I lease out a property to a tenant (apartment, retail,
| industrial use, whatever) and that tenant is committing
| an illegal activity on the property. Would the landlord
| be liable for knowing it? Or not?
|
| "Sorry FBI, the tenant renting my warehouse out to
| manufacturing cocaine is not my responsibility. I won't
| do anything about it. You deal with them."
|
| Nope, that's a failure of a duty to act and aiding and
| abetting a criminal activity if you hace constructive
| knowledge.
| mistrial9 wrote:
| the way this has been addressed in complex product liability
| in the past in the USA is that the public-facing Brand Owner
| has certain legal liability for the product, despite
| contractors or supply chains. In this case, it appears that
| the Flock company is the brand owner and is public-facing.
| halJordan wrote:
| It easily goes both ways. But we do sue American gun makers
| for deaths caused by lunatics. We sue drug makers for drugs
| prescribed by a doctor. We sue cloud providers for not
| reporting illegal photos. Printers are forced to id every
| printed page to combat counterfeiting. Banks are forced to do
| close accounts even though it's not their dirty money
| thebaine wrote:
| Most of those examples have to do with the manufacturers
| knowing that their products were dangerous, addictive or
| illegal and advertising them aggressively as safe. They're
| mostly litigated on product liability claims. Banks are
| regulated by an entire architecture of laws, and we could
| enact laws that would regulate Flock too, as one of the
| other commenters pointed out they're doing in Oregon.
| BobaFloutist wrote:
| > But we do sue American gun makers for deaths caused by
| lunatics.
|
| No we don't, there's a federal law explicitly protecting
| gun manufacturers from liability for gun crime. https://en.
| wikipedia.org/wiki/Protection_of_Lawful_Commerce_...
| dozerly wrote:
| I don't think you're informed on the topic. They do not just
| manufacture cameras.
| robot-wrangler wrote:
| > They were saying "don't write to us, talk to the people who
| own the cameras and ask them to delete the data".
|
| The response to this should just be, "Yes, very well, please
| divulge a complete list of your customers, their contact
| information, and information about camera locations so I will
| be able to pursue this per instructions".
|
| When that obviously doesn't work either then we can all agree
| the law as written is completely useless, and feel great
| about rewriting it in a way that's calculated for maximum
| damage to both the vendor and their customers, and collateral
| damage to the whole panopticon. Or, just spitballing here, we
| can just skip to the punchline here and do all that anyway
| beambot wrote:
| Isn't this the equivalent of asking Google to delete your
| image off every Android phone (not just yours)?
| themafia wrote:
| These laws get complicated quickly. There's a specific ALPR law
| in the CA civil code which seems to carve out several
| exceptions for a business like Flock:
|
| https://leginfo.legislature.ca.gov/faces/codes_displayText.x...
|
| The enforcement provisions are rather bleak as well and afford
| no opportunity to directly bring a case against the agency that
| operates the system but instead just the individual who misuses
| it.
|
| I think one of the more direct attacks would be going after
| jurisdictions that chronically have officers misusing the
| system. I think you're going to have to create precedent in
| this way to foment actual change.
| everdrive wrote:
| Nice work all the same. These systems need to be prodded and
| tested. Even unsuccessful results such as this tell us
| something about the situation we're in.
| nainachirps_ wrote:
| I am not a lawyer myself but can't one argue that this company
| has duty to ensure that data it is processing for client is
| legally obtained.
|
| If they are processing data after being told it was not
| obtained with consent do they not have any liability?
| Glyptodon wrote:
| I think you should write them back and ask that they provide
| you with a customer list and continually update you as they get
| new customers so that you may follow the advice they've given
| you.
| kstrauser wrote:
| Ooh. I like this.
| kube-system wrote:
| Why? The response is predictable. No company is going to
| give you a customer list.
| kstrauser wrote:
| I wouldn't be so sure. In this specific case, they told
| me to ask their customers to comply with my CCPA rights.
| Without that information, it's impossible for me to
| exercise those rights. IANAL, but that sounds like a
| pursuable path.
| kube-system wrote:
| I don't see any provision in CCPA that requires that. And
| outside of an explicit requirement to do so, nobody is
| required to help you.
|
| Edit: from https://oag.ca.gov/privacy/ccpa
|
| > If a service provider has said that it does not or
| cannot act on your request because it is a service
| provider, you may follow up to ask who the business is.
| However, sometimes the service provider will not be able
| to provide that information. You may be able to determine
| who the business is based on the services that the
| service provider provides, although sometimes this may be
| difficult or impossible.
| bloppe wrote:
| Perhaps the next step is writing to your state
| representative, or to Alastair Mactaggart, and complain
| about this hole in the legislation.
| singleshot_ wrote:
| I've been in the lobby of hundreds of different
| technology companies and my understanding is that all
| companies are going to give you a customer list, you just
| have to look in the right place.
| kube-system wrote:
| Ha -- you know what I meant: explicitly.
| ratdragon wrote:
| maybe eff.org would be able to help you lawyer up or otherwise
| to push this forward. good luck!
| kstrauser wrote:
| I've reached out, albeit very informally. I'll completely
| understand if this isn't something they have the time and
| energy to help with. If I accidentally caught them at a weak
| moment when they're looking for something to do, though, I'm
| all in.
| tptacek wrote:
| Wait, is it your data? If you drive your car in front of a Ring
| camera on my house (I don't have a Ring camera don't @ me), is
| it your claim that you own the data on that camera?
| kstrauser wrote:
| Did you put up a Ring camera on a stand in front of your
| house for the specific purpose of selling that I drove past
| at this specific timestamp? If so, yes. The CCPA[0] gives me
| explicit legal rights:
|
| * The right to know about the personal information a business
| collects about them and how it is used and shared;
|
| * The right to delete personal information collected from
| them (with some exceptions);
|
| * The right to opt-out of the sale or sharing of their
| personal information including via the GPC;
|
| This isn't someone incidentally taking pictures of license
| plates in an otherwise noncommercial setting. It's a company
| literally created to collect and sell PII. Laws are different
| for them than for us.
|
| [0]https://oag.ca.gov/privacy/ccpa
| snowwrestler wrote:
| "Personal information" has a legal definition and photos of
| you in a public street might not satisfy it, regardless of
| the photographer's intent.
| kstrauser wrote:
| I think it'd be challenging to rule that a license plate
| number is not personally identifiable information, when
| the same regulations often state that an IP address is.
| uoaei wrote:
| "Anyone could have been driving my car, you can't
| positively identify me in the driver's seat with the
| evidence you have submitted" is routinely used to toss
| out cases involving traffic violations. It's not
| necessarily common but it does happen. By this logic a
| license plate does not personally identify the person
| driving, only the person the car is registered to.
| lcnPylGDnU4H9OF wrote:
| Right, but in this context the license plate number is
| still personal information, just of a different person.
| uoaei wrote:
| Then the key aspect of our discussion is the
| "identifiable" part, which you've left out.
| lcnPylGDnU4H9OF wrote:
| Are you now saying that one cannot possibly "identify"
| the "person" who owns a vehicle, solely with the
| "information" on a license plate?
| kube-system wrote:
| The CCPA explictly says:
|
| > "Personal information" does not include [...]
| Information that a business has a reasonable basis to
| believe is lawfully made available to the general public
| by the consumer
| tptacek wrote:
| California has an entire statute regulating ALPR
| information, so we don't need to derive this
| axiomatically.
| danudey wrote:
| Yet the same is true of IP addresses. You (typically)
| cannot know for certain whether traffic from an IP
| address was originated by a specific person and yet it's
| typically considered PII because it can be used in
| conjunction with other information to identify you.
|
| Even your full legal name and birth date cannot be
| guaranteed to refer only to you specifically (as there
| could be someone else with an identical name and birth
| date), but it's obviously still PII because it helps
| narrow the field immensely if you can combine it with
| other information - for example, your IP address.
|
| So yeah, "anyone could have been driving my car", but if
| you also know that the car drove from _your_ home to
| _your_ work then that narrows down the list of likely
| individuals immensely.
|
| Conversely, if your license plate was spotted parked near
| an anti-ICE rally, then they can be pretty confident that
| you or someone you know was near an anti-ICE rally, which
| means they can harass you about it, follow you around,
| shoot you in the street, etc.
| tomwheeler wrote:
| The standard of proving someone's guilt in a crime or
| civil infraction is higher than the one for inferring
| that someone could plausibly be the person you want. This
| is the basis of parallel construction, wherein a
| government agency plays a game of "pin a crime on the
| suspect."
| adrr wrote:
| Or home address, phone number, etc
| lcnPylGDnU4H9OF wrote:
| Indeed, that definition is included in the CCPA.
|
| > (v) (1) "Personal information" means information that
| identifies, relates to, describes, is reasonably capable
| of being associated with, or could reasonably be linked,
| directly or indirectly, with a particular consumer or
| household. Personal information includes, but is not
| limited to, the following [...]:
|
| > (E) Biometric information.
|
| > (H) Audio, electronic, visual, thermal, olfactory, or
| similar information.
|
| https://leginfo.legislature.ca.gov/faces/codes_displaySec
| tio...
|
| To your point, the intent would presumably still matter
| for exceptions to when deletion requests must be honored
| (say for journalism), but a photo of someone walking down
| a public street would still logically be considered the
| subject's personal information, by the above definition.
| necovek wrote:
| Personal information usually does include photos of
| someone in public without their consent: exceptions
| usually hold for taking photos of people where it is in
| the public interest to be able to show them or
| impractical to get consent. This covers large gatherings
| and celebrities, but a portrait photo of a stranger might
| put you on the wrong side of the law.
|
| Obviously, the idea is to not disallow having someone
| take a photo of you as a background, passing figure as
| they take a front-and-center photo of their family, but
| not allow you to be the main subject unknowingly and
| especially when you object explicitly.
|
| On the other hand, a photographer still owns the
| copyright to a photo, so a subject (including in a
| portrait) cannot claim it or distribute it without
| permission even if they can potentially stop the
| photographer from distributing that photo.
|
| IANAL, but you are not by default allowed to use anyone's
| "likeness" for your individual profit.
| patrickmay wrote:
| > Personal information usually does include photos of
| someone in public without their consent
|
| This is not the case in the United States. There is no
| presumption of privacy in public. In fact, there is a
| whole genre known as "street photography" that involves
| taking pictures in public without explicit consent of the
| subjects.
| necovek wrote:
| You seem to be right, thanks for the correction!
|
| If https://legalclarity.org/can-you-post-someones-
| picture-witho... is to be trusted though, at least you
| get protection from your likeness being used for
| commercial purposes, though that seems a bit more limited
| than I'd expect.
| tadfisher wrote:
| This is true, and it may also be true that location
| tracking through surveillance networks crosses a line
| into violating one or more Constitutional rights. One of
| Flock's revenue streams is explicitly selling access to
| data made available by other customers. A commonly-cited
| example is the ability of local law enforcement to locate
| abortion suspects in other states using the Flock camera
| network [0]; one could imagine dragnet-style or geofenced
| queries to also cross the line.
|
| [0]: https://www.eff.org/deeplinks/2025/10/flock-safety-
| and-texas...
| tptacek wrote:
| People keep making this claim that Flock "explicitly
| sells access to data", but the link you provided doesn't
| demonstrate that, and Flock contracts I've read
| contradict the claim.
|
| I think what's happening here is that people are trying
| to colloquially define "selling access to data" to fit
| the camera data sharing that Flock enables, and then
| saying that because you have to pay to be a Flock
| customer to get access to that data, they're effectively
| selling it. I don' think that's how data brokerage laws
| work. Flock doesn't own the data they're providing access
| to, and they're providing that sharing access with the (
| _avid!_ ) consent of their customers.
| snowwrestler wrote:
| You're getting mixed up about commercial use and personal
| information.
| tadfisher wrote:
| Well, it matters if the photographer is the government
| (or contracted by the government, or subpoenaed by the
| government): see _Chatrie v. United States_ [0]. The
| Fourth Amendment exists, and it remains to be tested
| whether querying massive surveillance networks is a
| "reasonable" search.
|
| [0]: https://www.scotusblog.com/cases/case-files/chatrie-
| v-united...
| snowwrestler wrote:
| True but the Fourth Amendment doesn't rely on the CCPA
| for authority!
| tptacek wrote:
| I think you're going to find that you're wrong about this,
| and that you're not going to get anywhere targeting Flock
| in particular, as opposed to the owners of Flock cameras.
| Consider that California has had multiple rounds of
| legislation about red light camera legislation, including
| new limitations on it, and all of those cameras are also
| from commercial providers collecting your PII. Your
| argument proves too much.
|
| You're going to get a lot of cheerleading and support about
| this in venues like HN and Reddit, because you're
| narrowcasting to an audience already primed to be
| hyperconcerned about surveillance technology (I am too). I
| think you're going to find those attitudes do not in fact
| generalize to the public at large, and especially not to
| the legal system.
|
| Best of luck either way. It'll be an interesting experience
| to write up, and I'm happy to read about the outcome, even
| if I do think it's highly predictable.
| john_strinlai wrote:
| > _you 're not going to get anywhere targeting Flock in
| particular, as opposed to the owners of Flock cameras._
|
| fyi, flock owns the cameras.
|
| " _We operate using a lease model. What does that mean?
| Since we own the hardware, we own the problems that
| occur._ "
| kstrauser wrote:
| FWIW, I just did this as an experiment and turned it into
| a blog post afterward. I didn't really set out with an
| agenda or a deliberate audience, and I didn't share it
| here. Don't get me wrong, I'm happy to chat about it! But
| this ended up here without any special effort on my part.
| tptacek wrote:
| I know the feeling! My arguments here are positive, not
| normative. I don't know that I think it would be a worse
| world if your hypothesis was correct. I'm just reasonably
| sure it isn't.
| kstrauser wrote:
| For sure. This is the sort of conversation I'd typically
| rather be having at a bar with appropriate beverages. If
| it sounds like I'm arguing, it's because it's the kind of
| thing I'd debate with my friends for the fun of it.
| mindslight wrote:
| "Your data" isn't really a well defined term, right?
|
| But yes, data that can be used to track my movements in my
| vehicle is certainly a type of personally identifiable
| information. I'd argue there should be some exemptions for
| individuals operating on a small scale, which I believe the
| CCPA has (and if we actually got a US GDPR, that it should
| have). But also that kind of exception shouldn't apply to a
| camera jointly operated by and backhauling to Ring.
| necovek wrote:
| I believe you are still the owner of that data, but if you
| are holding someone's PII -- which time of passage, car model
| and license plates can be argued to be especially with a
| fixed location -- according to privacy regulations, they can
| ask a _business_ to remove it unless they have a legally
| acceptable reason to keep it (eg. they hit-and-run a parked
| vehicle).
|
| Now, with you likely not keeping that Ring tied to a business
| account, how that applies to non-businesses holding PII is a
| different matter.
| danudey wrote:
| The laws say that data about you is your data, information
| about you is your information. No one is saying that you "own
| the data", but by virtue of the data being personal
| information about you specificially you are allowed to exert
| control over that data, such as asking for it to be deleted.
| kasey_junk wrote:
| That view of data ownership is _highly_ jurisdiction
| dependent and is not the overwhelming norm in the US.
| captaincrisp wrote:
| While that's definitely true, in this particular case
| he's invoking his rights under CCPA.
| tptacek wrote:
| They're invoking a right they do not in fact have under
| CCPA. Flock is a service provider under CCPA, and isn't
| required to respond to their request so long as they're
| operating under the terms of their contract with the
| municipality (which is, in turn, exempt from CCPA.)
| mindslight wrote:
| Isn't this just the routine fascist playbook at this point?
| Start by declaring that the law doesn't even apply to them, on
| whatever flimsiest of bases.
|
| Personally I would really like to see torts for attorneys who
| willfully promulgate blatantly incorrect legal interpretations
| - they're effectively providing incorrect legal advice. A non-
| attorney is likely to believe such advice coming from a member
| of the Bar, and the net goal is to discourage the target from
| seeking further legal advice.
| SoftTalker wrote:
| An attorney whom you have not engaged in counsel is not
| providing legal advice.
| mindslight wrote:
| I'm well aware of how it's currently legally defined -
| hence "effectively". My comment is in the context of _what
| ought_ , not _what is_.
| snowwrestler wrote:
| It's not clear to me that it is actually your data. If I take a
| picture of you in a public place, I own the picture, not you.
|
| But maybe I am unclear on how Flock works.
| bjt wrote:
| Setting aside Flock, the "ownership" situation is not as
| clear as you say above.
|
| What you own is the image copyright. But the right to copy is
| only one of the rights at issue.
|
| Under various state laws (California in particular), you
| might not be entitled to do all the things with that picture
| that you could do of one that doesn't have my likeness.
| Privacy laws like the CCPA are one possible carve-out. A
| "right of publicity" is another.
|
| There's an old saying about property law that "property is a
| bundle of sticks". The bundle can be subdivided.
|
| https://www.law.cornell.edu/wex/publicity
| pksebben wrote:
| Isn't flock's whole thing that they extract information from
| the pictures they have?
|
| Like, say I have an interview in your office and you step out
| for coffee. I take a picture of the applicant list on your
| desk. That doesn't make the list of applicants "my data".
| lotsofpulp wrote:
| >I take a picture of the applicant list on your desk. That
| doesn't make the list of applicants "my data".
|
| If the list is sitting there out in the open, then yes, it
| does make it your data.
| throwway120385 wrote:
| Well, maybe not. A reasonable person might not think that
| about that applicant list. I bet you could make a
| different argument for taking a picture versus memorizing
| the list too.
|
| The legal system thrives on specifics of a situation, so
| simply asserting that the list of applicants is or is not
| "yours" because you can see it seems like a gross
| oversimplification. The specifics of how you came to be
| there, what your relationship with the officeholder is,
| and so on probably matters a lot in that situation and I
| think there might be some unwritten rules or social norms
| that you'd be expected to follow as well.
| throwway120385 wrote:
| You also might not be considered a commercial entity under
| the law. It's a bit more nuanced and the words written in a
| particular statute have to be interpreted together. So
| statements about "commercial entities" have to be limited to
| such entities even if we'd really like to be able to go to
| our neighbor's house and ask them to delete all of the
| surveillance they have of our cars driving up and down the
| street in front of their house. I think these laws are often
| narrowly written to avoid unintended consequences like de-
| facto banning private operation of surveillance systems on
| private property.
| goodluckchuck wrote:
| The CCPA clearly violates the 1st Amendment. If you're out in
| public, then people are allowed to see you, to remember it, to
| communicate that it happened, etc.
| necovek wrote:
| This answer is relevant:
| https://oag.ca.gov/privacy/ccpa#collapse6d
|
| In short, Flock is a "service provider" and not the entity
| doing the recording.
|
| Perhaps you can make a case that they are a "data broker"
| instead (https://oag.ca.gov/privacy/ccpa#collapse1i), but that
| is a separate law, and what you are really looking at is a
| combination of license plate, time and location being collected
| as data being collected and sold without your consent.
|
| Obviously, I am not a lawyer (and not even US-based), but I
| like when privacy is respected :)
| zbrozek wrote:
| I tried the same, got a similar response, and complained to the
| AG. Nothing.
| wakamoleguy wrote:
| The data ownership is really interesting, as many threads here
| are going into. I wonder if it's possible to sidestep that
| entirely, though! Under the CCPA, "personal information" is
| defined as information that identifies, relates to, describes,
| is reasonably capable of being associated with, or could
| reasonably be linked -- directly or indirectly -- with a
| particular consumer or household. That says nothing about
| ownership.
|
| To the extent that Flock is only storing the data on behalf of
| their customers, I'd understand they wouldn't be required to
| delete it. But to the extent that they are indexing it,
| deriving from it, aggregating it across customers, and sharing
| it via their platform, it seems they should be required to
| remove that data from those services.
|
| But then again, I am not a lawyer!
| tgsovlerkhgsel wrote:
| Under GDPR, I believe that would be accurate. I _think_ CCPA
| was to some extent inspired by GDPR so I wouldn 't be surprised
| if they copied this point too.
|
| Which, hilariously, means that under GDPR, you only need to
| contact the web site, and _they_ have to go talk to their 1207
| partners that value your privacy to fulfill your request (I 'm
| sure that in practice they'll say "sorry it's all 'anonymous'
| so we can't" or "we can't be sure that it's you even though you
| provided the identifier from your cookies"). I'm really
| disappointed that NOYB hasn't started going after web sites
| like that - that's quickly put a damper on the whole web
| surveillance economy.
| charcircuit wrote:
| >It's my data, not their customers'.
|
| Just because data is about you, that doesn't mean it is your
| data.
| john_strinlai wrote:
| you may be minunderstanding the california consumer privacy
| act (ccpa). in the ccpa, personal data is defined as:
|
| _" Personal information is information that identifies,
| relates to, or could reasonably be linked with you or your
| household."_
|
| and, you _do_ have the rights set forth in the ccpa (know,
| delete, correct, limit exposure, etc.) regarding that data.
| lmkg wrote:
| > which seems to directly oppose the CCPA.
|
| I have some background in data privacy compliance.
|
| It sounds like they are claiming to be a Service Provider under
| CCPA, which is similar to a Processor under GDPR. Long story
| short, a Controller is the one legally responsible for ensuring
| the rights of the data subject, and a service
| provider/processor is a "dumb pipe" for a Controller that does
| what they're told. So IF they are actually a Service Provider,
| they're correct that the legal responsibility for CCPA belongs
| to their customers and not them.
|
| That's a big IF, though.
|
| Being a Processor/Service Providor means trade-offs. The data
| you collect isn't yours, you're not allowed to benefit from it.
| If Flock aggregates data from one customer and sells that
| aggregate to a different customer, they're no longer just a
| service provider. They're using data for their own purposes,
| and cannot claim to be "just" a service provider.
| jsw97 wrote:
| You might reach out to the California AG. I suspect they are
| itching for this kind of thing right now.
| kstrauser wrote:
| Because life is weird, my kid played little league baseball
| against his.
|
| I might have to do that.
| AlBugdy wrote:
| Read a few of your posts. Just wanted to comment on how I like
| your to-the-point succinct style and how you care about
| privacy. :)
|
| As a suggestion, I saw you have RSS:
|
| https://honeypot.net/feed.xml
|
| I didn't see it mentioned in the main page or About or Archive.
| Maybe add it to a more visible place?
| kstrauser wrote:
| Aww, thanks! I appreciate that.
|
| And that's a good point. I'll look at that when I get home.
| barelysapient wrote:
| If that's a valid excuse than the CCPA isn't worth the paper its
| written on.
| dylan604 wrote:
| The rule of any documentation is that it is out of date as soon
| as the ink is dry. By the time a regulation is enacted,
| workarounds/loopholes have already been found (if not
| intentionally worked into it).
| ldoughty wrote:
| I would argue that the request was invalid in the first place.
|
| If I see a flash on a speed camera operated by a business on
| behalf of a police department, your argument states I should be
| able to use CCPA to force the business to delete my picture and
| the record of me speeding If I can get the request to them
| before the police can file with the court and request that data
| as evidence.
|
| The data belongs to the government, and you can't get around
| that right by going to business that holds the data and asking
| them to delete it.
| inetknght wrote:
| > _If I see a flash on a speed camera operated by a business
| on behalf of a police department, your argument states I
| should be able to use CCPA to force the business to delete my
| picture and the record of me speeding If I can get the
| request to them before the police can file with the court and
| request that data as evidence._
|
| Sounds reasonable to me. If the police want to put up a
| camera, then the police should put up a camera.
|
| Offloading their legal responsibilities to a third party
| company is shitty.
| SoftTalker wrote:
| So police departments should have to develop and host all
| their administrative software also? I think we can all see
| why that would be a terrible idea. Police are like any
| other government agency or business in that they contract
| with the private sector for a variety of services that are
| not in their area of expertise.
| inetknght wrote:
| > _So police departments should have to develop and host
| all their administrative software also?_
|
| Yes. We're in an high technology and information age.
| Police should be well-versed and capable of understanding
| the technologies and informations that people use.
|
| > _I think we can all see why that would be a terrible
| idea._
|
| I don't.
|
| > _Police are like any other government agency or
| business in that they contract with the private sector
| for a variety of services that are not in their area of
| expertise._
|
| Why shouldn't police (or some law enforcement agency) be
| capable of operating and maintaining law enforcement
| technologies?
| stephbook wrote:
| "Hey private prison please delete all data you have about
| me. And by the way, I'm locked up here by accident. Please
| release me."
| jakeydus wrote:
| Honestly private prisons are a farce anyways, so yeah
| this seems valid to me. The government doesn't get to get
| out of its obligations to citizens by outsourcing to
| third parties, and third parties don't get to wield
| government-level authority without government-level
| accountability.
| barelysapient wrote:
| But we're not talking about speed cameras or a private entity
| with exclusive contract with the police to provide traffic
| enforcement.
|
| We're talking about Flock. A company offering surveillance as
| a service. Per their website:
|
| >Trusted by over 12,000 public safety customers including
| cities, towns, counties, and business partners.
|
| If Flock's argument holds then most of the CCPA be
| circumvented this same way. All it takes is a few entities
| and clever contract language.
| TheRealPomax wrote:
| Except the data does NOT belong to the government, that's the
| whole point of Flock operating the way it does. It's not
| governmental data collection it's data collection by a
| _private_ company that is then _made available_ to the
| government upon request. And yeah: it is _literally_ allowed
| to delete data, because again: it 's not a government agency,
| it's _just_ private data, collected by a private company,
| with the exact same status as you recording an public
| intersection with a camera from your window.
| ranger_danger wrote:
| To me this sounds like the equivalent of visiting a website that
| sells your data, and then asking AWS to delete your personal data
| when it actually belongs to a customer of theirs and only resides
| within their private storage.
|
| Would you ask your local ISP to delete data they provided to
| Tinder like your IP address? That doesn't make sense to me.
| terrabitz wrote:
| Yeah I was getting the same feeling. I wonder if an equivalent
| request to California police agencies that contract Flock
| technologies would work though.
| OkayPhysicist wrote:
| Probably not, as the law enforcement agencies get a bunch of
| exceptions to the CCPA.
| monooso wrote:
| As I understand it, the author wrote to Flock as they are the
| entity collecting the PII. Your analogy would only make sense
| if the author had written to Flock's customers (and even then
| it's a rather strained comparison).
| ranger_danger wrote:
| > they are the entity collecting the PII
|
| I'm not convinced this is the case. It might be equipment
| made by them, but does that necessarily mean they were ever
| even in possession of the data in question?
|
| Would you ask the manufacturer of your oven what you ate for
| dinner last week? No, you're just using an appliance that
| they made.
|
| In the case of Flock I don't think we have any evidence of
| whether Flock themselves ever hold or store any data produced
| by their devices when operated by a customer.
| alt227 wrote:
| Yes, I have asked multiple companies to destroy my data under
| GDPR. Its quite common in Europe.
| ldoughty wrote:
| I think you're going to have a hard time with this...
|
| Flock seems to leave the data in ownership of the government.
| They are just providing the service of being custodians for
| storing and accessing that data.
|
| You probably would get a similar response by submitting your
| request to Amazon web services or Google cloud or whoever has
| Flocks data: "sorry, we're just holding the data on behalf of
| Flock"
|
| In either my example case or your stated case, you would have a
| very hard time convincing the host business to destroy their
| customers data without a court order or court case that shows
| their policy is invalid and they must comply.
|
| Not a lawyer, just noting the parallel.
|
| I do appreciate that Flock's response says that they cannot use
| the data they've collected for other purposes.. which further
| reinforces my cloud storage analogy -- the cloud vendor can't
| look at your data you upload to storage to e.g. build profiles on
| you/your business.
| Barbing wrote:
| > the cloud vendor can't look at your data you upload to
| storage to e.g. build profiles on you/your business.
|
| Would our main check on this be whistleblowers?
| calmbonsai wrote:
| Per my understanding of the law for these sorts of data
| collectors, at least in the U.S., you need to contact the local
| municipalities (Flock's customers) for this redaction and the
| jurisprudence is governed at the state and municipal level.
|
| The best source of this information is https://deflock.org/ .
| FWIW, this is run by a neighbor in Boulder, CO which has been
| wrestling with the use of these cameras.
| cousinbryce wrote:
| Automating requests to every municipality sure would be fun
| nekusar wrote:
| The only opt-out the citizenry has is with any of the following:
| 2x4 rebar spraypaint spray foam
| battery powered metal cutter
|
| And bash those pieces of shit to chunks or completely ruin the
| lens and solar.
|
| Republican community? They love corporate surveillance. Democrat
| community? They too love corporate surveillance.
|
| There is no "Peoples' Party" that rejects this garbage.
| MengerSponge wrote:
| https://www.techspot.com/news/108045-lidar-great-cars-but-ca...
|
| It would be a pity if someone made dense point clouds of these
| devices.
| maccam912 wrote:
| One could start doing tours of their city to show tourists
| where each and every camera is. They're kinda small though,
| it might be worth a strong laser pointer so you can direct
| their attention to the cameras easily...
| pugworthy wrote:
| All materials available at major home improvement centers -
| which happen to be very popular Flock camera locations.
| empathy_m wrote:
| I noticed that the company is glossed as "Flock" and not "Flock
| Safety (YC S17)" in posts like this and last week's "US cities
| are axing Flock Safety surveillance technology",
| https://news.ycombinator.com/item?id=47689237.
|
| Did YC house style change a while back to drop the "(YC xxx)"
| annotation since so many popular firms particpate / or because
| it's well known?
| mikey_p wrote:
| Who know, maybe they're trying to distance themselves from the
| privacy disaster, but I doubt anyone at YC or HN is smart
| enough to read the room on Flock.
| bix6 wrote:
| Which room? The one paying them millions to spy on people?
| Cash Rules Everything Around Me.
| tptacek wrote:
| I see less of it now across the board but note that this
| headline was almost certainly created by the story's submitter;
| it's not like there's an automated process to apply the label.
| kube-system wrote:
| I don't think they need your permission to use ALPR on your
| publicly displayed license plate.
|
| > (2) (A) "Personal information" does not include publicly
| available information [...]
|
| > (B) (i) For purposes of this paragraph, "publicly available"
| means any of the following:
|
| > (I) Information that is lawfully made available from federal,
| state, or local government records.
|
| > (II) Information that a business has a reasonable basis to
| believe is lawfully made available to the general public by the
| consumer
| _moof wrote:
| The information being collected isn't your license plate, it's
| your location. (Still might not be personal information.)
| wcv wrote:
| Flock has stonewalled with the "we are not the controllers"
| excuse here in MN too. We have similar rights to opt-out and
| delete under the MCDPA [0].
|
| [0] https://ag.state.mn.us/Data-Privacy/Consumer/
| tptacek wrote:
| They're not stonewalling; they're following the law. Their
| state and municipal customers would not want them honoring
| these requests!
| deepsun wrote:
| If Flock collects and processes PII data, then all their
| customers are "subprocessors". Flock should really have a Data
| Processing Agreement with their subprocessors, to legally ensure
| they follow the same PII handling controls as Flock does.
|
| For example, if Flock receives a legitimate request to delete
| some data, then Flock must forward that request to all their Data
| Processors (e.g. including AWS/GCP/Cloudflare) and they must
| delete it as well.
| Aaargh20318 wrote:
| It's the other way around. Flock is the subprocessor for
| whoever hired them to collect data. If they are collecting data
| on behalf a city or municipality, those are the entities you
| need to address.
| mmmlinux wrote:
| Lot of Flock Defenders in here.
| pwython wrote:
| Not Flock defenders, just people explaining how this is not a
| CCPA violation. I could set up 100 cameras around town (with
| property owners permission) and record cars driving by, birds,
| etc all day. Then I could sell access to that footage to
| whoever I want. If they want to scrape license plates that's up
| to the customer and their problem. Or if they want to track
| birds, cool, that could be in the frame too.
| kstrauser wrote:
| It gets a little weird when you explicitly market them for a
| purpose, though. Flock doesn't advertise a fleet of cameras
| suitable for birdwatching or other random activities. They
| market them specifically for the collection and processing of
| PII.
|
| By analogy, Google Docs isn't marketed for healthcare use. If
| you wanted, you could put a bunch of PHI in a Google doc and
| it wouldn't be their responsibility. They certainly didn't
| tell you to do that. However, if they marketed Google Docs as
| a great place to store PHI, yeah, then suddenly they're on
| the hook for complying with the relevant laws like HIPAA.
|
| (Although in this case Google _will_ sign a HIPAA business
| associate agreement with you and voluntarily agree to comply.
| They still don 't market it that way, or at least don't
| predominantly do so.)
| annoyingnoob wrote:
| I've had the same kind of response from Email providers like
| Sendgrid, they claim its not their data. There is no way to have
| Sendgrid block you in their entire network, you have to play
| whack-a-mole with their customers. Seems like a flaw in these
| privacy laws when you can't ask the actual record holder to
| remove the records.
| hmokiguess wrote:
| https://www.flocksafety.com/legal/lpr-policy
|
| > In accordance with its Terms and Conditions, Flock Safety may
| access, use, preserve and/or disclose the LPR data to law
| enforcement authorities, government officials, and/or third
| parties, if legally required to do so or if Flock has a good
| faith belief that such access, use, preservation or disclosure is
| reasonably necessary to comply with a legal process, enforce the
| agreement between Flock and the customer, or detect, prevent or
| otherwise address security, privacy, fraud or technical issues.
| Additionally, Flock uses a fraction of LPR images (less than one
| percent), which are stripped of all metadata and identifying
| information, solely for the purpose of improving Flock Services
| through machine learning.
|
| In this document, to which they linked in their reply, it says
| clearly "address ... privacy ... issues."
|
| Does your case not constitute a privacy issue? I would say so.
|
| Continuing down below, their claim on "Trust Us" about how they
| employ machine learning would need some proper transparency into
| how can that be guaranteed.
| FireBeyond wrote:
| > Continuing down below, their claim on "Trust Us" about how
| they employ machine learning would need some proper
| transparency into how can that be guaranteed.
|
| Wait til you see their "Transparency Portal" which, if my
| County and neighboring can be used as a sample size, doesn't
| even name at least 30% of agencies using Flock.
| _moof wrote:
| They seem to be implying that because they are a "service
| provider," they aren't responsible for complying with CCPA rules
| even though they are the ones with the data.
|
| Does this hold water? I'm reading the CCPA rules now but if
| anyone knows, it would save me some tedious research.
| ezfe wrote:
| I guess if one likens it to AWS S3 holding your data on behalf
| of Apple it makes sense
| pugworthy wrote:
| An interesting quandary here is that they'd need to constantly
| scan for you and your vehicle, etc. so that they could know it
| was you then delete you. So to ensure they don't observe you,
| they need to observe you.
| rdiddly wrote:
| Flock's customers own the data the same way Uber drivers are
| independent contractors, i.e. it's designed for weaseling out of
| obligations.
| lacker wrote:
| Isn't that how it should work?
|
| If you write the police and ask them to delete all their data
| about you, that isn't a thing that they do. It shouldn't matter
| if the police store their data on AWS or their own servers.
|
| Flock is a tool used by the police so it should work the same
| way.
| nerevarthelame wrote:
| You're right are exemptions for both GDPR [0] and the CCPA [1]
| where organizations aren't obligated to comply with erasure
| requests if it would limit their ability to prevent or
| investigate crimes, fraud, or similar matters.
|
| But that's not what Flock is claiming. They're claiming that
| they don't even have to consider the request because they don't
| own the data.
|
| [0] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-
| re...
|
| [1] https://www.clarip.com/data-privacy/ccpa-erasure-
| exemptions/
| dsr_ wrote:
| Remember that the difference between "Flock can do whatever the
| hell it wants" and "Flock is required to delete your data at your
| request" is a law. Citizens vote for legislators. If you want
| this to be a higher priority for your legislators, buy them off.
|
| Or vote for/against them, that might work too.
| joquarky wrote:
| Reminds me of this article from a while back:
|
| https://theonion.com/american-people-hire-high-powered-lobby...
| cold_tom wrote:
| Feels like a classic "we're just the processor" answer But in
| reality you have no way to find or contact whoever actually
| controls the data, so it doesn't really help. Kind of shows the
| gap between how the law works on paper vs how these systems work
| in practice.
| sklargh wrote:
| The concept of what constitutes a sale under CCPA is pretty
| expansive. An exchange of value can be a sale that occurs outside
| of a processing relationship. I'd say their note is inaccurate.
| carabiner wrote:
| It's not much worse than all the tracking adtech used by FAANG
| industry. Smartest people in the world working on these systems.
| kstrauser wrote:
| I'd contend that it absolutely is. Adtech is creepy and
| invasive and weird. Flock is going a step further and actively
| tracking our movement through the cities where we live.
|
| I don't like either of those activities, but I think one of
| them is much worse.
| jakeydus wrote:
| One is making implicit assumptions based on data available to
| it. The other is literally saying "hey they're right here at
| this time". At least adtech has _some_ level of obfuscation
| to it.
|
| But I'm with you both suck.
| rbbydotdev wrote:
| it would be nice if flock did not and could not exist
| atmosx wrote:
| Back in 2018, CloudFormation data leaked through a public gist
| (misconfigured gist plugin, I thought the gist was private but it
| wasn't... I had change the default config) and showed up on an
| obscure website being served via CloudFlare. When I contacted CF,
| they claimed they couldn't remove the cached content because
| their system "doesn't work like that". I pushed back and then
| they said that they're not responsible for the content and that I
| should send another email to abuse@cf... to get data about the
| hosting provider and deal with the content provider (e.g. VPS,
| ISP, whatever). After a few back and forth msgs, I made it clear
| that if the data wasn't taken down within a week or so, I would
| escalate the issue to the local and German GDPR authority (see
| https://www.ombudsman.europa.eu/en/european-network-of-ombud...).
|
| And what do you know? I got not reply, but the content
| disappeared in ~48hrs.
| gguncth wrote:
| It's fascinating how America could completely get rid of Flock
| cameras by sending criminals to prison and leaving them there,
| but we won't do that so we have these endless arguments about
| these cameras.
| AlotOfReading wrote:
| I'm trying to understand the argument here. Are you saying that
| never releasing convicted criminals would _completely_
| eliminate crime?
|
| That doesn't seem correct, even leaving aside the obvious moral
| issues with that.
| kstrauser wrote:
| My interpretation was that they were saying Flock were
| criminals who should be sent away for good. I don't know if
| that's right but it would be consistent that way.
| AlotOfReading wrote:
| That makes much more sense, yeah.
| pext wrote:
| This reminds me of the Andrew Yang's "Data Dividend" project that
| ideally would have paid end users for their data rather than
| knowingly giving it aware for free. IMO, it was a great idea but
| flawed execution against all the lobbying.
| thangalin wrote:
| Sent to Benn Jordan:
|
| https://i.ibb.co/WWWYznHX/flock-future.png
|
| See also a poster from IBM's German subsidiary, circa 1934. The
| approximate translation: "See everything with Hollerith punch
| cards."
|
| https://www.clevelandjewishnews.com/opinion/op-eds/new-detai...
___________________________________________________________________
(page generated 2026-04-14 23:00 UTC)