Back to campaign

Corporate misuse or mishandling of private data

A directory of surveillance providers, data brokers, cloud platforms, and federal contractors.

36unique companies
3functional tiers
14sourced public records

Who's on our watchlist?

We track companies whose products, data practices, or government-facing services warrant scrutiny under the proposed acts. A place on this watchlist is not a finding of wrongdoing, and it does not mean that every contract, product, or deployment would be covered.

Surveillance Company Supply Chain Directory

15companies shown
Tier 1

Axon Enterprise

Both acts — very high

Axon Fusus integrates public and private camera feeds, ALPR, geolocation, gunshot alerts, CAD, live video, and real-time crime-center operations. Axon Lightpost adds fixed-position ALPR and live streaming.

Review documented public record
Tier 1

Motorola Solutions

Both acts — very high

Vigilant and VehicleManager support plate searches, vehicle location history, multi-location analysis, nationwide scan databases, video integration, and investigative workflows.

Tier 1

Peregrine Technologies

Both acts — very high

Unifies historical police records and live sensor feeds for real-time crime centers, investigations, people/place/event analysis, interagency sharing, and operational decisions.

Tier 1

Rekor Systems

Both acts — high

Rekor Scout and the Rekor Public Safety Network provide cloud or on-premise ALPR, vehicle recognition, searchable historical records, hotlist alerts, and law-enforcement networking.

Tier 1

Genetec

Both acts — high

AutoVu and Cloudrunner provide fixed and mobile ALPR, vehicle tracking, collaborative data sharing, and unified city-wide video, emergency-response, and investigative systems.

Tier 1

BriefCam / Milestone Systems

Both acts — high

Converts surveillance video into searchable metadata, retrospective person and vehicle searches, behavioral filters, alerts, and city-wide analytics for police and real-time crime centers. BriefCam is now presented within Milestone Systems' portfolio.

Tier 1

Skydio

Both acts — high

Drone-as-First-Responder systems provide persistent or incident-triggered live aerial intelligence directly to officers and real-time crime centers, sometimes before officers arrive.

Tier 1

DataWorks Plus

Both acts — high

Supplies law-enforcement facial recognition, fingerprint, iris, mugshot, mobile rapid-identification, and database-matching systems.

Tier 1

NEC

Both acts — high

Markets face-recognition and biometric systems for crime investigation, public safety, border control, airports, and government identification.

Tier 1

ZeroEyes

Both acts — medium/high

Applies AI and human review to continuously monitored camera feeds to detect visible firearms and alert authorities. It is less identity-oriented than ALPR or facial recognition but fits observational and automated-alert provisions.

Current controversies and public records for surveillance businesses

This is a selected, non-exhaustive record. Each entry identifies the source type and states relevant limits because findings, settlements, audits, allegations, and criticism are not interchangeable.

City disclosureMarch 2026

Flock Safety

Vendor configuration allowed unauthorized out-of-state queries

The City of Ventura said a Flock configuration error allowed two out-of-state agencies to query a system that the city had restricted to California agencies.

Context and limits

The city reported that no federal agency accessed the system and said it could not determine whether vehicle data was returned. Flock later implemented additional safeguards.

City of Ventura
Court-approved settlementMay 2022

Clearview AI

Consent order restricted access to the faceprint database

A court-approved settlement in ACLU v. Clearview AI permanently barred the company from making its faceprint database available to most private entities nationwide.

Context and limits

The case alleged violations of the Illinois Biometric Information Privacy Act. It ended by consent order, not a trial judgment on every allegation.

ACLU case record and consent order
Official auditAugust 2021

SoundThinking

Chicago watchdog found limited documented results from ShotSpotter alerts

Chicago’s Office of Inspector General found evidence of a gun-related criminal offense in 9.1% of the police responses with a recorded disposition in its review period.

Context and limits

The report examined police outcomes, not the acoustic accuracy of every alert. SoundThinking and supporters have disputed broader claims that the technology is ineffective.

Chicago Office of Inspector General
FTC final orderJanuary 2025

Venntel / Gravy Analytics

Federal order restricted sale and use of sensitive location data

The FTC finalized an order addressing the collection, use, and sale of sensitive location information, including data associated with health-related locations and places of worship.

Context and limits

The order followed an FTC complaint alleging collection and use without verifiable consent for commercial and government uses, with limited exceptions in the final order.

Federal Trade Commission
FTC challenge2020-2023

Axon Enterprise

Regulator challenged the completed VieVu body-camera acquisition

The FTC alleged that Axon’s acquisition of VieVu reduced competition for body-camera systems sold to large metropolitan police departments.

Context and limits

Safariland separately settled claims about related agreements. The FTC withdrew its adjudication against Axon in 2023 after procedural litigation, so the challenge did not produce a final merits ruling against Axon.

Federal Trade Commission matter docket
Federal security reviewApril 2024

Microsoft

Cyber Safety Review Board examined the 2023 Exchange Online intrusion

The federal review detailed operational and strategic decisions that contributed to a compromise affecting government email accounts and issued security recommendations.

Context and limits

This record concerns cloud security and stewardship risk, not surveillance-product misconduct. It matters here because GISA assigns continuing duties around sensitive government information held in contractor systems.

Cybersecurity and Infrastructure Security Agency
Civil settlementJuly 2023

Booz Allen Hamilton

Company paid $377.45 million to resolve federal billing allegations

The Justice Department said Booz Allen agreed to resolve allegations that commercial and international costs were improperly charged to government contracts and subcontracts.

Context and limits

The settlement agreement states that Booz Allen denied the allegations and that the compromise was not an admission of liability.

U.S. Department of Justice
DOJ OIG auditMarch 2022

IDEMIA Public Security

FBI biometric algorithm purchase lacked required safeguards and documentation

The Justice Department Inspector General found that the FBI’s $87.5 million-ceiling IDEMIA purchase was rushed, used an improper noncompetitive procurement method, and omitted clauses addressing accountability, privacy, and other risks.

Context and limits

The audit focused on the FBI’s acquisition and contract administration. It reported no questioned costs and did not find that IDEMIA violated the law.

Department of Justice Office of Inspector General
Labor consent decreeApril 2017

Palantir Technologies

Federal contractor resolved systemic hiring-discrimination charges

The Department of Labor entered a consent decree resolving allegations that Palantir discriminated against Asian applicants for engineering positions.

Context and limits

The decree required $1.66 million in back wages and other relief plus job offers to eight eligible applicants. This employment matter does not concern the operation of Palantir’s data platforms.

U.S. Department of Labor
State privacy settlementSeptember 2023

Google Cloud / Google Public Sector

Google agreed to a $93 million location-privacy settlement

California resolved allegations that Google collected, stored, and used consumer location data for profiling and advertising without informed consent.

Context and limits

The stipulated judgment addressed consumer location settings and advertising practices at Google. It was not a finding about Google Cloud or a government-cloud deployment.

California Department of Justice
SEC settled chargesSeptember 2022

Oracle

Oracle paid more than $23 million to resolve FCPA charges

The SEC said Oracle subsidiaries in Turkey, the United Arab Emirates, and India created and used off-book funds in connection with business involving foreign officials.

Context and limits

This is a corporate anti-bribery and internal-controls record, not a finding about Oracle’s U.S. government cloud or its handling of government information.

U.S. Securities and Exchange Commission
Civil settlementJune 2019

IBM

IBM paid $14.8 million over health-exchange procurement allegations

IBM and Cúram Software resolved allegations that they made material misrepresentations about software development, functionality, and integration during Maryland’s health-exchange contract process.

Context and limits

Maryland later replaced the platform after launch problems. The settlement resolved allegations only and did not determine liability; it does not concern IBM’s current federal AI offerings.

U.S. Department of Justice
Civil settlementJanuary 2018

Accenture Federal Services

Accenture Federal Services settled government-contract overcharges

Accenture Federal Services paid approximately $1.74 million to settle overcharges on a General Services Administration schedule contract caused by unauthorized subcontractor purchases.

Context and limits

Accenture disclosed the issue after an internal investigation and assisted the government. The civil claims were allegations only, with no determination of liability.

U.S. Attorney’s Office, Eastern District of Virginia
Civil settlementOctober 2014

Leidos

Leidos predecessor resolved organizational-conflict allegations

The Justice Department announced a $1.5 million settlement with SAIC, identified in the release as then known as Leidos Holdings, over alleged undisclosed conflicts on Nuclear Regulatory Commission work.

Context and limits

The underlying conduct dated from 1992 through 2000. The False Claims Act claims were allegations only, and the settlement made no liability determination.

U.S. Department of Justice

Private data stewardship failures

Eighteen case studies document how sensitive consumer information can be exposed, repurposed, transferred, or retained. This companion research is broader than the company tiers above and does not claim that every case falls under the proposed acts.

Read the full report31 pages, research current through July 25, 2026
18case studies
8failure categories
12recurring patterns

How data enters the market

Private information begins inside ordinary services, safety tools, and background collection. People usually evaluate the immediate service, not the downstream market.

What happens inside the market

Commercial value grows when information can be reused, combined, copied, and transferred. These activities can occur together or independently.

How harm reaches people

Organizations capture the value of collection and reuse. The people described by the data bear consequences that are difficult to prevent, measure, or reverse.

Commercial data becomes public power

Location and identity information collected in consumer markets can become available for law-enforcement, national-security, or other government use.

Stewardship failures by category

Category assignments are editorial classifications from the report. They support comparison and do not establish statutory liability.

18case studies
Regulatory findings and bankruptcy transaction2023-2025

23andMe

Security failureAcquisition riskBankruptcy risk
Data at issue

Genetic data, health reports, ancestry information, relatives, family trees, and demographic attributes.

A credential-stuffing campaign reached a limited group of accounts, while connected relatives and family features expanded the exposure to almost seven million people worldwide. The company entered Chapter 11 in March 2025.

Outcome

The UK ICO imposed a GBP 2.31 million penalty. Canadian and UK regulators addressed bankruptcy protections before TTAM Research Institute completed the acquisition.

UK Information Commissioner
FTC final order2023

1Health.io / Vitagene

Security failureBroken privacy promisePurpose expansionDerived-data retention
Data at issue

DNA test results, genetic and health information, customer identities, and biological samples.

The FTC alleged that the company left unencrypted genetic and health data in publicly accessible cloud storage, changed its privacy policy retroactively, and failed to honor deletion commitments.

Outcome

The final order required a privacy and security program, deletion or destruction obligations, limits on retroactive policy changes, and $75,000 for consumer refunds.

Federal Trade Commission
FTC final order2024

Avast / Jumpshot

Broken privacy promisePurpose expansionCommercial sharingDerived-data retention
Data at issue

Granular web-browsing histories collected through antivirus software and browser extensions.

The FTC alleged that Avast promoted protection from tracking while collecting detailed browsing information and transferring it to Jumpshot for sale to more than 100 third parties.

Outcome

Avast agreed to pay $16.5 million. The order banned specified sales and required deletion of transferred browsing data and products or algorithms derived from it.

Federal Trade Commission
FTC final order2023

BetterHelp

Broken privacy promisePurpose expansionCommercial sharing
Data at issue

Email and IP addresses, therapy enrollment, mental-health questionnaire responses, and related information.

The FTC alleged that BetterHelp disclosed health-related identifiers and questionnaire information to advertising platforms despite representations about limited and confidential use.

Outcome

The $7.8 million order banned health-data sharing for advertising and required consent, deletion instructions to recipients, and a retention schedule.

Federal Trade Commission
FTC enforcement settlement2023

GoodRx

Broken privacy promisePurpose expansionCommercial sharing
Data at issue

Prescription medications, health conditions, contact details, device identifiers, and service activity.

The FTC alleged that GoodRx sent prescription and health information to advertising platforms and used customer lists to target medication- and condition-specific advertisements.

Outcome

GoodRx agreed to a $1.5 million civil penalty in the first FTC Health Breach Notification Rule enforcement action, plus advertising and deletion restrictions.

Federal Trade Commission
FTC final order2021

Flo Health

Broken privacy promisePurpose expansionCommercial sharing
Data at issue

Menstrual-cycle, fertility, pregnancy, and other reproductive-health activity recorded through the app.

The FTC alleged that Flo transmitted sensitive app events to marketing and analytics providers after promising to keep users' health information private.

Outcome

The order required affirmative consent, notice to affected users, deletion instructions to third parties, and an independent privacy review.

Federal Trade Commission
Proposed FTC order2024

Cerebral

Security failureBroken privacy promisePurpose expansionCommercial sharing
Data at issue

Mental-health and prescription histories, treatment plans, insurance data, identity documents, and beliefs.

The FTC alleged that tracking technologies disclosed sensitive information to advertising platforms and that the company maintained weak access controls and other security practices.

Outcome

The proposed order included more than $7 million in payments, advertising restrictions, consent and deletion requirements, and a privacy and security program.

Federal Trade Commission
FTC settlement2024

Monument

Broken privacy promisePurpose expansionCommercial sharing
Data at issue

Alcohol-addiction treatment, therapy and medication activity, identifiers, and service interactions.

The FTC alleged that Monument disclosed information capable of revealing that a person sought alcohol-addiction treatment to Meta and Google through advertising technologies.

Outcome

The settlement banned health-data disclosure for advertising and required consent for specified sharing. A $2.5 million civil penalty was suspended based on ability to pay.

Federal Trade Commission
FTC final order2021

Everalbum / Paravision

Broken privacy promisePurpose expansionDerived-data retention
Data at issue

Personal photos and videos, facial embeddings, facial-recognition models, and retained account content.

The FTC alleged that Everalbum misrepresented when facial recognition would be enabled and retained content from deactivated accounts for face-recognition development.

Outcome

The order required express consent and deletion of affected photos, videos, face embeddings, and models or algorithms developed from improperly retained or used data.

Federal Trade Commission
FTC settlement2023

Ring

Security failureBroken privacy promisePurpose expansionAcquisition riskDerived-data retention
Data at issue

Private home-security video, account data, face embeddings, and work products derived from recordings.

The FTC alleged overly broad employee and contractor access, video use for algorithm development without adequate consent, and failures to reduce credential-stuffing attacks.

Outcome

Ring agreed to pay $5.8 million and implement a privacy and security program. The order required deletion of specified videos, embeddings, and derived work products.

Federal Trade Commission
FTC and DOJ settlement2023

Amazon Alexa

Broken privacy promisePurpose expansionDerived-data retention
Data at issue

Voice recordings and transcripts, geolocation, account activity, and algorithm-training material.

The FTC and DOJ alleged that Amazon retained children's Alexa recordings indefinitely by default and failed to remove some transcripts after deletion requests.

Outcome

Amazon agreed to a $25 million civil penalty, revised deletion practices, and limits on using data subject to deletion requests to improve data products.

Federal Trade Commission
FTC and DOJ settlement2022

Twitter (now X)

Broken privacy promisePurpose expansion
Data at issue

Phone numbers and email addresses supplied for account security, authentication, and recovery.

The FTC and DOJ charged Twitter with allowing advertisers to use account-security contact information for targeting from 2014 through 2019.

Outcome

Twitter agreed to a $150 million penalty and restrictions on profiting from deceptively collected security data, with compliance and user-notice obligations.

Federal Trade Commission
FTC orders and settlements2019

Meta / Facebook / Cambridge Analytica

Broken privacy promisePurpose expansionCommercial sharingDerived-data retention
Data at issue

Social profiles, friend networks, app permissions, interests, political profiles, and advertising identifiers.

FTC actions addressed Facebook privacy representations and third-party app access, as well as Cambridge Analytica voter-profiling activity using data collected through an app.

Outcome

Facebook agreed to a $5 billion penalty and a 20-year privacy-governance order. Separate Cambridge Analytica matters imposed deletion and use restrictions.

Federal Trade Commission
Multi-agency settlement2017-2019

Equifax

Security failure
Data at issue

Names, Social Security numbers, birth dates, addresses, credit information, and some identity documents.

The 2017 breach exposed identifiers and credit-related information associated with approximately 147 million people.

Outcome

Equifax agreed to pay at least $575 million, and potentially up to $700 million, in a settlement with the FTC, CFPB, states, and territories.

Federal Trade Commission
FTC final order2024

Marriott / Starwood

Security failureAcquisition risk
Data at issue

Passport and payment-card data, loyalty numbers, dates of birth, email addresses, and reservations.

The FTC alleged that security failures contributed to three breaches affecting more than 344 million customers. The Starwood intrusion began before Marriott completed its acquisition.

Outcome

The final order required an information-security program, retention limits, and a deletion-request mechanism. Marriott also reached a parallel state settlement.

Federal Trade Commission
ICO penalty2022-2025

LastPass

Security failureDerived-data retention
Data at issue

Customer-account information and encrypted password-vault backup data.

The UK ICO found that LastPass failed to implement sufficiently robust safeguards before a threat actor exfiltrated personal data for approximately 1.6 million UK customers from a backup database.

Outcome

The ICO imposed a GBP 1,228,283 penalty. It reported no evidence that customer vault passwords were decrypted.

UK Information Commissioner
FCC settlement2021-2024

T-Mobile

Security failure
Data at issue

Subscriber identity, account, contact, telecommunications, and related customer information.

The FCC investigated significant T-Mobile breaches in 2021, 2022, and 2023 that affected millions of U.S. consumers.

Outcome

T-Mobile agreed to a $15.75 million civil penalty and a further $15.75 million cybersecurity investment, including zero-trust and phishing-resistant authentication commitments.

Federal Communications Commission
FTC final order2025

Gravy Analytics / Venntel

Purpose expansionCommercial sharingGovernment access
Data at issue

Precise mobile-device location, movement histories, visits to sensitive places, and geolocation analytics.

The FTC alleged that Gravy and Venntel collected, used, and sold sensitive location data, including information used in public-sector, national-security, and law-enforcement markets.

Outcome

The final order restricted sale, disclosure, and use of sensitive location data, subject to limited law-enforcement and national-security circumstances.

Federal Trade Commission

Research reports

The Public Power Act regulates the market supplying investigative capability. GISA governs the government information lifecycle after acquisition, including contractor-held systems and derived data.

Company names and marks are used only for identification and do not imply endorsement. Site icons are cached from the listed official domains; trademark rights remain with their respective owners.