Last Update: 08/01/2026 at 1:34 PM EST

Morning Briefing: Privacy

Friday, June 26, 2026

June 26, 2026

Appleton Moves to Shut Down Flock ALPR Cameras

Yesterday was a governance day rather than a sweeping rulemaking day. The most concrete development was Appleton, Wisconsin moving to shut down its Flock ALPR cameras early, asking the vendor to verify that the cameras remain disabled until removal. That matters because the fight over local surveillance is no longer only about whether cities should buy these systems. It is increasingly about whether they can prove how the systems are configured, who can use them, and whether they can be turned off when trust breaks down.

Seen alongside EFF’s analysis of Flock hotlist subscriptions, Vermont’s new state privacy law, the KIDS Act age-verification fight, and another round of breach disclosures and settlements, the day made one thing clearer: privacy protections now depend heavily on operational proof. Policy language, transparency portals, breach notices, and vendor promises matter, but the decisive questions are often more practical: which lists are enabled, which users have access, when the notification clock starts, and what new data a company must collect to comply with another law.

Appleton’s move against Flock was the day’s clearest hard development. The Appleton Post-Crescent reported that the city asked Flock Safety to confirm that 20 ALPR cameras remain disabled until their removal by July 31, after the city moved to terminate its contract early and end ALPR use effective June 30. The local context is important: police and prosecutors described alleged misuse of Flock systems by officers tracking former partners’ vehicles. That turns an abstract privacy concern into a governance failure with names, charges, and a direct remedy: stop the service, verify disablement, and remove the hardware.

EFF’s reporting on ALPR hotlists added a second, more technical layer to the Flock debate. EFF said agencies using Flock can subscribe to FBI NCIC topics, including an ICE-maintained Immigration Violator hotlist, and cited records indicating that Sparks Police Department used that hotlist despite transparency language saying the system was not for immigration enforcement. This is not the same as a new court ruling or regulator finding. But it is a useful reminder that surveillance risk often sits inside administrative settings and list subscriptions, not just in the camera on the pole.

Vermont’s new comprehensive privacy law was the quieter but more durable legal development. Lexology detailed the Vermont Data Privacy and Online Surveillance Act, signed June 16 and effective January 1, 2028. The law adds consumer rights, sensitive-data consent duties, profiling assessments, opt-outs for targeted advertising and sale, and a consumer health data section that restricts unauthorized access and bans certain health data collection through geofencing near health care facilities. Enforcement rests with the Vermont Attorney General, with no private right of action. For compliance teams, the long runway should not obscure the point: state privacy obligations are still becoming more specific even without a federal baseline.

Breach fallout remained broad and practical. GovTech reported that Alamo Heights Independent School District exposed personal information of more than 26,000 people, including Social Security numbers, driver’s license numbers, and financial or medical information. DataBreachToday’s roundup included the Texas Parks and Wildlife vendor incident affecting more than 3 million people, London Hydro’s customer-data investigation, and technical risks involving Cisco SD-WAN, Ubiquiti UniFi OS, and cloud bucket hijacking. Separately, LastPass and Lemonade settlements kept post-breach liability visible as consumers were offered payments, credit monitoring, or reimbursement for documented losses.

The KIDS Act remained proposal-stage, but it deserves attention because its privacy consequences would be immediate if enacted. EFF argued that the package would push online services toward age verification or age estimation, including possible collection of driver’s licenses, passports, facial scans, or behavioral inferences. The important distinction is that this is not yet a finalized obligation. Still, it reflects a recurring policy tension: child-safety rules can reduce some online harms while encouraging platforms to collect more identity data from everyone.

Key Points

  • Local surveillance resistance is becoming more administrative and less rhetorical. Appleton did not merely criticize Flock; it asked for verification that cameras are disabled and set a removal timeline. That is the kind of operational control privacy advocates and city officials increasingly seek: not a promise of responsible use, but a way to confirm status, access, and compliance.
  • Public-facing transparency can diverge from system configuration. EFF’s Flock hotlist reporting matters because it points to a gap between what residents may read in a portal and what an agency may have enabled inside a platform. For public agencies, the hard privacy work is now in audit logs, hotlist subscriptions, user permissions, and exception reports.
  • The state-federal privacy split remains unresolved. Vermont moved forward with a new comprehensive law and health-data restrictions, while the federal child-safety debate appears to be moving through age-assurance pressure rather than a broad consumer privacy framework. The result for companies is not clarity; it is more obligation by category, state, user age, and data type.
  • Breach accountability continues to arrive mostly after the incident. The day’s breach stories were followed by notices, credit monitoring, settlement funds, claim deadlines, and documentation requirements. That does not mean these remedies are meaningless, but it does show how much of privacy enforcement in practice still happens after sensitive data has already moved outside the organization’s control.
  • Incident response is becoming a timing problem as much as a forensic problem. Security Scientist’s GDPR discussion was not a new rule, but it fit the day’s breach-heavy context: under GDPR Article 33, organizations generally should not wait for a complete forensic investigation before making an initial supervisory notice once they are aware of a likely personal data breach.

Implications

Public agencies using ALPR or similar surveillance tools should treat configuration review as core privacy governance. That means documented hotlist subscriptions, user access limits, retention settings, audit trails, misuse escalation, and clear shutdown procedures. Contract language alone will not answer the questions Appleton is now forcing into the open.

Companies should treat vendors, connected platforms, and infrastructure dependencies as privacy exposure points, not merely security concerns. The same day’s reporting included school data, state licensing records, utility customer data, cloud storage risks, and administrative credentials. The common issue is not one type of attacker; it is how much sensitive data sits in connected systems that many organizations do not directly operate.

Product teams working on youth-safety compliance should start from data minimization rather than bolt it on later. If legislation encourages platforms to know users’ ages, the temptation will be to collect stronger identity evidence. The privacy challenge is to satisfy age-related duties without turning ordinary access to online services into routine ID presentation.

Businesses that may fall within Vermont’s law have time, but not as much as the 2028 effective date may suggest. Low applicability thresholds, sensitive-data consent, consumer health data controls, opt-out mechanisms, profiling assessments, and consent-revocation timelines all require data mapping and product changes that are difficult to retrofit.

Consumers affected by breach settlements should expect redress to be documentation-heavy. The LastPass and Lemonade settlements both illustrate a familiar pattern: smaller baseline payments may be easier to claim, but meaningful reimbursement usually depends on proof of losses, notices, deadlines, and in some cases special review.

Watchpoints

Watch

Whether Flock confirms Appleton’s cameras are disabled, whether removal occurs by July 31, and whether the dispute leads to stronger audit or reporting rules in other Wisconsin municipalities.

Watch

Whether local records requests reveal more agencies subscribing to the NCIC Immigration Violator hotlist through ALPR systems, and whether Flock or police departments clarify how portal disclosures match actual settings.

Watch

Whether the KIDS Act advances in its current form or is narrowed to reduce pressure for ID checks, facial estimation, or age inference across private messages, chatbots, and general platforms.

Watch

Whether Vermont’s Attorney General issues implementation guidance before 2028, especially on consumer health data, geofencing, profiling assessments, consent revocation, and opt-out mechanics.

Watch

Whether the Alamo Heights ISD, Texas Parks and Wildlife, London Hydro, Columbia Pacific Advisors, LastPass, or Lemonade matters produce additional regulator scrutiny, litigation, or fuller explanations of the control failures involved.

Watch

Whether breach-notification practice shifts as automated detection tools make it harder for organizations to argue that they were not yet aware of an incident.

Fallout

Yesterday’s meaningful movement clustered around four privacy issues: local ALPR governance, breach exposure and remediation, state privacy law, and age-verification pressure. The strongest development was local and concrete, but the broader lesson was operational: privacy obligations are increasingly tested in settings, logs, notices, and implementation details.

Local ALPR Surveillance and Immigration Data Sharing

ALPR systems turn vehicle movement into searchable records. The privacy stakes depend not only on camera placement, but on retention rules, hotlists, cross-agency sharing, user access, and whether agencies can verify that controls are working.

Fresh developments

Appleton moved to shut down its Flock ALPR program early, asking Flock Safety to verify that 20 cameras remain disabled until removal. The city’s action followed alleged misuse of Flock systems by officers tracking former partners’ vehicles and came amid broader Wisconsin municipal reconsideration of Flock contracts. EFF separately argued that Flock’s administrative tools can allow local agencies to subscribe to FBI NCIC hotlists, including an ICE-maintained Immigration Violator list.

Why we noticed

This is where local surveillance governance becomes tangible. Appleton’s response is not a symbolic resolution; it is a demand for operational proof. EFF’s reporting adds the related concern that immigration-related use may be shaped by backend settings and subscriptions that residents cannot easily see. Together, they make ALPR oversight less about procurement alone and more about auditability after deployment.

Watch for:

  • Whether Appleton receives satisfactory disablement verification from Flock and completes physical removal by July 31.
  • Whether other municipalities move from public concern to contract termination, vendor switching, or stricter annual reporting.
  • Whether agencies disclose NCIC hotlist subscriptions and reconcile those settings with public transparency statements.

Breach Exposure and Post-Incident Accountability

Breach risk remains one of the most concrete privacy issues because it turns data governance failures into legal notices, identity-theft risk, class actions, remediation costs, and regulator questions.

Fresh developments

Alamo Heights ISD disclosed that a cyberattack exposed personal information of more than 26,000 people and disrupted internet access for nearly a week. Broader breach reporting included the Texas Parks and Wildlife vendor incident affecting more than 3 million people, a London Hydro investigation, and technical risks involving SD-WAN, UniFi OS, and cloud storage bucket hijacking. Settlement coverage around LastPass and Lemonade showed how older breaches continue to generate consumer claims and legal costs.

Why we noticed

The day reinforced that breach accountability is rarely a single event. It moves from intrusion to forensic review, notice, state reporting, credit monitoring, litigation, and settlement administration. For organizations, the practical lesson is that privacy exposure often comes through vendors, infrastructure, credentials, and old data stores; for affected people, the consequence is a long tail of notices, documentation, and claims.

Watch for:

  • Whether state attorneys general or sector regulators scrutinize notification timing and reasonable security controls in the newly disclosed incidents.
  • Whether the Texas Parks and Wildlife vendor incident produces more detail on contract controls and exposed fields.
  • Whether breach settlements continue to standardize higher reimbursement caps, longer monitoring, or documentation requirements.

State Privacy Law and Consumer Health Data Rules

State privacy laws continue to define the practical US compliance landscape, especially as Congress has not produced a comprehensive federal privacy law. The most important developments are often specific obligations around sensitive data, health data, profiling, targeted advertising, and consumer rights workflows.

Fresh developments

Vermont enacted the Vermont Data Privacy and Online Surveillance Act, a comprehensive privacy law with low applicability thresholds, consent duties for sensitive data, consumer access and deletion rights, opt-outs for sale and targeted advertising, profiling-related rights, and a consumer health data section that restricts access and bars certain geofencing around health care facilities. The law takes effect January 1, 2028 and is enforced exclusively by the Vermont Attorney General.

Why we noticed

This was actual legal movement, not commentary. Vermont’s law shows the state privacy patchwork becoming more granular, particularly around health-related data and geolocation. The absence of a private right of action reduces one litigation pathway, but the operational obligations still require data inventories, consent systems, opt-out handling, appeals processes, and processor controls.

Watch for:

  • Attorney General guidance on consumer health data, geofencing, profiling assessments, and consent revocation.
  • Whether other states borrow Vermont’s health-data and location-based restrictions.
  • How companies use the 2028 runway to update data maps, consent flows, and vendor contracts.

Age Verification and Youth Safety Legislation

Youth-safety proposals increasingly create a privacy tradeoff: to identify minors, platforms may need to collect or infer more information about everyone. The design question is whether safety obligations can be met without normalizing identity checks across ordinary online activity.

Fresh developments

EFF warned that the KIDS Act, now moving toward an expedited congressional vote, would push platforms toward age checks and government-directed moderation duties across broad content categories. EFF argued that the package could lead platforms to collect driver’s licenses or passports, use age-estimation tools, or infer age from activity or facial scanning, including in contexts such as chatbots, explicit content, direct messages, and disappearing messages.

Why we noticed

The bill is not enacted, so the development should not be treated as a new compliance mandate. But the direction matters because it shows how child-safety law can change data incentives before any platform policy is rewritten. A negligence-style standard tied to what a platform knew or should have known may encourage more collection, not less, unless lawmakers or platforms build privacy-preserving age assurance into the design.

Watch for:

  • Whether the expedited vote occurs and which age-assurance provisions remain in the final package.
  • Whether lawmakers add limits on ID retention, facial analysis, secondary use, or age-estimation error.
  • Whether platforms begin changing age-checking or chatbot policies before a final law is enacted.

Final Thought

The day’s most useful lesson was that privacy failures often emerge in the gap between policy and proof. A city can say cameras are no longer in use, a portal can say data is not used for immigration enforcement, and a company can say a breach is under investigation. The real test is whether the underlying systems, records, settings, and timelines support those statements.