Tier 1Flock Safety
Both acts — very high
Networked ALPR cameras convert plates, vehicle descriptions, locations, and timestamps into searchable investigative data used by law enforcement, businesses, and communities.
Review documented public recordA directory of surveillance providers, data brokers, cloud platforms, and federal contractors.
We track companies whose products, data practices, or government-facing services warrant scrutiny under the proposed acts. A place on this watchlist is not a finding of wrongdoing, and it does not mean that every contract, product, or deployment would be covered.
Tier 1Both acts — very high
Networked ALPR cameras convert plates, vehicle descriptions, locations, and timestamps into searchable investigative data used by law enforcement, businesses, and communities.
Review documented public record
Tier 1Both acts — very high
Axon Fusus integrates public and private camera feeds, ALPR, geolocation, gunshot alerts, CAD, live video, and real-time crime-center operations. Axon Lightpost adds fixed-position ALPR and live streaming.
Review documented public record
Tier 1Both acts — very high
Vigilant and VehicleManager support plate searches, vehicle location history, multi-location analysis, nationwide scan databases, video integration, and investigative workflows.
Tier 1Both acts — very high
Facial-recognition search platform marketed to federal, state, and local law-enforcement agencies.
Review documented public record
Tier 1Both acts — very high
Unifies historical police records and live sensor feeds for real-time crime centers, investigations, people/place/event analysis, interagency sharing, and operational decisions.
Tier 1Both acts — very high
Gotham supports integrated government intelligence workflows, including sensor tasking, data fusion, investigation, and AI-assisted operational decisions.
Review documented public record
Tier 1Both acts — very high
Operates ShotSpotter gunshot detection, PlateRanger ALPR, CrimeTracer investigative data, and an integrated public-safety intelligence platform.
Review documented public record
Tier 1Both acts — high
Rekor Scout and the Rekor Public Safety Network provide cloud or on-premise ALPR, vehicle recognition, searchable historical records, hotlist alerts, and law-enforcement networking.
Tier 1Both acts — high
AutoVu and Cloudrunner provide fixed and mobile ALPR, vehicle tracking, collaborative data sharing, and unified city-wide video, emergency-response, and investigative systems.
Tier 1Both acts — high
Converts surveillance video into searchable metadata, retrospective person and vehicle searches, behavioral filters, alerts, and city-wide analytics for police and real-time crime centers. BriefCam is now presented within Milestone Systems' portfolio.
Tier 1Both acts — high
Drone-as-First-Responder systems provide persistent or incident-triggered live aerial intelligence directly to officers and real-time crime centers, sometimes before officers arrive.
Tier 1Both acts — high
Supplies law-enforcement facial recognition, fingerprint, iris, mugshot, mobile rapid-identification, and database-matching systems.
Tier 1Both acts — high
Provides facial recognition, biometric databases, mobile identity, fingerprint matching, and investigative face-search products to government and law enforcement.
Review documented public record
Tier 1Both acts — high
Markets face-recognition and biometric systems for crime investigation, public safety, border control, airports, and government identification.
Tier 1Both acts — medium/high
Applies AI and human review to continuously monitored camera feeds to detect visible firearms and alert authorities. It is less identity-oriented than ALPR or facial recognition but fits observational and automated-alert provisions.
This is a selected, non-exhaustive record. Each entry identifies the source type and states relevant limits because findings, settlements, audits, allegations, and criticism are not interchangeable.

Flock Safety
The City of Ventura said a Flock configuration error allowed two out-of-state agencies to query a system that the city had restricted to California agencies.
The city reported that no federal agency accessed the system and said it could not determine whether vehicle data was returned. Flock later implemented additional safeguards.

Clearview AI
A court-approved settlement in ACLU v. Clearview AI permanently barred the company from making its faceprint database available to most private entities nationwide.
The case alleged violations of the Illinois Biometric Information Privacy Act. It ended by consent order, not a trial judgment on every allegation.

SoundThinking
Chicago’s Office of Inspector General found evidence of a gun-related criminal offense in 9.1% of the police responses with a recorded disposition in its review period.
The report examined police outcomes, not the acoustic accuracy of every alert. SoundThinking and supporters have disputed broader claims that the technology is ineffective.

Venntel / Gravy Analytics
The FTC finalized an order addressing the collection, use, and sale of sensitive location information, including data associated with health-related locations and places of worship.
The order followed an FTC complaint alleging collection and use without verifiable consent for commercial and government uses, with limited exceptions in the final order.

Axon Enterprise
The FTC alleged that Axon’s acquisition of VieVu reduced competition for body-camera systems sold to large metropolitan police departments.
Safariland separately settled claims about related agreements. The FTC withdrew its adjudication against Axon in 2023 after procedural litigation, so the challenge did not produce a final merits ruling against Axon.

Microsoft
The federal review detailed operational and strategic decisions that contributed to a compromise affecting government email accounts and issued security recommendations.
This record concerns cloud security and stewardship risk, not surveillance-product misconduct. It matters here because GISA assigns continuing duties around sensitive government information held in contractor systems.

Booz Allen Hamilton
The Justice Department said Booz Allen agreed to resolve allegations that commercial and international costs were improperly charged to government contracts and subcontracts.
The settlement agreement states that Booz Allen denied the allegations and that the compromise was not an admission of liability.

IDEMIA Public Security
The Justice Department Inspector General found that the FBI’s $87.5 million-ceiling IDEMIA purchase was rushed, used an improper noncompetitive procurement method, and omitted clauses addressing accountability, privacy, and other risks.
The audit focused on the FBI’s acquisition and contract administration. It reported no questioned costs and did not find that IDEMIA violated the law.

Palantir Technologies
The Department of Labor entered a consent decree resolving allegations that Palantir discriminated against Asian applicants for engineering positions.
The decree required $1.66 million in back wages and other relief plus job offers to eight eligible applicants. This employment matter does not concern the operation of Palantir’s data platforms.

Google Cloud / Google Public Sector
California resolved allegations that Google collected, stored, and used consumer location data for profiling and advertising without informed consent.
The stipulated judgment addressed consumer location settings and advertising practices at Google. It was not a finding about Google Cloud or a government-cloud deployment.

Oracle
The SEC said Oracle subsidiaries in Turkey, the United Arab Emirates, and India created and used off-book funds in connection with business involving foreign officials.
This is a corporate anti-bribery and internal-controls record, not a finding about Oracle’s U.S. government cloud or its handling of government information.

IBM
IBM and Cúram Software resolved allegations that they made material misrepresentations about software development, functionality, and integration during Maryland’s health-exchange contract process.
Maryland later replaced the platform after launch problems. The settlement resolved allegations only and did not determine liability; it does not concern IBM’s current federal AI offerings.

Accenture Federal Services
Accenture Federal Services paid approximately $1.74 million to settle overcharges on a General Services Administration schedule contract caused by unauthorized subcontractor purchases.
Accenture disclosed the issue after an internal investigation and assisted the government. The civil claims were allegations only, with no determination of liability.

Leidos
The Justice Department announced a $1.5 million settlement with SAIC, identified in the release as then known as Leidos Holdings, over alleged undisclosed conflicts on Nuclear Regulatory Commission work.
The underlying conduct dated from 1992 through 2000. The False Claims Act claims were allegations only, and the settlement made no liability determination.
Eighteen case studies document how sensitive consumer information can be exposed, repurposed, transferred, or retained. This companion research is broader than the company tiers above and does not claim that every case falls under the proposed acts.
Private information begins inside ordinary services, safety tools, and background collection. People usually evaluate the immediate service, not the downstream market.
Therapy, prescriptions, fertility tracking, addiction treatment, and DNA testing create records about conditions, family relationships, and intimate decisions.
Password vaults, home cameras, voice assistants, antivirus tools, and account-recovery systems collect data because people are trying to protect themselves or simplify a task.
Location signals, advertising events, friend networks, connected relatives, and device identifiers can extend one disclosure across places, services, and other people.
Commercial value grows when information can be reused, combined, copied, and transferred. These activities can occur together or independently.
Authentication, encryption, employee access, monitoring, segmentation, and backup safeguards fail to match the sensitivity or reach of the data.
Information supplied for care, security, storage, or account recovery becomes an input for advertising, analytics, targeting, or product development.
Pixels, software kits, APIs, audience lists, brokers, contractors, and analytics platforms move data beyond the original service relationship.
Backups, transcripts, face embeddings, profiles, models, and algorithms can preserve information or its commercial value after the visible record is deleted.
Mergers, acquisitions, bankruptcy, and asset sales transfer sensitive datasets, inherited security problems, and privacy obligations to new organizations.
Organizations capture the value of collection and reuse. The people described by the data bear consequences that are difficult to prevent, measure, or reverse.
DNA, biometrics, identity records, location histories, and security credentials cannot always be replaced or made private again after a breach.
A technical event or identifier can reveal pregnancy, treatment, addiction, home activity, political interests, or visits to sensitive locations.
A person may close an account while recipients, backups, models, profiles, and physical samples remain outside the deletion request.
Location and identity information collected in consumer markets can become available for law-enforcement, national-security, or other government use.
Category assignments are editorial classifications from the report. They support comparison and do not establish statutory liability.

Genetic data, health reports, ancestry information, relatives, family trees, and demographic attributes.
A credential-stuffing campaign reached a limited group of accounts, while connected relatives and family features expanded the exposure to almost seven million people worldwide. The company entered Chapter 11 in March 2025.
The UK ICO imposed a GBP 2.31 million penalty. Canadian and UK regulators addressed bankruptcy protections before TTAM Research Institute completed the acquisition.

DNA test results, genetic and health information, customer identities, and biological samples.
The FTC alleged that the company left unencrypted genetic and health data in publicly accessible cloud storage, changed its privacy policy retroactively, and failed to honor deletion commitments.
The final order required a privacy and security program, deletion or destruction obligations, limits on retroactive policy changes, and $75,000 for consumer refunds.

Granular web-browsing histories collected through antivirus software and browser extensions.
The FTC alleged that Avast promoted protection from tracking while collecting detailed browsing information and transferring it to Jumpshot for sale to more than 100 third parties.
Avast agreed to pay $16.5 million. The order banned specified sales and required deletion of transferred browsing data and products or algorithms derived from it.

Email and IP addresses, therapy enrollment, mental-health questionnaire responses, and related information.
The FTC alleged that BetterHelp disclosed health-related identifiers and questionnaire information to advertising platforms despite representations about limited and confidential use.
The $7.8 million order banned health-data sharing for advertising and required consent, deletion instructions to recipients, and a retention schedule.

Prescription medications, health conditions, contact details, device identifiers, and service activity.
The FTC alleged that GoodRx sent prescription and health information to advertising platforms and used customer lists to target medication- and condition-specific advertisements.
GoodRx agreed to a $1.5 million civil penalty in the first FTC Health Breach Notification Rule enforcement action, plus advertising and deletion restrictions.

Menstrual-cycle, fertility, pregnancy, and other reproductive-health activity recorded through the app.
The FTC alleged that Flo transmitted sensitive app events to marketing and analytics providers after promising to keep users' health information private.
The order required affirmative consent, notice to affected users, deletion instructions to third parties, and an independent privacy review.

Mental-health and prescription histories, treatment plans, insurance data, identity documents, and beliefs.
The FTC alleged that tracking technologies disclosed sensitive information to advertising platforms and that the company maintained weak access controls and other security practices.
The proposed order included more than $7 million in payments, advertising restrictions, consent and deletion requirements, and a privacy and security program.

Alcohol-addiction treatment, therapy and medication activity, identifiers, and service interactions.
The FTC alleged that Monument disclosed information capable of revealing that a person sought alcohol-addiction treatment to Meta and Google through advertising technologies.
The settlement banned health-data disclosure for advertising and required consent for specified sharing. A $2.5 million civil penalty was suspended based on ability to pay.

Personal photos and videos, facial embeddings, facial-recognition models, and retained account content.
The FTC alleged that Everalbum misrepresented when facial recognition would be enabled and retained content from deactivated accounts for face-recognition development.
The order required express consent and deletion of affected photos, videos, face embeddings, and models or algorithms developed from improperly retained or used data.

Private home-security video, account data, face embeddings, and work products derived from recordings.
The FTC alleged overly broad employee and contractor access, video use for algorithm development without adequate consent, and failures to reduce credential-stuffing attacks.
Ring agreed to pay $5.8 million and implement a privacy and security program. The order required deletion of specified videos, embeddings, and derived work products.

Voice recordings and transcripts, geolocation, account activity, and algorithm-training material.
The FTC and DOJ alleged that Amazon retained children's Alexa recordings indefinitely by default and failed to remove some transcripts after deletion requests.
Amazon agreed to a $25 million civil penalty, revised deletion practices, and limits on using data subject to deletion requests to improve data products.

Phone numbers and email addresses supplied for account security, authentication, and recovery.
The FTC and DOJ charged Twitter with allowing advertisers to use account-security contact information for targeting from 2014 through 2019.
Twitter agreed to a $150 million penalty and restrictions on profiting from deceptively collected security data, with compliance and user-notice obligations.

Social profiles, friend networks, app permissions, interests, political profiles, and advertising identifiers.
FTC actions addressed Facebook privacy representations and third-party app access, as well as Cambridge Analytica voter-profiling activity using data collected through an app.
Facebook agreed to a $5 billion penalty and a 20-year privacy-governance order. Separate Cambridge Analytica matters imposed deletion and use restrictions.

Names, Social Security numbers, birth dates, addresses, credit information, and some identity documents.
The 2017 breach exposed identifiers and credit-related information associated with approximately 147 million people.
Equifax agreed to pay at least $575 million, and potentially up to $700 million, in a settlement with the FTC, CFPB, states, and territories.

Passport and payment-card data, loyalty numbers, dates of birth, email addresses, and reservations.
The FTC alleged that security failures contributed to three breaches affecting more than 344 million customers. The Starwood intrusion began before Marriott completed its acquisition.
The final order required an information-security program, retention limits, and a deletion-request mechanism. Marriott also reached a parallel state settlement.

Customer-account information and encrypted password-vault backup data.
The UK ICO found that LastPass failed to implement sufficiently robust safeguards before a threat actor exfiltrated personal data for approximately 1.6 million UK customers from a backup database.
The ICO imposed a GBP 1,228,283 penalty. It reported no evidence that customer vault passwords were decrypted.

Subscriber identity, account, contact, telecommunications, and related customer information.
The FCC investigated significant T-Mobile breaches in 2021, 2022, and 2023 that affected millions of U.S. consumers.
T-Mobile agreed to a $15.75 million civil penalty and a further $15.75 million cybersecurity investment, including zero-trust and phishing-resistant authentication commitments.

Precise mobile-device location, movement histories, visits to sensitive places, and geolocation analytics.
The FTC alleged that Gravy and Venntel collected, used, and sold sensitive location data, including information used in public-sector, national-security, and law-enforcement markets.
The final order restricted sale, disclosure, and use of sensitive location data, subject to limited law-enforcement and national-security circumstances.
The Public Power Act regulates the market supplying investigative capability. GISA governs the government information lifecycle after acquisition, including contractor-held systems and derived data.
Company names and marks are used only for identification and do not imply endorsement. Site icons are cached from the listed official domains; trademark rights remain with their respective owners.