Live data from Hacker News

I wrote to Flock's privacy contact to opt out of their domestic spying program

honeypot.net

221–230 of 276 posts

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#221

Earlier quoted context omitted.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

If Flock's customers, using Flock's infrastructure or tooling, can share data with each other, that would be bad. I'm not saying that's what's happening, but that's what I thought was happening before reading this thread, and now I have to go and run through their policies. Either way ALPRs and AI-facial scanners in public are a huge violation of privacy and I loathe them, but I hope it's correct that Flock customers…

> If Flock's customers, using Flock's infrastructure or tooling, can share data with each other, that would be bad.

Ex-employee of Flock here, that's ABSOLUTELY what's happening.

And what's more Flock lets them do so even when they know the agencies are legally not permitted to do so. They turn a blind eye, say it's not their problem to enforce ("oh, doing so in state X is illegal? Well, even if your agency is in state X, we didn't disable that feature"), then happily provide training to do enable those agencies to do so (and it's a nudge nudge wink wink part of the sales process.)

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#222
post #87

Earlier quoted context omitted.

Personal information usually does include photos of someone in public without their consent: exceptions usually hold for taking photos of people where it is in the public interest to be able to show them or impractical to get consent. This covers large gatherings and celebrities, but a portrait photo of a stranger might put you on the wrong side of the law. Obviously, the idea is to not disallow having someone take a…

> Personal information usually does include photos of someone in public without their consent This is not the case in the United States. There is no presumption of privacy in public. In fact, there is a whole genre known as "street photography" that involves taking pictures in public without explicit consent of the subjects.

> In fact, there is a whole genre known as "street photography" that involves taking pictures in public without explicit consent of the subjects.

Try taking an upskirt photo of someone in public without their explicit consent. You'll find that there are limitations to that under both Federal and State laws.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#223
post #214

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

In GDPR terms, the point they're making is that people who own Flock hardware are the Data Controllers, and Flock act only as Data Processors. I'm not sure how (whether?) those roles map to the CCPA, and whether any court of law would agree with them is up for discussion, but at least the concept is not completely absurd. Of course, the word "owner" is almost rage baiting on their part.

Except under Flock's own contracts and their own website, Flock are the people who own Flock hardware. And this correlates with my understanding from when I was an employee.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#224
post #197

Earlier quoted context omitted.

Flock's facilitation of data-sharing is a huge part of their value proposition over other cameras, and why their customers buy from them over their competitors. As such, even if they can contract it such that they are not legally responsible for such use, they are very much knowingly facilitating it. If this was physical goods, rather than data, they would probably been as responsible as their customers.

I've read our contract . I know what it says. This isn't an abstraction. They can do lots of things. What they actually do is not data brokerage under California Law, at least not that I can tell.

What Flock names the relationship in their contract does not make it one, as the courts do very much duck type.

Flock knowingly collects PII of people they have no direct relationship with, and transfers it to third parties. If that transfer, which Flock seem to gain from, is legally a sale is something to be argued at a great expense in front of the court.

But regardless of that definition, I so think that any reasonable person (= not a corporate lawyer) would consider there is a sale of data here.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#225
post #123

Earlier quoted context omitted.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

Equivocation. My stock broker doesn't own my stocks either, they merely hold my assets in a brokerage account.

Technically, most stocks are registered in the name of a securities holding company, with you named as beneficial owner. That makes it frictionless for you to buy and sell. You enjoy all the rights of ownership, unless the broker lends your shares out to someone else.

You _can_ get shares registered in your name.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#226

Earlier quoted context omitted.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

If Flock's customers, using Flock's infrastructure or tooling, can share data with each other, that would be bad. I'm not saying that's what's happening, but that's what I thought was happening before reading this thread, and now I have to go and run through their policies. Either way ALPRs and AI-facial scanners in public are a huge violation of privacy and I loathe them, but I hope it's correct that Flock customers…

Sharing data between customers is a large part of the point of the product.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#227

Earlier quoted context omitted.

I may or may not know a business owner who got criminals off their business' street by saying he thinks he saw a gun any time criminals showed up to do things, everything from prostitution to selling drugs. Cops showed up immediately. They stopped coming by altogether, probably the safest street in quite a rough part of town. It's crazy how cops just rush to very specific and nuanced crimes. Someone likely said they…

> It's crazy how cops just rush to very specific and nuanced crimes. Someone likely said they heard gun shots, and then they scrambled to find them. Is it crazy? Shouldn't the response be proportional?

Contrast to someone being shot dead, if the killer drives away, they might be there half an hour later.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#228

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

It would be revealing to see a judge scrutinize the degree of control Flock maintains over the system and deliberate on whether the company truly is as hands-off as it claims when it comes to privacy obligations. Personally I feel if you're going to build so turnkey a system to facilitate collection of personal data by your customers at the scale Flock seeks, then at a minimum you should build an equally turnkey meth…

it is distinctly against Flock's interests to offer a turnkey system to help people opt out of data collection from among Flock's many customers. It might be a service to the general public, but it certainly would not be a service that Flock's actual customers would generally be interested in, at all

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#229
post #58

If Flock collects and processes PII data, then all their customers are "subprocessors". Flock should really have a Data Processing Agreement with their subprocessors, to legally ensure they follow the same PII handling controls as Flock does. For example, if Flock receives a legitimate request to delete some data, then Flock must forward that request to all their Data Processors (e.g. including AWS/GCP/Cloudflare) an…

It’s the other way around. Flock is the subprocessor for whoever hired them to collect data. If they are collecting data on behalf a city or municipality, those are the entities you need to address.

I'm not sure about that, I'm pretty sure any company that has your PII is obliged to follow the law, regardless of their contracts with their customers/vendors. Law doesn't make you investigate who's the end customer for your data, only who has it.

As for "subprocessor" -- it might as well be the case that both sides are subprocessors for each other, nothing wrong with that.

Post reply on HN