Follow surveillance companies across the supply chain, then examine the security, privacy, reuse, transfer, and government-access failures that turn private data into public power.
ALPR cameras in Pensacola Beach. Tony Webster, CC BY-SA 2.0.
Company coverage index
One working dataset, organized through two views. Every record is tagged to the relevant watchlist company, its place in the surveillance supply chain, and any documented data-stewardship failure.
The City of Ventura said a Flock configuration error allowed two out-of-state agencies to query a system that the city had restricted to California agencies.
The city reported that no federal agency accessed the system and said it could not determine whether vehicle data was returned. Flock later implemented additional safeguards.
Chatrie tests whether police can use a provider to identify devices near a place and time, the same reverse-search pattern the Public Power report flags.
Federal order restricted sale and use of sensitive location data
The FTC finalized an order addressing the collection, use, and sale of sensitive location information, including data associated with health-related locations and places of worship.
The order followed an FTC complaint alleging collection and use without verifiable consent for commercial and government uses, with limited exceptions in the final order. Precise mobile-device location, movement histories, visits to sensitive places, and geolocation analytics. The final order restricted sale, disclosure, and use of sensitive location data, subject to limited law-enforcement and national-security circumstances.
Cyber Safety Review Board examined the 2023 Exchange Online intrusion
The federal review detailed operational and strategic decisions that contributed to a compromise affecting government email accounts and issued security recommendations.
This record concerns cloud security and stewardship risk, not surveillance-product misconduct. It matters here because GISA assigns continuing duties around sensitive government information held in contractor systems.
FTC restricts Mobilewalla sensitive location data sales
The Mobilewalla action shows why broker consent, sensitive-location screening, retention, deletion, and customer-use controls belong in the campaign frame.
Ring’s policy change illustrates how consumer devices can become police-access infrastructure unless product rules, defaults, and legal process are constrained.
First Amendment and Fourth Amendment lawsuit in Norfolk
Residents challenged the city’s use of Flock ALPRs, arguing the network allowed pervasive location tracking without adequate constitutional safeguards.
Regulator challenged the completed VieVu body-camera acquisition
The FTC alleged that Axon’s acquisition of VieVu reduced competition for body-camera systems sold to large metropolitan police departments.
Safariland separately settled claims about related agreements. The FTC withdrew its adjudication against Axon in 2023 after procedural litigation, so the challenge did not produce a final merits ruling against Axon.
Company paid $377.45 million to resolve federal billing allegations
The Justice Department said Booz Allen agreed to resolve allegations that commercial and international costs were improperly charged to government contracts and subcontracts.
The settlement agreement states that Booz Allen denied the allegations and that the compromise was not an admission of liability.
Google agreed to a $93 million location-privacy settlement
California resolved allegations that Google collected, stored, and used consumer location data for profiling and advertising without informed consent.
The stipulated judgment addressed consumer location settings and advertising practices at Google. It was not a finding about Google Cloud or a government-cloud deployment.
The FTC alleged overly broad employee and contractor access, video use for algorithm development without adequate consent, and failures to reduce credential-stuffing attacks.
Private home-security video, account data, face embeddings, and work products derived from recordings. Ring agreed to pay $5.8 million and implement a privacy and security program. The order required deletion of specified videos, embeddings, and derived work products.
The FTC and DOJ alleged that Amazon retained children's Alexa recordings indefinitely by default and failed to remove some transcripts after deletion requests.
Voice recordings and transcripts, geolocation, account activity, and algorithm-training material. Amazon agreed to a $25 million civil penalty, revised deletion practices, and limits on using data subject to deletion requests to improve data products.
Consent order restricted access to the faceprint database
A court-approved settlement in ACLU v. Clearview AI permanently barred the company from making its faceprint database available to most private entities nationwide.
The case alleged violations of the Illinois Biometric Information Privacy Act. It ended by consent order, not a trial judgment on every allegation.
FBI biometric algorithm purchase lacked required safeguards and documentation
The Justice Department Inspector General found that the FBI’s $87.5 million-ceiling IDEMIA purchase was rushed, used an improper noncompetitive procurement method, and omitted clauses addressing accountability, privacy, and other risks.
The audit focused on the FBI’s acquisition and contract administration. It reported no questioned costs and did not find that IDEMIA violated the law.
Oracle paid more than $23 million to resolve FCPA charges
The SEC said Oracle subsidiaries in Turkey, the United Arab Emirates, and India created and used off-book funds in connection with business involving foreign officials.
This is a corporate anti-bribery and internal-controls record, not a finding about Oracle’s U.S. government cloud or its handling of government information.
Chicago watchdog found limited documented results from ShotSpotter alerts
Chicago’s Office of Inspector General found evidence of a gun-related criminal offense in 9.1% of the police responses with a recorded disposition in its review period.
The report examined police outcomes, not the acoustic accuracy of every alert. SoundThinking and supporters have disputed broader claims that the technology is ineffective.
The FTC alleged that Everalbum misrepresented when facial recognition would be enabled and retained content from deactivated accounts for face-recognition development.
Personal photos and videos, facial embeddings, facial-recognition models, and retained account content. The order required express consent and deletion of affected photos, videos, face embeddings, and models or algorithms developed from improperly retained or used data.
Chicago watchdog scrutinizes gunshot detection alerts
The ShotSpotter review shows the governance problem when vendor-generated alerts change police behavior but accountability turns on accuracy, documentation, and downstream stops.
IBM paid $14.8 million over health-exchange procurement allegations
IBM and Cúram Software resolved allegations that they made material misrepresentations about software development, functionality, and integration during Maryland’s health-exchange contract process.
Maryland later replaced the platform after launch problems. The settlement resolved allegations only and did not determine liability; it does not concern IBM’s current federal AI offerings.
Meta / Facebook / Cambridge Analytica: FTC orders and settlements
FTC actions addressed Facebook privacy representations and third-party app access, as well as Cambridge Analytica voter-profiling activity using data collected through an app.
Social profiles, friend networks, app permissions, interests, political profiles, and advertising identifiers. Facebook agreed to a $5 billion penalty and a 20-year privacy-governance order. Separate Cambridge Analytica matters imposed deletion and use restrictions.
Accenture Federal Services settled government-contract overcharges
Accenture Federal Services paid approximately $1.74 million to settle overcharges on a General Services Administration schedule contract caused by unauthorized subcontractor purchases.
Accenture disclosed the issue after an internal investigation and assisted the government. The civil claims were allegations only, with no determination of liability.
Federal contractor resolved systemic hiring-discrimination charges
The Department of Labor entered a consent decree resolving allegations that Palantir discriminated against Asian applicants for engineering positions.
The decree required $1.66 million in back wages and other relief plus job offers to eight eligible applicants. This employment matter does not concern the operation of Palantir’s data platforms.
The Justice Department announced a $1.5 million settlement with SAIC, identified in the release as then known as Leidos Holdings, over alleged undisclosed conflicts on Nuclear Regulatory Commission work.
The underlying conduct dated from 1992 through 2000. The False Claims Act claims were allegations only, and the settlement made no liability determination.
Cloud evidence platforms centralize police records
Vendor evidence platforms show the stewardship side of the PDFs: capture, storage, AI search, disclosure, chain of custody, retention, and interagency sharing.
Official product framing: detection, investigation, response
The company describes its platform as connecting detection, investigation, and response, a useful public-facing contrast for the site’s policy argument.
Systems are purchased and networked first. Questions about access, accuracy, public records, and constitutional limits often arrive only after the infrastructure is embedded.
2017 onward
National
Flock builds a leased camera network for public and private customers
The market pattern matters: cameras can be owned and operated by a vendor while governments, businesses, schools, neighborhoods, and property managers participate in a shared investigative network.
Private commercial sites become surveillance nodes
The campaign should show how a camera outside an ordinary store or property can become part of a broader public-private search layer when data is shared or queried for government purposes.
Ring shuts down police video request tool after privacy backlash
Amazon Ring said it would stop letting police request doorbell footage directly from users through the Neighbors app, showing how household devices can become law-enforcement access infrastructure unless product rules change.
Federal appeals courts split over geofence warrants
The Fourth Circuit allowed geofence evidence in Chatrie while the Fifth Circuit held the geofence warrant in Smith unconstitutional, exposing the unstable doctrine around reverse-location searches of provider-held data.
FTC targets sale of sensitive mobile location data
FTC actions against Mobilewalla, Gravy Analytics, Venntel, and related broker practices illustrate the commercial supply chain that can expose visits to homes, clinics, places of worship, shelters, and political or associational spaces.
The Supreme Court held that obtaining stored phone-location records from a company triggers Fourth Amendment scrutiny, reinforcing the campaign premise that private custody should not erase public-law safeguards.
Illinois officials object to out-of-state ALPR searches
Illinois officials said Texas law enforcement used a nationwide ALPR search involving more than 83,000 cameras in a matter connected to abortion care, and the state found additional immigration-related searches.
EFF reported that documents and court records showed the ALPR query was tied to an abortion investigation, sharpening the need for purpose limits, audit trails, and cross-jurisdiction controls.
Court treats vendor-held Flock camera data as public records
A Washington trial court rejected the argument that ALPR data stored by Flock was outside public-records access when the cameras were paid for and used for a governmental purpose.
Business Insider reported LAPD allowed its agreement to expire after concerns over civil liberties, data ownership, security, and possible federal access to locally collected data.