Live data from Hacker News

I wrote to Flock's privacy contact to opt out of their domestic spying program

honeypot.net

131–140 of 276 posts

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#131
post #115

Isn't that how it should work? If you write the police and ask them to delete all their data about you, that isn't a thing that they do. It shouldn't matter if the police store their data on AWS or their own servers. Flock is a tool used by the police so it should work the same way.

You're right are exemptions for both GDPR [0] and the CCPA [1] where organizations aren't obligated to comply with erasure requests if it would limit their ability to prevent or investigate crimes, fraud, or similar matters.

But that's not what Flock is claiming. They're claiming that they don't even have to consider the request because they don't own the data.

[0] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...

[1] https://www.clarip.com/data-privacy/ccpa-erasure-exemptions/

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#132

Earlier quoted context omitted.

FWIW, I just did this as an experiment and turned it into a blog post afterward. I didn't really set out with an agenda or a deliberate audience, and I didn't share it here. Don't get me wrong, I'm happy to chat about it! But this ended up here without any special effort on my part.

I know the feeling! My arguments here are positive, not normative. I don't know that I think it would be a worse world if your hypothesis was correct. I'm just reasonably sure it isn't.

For sure. This is the sort of conversation I'd typically rather be having at a bar with appropriate beverages. If it sounds like I'm arguing, it's because it's the kind of thing I'd debate with my friends for the fun of it.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#133

Earlier quoted context omitted.

> Personal information usually does include photos of someone in public without their consent This is not the case in the United States. There is no presumption of privacy in public. In fact, there is a whole genre known as "street photography" that involves taking pictures in public without explicit consent of the subjects.

This is true, and it may also be true that location tracking through surveillance networks crosses a line into violating one or more Constitutional rights. One of Flock's revenue streams is explicitly selling access to data made available by other customers. A commonly-cited example is the ability of local law enforcement to locate abortion suspects in other states using the Flock camera network [0]; one could imagin…

People keep making this claim that Flock "explicitly sells access to data", but the link you provided doesn't demonstrate that, and Flock contracts I've read contradict the claim.

I think what's happening here is that people are trying to colloquially define "selling access to data" to fit the camera data sharing that Flock enables, and then saying that because you have to pay to be a Flock customer to get access to that data, they're effectively selling it. I don' think that's how data brokerage laws work. Flock doesn't own the data they're providing access to, and they're providing that sharing access with the (avid!) consent of their customers.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#134

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

>It's my data, not their customers'.

Just because data is about you, that doesn't mean it is your data.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#135

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

> which seems to directly oppose the CCPA.

I have some background in data privacy compliance.

It sounds like they are claiming to be a Service Provider under CCPA, which is similar to a Processor under GDPR. Long story short, a Controller is the one legally responsible for ensuring the rights of the data subject, and a service provider/processor is a "dumb pipe" for a Controller that does what they're told. So IF they are actually a Service Provider, they're correct that the legal responsibility for CCPA belongs to their customers and not them.

That's a big IF, though.

Being a Processor/Service Providor means trade-offs. The data you collect isn't yours, you're not allowed to benefit from it. If Flock aggregates data from one customer and sells that aggregate to a different customer, they're no longer just a service provider. They're using data for their own purposes, and cannot claim to be "just" a service provider.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#136

Earlier quoted context omitted.

I looked it up at https://cppa.ca.gov/data_broker_registry/ and didn't find Flock / Flock Safety in that list of the currently registered 566 data brokers.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

[deleted]

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#137
post #14

To me this sounds like the equivalent of visiting a website that sells your data, and then asking AWS to delete your personal data when it actually belongs to a customer of theirs and only resides within their private storage. Would you ask your local ISP to delete data they provided to Tinder like your IP address? That doesn't make sense to me.

As I understand it, the author wrote to Flock as they are the entity collecting the PII. Your analogy would only make sense if the author had written to Flock's customers (and even then it's a rather strained comparison).

> they are the entity collecting the PII

I'm not convinced this is the case. It might be equipment made by them, but does that necessarily mean they were ever even in possession of the data in question?

Would you ask the manufacturer of your oven what you ate for dinner last week? No, you're just using an appliance that they made.

In the case of Flock I don't think we have any evidence of whether Flock themselves ever hold or store any data produced by their devices when operated by a customer.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#138
post #123

Earlier quoted context omitted.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

Equivocation. My stock broker doesn't own my stocks either, they merely hold my assets in a brokerage account.

And you would (rightfully) be angered if your stock broker sold your shares and pocketed the proceeds, because you own them.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#139

I wrote this. I had/have absolutely no expectation that Flock would comply with my request, but figured I should try anyway For Science. Their reply rubbed me wrong, though. They seem to claim that there are no restrictions on their collection and processing of PII because other people pay them for it. They say: > Flock Safety’s customers own the data and make all decisions around how such data is used and shared. wh…

>It's my data, not their customers'. Just because data is about you, that doesn't mean it is your data.

you may be minunderstanding the california consumer privacy act (ccpa). in the ccpa, personal data is defined as:

"Personal information is information that identifies, relates to, or could reasonably be linked with you or your household."

and, you do have the rights set forth in the ccpa (know, delete, correct, limit exposure, etc.) regarding that data.

Re: I wrote to Flock's privacy contact to opt out of their domestic spying program

#140

Earlier quoted context omitted.

I looked it up at https://cppa.ca.gov/data_broker_registry/ and didn't find Flock / Flock Safety in that list of the currently registered 566 data brokers.

Because Flock isn't a data broker. Flock's customers own their data, not Flock, and they use Flock's platform voluntarily to share data with other customers.

So… Flock uses their own platform and top to bottom tech stack to do everything technically? Your local PD doesn’t use random cameras (like Reolink), doesn’t run a custom software stack (like Frigate in a container on some random VM hosted with AWS), doesn’t store the data wherever (like Backblaze)? The customers just have to install the Flock cameras and “order” the subsequent data from Flock? But you say they’re not at all responsible or accountable for any it because despite doing everything at every step, they’re “just a broker”?
Post reply on HN