[HN Gopher] I wrote to Flock's privacy contact to opt out of the...
       ___________________________________________________________________
        
       I wrote to Flock's privacy contact to opt out of their domestic
       spying program
        
       Author : speckx
       Score  : 424 points
       Date   : 2026-04-14 17:47 UTC (5 hours ago)
        
 (HTM) web link (honeypot.net)
 (TXT) w3m dump (honeypot.net)
        
       | kstrauser wrote:
       | I wrote this. I had/have absolutely no expectation that Flock
       | would comply with my request, but figured I should try anyway For
       | Science. Their reply rubbed me wrong, though. They seem to claim
       | that there are no restrictions on their collection and processing
       | of PII because other people pay them for it. They say:
       | 
       | > Flock Safety's customers own the data and make all decisions
       | around how such data is used and shared.
       | 
       | which seems to directly oppose the CCPA. It's _my_ data, not
       | their customers '.
       | 
       | Again, I didn't really expect this to work. And yet, I'm still
       | disappointed with the path by which it didn't work.
        
         | carefree-bob wrote:
         | They were saying "don't write to us, talk to the people who own
         | the cameras and ask them to delete the data". A company that
         | manufactures video cameras is not the one to talk to when
         | someone records you, talk to the person who recorded you.
         | 
         | But a reasonable person would say -- the data is stored on
         | Flock servers, not with the camera owners. And Flock would say,
         | just because we sell data storage functionality to camera
         | owners doesn't mean we own the data, anymore than a storage
         | service you rent a space from owns what you put in that space.
         | 
         | But then an even more reasonable person would say: the
         | infrastructure is designed in such a way as to create
         | inadvertent sharing, and the system has vulnerabilities that
         | compromise the data, so Flock has responsibility for setting up
         | the system in such a way that it's basically designed to
         | violate privacy.
         | 
         | And _that_ is the main criticism of Flock. You need to have a
         | more nuanced criticism. It would be really interesting to see
         | this litigated.
        
           | fudgy73 wrote:
           | AFAIK Flock owns the cameras and leases them out [0].
           | 
           | [0] https://www.flocksafety.com/blog/flock-safety-does-my-
           | neighb...
        
             | mminer237 wrote:
             | If you go to Rent-A-Center and rent a DSLR, that doesn't
             | make Rent-A-Center responsible for the pictures taken by
             | their cameras.
        
               | kstrauser wrote:
               | If Rent-A-Center installed the camera in a bathroom, I'd
               | contend that it does.
               | 
               | Flock's cameras aren't in bathrooms. However, they're
               | still recording people who haven't opted into it. ("But
               | you have no expectation of privacy in a public place!"
               | "You have the expectation that someone might
               | inadvertently overhear you. You don't have the
               | expectation that someone is actively recording you at all
               | times.")
        
               | danielsunsu wrote:
               | I think if it were only offline storage it would not be
               | as big of an issue. A more accurate analogy would be
               | renting a DSLR that automatically transmits every picture
               | to Rent-A-Center servers.
        
               | yabutlivnWoods wrote:
               | Your example is apples and oranges. Flock maintains
               | private infrastructure that stores data.
               | 
               | If the DSLR uploaded them to Rent-A-Center owned/leased
               | servers it would in fact require Rent-A-Center to take
               | the necessary steps.
               | 
               | As Rent-A-Center would be the only group with proper
               | access to data storage they would have inserted
               | themselves into the chain of custody, and thereby have
               | such obligation to ensure others data is wiped from
               | systems they control.
        
               | tptacek wrote:
               | AWS also maintains private infrastructure that stores
               | data. Go write them asking to purge data pertaining to
               | you from S3 and see how that goes.
        
               | itsdesmond wrote:
               | Flock has knowledge/use of the data. Their system
               | processes can relate the photos "owned" by two different
               | entities. They're interacting with it and selling their
               | access to it as a feature. That's obviously distinct from
               | S3.
               | 
               | But you knew that.
        
               | tptacek wrote:
               | I know quite a bit about Flock, having been intimately
               | involved in the process of evicting it from our
               | municipality, and I don't think the distinction you're
               | trying to draw here is meaningful. Flock will say they
               | provide a service, one avidly sought by the actual owners
               | of the data, to generate analysis based on that data.
               | 
               | They're contractually forbidden from "selling their
               | access to it" to arbitrary parties; they can share data
               | only with the consent of their customers, almost all of
               | whom actively want that data shared --- this is a very
               | rare case of a data collection product where that's
               | actually the case.
        
               | dureuill wrote:
               | Except their customer's data isn't actually theirs: OP
               | requested their private data to be deleted from the
               | system. So OP expressed a clear intent for their data not
               | to be used by Flock's customer. We could say that the
               | data thus becomes abusively retained on these systems. As
               | a result, IF Flock has the technical means of performing
               | the requested data deletion, it should be compelled to
               | perform it.
               | 
               | This is the same situation as a web hosting provider: if
               | it is communicated to them that one of their customers
               | uses their service to host illegal content, then it
               | becomes the web hosting provider's responsibility to
               | remove that content.
               | 
               | Reasonable technical feasibility for the service provider
               | is key here, but it can be argued since the data can
               | apparently be shared in ways that identify OP.
               | 
               | Probably not how the law currently works (don't know, not
               | a lawyer), but I guess it should, as otherwise it allows
               | creating a platform that shares abusively retained data
               | without any reasonable recourse for the subjects of this
               | data to remove the data from the platform.
        
               | tptacek wrote:
               | I do not believe this is how the law works. Two _totally_
               | different regimes.
        
               | Mordisquitos wrote:
               | Does AWS actively and by design parse and keep track of
               | personally identifiable information of the data that AWS
               | customers store on their S3 buckets? If that were the
               | case they would absolutely be subject to CCPA (and GDPR)
               | requests for deletion.
               | 
               | However, I suspect that is not the case. AWS is agnostic
               | as to the type of data stored on S3, and deletion of PII
               | stored on S3 is the sole responsibility of the AWS
               | customer that chooses to store it.
        
               | danudey wrote:
               | If AWS maintained private infrastructure that stored and
               | indexed data associated with people's license plates and
               | vehicles and then charged customers to do searches
               | against that data then yes, you could write them to ask
               | them to purge data pertaining to you.
               | 
               | If Flock was just an opaque cloud storage service for law
               | enforcement to back up their mass surveillance to then
               | sure, your argument would have merit; it's not, it's a
               | giant database of photos, locations, times, license plate
               | information, and likely a lot more. They're not selling
               | cloud storage, they're selling (leasing?) surveillance
               | devices and tools.
        
               | tptacek wrote:
               | The argument you're making implicates way more than just
               | Flock, and is in a practical sense novel. If you can cite
               | jurisprudence (or even legal experts) backing it up, I'm
               | interested in reading it. Otherwise, I'm happy to accept
               | that we just have premises about the law that are too far
               | apart for an argument to be productive.
               | 
               | My experience on HN is that these kinds of discussions
               | almost immediately devolve into debates about what people
               | want the law to be, as opposed to what it actually is.
        
               | Karrot_Kream wrote:
               | Realistically speaking you're never going to get pro
               | Flock people in any numbers on this site writing comments
               | at all. The anti surveillance position's popularity when
               | it comes to up votes, down votes, and flags on this site
               | is such that pros will continue posting about what they
               | want the law to be and antis will stay out. That's just
               | how crowd voting dynamics shape out.
        
               | yabutlivnWoods wrote:
               | I don't live in a state with a law like California's so
               | your "gotcha" isn't relevant.
               | 
               | Californians would have standing under the law but need
               | expensive lawyers to litigate.
               | 
               | AWS has employed expensive lawyers to argue semantics;
               | they host OS VMs and databases. This provides them legal
               | cover for what AWS customers store.
               | 
               | Amazon the retailer stores customer data. A non-customer
               | would have standing under California law to litigate
               | removal of PII should they decide to hire lawyers.
               | 
               | Your reductionism is to law what a Linux beige box on a
               | routable IP, no firewall, hosting a production health
               | database with creds set to admin/pwd1234 is to software
               | engineering.
               | 
               | Coincidentally 1234 happens to be the code to my luggage.
        
             | ldoughty wrote:
             | But the data collected is property of the government and
             | flock is not allowed to use that data for additional
             | business gain (according to their statements)...
             | 
             | So they can't sell the fact that you're at Target at 8:00
             | p.m. on Thursday to anybody... Nor build profiles to sell
             | to advertisers... And if that's the case that's very
             | similar to cloud storage vendors.
             | 
             | If I access hacker news, and the record of my visit is
             | stored in an AWS S3 bucket, I can't submit to AWS to delete
             | my visitor record, even though the server, network cards,
             | wires, and storage medium are AWS property, it was hacker
             | news' website that generated that record and their
             | responsibility to take my request to delete it.. AWS'
             | stance would rightly be "talk to the website operator for
             | CCPA requests"
        
               | tptacek wrote:
               | This is also true according to their contracts (we were
               | one of the first munis in the country to ostentatiously
               | cancel our Flock contract, and the lead up to that was a
               | bunch of progressive legal experts poring over that
               | contract looking for holes.)
        
               | fsckboy wrote:
               | > _a bunch of progressive legal experts poring over that
               | contract looking for holes_
               | 
               | all attorneys represent their clients; your attorney does
               | not have to share your opinion of the law or public
               | policy, they can still interpret what the law means to
               | you.
               | 
               | if you are afraid your attorney might have a bias (they
               | are human) you may get better advice from the
               | "misaligned" POV: the flaws/holes in a privacy law found
               | by a pro-business conservative attorney are more likely
               | to find sympathy in the courts from both fellow
               | conservatives and progressive judges.
        
               | shermantanktop wrote:
               | As a practical matter, this may be good advice. But it
               | also places a demand on someone with a legitimate concern
               | that they go find an ideological "beard" to make
               | themselves more palatable and sympathetic.
               | 
               | It's not hard to see how this enables an institution to
               | gate itself from criticism.
        
               | thaumaturgy wrote:
               | Except that Flock very clearly benefits financially from
               | having direct access to this data: owning (and in their
               | own documentation, they very clearly _do_ own it) a
               | network of 80,000 surveillance devices across the
               | country, and owning every single transit point for the
               | data they collect, is what gets them to a $7.5 billion
               | valuation from investors.
               | 
               | The fact of the matter is that Flock is playing two-step
               | with the concept of "ownership" of data. They disclaim
               | ownership as a way to leave local agencies holding the
               | bag for liabilities, but they fight _tenaciously_ to
               | retain complete and unfettered access to that data.
               | 
               | (After organizing a community group that won Flock
               | contract cancellations in multiple jurisdictions in
               | Oregon, I went on to coauthor state legislation
               | regulating ALPRs. I am very well familiar with all the
               | dirty ball they play.)
               | 
               | Also, Flock's cameras collect more data than is provided
               | to police agencies. Who owns _that_ data, I wonder?
        
               | necovek wrote:
               | That makes them a data broker in my reading, and at least
               | in California, Data Broker legislation should apply. CA
               | Data Broker registry gives me access denied, but that
               | could be because I am outside US.
        
               | ScoobleDoodle wrote:
               | I looked it up at
               | https://cppa.ca.gov/data_broker_registry/ and didn't find
               | Flock / Flock Safety in that list of the currently
               | registered 566 data brokers.
        
               | tptacek wrote:
               | Because Flock isn't a data broker. Flock's customers own
               | their data, not Flock, and they use Flock's platform
               | voluntarily to share data with other customers.
        
               | necovek wrote:
               | I was referring to the claim that "Flock's cameras
               | collect more data than is provided to police agencies" --
               | that suggests that there is data not "owned" by the
               | customers, which implies it's Flock's data, thus it might
               | make them liable under Data Broker legislation.
        
               | cwillu wrote:
               | Equivocation. My stock broker doesn't own my stocks
               | either, they merely hold my assets in a brokerage
               | account.
        
               | tptacek wrote:
               | I encourage you to present that analogy to an actual
               | court and see how far it gets you. It's very easy to find
               | the statutory definition of a "data broker" under
               | California law.
               | 
               | This is what I mean by the fruitlessness of these kinds
               | of legal discussions on HN. What do you want me to argue,
               | that you're wrong to _want_ the law to work that way?
        
               | jaredwiener wrote:
               | And you would (rightfully) be angered if your stock
               | broker sold your shares and pocketed the proceeds,
               | because you own them.
        
               | tadfisher wrote:
               | Flock charges to access the data which is voluntarily
               | shared by other customers. I am struggling to note a
               | difference in this practice from any other data brokerage
               | service in existence.
               | 
               | Does Flock do some kind of P2P dance to avoid the data
               | transiting their systems?
        
               | close04 wrote:
               | So... Flock uses their own platform and top to bottom
               | tech stack to do everything technically? Your local PD
               | doesn't use random cameras (like Reolink), doesn't run a
               | custom software stack (like Frigate in a container on
               | some random VM hosted with AWS), doesn't store the data
               | wherever (like Backblaze)? The customers just have to
               | install the Flock cameras and "order" the subsequent data
               | from Flock? But you say they're not at all responsible or
               | accountable for any it because despite doing everything
               | at every step, they're "just a broker"?
        
               | unethical_ban wrote:
               | If Flock's customers, using Flock's infrastructure or
               | tooling, can share data with each other, that would be
               | bad.
               | 
               | I'm not saying that's what's happening, but that's what I
               | _thought_ was happening before reading this thread, and
               | now I have to go and run through their policies.
               | 
               | Either way ALPRs and AI-facial scanners in public are a
               | huge violation of privacy and I loathe them, but I hope
               | it's correct that Flock customers cannot easily share
               | information with one another.
        
               | unethical_ban wrote:
               | This is worth validating independently, but to be clear:
               | 
               | Are you saying Flock itself does not have access to any
               | of the data, and that the data they store on behalf of
               | local governments is not fed into any central datalake?
               | That every organization's data is completely, unalterably
               | separate from everyone else's?
               | 
               | If so, that makes the panopticon _slightly_ less
               | powerful.
        
               | valeriozen wrote:
               | The AWS analogy breaks down because AWS doesn't encourage
               | customers to pool their S3 buckets into a nationwide
               | searchable index.
               | 
               | Flock operates a federated network. If you drive past an
               | unmarked camera, you have absolutely no way of knowing
               | which specific HOA or town leased it so how are you
               | realistically supposed to know who the "data controller"
               | is to send your ccpa or deletion request to?
        
               | giancarlostoro wrote:
               | Start standing in front of the cameras looking sketchy
               | long enough till police are sent out to ya, then ask the
               | cop who called.
        
               | chaps wrote:
               | Someone once dropped some fireworks not too far from me
               | at 3am a few years back. They were loud and, yeah, cops
               | were called. A few minutes later about five cars drive
               | past me about 30mph over the limit. Not sure how they
               | didn't see me or try to see me. But I know they didn't
               | catch the BRIGHT orange and lifted care.
               | 
               | Me being me, I submitted a FOIA request for the dashcam
               | footage of the five cop cars and the dispatch logs.
               | 
               | Instead of pulling over the easily identifiable car, they
               | pulled over some random guy. They were behind him the
               | whole time but five cop cars pulled behind him thinking
               | that he fired a gun a few minutes back.
               | 
               | He was let go without a citation, but the official
               | reason, despite being paired with the dispatch for the
               | firecracker, was a broken headlamp.
        
               | jnovek wrote:
               | I don't care. I don't care who owns the data. If I can't
               | easily get private information like my movements removed
               | from a database like this, the legislation does not
               | sufficiently protect me.
               | 
               | It should _absolutely_ be Flock's responsibility to
               | remove my data and we should absolutely require it by
               | law. Full stop.
        
               | lazide wrote:
               | A reasonably nuanced defense could likely claim that to
               | be able to do what you want, would have much worse side
               | effects on privacy.
               | 
               | For example, would you want to be able to tell Public
               | Storage (or some other storage unit place) to remove any
               | naked photos of you stored anywhere in their storage
               | units?
               | 
               | For them to actually be able to do that would require
               | they have nigh omniscience on everything stored by/for
               | everyone in every one of their storage units. Even inside
               | closed boxes.
               | 
               | Now, it's not the same thing of course - but hopefully
               | you understand what I'm referring to?
        
               | LadyCailin wrote:
               | Except that the analogy is that they already have, or can
               | easily create, that list. If they couldn't, their value
               | proposition would be lame. "We know you're looking for a
               | specific license plate, here's a million hours of footage
               | from all over the city, have at looking through it all."
        
               | lazide wrote:
               | Only for paying customers, which you aren't of course. If
               | those customers paid public storage to inventory their
               | stuff, then that inventory is their property. Surely it
               | would be inappropriate to use their inventory data to
               | find your naked photos. A violation of privacy even. (/s,
               | kinda)
               | 
               | I was enumerating the likely defense, not that it's
               | valid.
        
               | tptacek wrote:
               | The law cares about lots of things we don't care about.
        
               | eagleinparadise wrote:
               | If I lease out a property to a tenant (apartment, retail,
               | industrial use, whatever) and that tenant is committing
               | an illegal activity on the property. Would the landlord
               | be liable for knowing it? Or not?
               | 
               | "Sorry FBI, the tenant renting my warehouse out to
               | manufacturing cocaine is not my responsibility. I won't
               | do anything about it. You deal with them."
               | 
               | Nope, that's a failure of a duty to act and aiding and
               | abetting a criminal activity if you hace constructive
               | knowledge.
        
           | mistrial9 wrote:
           | the way this has been addressed in complex product liability
           | in the past in the USA is that the public-facing Brand Owner
           | has certain legal liability for the product, despite
           | contractors or supply chains. In this case, it appears that
           | the Flock company is the brand owner and is public-facing.
        
           | halJordan wrote:
           | It easily goes both ways. But we do sue American gun makers
           | for deaths caused by lunatics. We sue drug makers for drugs
           | prescribed by a doctor. We sue cloud providers for not
           | reporting illegal photos. Printers are forced to id every
           | printed page to combat counterfeiting. Banks are forced to do
           | close accounts even though it's not their dirty money
        
             | thebaine wrote:
             | Most of those examples have to do with the manufacturers
             | knowing that their products were dangerous, addictive or
             | illegal and advertising them aggressively as safe. They're
             | mostly litigated on product liability claims. Banks are
             | regulated by an entire architecture of laws, and we could
             | enact laws that would regulate Flock too, as one of the
             | other commenters pointed out they're doing in Oregon.
        
             | BobaFloutist wrote:
             | > But we do sue American gun makers for deaths caused by
             | lunatics.
             | 
             | No we don't, there's a federal law explicitly protecting
             | gun manufacturers from liability for gun crime. https://en.
             | wikipedia.org/wiki/Protection_of_Lawful_Commerce_...
        
           | dozerly wrote:
           | I don't think you're informed on the topic. They do not just
           | manufacture cameras.
        
           | robot-wrangler wrote:
           | > They were saying "don't write to us, talk to the people who
           | own the cameras and ask them to delete the data".
           | 
           | The response to this should just be, "Yes, very well, please
           | divulge a complete list of your customers, their contact
           | information, and information about camera locations so I will
           | be able to pursue this per instructions".
           | 
           | When that obviously doesn't work either then we can all agree
           | the law as written is completely useless, and feel great
           | about rewriting it in a way that's calculated for maximum
           | damage to both the vendor and their customers, and collateral
           | damage to the whole panopticon. Or, just spitballing here, we
           | can just skip to the punchline here and do all that anyway
        
           | beambot wrote:
           | Isn't this the equivalent of asking Google to delete your
           | image off every Android phone (not just yours)?
        
         | themafia wrote:
         | These laws get complicated quickly. There's a specific ALPR law
         | in the CA civil code which seems to carve out several
         | exceptions for a business like Flock:
         | 
         | https://leginfo.legislature.ca.gov/faces/codes_displayText.x...
         | 
         | The enforcement provisions are rather bleak as well and afford
         | no opportunity to directly bring a case against the agency that
         | operates the system but instead just the individual who misuses
         | it.
         | 
         | I think one of the more direct attacks would be going after
         | jurisdictions that chronically have officers misusing the
         | system. I think you're going to have to create precedent in
         | this way to foment actual change.
        
         | everdrive wrote:
         | Nice work all the same. These systems need to be prodded and
         | tested. Even unsuccessful results such as this tell us
         | something about the situation we're in.
        
         | nainachirps_ wrote:
         | I am not a lawyer myself but can't one argue that this company
         | has duty to ensure that data it is processing for client is
         | legally obtained.
         | 
         | If they are processing data after being told it was not
         | obtained with consent do they not have any liability?
        
         | Glyptodon wrote:
         | I think you should write them back and ask that they provide
         | you with a customer list and continually update you as they get
         | new customers so that you may follow the advice they've given
         | you.
        
           | kstrauser wrote:
           | Ooh. I like this.
        
             | kube-system wrote:
             | Why? The response is predictable. No company is going to
             | give you a customer list.
        
               | kstrauser wrote:
               | I wouldn't be so sure. In this specific case, they told
               | me to ask their customers to comply with my CCPA rights.
               | Without that information, it's impossible for me to
               | exercise those rights. IANAL, but that sounds like a
               | pursuable path.
        
               | kube-system wrote:
               | I don't see any provision in CCPA that requires that. And
               | outside of an explicit requirement to do so, nobody is
               | required to help you.
               | 
               | Edit: from https://oag.ca.gov/privacy/ccpa
               | 
               | > If a service provider has said that it does not or
               | cannot act on your request because it is a service
               | provider, you may follow up to ask who the business is.
               | However, sometimes the service provider will not be able
               | to provide that information. You may be able to determine
               | who the business is based on the services that the
               | service provider provides, although sometimes this may be
               | difficult or impossible.
        
               | bloppe wrote:
               | Perhaps the next step is writing to your state
               | representative, or to Alastair Mactaggart, and complain
               | about this hole in the legislation.
        
               | singleshot_ wrote:
               | I've been in the lobby of hundreds of different
               | technology companies and my understanding is that all
               | companies are going to give you a customer list, you just
               | have to look in the right place.
        
               | kube-system wrote:
               | Ha -- you know what I meant: explicitly.
        
         | ratdragon wrote:
         | maybe eff.org would be able to help you lawyer up or otherwise
         | to push this forward. good luck!
        
           | kstrauser wrote:
           | I've reached out, albeit very informally. I'll completely
           | understand if this isn't something they have the time and
           | energy to help with. If I accidentally caught them at a weak
           | moment when they're looking for something to do, though, I'm
           | all in.
        
         | tptacek wrote:
         | Wait, is it your data? If you drive your car in front of a Ring
         | camera on my house (I don't have a Ring camera don't @ me), is
         | it your claim that you own the data on that camera?
        
           | kstrauser wrote:
           | Did you put up a Ring camera on a stand in front of your
           | house for the specific purpose of selling that I drove past
           | at this specific timestamp? If so, yes. The CCPA[0] gives me
           | explicit legal rights:
           | 
           | * The right to know about the personal information a business
           | collects about them and how it is used and shared;
           | 
           | * The right to delete personal information collected from
           | them (with some exceptions);
           | 
           | * The right to opt-out of the sale or sharing of their
           | personal information including via the GPC;
           | 
           | This isn't someone incidentally taking pictures of license
           | plates in an otherwise noncommercial setting. It's a company
           | literally created to collect and sell PII. Laws are different
           | for them than for us.
           | 
           | [0]https://oag.ca.gov/privacy/ccpa
        
             | snowwrestler wrote:
             | "Personal information" has a legal definition and photos of
             | you in a public street might not satisfy it, regardless of
             | the photographer's intent.
        
               | kstrauser wrote:
               | I think it'd be challenging to rule that a license plate
               | number is not personally identifiable information, when
               | the same regulations often state that an IP address is.
        
               | uoaei wrote:
               | "Anyone could have been driving my car, you can't
               | positively identify me in the driver's seat with the
               | evidence you have submitted" is routinely used to toss
               | out cases involving traffic violations. It's not
               | necessarily common but it does happen. By this logic a
               | license plate does not personally identify the person
               | driving, only the person the car is registered to.
        
               | lcnPylGDnU4H9OF wrote:
               | Right, but in this context the license plate number is
               | still personal information, just of a different person.
        
               | uoaei wrote:
               | Then the key aspect of our discussion is the
               | "identifiable" part, which you've left out.
        
               | lcnPylGDnU4H9OF wrote:
               | Are you now saying that one cannot possibly "identify"
               | the "person" who owns a vehicle, solely with the
               | "information" on a license plate?
        
               | kube-system wrote:
               | The CCPA explictly says:
               | 
               | > "Personal information" does not include [...]
               | Information that a business has a reasonable basis to
               | believe is lawfully made available to the general public
               | by the consumer
        
               | tptacek wrote:
               | California has an entire statute regulating ALPR
               | information, so we don't need to derive this
               | axiomatically.
        
               | danudey wrote:
               | Yet the same is true of IP addresses. You (typically)
               | cannot know for certain whether traffic from an IP
               | address was originated by a specific person and yet it's
               | typically considered PII because it can be used in
               | conjunction with other information to identify you.
               | 
               | Even your full legal name and birth date cannot be
               | guaranteed to refer only to you specifically (as there
               | could be someone else with an identical name and birth
               | date), but it's obviously still PII because it helps
               | narrow the field immensely if you can combine it with
               | other information - for example, your IP address.
               | 
               | So yeah, "anyone could have been driving my car", but if
               | you also know that the car drove from _your_ home to
               | _your_ work then that narrows down the list of likely
               | individuals immensely.
               | 
               | Conversely, if your license plate was spotted parked near
               | an anti-ICE rally, then they can be pretty confident that
               | you or someone you know was near an anti-ICE rally, which
               | means they can harass you about it, follow you around,
               | shoot you in the street, etc.
        
               | tomwheeler wrote:
               | The standard of proving someone's guilt in a crime or
               | civil infraction is higher than the one for inferring
               | that someone could plausibly be the person you want. This
               | is the basis of parallel construction, wherein a
               | government agency plays a game of "pin a crime on the
               | suspect."
        
               | adrr wrote:
               | Or home address, phone number, etc
        
               | lcnPylGDnU4H9OF wrote:
               | Indeed, that definition is included in the CCPA.
               | 
               | > (v) (1) "Personal information" means information that
               | identifies, relates to, describes, is reasonably capable
               | of being associated with, or could reasonably be linked,
               | directly or indirectly, with a particular consumer or
               | household. Personal information includes, but is not
               | limited to, the following [...]:
               | 
               | > (E) Biometric information.
               | 
               | > (H) Audio, electronic, visual, thermal, olfactory, or
               | similar information.
               | 
               | https://leginfo.legislature.ca.gov/faces/codes_displaySec
               | tio...
               | 
               | To your point, the intent would presumably still matter
               | for exceptions to when deletion requests must be honored
               | (say for journalism), but a photo of someone walking down
               | a public street would still logically be considered the
               | subject's personal information, by the above definition.
        
               | necovek wrote:
               | Personal information usually does include photos of
               | someone in public without their consent: exceptions
               | usually hold for taking photos of people where it is in
               | the public interest to be able to show them or
               | impractical to get consent. This covers large gatherings
               | and celebrities, but a portrait photo of a stranger might
               | put you on the wrong side of the law.
               | 
               | Obviously, the idea is to not disallow having someone
               | take a photo of you as a background, passing figure as
               | they take a front-and-center photo of their family, but
               | not allow you to be the main subject unknowingly and
               | especially when you object explicitly.
               | 
               | On the other hand, a photographer still owns the
               | copyright to a photo, so a subject (including in a
               | portrait) cannot claim it or distribute it without
               | permission even if they can potentially stop the
               | photographer from distributing that photo.
               | 
               | IANAL, but you are not by default allowed to use anyone's
               | "likeness" for your individual profit.
        
               | patrickmay wrote:
               | > Personal information usually does include photos of
               | someone in public without their consent
               | 
               | This is not the case in the United States. There is no
               | presumption of privacy in public. In fact, there is a
               | whole genre known as "street photography" that involves
               | taking pictures in public without explicit consent of the
               | subjects.
        
               | necovek wrote:
               | You seem to be right, thanks for the correction!
               | 
               | If https://legalclarity.org/can-you-post-someones-
               | picture-witho... is to be trusted though, at least you
               | get protection from your likeness being used for
               | commercial purposes, though that seems a bit more limited
               | than I'd expect.
        
               | tadfisher wrote:
               | This is true, and it may also be true that location
               | tracking through surveillance networks crosses a line
               | into violating one or more Constitutional rights. One of
               | Flock's revenue streams is explicitly selling access to
               | data made available by other customers. A commonly-cited
               | example is the ability of local law enforcement to locate
               | abortion suspects in other states using the Flock camera
               | network [0]; one could imagine dragnet-style or geofenced
               | queries to also cross the line.
               | 
               | [0]: https://www.eff.org/deeplinks/2025/10/flock-safety-
               | and-texas...
        
               | tptacek wrote:
               | People keep making this claim that Flock "explicitly
               | sells access to data", but the link you provided doesn't
               | demonstrate that, and Flock contracts I've read
               | contradict the claim.
               | 
               | I think what's happening here is that people are trying
               | to colloquially define "selling access to data" to fit
               | the camera data sharing that Flock enables, and then
               | saying that because you have to pay to be a Flock
               | customer to get access to that data, they're effectively
               | selling it. I don' think that's how data brokerage laws
               | work. Flock doesn't own the data they're providing access
               | to, and they're providing that sharing access with the (
               | _avid!_ ) consent of their customers.
        
               | snowwrestler wrote:
               | You're getting mixed up about commercial use and personal
               | information.
        
               | tadfisher wrote:
               | Well, it matters if the photographer is the government
               | (or contracted by the government, or subpoenaed by the
               | government): see _Chatrie v. United States_ [0]. The
               | Fourth Amendment exists, and it remains to be tested
               | whether querying massive surveillance networks is a
               | "reasonable" search.
               | 
               | [0]: https://www.scotusblog.com/cases/case-files/chatrie-
               | v-united...
        
               | snowwrestler wrote:
               | True but the Fourth Amendment doesn't rely on the CCPA
               | for authority!
        
             | tptacek wrote:
             | I think you're going to find that you're wrong about this,
             | and that you're not going to get anywhere targeting Flock
             | in particular, as opposed to the owners of Flock cameras.
             | Consider that California has had multiple rounds of
             | legislation about red light camera legislation, including
             | new limitations on it, and all of those cameras are also
             | from commercial providers collecting your PII. Your
             | argument proves too much.
             | 
             | You're going to get a lot of cheerleading and support about
             | this in venues like HN and Reddit, because you're
             | narrowcasting to an audience already primed to be
             | hyperconcerned about surveillance technology (I am too). I
             | think you're going to find those attitudes do not in fact
             | generalize to the public at large, and especially not to
             | the legal system.
             | 
             | Best of luck either way. It'll be an interesting experience
             | to write up, and I'm happy to read about the outcome, even
             | if I do think it's highly predictable.
        
               | john_strinlai wrote:
               | > _you 're not going to get anywhere targeting Flock in
               | particular, as opposed to the owners of Flock cameras._
               | 
               | fyi, flock owns the cameras.
               | 
               | " _We operate using a lease model. What does that mean?
               | Since we own the hardware, we own the problems that
               | occur._ "
        
               | kstrauser wrote:
               | FWIW, I just did this as an experiment and turned it into
               | a blog post afterward. I didn't really set out with an
               | agenda or a deliberate audience, and I didn't share it
               | here. Don't get me wrong, I'm happy to chat about it! But
               | this ended up here without any special effort on my part.
        
               | tptacek wrote:
               | I know the feeling! My arguments here are positive, not
               | normative. I don't know that I think it would be a worse
               | world if your hypothesis was correct. I'm just reasonably
               | sure it isn't.
        
               | kstrauser wrote:
               | For sure. This is the sort of conversation I'd typically
               | rather be having at a bar with appropriate beverages. If
               | it sounds like I'm arguing, it's because it's the kind of
               | thing I'd debate with my friends for the fun of it.
        
           | mindslight wrote:
           | "Your data" isn't really a well defined term, right?
           | 
           | But yes, data that can be used to track my movements in my
           | vehicle is certainly a type of personally identifiable
           | information. I'd argue there should be some exemptions for
           | individuals operating on a small scale, which I believe the
           | CCPA has (and if we actually got a US GDPR, that it should
           | have). But also that kind of exception shouldn't apply to a
           | camera jointly operated by and backhauling to Ring.
        
           | necovek wrote:
           | I believe you are still the owner of that data, but if you
           | are holding someone's PII -- which time of passage, car model
           | and license plates can be argued to be especially with a
           | fixed location -- according to privacy regulations, they can
           | ask a _business_ to remove it unless they have a legally
           | acceptable reason to keep it (eg. they hit-and-run a parked
           | vehicle).
           | 
           | Now, with you likely not keeping that Ring tied to a business
           | account, how that applies to non-businesses holding PII is a
           | different matter.
        
           | danudey wrote:
           | The laws say that data about you is your data, information
           | about you is your information. No one is saying that you "own
           | the data", but by virtue of the data being personal
           | information about you specificially you are allowed to exert
           | control over that data, such as asking for it to be deleted.
        
             | kasey_junk wrote:
             | That view of data ownership is _highly_ jurisdiction
             | dependent and is not the overwhelming norm in the US.
        
               | captaincrisp wrote:
               | While that's definitely true, in this particular case
               | he's invoking his rights under CCPA.
        
               | tptacek wrote:
               | They're invoking a right they do not in fact have under
               | CCPA. Flock is a service provider under CCPA, and isn't
               | required to respond to their request so long as they're
               | operating under the terms of their contract with the
               | municipality (which is, in turn, exempt from CCPA.)
        
         | mindslight wrote:
         | Isn't this just the routine fascist playbook at this point?
         | Start by declaring that the law doesn't even apply to them, on
         | whatever flimsiest of bases.
         | 
         | Personally I would really like to see torts for attorneys who
         | willfully promulgate blatantly incorrect legal interpretations
         | - they're effectively providing incorrect legal advice. A non-
         | attorney is likely to believe such advice coming from a member
         | of the Bar, and the net goal is to discourage the target from
         | seeking further legal advice.
        
           | SoftTalker wrote:
           | An attorney whom you have not engaged in counsel is not
           | providing legal advice.
        
             | mindslight wrote:
             | I'm well aware of how it's currently legally defined -
             | hence "effectively". My comment is in the context of _what
             | ought_ , not _what is_.
        
         | snowwrestler wrote:
         | It's not clear to me that it is actually your data. If I take a
         | picture of you in a public place, I own the picture, not you.
         | 
         | But maybe I am unclear on how Flock works.
        
           | bjt wrote:
           | Setting aside Flock, the "ownership" situation is not as
           | clear as you say above.
           | 
           | What you own is the image copyright. But the right to copy is
           | only one of the rights at issue.
           | 
           | Under various state laws (California in particular), you
           | might not be entitled to do all the things with that picture
           | that you could do of one that doesn't have my likeness.
           | Privacy laws like the CCPA are one possible carve-out. A
           | "right of publicity" is another.
           | 
           | There's an old saying about property law that "property is a
           | bundle of sticks". The bundle can be subdivided.
           | 
           | https://www.law.cornell.edu/wex/publicity
        
           | pksebben wrote:
           | Isn't flock's whole thing that they extract information from
           | the pictures they have?
           | 
           | Like, say I have an interview in your office and you step out
           | for coffee. I take a picture of the applicant list on your
           | desk. That doesn't make the list of applicants "my data".
        
             | lotsofpulp wrote:
             | >I take a picture of the applicant list on your desk. That
             | doesn't make the list of applicants "my data".
             | 
             | If the list is sitting there out in the open, then yes, it
             | does make it your data.
        
               | throwway120385 wrote:
               | Well, maybe not. A reasonable person might not think that
               | about that applicant list. I bet you could make a
               | different argument for taking a picture versus memorizing
               | the list too.
               | 
               | The legal system thrives on specifics of a situation, so
               | simply asserting that the list of applicants is or is not
               | "yours" because you can see it seems like a gross
               | oversimplification. The specifics of how you came to be
               | there, what your relationship with the officeholder is,
               | and so on probably matters a lot in that situation and I
               | think there might be some unwritten rules or social norms
               | that you'd be expected to follow as well.
        
           | throwway120385 wrote:
           | You also might not be considered a commercial entity under
           | the law. It's a bit more nuanced and the words written in a
           | particular statute have to be interpreted together. So
           | statements about "commercial entities" have to be limited to
           | such entities even if we'd really like to be able to go to
           | our neighbor's house and ask them to delete all of the
           | surveillance they have of our cars driving up and down the
           | street in front of their house. I think these laws are often
           | narrowly written to avoid unintended consequences like de-
           | facto banning private operation of surveillance systems on
           | private property.
        
         | goodluckchuck wrote:
         | The CCPA clearly violates the 1st Amendment. If you're out in
         | public, then people are allowed to see you, to remember it, to
         | communicate that it happened, etc.
        
         | necovek wrote:
         | This answer is relevant:
         | https://oag.ca.gov/privacy/ccpa#collapse6d
         | 
         | In short, Flock is a "service provider" and not the entity
         | doing the recording.
         | 
         | Perhaps you can make a case that they are a "data broker"
         | instead (https://oag.ca.gov/privacy/ccpa#collapse1i), but that
         | is a separate law, and what you are really looking at is a
         | combination of license plate, time and location being collected
         | as data being collected and sold without your consent.
         | 
         | Obviously, I am not a lawyer (and not even US-based), but I
         | like when privacy is respected :)
        
         | zbrozek wrote:
         | I tried the same, got a similar response, and complained to the
         | AG. Nothing.
        
         | wakamoleguy wrote:
         | The data ownership is really interesting, as many threads here
         | are going into. I wonder if it's possible to sidestep that
         | entirely, though! Under the CCPA, "personal information" is
         | defined as information that identifies, relates to, describes,
         | is reasonably capable of being associated with, or could
         | reasonably be linked -- directly or indirectly -- with a
         | particular consumer or household. That says nothing about
         | ownership.
         | 
         | To the extent that Flock is only storing the data on behalf of
         | their customers, I'd understand they wouldn't be required to
         | delete it. But to the extent that they are indexing it,
         | deriving from it, aggregating it across customers, and sharing
         | it via their platform, it seems they should be required to
         | remove that data from those services.
         | 
         | But then again, I am not a lawyer!
        
         | tgsovlerkhgsel wrote:
         | Under GDPR, I believe that would be accurate. I _think_ CCPA
         | was to some extent inspired by GDPR so I wouldn 't be surprised
         | if they copied this point too.
         | 
         | Which, hilariously, means that under GDPR, you only need to
         | contact the web site, and _they_ have to go talk to their 1207
         | partners that value your privacy to fulfill your request (I 'm
         | sure that in practice they'll say "sorry it's all 'anonymous'
         | so we can't" or "we can't be sure that it's you even though you
         | provided the identifier from your cookies"). I'm really
         | disappointed that NOYB hasn't started going after web sites
         | like that - that's quickly put a damper on the whole web
         | surveillance economy.
        
         | charcircuit wrote:
         | >It's my data, not their customers'.
         | 
         | Just because data is about you, that doesn't mean it is your
         | data.
        
           | john_strinlai wrote:
           | you may be minunderstanding the california consumer privacy
           | act (ccpa). in the ccpa, personal data is defined as:
           | 
           |  _" Personal information is information that identifies,
           | relates to, or could reasonably be linked with you or your
           | household."_
           | 
           | and, you _do_ have the rights set forth in the ccpa (know,
           | delete, correct, limit exposure, etc.) regarding that data.
        
         | lmkg wrote:
         | > which seems to directly oppose the CCPA.
         | 
         | I have some background in data privacy compliance.
         | 
         | It sounds like they are claiming to be a Service Provider under
         | CCPA, which is similar to a Processor under GDPR. Long story
         | short, a Controller is the one legally responsible for ensuring
         | the rights of the data subject, and a service
         | provider/processor is a "dumb pipe" for a Controller that does
         | what they're told. So IF they are actually a Service Provider,
         | they're correct that the legal responsibility for CCPA belongs
         | to their customers and not them.
         | 
         | That's a big IF, though.
         | 
         | Being a Processor/Service Providor means trade-offs. The data
         | you collect isn't yours, you're not allowed to benefit from it.
         | If Flock aggregates data from one customer and sells that
         | aggregate to a different customer, they're no longer just a
         | service provider. They're using data for their own purposes,
         | and cannot claim to be "just" a service provider.
        
         | jsw97 wrote:
         | You might reach out to the California AG. I suspect they are
         | itching for this kind of thing right now.
        
           | kstrauser wrote:
           | Because life is weird, my kid played little league baseball
           | against his.
           | 
           | I might have to do that.
        
         | AlBugdy wrote:
         | Read a few of your posts. Just wanted to comment on how I like
         | your to-the-point succinct style and how you care about
         | privacy. :)
         | 
         | As a suggestion, I saw you have RSS:
         | 
         | https://honeypot.net/feed.xml
         | 
         | I didn't see it mentioned in the main page or About or Archive.
         | Maybe add it to a more visible place?
        
           | kstrauser wrote:
           | Aww, thanks! I appreciate that.
           | 
           | And that's a good point. I'll look at that when I get home.
        
       | barelysapient wrote:
       | If that's a valid excuse than the CCPA isn't worth the paper its
       | written on.
        
         | dylan604 wrote:
         | The rule of any documentation is that it is out of date as soon
         | as the ink is dry. By the time a regulation is enacted,
         | workarounds/loopholes have already been found (if not
         | intentionally worked into it).
        
         | ldoughty wrote:
         | I would argue that the request was invalid in the first place.
         | 
         | If I see a flash on a speed camera operated by a business on
         | behalf of a police department, your argument states I should be
         | able to use CCPA to force the business to delete my picture and
         | the record of me speeding If I can get the request to them
         | before the police can file with the court and request that data
         | as evidence.
         | 
         | The data belongs to the government, and you can't get around
         | that right by going to business that holds the data and asking
         | them to delete it.
        
           | inetknght wrote:
           | > _If I see a flash on a speed camera operated by a business
           | on behalf of a police department, your argument states I
           | should be able to use CCPA to force the business to delete my
           | picture and the record of me speeding If I can get the
           | request to them before the police can file with the court and
           | request that data as evidence._
           | 
           | Sounds reasonable to me. If the police want to put up a
           | camera, then the police should put up a camera.
           | 
           | Offloading their legal responsibilities to a third party
           | company is shitty.
        
             | SoftTalker wrote:
             | So police departments should have to develop and host all
             | their administrative software also? I think we can all see
             | why that would be a terrible idea. Police are like any
             | other government agency or business in that they contract
             | with the private sector for a variety of services that are
             | not in their area of expertise.
        
               | inetknght wrote:
               | > _So police departments should have to develop and host
               | all their administrative software also?_
               | 
               | Yes. We're in an high technology and information age.
               | Police should be well-versed and capable of understanding
               | the technologies and informations that people use.
               | 
               | > _I think we can all see why that would be a terrible
               | idea._
               | 
               | I don't.
               | 
               | > _Police are like any other government agency or
               | business in that they contract with the private sector
               | for a variety of services that are not in their area of
               | expertise._
               | 
               | Why shouldn't police (or some law enforcement agency) be
               | capable of operating and maintaining law enforcement
               | technologies?
        
             | stephbook wrote:
             | "Hey private prison please delete all data you have about
             | me. And by the way, I'm locked up here by accident. Please
             | release me."
        
               | jakeydus wrote:
               | Honestly private prisons are a farce anyways, so yeah
               | this seems valid to me. The government doesn't get to get
               | out of its obligations to citizens by outsourcing to
               | third parties, and third parties don't get to wield
               | government-level authority without government-level
               | accountability.
        
           | barelysapient wrote:
           | But we're not talking about speed cameras or a private entity
           | with exclusive contract with the police to provide traffic
           | enforcement.
           | 
           | We're talking about Flock. A company offering surveillance as
           | a service. Per their website:
           | 
           | >Trusted by over 12,000 public safety customers including
           | cities, towns, counties, and business partners.
           | 
           | If Flock's argument holds then most of the CCPA be
           | circumvented this same way. All it takes is a few entities
           | and clever contract language.
        
           | TheRealPomax wrote:
           | Except the data does NOT belong to the government, that's the
           | whole point of Flock operating the way it does. It's not
           | governmental data collection it's data collection by a
           | _private_ company that is then _made available_ to the
           | government upon request. And yeah: it is _literally_ allowed
           | to delete data, because again: it 's not a government agency,
           | it's _just_ private data, collected by a private company,
           | with the exact same status as you recording an public
           | intersection with a camera from your window.
        
       | ranger_danger wrote:
       | To me this sounds like the equivalent of visiting a website that
       | sells your data, and then asking AWS to delete your personal data
       | when it actually belongs to a customer of theirs and only resides
       | within their private storage.
       | 
       | Would you ask your local ISP to delete data they provided to
       | Tinder like your IP address? That doesn't make sense to me.
        
         | terrabitz wrote:
         | Yeah I was getting the same feeling. I wonder if an equivalent
         | request to California police agencies that contract Flock
         | technologies would work though.
        
           | OkayPhysicist wrote:
           | Probably not, as the law enforcement agencies get a bunch of
           | exceptions to the CCPA.
        
         | monooso wrote:
         | As I understand it, the author wrote to Flock as they are the
         | entity collecting the PII. Your analogy would only make sense
         | if the author had written to Flock's customers (and even then
         | it's a rather strained comparison).
        
           | ranger_danger wrote:
           | > they are the entity collecting the PII
           | 
           | I'm not convinced this is the case. It might be equipment
           | made by them, but does that necessarily mean they were ever
           | even in possession of the data in question?
           | 
           | Would you ask the manufacturer of your oven what you ate for
           | dinner last week? No, you're just using an appliance that
           | they made.
           | 
           | In the case of Flock I don't think we have any evidence of
           | whether Flock themselves ever hold or store any data produced
           | by their devices when operated by a customer.
        
         | alt227 wrote:
         | Yes, I have asked multiple companies to destroy my data under
         | GDPR. Its quite common in Europe.
        
       | ldoughty wrote:
       | I think you're going to have a hard time with this...
       | 
       | Flock seems to leave the data in ownership of the government.
       | They are just providing the service of being custodians for
       | storing and accessing that data.
       | 
       | You probably would get a similar response by submitting your
       | request to Amazon web services or Google cloud or whoever has
       | Flocks data: "sorry, we're just holding the data on behalf of
       | Flock"
       | 
       | In either my example case or your stated case, you would have a
       | very hard time convincing the host business to destroy their
       | customers data without a court order or court case that shows
       | their policy is invalid and they must comply.
       | 
       | Not a lawyer, just noting the parallel.
       | 
       | I do appreciate that Flock's response says that they cannot use
       | the data they've collected for other purposes.. which further
       | reinforces my cloud storage analogy -- the cloud vendor can't
       | look at your data you upload to storage to e.g. build profiles on
       | you/your business.
        
         | Barbing wrote:
         | > the cloud vendor can't look at your data you upload to
         | storage to e.g. build profiles on you/your business.
         | 
         | Would our main check on this be whistleblowers?
        
       | calmbonsai wrote:
       | Per my understanding of the law for these sorts of data
       | collectors, at least in the U.S., you need to contact the local
       | municipalities (Flock's customers) for this redaction and the
       | jurisprudence is governed at the state and municipal level.
       | 
       | The best source of this information is https://deflock.org/ .
       | FWIW, this is run by a neighbor in Boulder, CO which has been
       | wrestling with the use of these cameras.
        
         | cousinbryce wrote:
         | Automating requests to every municipality sure would be fun
        
       | nekusar wrote:
       | The only opt-out the citizenry has is with any of the following:
       | 2x4         rebar         spraypaint         spray foam
       | battery powered metal cutter
       | 
       | And bash those pieces of shit to chunks or completely ruin the
       | lens and solar.
       | 
       | Republican community? They love corporate surveillance. Democrat
       | community? They too love corporate surveillance.
       | 
       | There is no "Peoples' Party" that rejects this garbage.
        
         | MengerSponge wrote:
         | https://www.techspot.com/news/108045-lidar-great-cars-but-ca...
         | 
         | It would be a pity if someone made dense point clouds of these
         | devices.
        
           | maccam912 wrote:
           | One could start doing tours of their city to show tourists
           | where each and every camera is. They're kinda small though,
           | it might be worth a strong laser pointer so you can direct
           | their attention to the cameras easily...
        
         | pugworthy wrote:
         | All materials available at major home improvement centers -
         | which happen to be very popular Flock camera locations.
        
       | empathy_m wrote:
       | I noticed that the company is glossed as "Flock" and not "Flock
       | Safety (YC S17)" in posts like this and last week's "US cities
       | are axing Flock Safety surveillance technology",
       | https://news.ycombinator.com/item?id=47689237.
       | 
       | Did YC house style change a while back to drop the "(YC xxx)"
       | annotation since so many popular firms particpate / or because
       | it's well known?
        
         | mikey_p wrote:
         | Who know, maybe they're trying to distance themselves from the
         | privacy disaster, but I doubt anyone at YC or HN is smart
         | enough to read the room on Flock.
        
           | bix6 wrote:
           | Which room? The one paying them millions to spy on people?
           | Cash Rules Everything Around Me.
        
         | tptacek wrote:
         | I see less of it now across the board but note that this
         | headline was almost certainly created by the story's submitter;
         | it's not like there's an automated process to apply the label.
        
       | kube-system wrote:
       | I don't think they need your permission to use ALPR on your
       | publicly displayed license plate.
       | 
       | > (2) (A) "Personal information" does not include publicly
       | available information [...]
       | 
       | > (B) (i) For purposes of this paragraph, "publicly available"
       | means any of the following:
       | 
       | > (I) Information that is lawfully made available from federal,
       | state, or local government records.
       | 
       | > (II) Information that a business has a reasonable basis to
       | believe is lawfully made available to the general public by the
       | consumer
        
         | _moof wrote:
         | The information being collected isn't your license plate, it's
         | your location. (Still might not be personal information.)
        
       | wcv wrote:
       | Flock has stonewalled with the "we are not the controllers"
       | excuse here in MN too. We have similar rights to opt-out and
       | delete under the MCDPA [0].
       | 
       | [0] https://ag.state.mn.us/Data-Privacy/Consumer/
        
         | tptacek wrote:
         | They're not stonewalling; they're following the law. Their
         | state and municipal customers would not want them honoring
         | these requests!
        
       | deepsun wrote:
       | If Flock collects and processes PII data, then all their
       | customers are "subprocessors". Flock should really have a Data
       | Processing Agreement with their subprocessors, to legally ensure
       | they follow the same PII handling controls as Flock does.
       | 
       | For example, if Flock receives a legitimate request to delete
       | some data, then Flock must forward that request to all their Data
       | Processors (e.g. including AWS/GCP/Cloudflare) and they must
       | delete it as well.
        
         | Aaargh20318 wrote:
         | It's the other way around. Flock is the subprocessor for
         | whoever hired them to collect data. If they are collecting data
         | on behalf a city or municipality, those are the entities you
         | need to address.
        
       | mmmlinux wrote:
       | Lot of Flock Defenders in here.
        
         | pwython wrote:
         | Not Flock defenders, just people explaining how this is not a
         | CCPA violation. I could set up 100 cameras around town (with
         | property owners permission) and record cars driving by, birds,
         | etc all day. Then I could sell access to that footage to
         | whoever I want. If they want to scrape license plates that's up
         | to the customer and their problem. Or if they want to track
         | birds, cool, that could be in the frame too.
        
           | kstrauser wrote:
           | It gets a little weird when you explicitly market them for a
           | purpose, though. Flock doesn't advertise a fleet of cameras
           | suitable for birdwatching or other random activities. They
           | market them specifically for the collection and processing of
           | PII.
           | 
           | By analogy, Google Docs isn't marketed for healthcare use. If
           | you wanted, you could put a bunch of PHI in a Google doc and
           | it wouldn't be their responsibility. They certainly didn't
           | tell you to do that. However, if they marketed Google Docs as
           | a great place to store PHI, yeah, then suddenly they're on
           | the hook for complying with the relevant laws like HIPAA.
           | 
           | (Although in this case Google _will_ sign a HIPAA business
           | associate agreement with you and voluntarily agree to comply.
           | They still don 't market it that way, or at least don't
           | predominantly do so.)
        
       | annoyingnoob wrote:
       | I've had the same kind of response from Email providers like
       | Sendgrid, they claim its not their data. There is no way to have
       | Sendgrid block you in their entire network, you have to play
       | whack-a-mole with their customers. Seems like a flaw in these
       | privacy laws when you can't ask the actual record holder to
       | remove the records.
        
       | hmokiguess wrote:
       | https://www.flocksafety.com/legal/lpr-policy
       | 
       | > In accordance with its Terms and Conditions, Flock Safety may
       | access, use, preserve and/or disclose the LPR data to law
       | enforcement authorities, government officials, and/or third
       | parties, if legally required to do so or if Flock has a good
       | faith belief that such access, use, preservation or disclosure is
       | reasonably necessary to comply with a legal process, enforce the
       | agreement between Flock and the customer, or detect, prevent or
       | otherwise address security, privacy, fraud or technical issues.
       | Additionally, Flock uses a fraction of LPR images (less than one
       | percent), which are stripped of all metadata and identifying
       | information, solely for the purpose of improving Flock Services
       | through machine learning.
       | 
       | In this document, to which they linked in their reply, it says
       | clearly "address ... privacy ... issues."
       | 
       | Does your case not constitute a privacy issue? I would say so.
       | 
       | Continuing down below, their claim on "Trust Us" about how they
       | employ machine learning would need some proper transparency into
       | how can that be guaranteed.
        
         | FireBeyond wrote:
         | > Continuing down below, their claim on "Trust Us" about how
         | they employ machine learning would need some proper
         | transparency into how can that be guaranteed.
         | 
         | Wait til you see their "Transparency Portal" which, if my
         | County and neighboring can be used as a sample size, doesn't
         | even name at least 30% of agencies using Flock.
        
       | _moof wrote:
       | They seem to be implying that because they are a "service
       | provider," they aren't responsible for complying with CCPA rules
       | even though they are the ones with the data.
       | 
       | Does this hold water? I'm reading the CCPA rules now but if
       | anyone knows, it would save me some tedious research.
        
         | ezfe wrote:
         | I guess if one likens it to AWS S3 holding your data on behalf
         | of Apple it makes sense
        
       | pugworthy wrote:
       | An interesting quandary here is that they'd need to constantly
       | scan for you and your vehicle, etc. so that they could know it
       | was you then delete you. So to ensure they don't observe you,
       | they need to observe you.
        
       | rdiddly wrote:
       | Flock's customers own the data the same way Uber drivers are
       | independent contractors, i.e. it's designed for weaseling out of
       | obligations.
        
       | lacker wrote:
       | Isn't that how it should work?
       | 
       | If you write the police and ask them to delete all their data
       | about you, that isn't a thing that they do. It shouldn't matter
       | if the police store their data on AWS or their own servers.
       | 
       | Flock is a tool used by the police so it should work the same
       | way.
        
         | nerevarthelame wrote:
         | You're right are exemptions for both GDPR [0] and the CCPA [1]
         | where organizations aren't obligated to comply with erasure
         | requests if it would limit their ability to prevent or
         | investigate crimes, fraud, or similar matters.
         | 
         | But that's not what Flock is claiming. They're claiming that
         | they don't even have to consider the request because they don't
         | own the data.
         | 
         | [0] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-
         | re...
         | 
         | [1] https://www.clarip.com/data-privacy/ccpa-erasure-
         | exemptions/
        
       | dsr_ wrote:
       | Remember that the difference between "Flock can do whatever the
       | hell it wants" and "Flock is required to delete your data at your
       | request" is a law. Citizens vote for legislators. If you want
       | this to be a higher priority for your legislators, buy them off.
       | 
       | Or vote for/against them, that might work too.
        
         | joquarky wrote:
         | Reminds me of this article from a while back:
         | 
         | https://theonion.com/american-people-hire-high-powered-lobby...
        
       | cold_tom wrote:
       | Feels like a classic "we're just the processor" answer But in
       | reality you have no way to find or contact whoever actually
       | controls the data, so it doesn't really help. Kind of shows the
       | gap between how the law works on paper vs how these systems work
       | in practice.
        
       | sklargh wrote:
       | The concept of what constitutes a sale under CCPA is pretty
       | expansive. An exchange of value can be a sale that occurs outside
       | of a processing relationship. I'd say their note is inaccurate.
        
       | carabiner wrote:
       | It's not much worse than all the tracking adtech used by FAANG
       | industry. Smartest people in the world working on these systems.
        
         | kstrauser wrote:
         | I'd contend that it absolutely is. Adtech is creepy and
         | invasive and weird. Flock is going a step further and actively
         | tracking our movement through the cities where we live.
         | 
         | I don't like either of those activities, but I think one of
         | them is much worse.
        
           | jakeydus wrote:
           | One is making implicit assumptions based on data available to
           | it. The other is literally saying "hey they're right here at
           | this time". At least adtech has _some_ level of obfuscation
           | to it.
           | 
           | But I'm with you both suck.
        
       | rbbydotdev wrote:
       | it would be nice if flock did not and could not exist
        
       | atmosx wrote:
       | Back in 2018, CloudFormation data leaked through a public gist
       | (misconfigured gist plugin, I thought the gist was private but it
       | wasn't... I had change the default config) and showed up on an
       | obscure website being served via CloudFlare. When I contacted CF,
       | they claimed they couldn't remove the cached content because
       | their system "doesn't work like that". I pushed back and then
       | they said that they're not responsible for the content and that I
       | should send another email to abuse@cf... to get data about the
       | hosting provider and deal with the content provider (e.g. VPS,
       | ISP, whatever). After a few back and forth msgs, I made it clear
       | that if the data wasn't taken down within a week or so, I would
       | escalate the issue to the local and German GDPR authority (see
       | https://www.ombudsman.europa.eu/en/european-network-of-ombud...).
       | 
       | And what do you know? I got not reply, but the content
       | disappeared in ~48hrs.
        
       | gguncth wrote:
       | It's fascinating how America could completely get rid of Flock
       | cameras by sending criminals to prison and leaving them there,
       | but we won't do that so we have these endless arguments about
       | these cameras.
        
         | AlotOfReading wrote:
         | I'm trying to understand the argument here. Are you saying that
         | never releasing convicted criminals would _completely_
         | eliminate crime?
         | 
         | That doesn't seem correct, even leaving aside the obvious moral
         | issues with that.
        
           | kstrauser wrote:
           | My interpretation was that they were saying Flock were
           | criminals who should be sent away for good. I don't know if
           | that's right but it would be consistent that way.
        
             | AlotOfReading wrote:
             | That makes much more sense, yeah.
        
       | pext wrote:
       | This reminds me of the Andrew Yang's "Data Dividend" project that
       | ideally would have paid end users for their data rather than
       | knowingly giving it aware for free. IMO, it was a great idea but
       | flawed execution against all the lobbying.
        
       | thangalin wrote:
       | Sent to Benn Jordan:
       | 
       | https://i.ibb.co/WWWYznHX/flock-future.png
       | 
       | See also a poster from IBM's German subsidiary, circa 1934. The
       | approximate translation: "See everything with Hollerith punch
       | cards."
       | 
       | https://www.clevelandjewishnews.com/opinion/op-eds/new-detai...
        
       ___________________________________________________________________
       (page generated 2026-04-14 23:00 UTC)