Los Angeles Presses LAPD to End Flock Relationship
Yesterday’s privacy developments were less about a new national rule than about who gets to set the operating conditions for surveillance. In Los Angeles, the mayor intervened directly in LAPD’s relationship with Flock Safety; in West Virginia, lawmakers prepared to examine the same kind of vehicle-surveillance network. At the same time, facial recognition continued moving into ordinary retail entrances, where consumers can be scanned before any privacy right can realistically be exercised.
The common question is becoming more concrete: not whether data-intensive systems can be useful, but whether their deployers can demonstrate enforceable limits on retention, sharing, access and redress. For now, those answers are still being negotiated city by city, contract by contract, and product by product.
The strongest development was Mayor Karen Bass’s call for LAPD to end its relationship with Flock Safety. The Los Angeles Times reported that Bass cited public distrust and concern that license-plate data could aid immigration enforcement. LAPD has been negotiating revised terms, but an inspector general had already found that its agreements with Flock, Axon and Motorola lacked clear provisions on retention and third-party sharing. This is not yet a contract termination; it is meaningful executive pressure at a moment when the safeguards themselves remain unsettled.
West Virginia added a second front in the debate over automated license plate readers. WSAZ reported that state lawmakers will hear from Flock and the Institute for Justice, with possible legislation addressing data ownership, authorized access, audit trails and local approval. The importance lies in the specificity of the questions: lawmakers are moving past broad arguments over surveillance toward the mechanics that determine whether a searchable movement database can be constrained.
Commercial biometric collection kept advancing. Grocery Outlet is using SAFR Guard facial recognition at entrances to some Bay Area stores to compare shoppers with security watchlists. The company’s vendor says images that do not match are deleted immediately, but the practical privacy issue precedes retention: a shopper is scanned before deciding whether to seek deletion or restrict sharing, and avoiding collection means avoiding the store altogether.
Federal scrutiny of data-driven pricing advanced procedurally, not legally. Senator Josh Hawley said he plans legislation against AI-enabled individualized pricing based on personal data. States have already adopted differing restrictions, but the prospective federal measure has no published text, settled definitions or enforcement model. It is a warning for retailers and platforms to understand their pricing inputs, not a new compliance obligation.
Key Points
- Los Angeles and West Virginia show that the fight over networked police surveillance is increasingly being conducted through procurement and oversight rather than through a settled constitutional or federal privacy rule. Retention periods, immigration-related access, interagency sharing, search justifications and audit logs are no longer administrative details; they are the substance of the policy dispute.
- Retail facial recognition is becoming a routine loss-prevention proposition even after the Federal Trade Commission’s prior action against Rite Aid. That makes the quality of watchlists, accuracy testing, escalation procedures and alternatives for people who decline scanning more important than generic assurances that nonmatching images are deleted.
- The reported guilty plea connected to the 2024 Snowflake customer-account campaign reinforces a separate but related lesson: privacy harm often begins with identity controls. Stolen credentials, missing MFA enforcement, unrotated passwords and weak tenant logging enabled access across many organizations, showing why authentication and visibility are privacy infrastructure as much as security infrastructure.
Implications
Police agencies using Flock or comparable systems should review whether their vendor terms clearly define who may search records, which outside agencies may receive them, how long data is retained, how misuse is detected and whether independent review is possible. A policy statement without enforceable contractual duties is unlikely to satisfy the concerns now driving local resistance.
Retailers using facial recognition need controls that begin before collection, not only after it. Clear entry notice, narrowly justified watchlists, tested accuracy, trained human review, retention limits and a workable alternative for unscanned customers are increasingly central to a defensible deployment.
Companies using behavioral, loyalty, location or inferred data in pricing should inventory the inputs and decision rules now. The emerging policy concern is shifting from disclosure alone toward the outcome of profiling: whether personal data changes the price a particular customer sees.
Snowflake customers have a practical deadline ahead of October 2026, when the company plans to restrict password-only sign-ins for most human and service accounts. Phishing-resistant MFA, credential rotation, service-account governance and usable tenant logs will determine whether that transition reduces risk or merely exposes deferred remediation.
Watchpoints
Watch
Whether LAPD revises, suspends or ends its Flock agreement, and whether any revised terms address retention, third-party sharing, immigration-related access and auditability.
Watch
Whether West Virginia’s fact-finding session produces legislation with enforceable rules on automated license plate reader ownership, access, retention and local adoption.
Watch
Release of text for Hawley’s proposed surveillance-pricing bill, including its treatment of biometrics, delivery platforms, food retail and conventional promotions.
Watch
Whether Grocery Outlet’s facial-recognition use prompts fuller disclosure, regulatory inquiry or litigation over watchlist practices, retention and consumer alternatives.
Watch
Whether Snowflake customers complete the identity-control changes needed before the company’s planned October authentication restrictions.
Fallout
Meaningful movement centered on location surveillance, commercial biometrics and data-driven consumer practices. The day also reinforced that identity and access controls remain a decisive determinant of breach scale.
Location Surveillance
Automated license plate readers turn ordinary vehicle sightings into searchable location records. The lasting governance questions are who can query those records, for what purpose, for how long, and with what accountability.
Fresh developments
Mayor Bass urged LAPD to end its Flock relationship after concerns about immigration-related use and weak contractual protections. Separately, West Virginia lawmakers scheduled a fact-finding session that will examine ownership, access, audit trails and local approval of similar systems.
Why we noticed
These developments sharpen a pattern visible over recent weeks: practical limits on vehicle-surveillance networks are being made locally, through contracts and legislative proposals, rather than by a uniform national standard. The distinction matters because the same technology can operate under very different sharing and audit rules from one jurisdiction to another.
Watch for:
- LAPD’s response to the mayor and the terms of any revised agreement.
- West Virginia bill language on retention, external access and audit requirements.
- Whether other cities treat vendor-contract terms as a condition of continued ALPR use.
Biometric Governance
Facial recognition is spreading through retail, transport and public spaces, raising recurring questions about notice, consent, false matches, retention, watchlists and the ability to contest consequential decisions.
Fresh developments
Grocery Outlet’s deployment of SAFR Guard at some Bay Area store entrances offered a current example of commercial facial recognition used before customers can meaningfully decline collection. The vendor says nonmatching images are immediately deleted, while shoppers can later invoke California privacy rights.
Why we noticed
Deletion commitments address only one stage of a biometric system. The more difficult issue is unavoidable initial capture: shoppers are scanned at the threshold, and the available reporting offers limited independent detail on watchlist criteria, accuracy testing, retention verification or recourse for people incorrectly identified.
Watch for:
- Disclosure of Grocery Outlet’s watchlist, review and retention practices.
- Regulatory or litigation response to entrance-based retail facial recognition.
- Whether retailers introduce workable alternatives for customers who decline scanning.
Commercial Data Monetization
Retailers and platforms increasingly use behavioral, loyalty, location and inferred data to personalize offers, target promotions and potentially influence prices. Policymakers are beginning to focus on the outcomes produced by such profiling, not only the notice given before collection.
Fresh developments
Senator Hawley said he will introduce legislation aimed at AI-powered surveillance pricing. The announcement follows a Senate hearing and arrives as Maryland, Connecticut and New Jersey take differing approaches to restrictions and disclosures.
Why we noticed
The proposal does not create an immediate federal rule, but it increases pressure on organizations to distinguish ordinary promotions from price differences produced by personal-data profiling. That distinction will be difficult to administer unless companies can explain the data sources and decision logic behind individualized offers.
Watch for:
- Publication of the federal bill and its definitions of individualized pricing.
- Whether the measure covers food retail, delivery services and biometric data.
- Further state enforcement or disclosure requirements for personalized pricing.
Breach Accountability
Large privacy incidents repeatedly turn on credential theft, weak authentication, inadequate access visibility and incomplete incident scoping. The resulting harm often spreads across organizations that share a cloud platform or service provider.
Fresh developments
Reporting on a guilty plea in the Snowflake customer-account campaign returned attention to the mechanics of the 2024 intrusions: credentials harvested by infostealer malware, accounts without enforced MFA, stale passwords and limited tenant logging. Snowflake plans further restrictions on password-only access in October.
Why we noticed
Criminal accountability is important, but the operational lesson is more durable. A cloud provider can strengthen its baseline, yet customers still need to know which identities can access sensitive stores, whether authentication is enforced, and whether logs can rapidly establish what an attacker reached.
Watch for:
- Snowflake’s October implementation and customer readiness.
- Further court proceedings and victim-specific information from the breach campaign.
- Whether affected organizations disclose additional remediation or litigation outcomes.
Article links:
Final Thought
The day’s most important lesson is that privacy protection is increasingly decided at the point of operation: in a police contract, at a store entrance, inside a pricing model or through an account-login policy. Broad principles matter, but enforceable limits are what determine how much data power a system actually holds.
