Categories
Mission News privacy shotspotter

End Cambridge’s Use of ShotSpotter Once and for All

[This alert is from The Black Response; Digital Fourth is a member of “Stop ShotSpotter Camberville,” a coalition of community groups opposed to this surveillance technology.]

“On Monday, May 11, 2026, at 5:30 p.m., the Cambridge City Council is scheduled to vote on a policy order to end the City’s use of ShotSpotter microphones and remove the devices from Cambridge neighborhoods.

ShotSpotter is a network of microphones installed across the Port and Riverside (Coast) neighborhoods (see ShotSpotter dashboard). The system is marketed as a technology that detects loud sounds and alerts police to possible gunfire.

However, during the April 29 Public Safety Committee hearing (video not yet available), it became clear to council members and attendees that ShotSpotter is continuously listening. The Cambridge Police Department explained that when ShotSpotter detects a gunshot, the company provides them with an audio clip containing one second before and one second after the sound. This raised significant concerns because the existence of audio from before the alleged gunshot indicates that the system is actively listening at all times. [Not only that, but ShotSpotter records continuously over a 48-hour period; Cambridge PD acknowledged that that was so, and that recordings from within that timeframe were “useful for evidence.” – Digital Fourth]

Boston University Professor Spencer Piston emphasized the distinction between continuous recording and the alert that the police eventually receive, noting that while ShotSpotter may not permanently store all audio, the technology still relies on constant monitoring in order to generate alerts. This raises serious concerns.

Additional concerns were raised about the structure and oversight of the program in Cambridge. The current ShotSpotter system is funded through a Department of Homeland Security (DHS) grant, the same federal department that oversees ICE. Harvard Law School Professor Mason Kortz testified that the City of Cambridge is not itself a party to the current ShotSpotter contract operating in the city. As a result, city officials have reportedly faced difficulties obtaining and reviewing the contract. Since we are not party to the contract, residents lack clear protections regarding how data may be accessed, shared, or used.

The ACLU of Massachusetts, represented by lawyer Gideon Epstein, explained why ShotSpotter appears inconsistent with the standards established under Cambridge’s surveillance technology ordinance, a framework the ACLU helped develop.

Taken together, these concerns paint a troubling picture. Cambridge’s use of ShotSpotter may create risks that sensitive surveillance data could be accessed by federal agencies, including ICE, potentially undermining Cambridge’s commitments as a sanctuary city and Welcoming Community.

Four of the five members of the Cambridge Public Safety Committee, Councillors Al Zubi, McGovern, Nolan, and Sobrinho-Wheeler, have sponsored and submitted a policy order for the Monday, May 11, 2026 City Council meeting to remove ShotSpotter from Cambridge. The ShotSpotter policy order is the second item on the agenda: POR 2026-98.

We encourage community members to sign up for public comment and send letters in support of the policy order and to attend the meeting if possible. Please join us in supporting this important step toward ending Cambridge’s use of ShotSpotter.

Categories
privacy state

Support (and amend) the Mass. Consumer Data Privacy Act

We’re working hard, in coalition with a whole heap of other advocacy groups, to pass the first good general commercial privacy law for Massachusetts. It’s going surprisingly well. There’s a lot of legislative support, and it helps that people’s privacy is much in the news.

The Senate already passed their version, which had limitations – most notably, that it didn’t include a “private right of action” to enable individuals to sue corporations for violating their privacy.

Now, we’re working on the House, where the “Massachusetts Consumer Data Privacy Act” has been reported out of committee with a private right of action, and is with the Ways and Means Committee – the last step before reaching the floor for a vote. House Ways and Means is now under heavy industry pressure to weaken the bill before it gets there, which is what happened in the Senate.

We’re therefore urging Ways and Means members, and House legislators more generally, to report the MCDPA out favorably, without weakening it, and with four important strengthening amendments. These are:

  1. THRESHOLDS TO SUE: “EITHER/OR”, NOT “BOTH/AND”

Our first recommendation is to change H.4746’s language relating to the ability of private individuals to sue corporations that violate H.4746’s privacy rules. The Senate bill has no private right of action. The House bill’s private right of action is very limited. It sets a high, dual threshold, limiting it to corporations that have both over $200m in gross annual revenue and data on two million consumers. This dual barrier will enable certain companies that are collecting a lot of data, like phone apps, to slide under the radar.

Therefore, we’re suggesting that private individuals should be able to sue corporations that meet either of these thresholds. 

  1. PROTECT THE PRIVACY OF PEOPLE’S “PHILOSOPHICAL BELIEFS”

The federal government is investigating people to see if they pose a national security risk on the basis of their social media posts, communications or web searches. The President’s NSPM-7 memorandum declares philosophical beliefs like “anti-Americanism, anti-capitalism, and anti-Christianity; support for the overthrow of the United States Government; extremism on migration, race, and gender; and hostility towards those who hold traditional American views on family, religion, and morality”, as views that justify investigation of Americans by a Joint Terrorism Task Force (JTTF). Attorney General Bondi ordered the FBI’s JTTFs to prioritize the investigation of Americans with these beliefs, and ordinary Americans, like Renee Nicole Good, are being deemed “domestic terrorists” for nothing more than being in ICE’s way. A simple fix can protect the beliefs that we express in social media and communications, by including “philosophical beliefs” in the definition of sensitive data, as is already done in California’s Consumer Data Privacy Act.

  1. IMPROVE PROTECTION OF CHILDREN’S DATA

The Senate bill, S. 2619, says that data controllers are liable for mishandling “personal data of a consumer that a controller knows, or should have known, is a minor”. H.4746 changes this to “personal data of a consumer that a controller knows, or willfully disregards, is a minor.” That’s a significant weakening of the standard. It will be very hard for people suing a data controller to prove that the data controller “willfully disregarded” that the person whose data they mishandled was a minor. The Senate language is significantly better, and bringing the House language into line with the Senate’s in this respect would simplify the conferencing process.

  1. YOUR “GENETIC DATA” SHOULD NOT JUST INCLUDE YOUR DNA

The definition of sensitive data in the Senate bill includes “(iii) genetic, neural or biometric data” and “information derived therefrom.” This means that not only your DNA profile itself, but interpretive data, such as what 23andMe interprets your DNA profile to mean in terms of susceptibility to diseases or your inferred relationship to another person, would be classed as sensitive data. Similarly, not only the data “net” of your facial features created by facial recognition, but the fact that your face is interpreted as a 95% match to a criminal suspect, ought to qualify as sensitive data. So, we think that it is important to protect all data derived from cataloging the expression of our RNA and proteome. This could be accomplished by changing “genetic data” to “genomic data” (please see https://www.law.cornell.edu/cfr/text/28/202.224), and including the Senate’s phrase “information derived therefrom.”

LEGISLATIVE TEXT FOR THESE AMENDMENTS:

https://docs.google.com/document/d/1SgtWqTgLxSgWjw0hPp-BFfMGWeSlz2grgx4EHADiDS8/edit?tab=t.0 

Categories
cameras immigration News privacy

Cambridge Suspends Flock, But May Revive It Dec. 9

On Monday, October 20th, the Cambridge City Council voted to temporarily halt the city’s use of automatic license plate reader technology, including Flock Safety, because of concerns about privacy and data sharing with the federal government. 

Many community members offered oral public testimony, including members of Digital Fourth, the ACLU, collaborators, and other concerned citizens. Much of this testimony focused on issues with Flock Safety specifically, especially their issues with Flock’s recent history of sharing information with federal agencies. 

Members of the city council, including those who had voted in favor of moving forward with Flock Safety in February, were surprised and concerned by the issues with Flock Safety that were raised during public comment. Specifically, they were concerned by the idea that the information collected by Flock Safety cameras owned by Cambridge might be shared with Customs and Border Protection and Immigration and Customs Enforcement. Council Member Marc McGovern, who had initially voted in favor of Flock Safety in February, stated his concern about the testimony shared about the breaches of contract committed by Flock Safety against communities like Evanston, IL. McGovern said that “there are all sorts of loopholes in the control that we became more aware of over time.” 

After over an hour of public comment, the council voted unanimously to refer the issue to the Public Safety committee, and in the meantime, to suspend or revoke the use of Flock cameras. Many councilors expressed the desire to allow time for more public comment. 

The Cambridge Police Department has stated that none of the Flock Safety cameras are operational. Volunteers with Digital Fourth independently verified that the cameras have been removed. 

The governor’s thoughts on the development were shared in a recent CBS News article. She stated that “cameras are ubiquitous” and came out unambiguously in support of “responsible surveillance technology …when it comes to the investigation and deterrence of crime.” It remains to be seen what the Cambridge City Council and the Public Safety Committee will decide constitutes “responsible use.” 

Several members mentioned the possibility of working with a different automatic license plate reader company. However, recent reports have detailed issues of data sharing by other automatic license plate reader companies, as well. According to a recent report by 404 Media, an app recently demoed by Immigration and Customs Enforcement (ICE) allows officers to scan a license plate with their phones and cross-check it with millions of other records, like marriage records, license data, vehicle ownership, voter registrations, and ALPR data. This app partners with another ALPR company, Motorola Solutions. Though Flock has a particularly spotty record, when a municipal police department partners with an ALPR company, it is always difficult to confirm that the data collected by the cameras will not be used for purposes that the police department would not approve of. Even if an ALPR company seems to be using the data that they collect ethically at one point, this does not preclude them from changing their policies in the future. 

On December 9th, the city will discuss the Flock Safety at a Public Safety Committee meeting from 12pm-2pm. Invited panelists will include a Cambridge-based Digital Fourth representative, representatives from the ACLU, the Cambridge Police Department, and Flock Safety. 

As the Cambridge City Council prepares to turn over after the recent election, it is a vital time for privacy-concerned residents of Cambridge to make their voices heard. 

Categories
Mission News privacy state

Pass the Mass Digital Privacy Act

Your online identity without a good, comprehensive privacy law

Despite what industry would like us all to think, privacy is not dead!

Aren’t you tired of your data not being your own, of your digital life being carelessly smooshed up and segmented and sold across a thousand commercial and governmental databases? We’ve gotten used to putting up with what that means – the scams, the stress, the self-policing, the endless robocalls, the poorly targeted ads, the data-fueled AI chatbots and LLMs that mimic real thinking the way pink slime mimics a grass-fed steak. This is no way to live.

But it’s also not the only way to live. Here in the Commonwealth, we can do better, like Maryland and the EU have already done. Yesterday, Digital Fourth activists sent a coalition letter to Senate and House leadership, urging them to pass S.2516, the Massachusetts Digital Privacy Act. This is genuinely an excellent privacy bill — so good that industry has already swung into action against it, even though the bill is barely out of the Senate Committee on Advanced Technology (who did great work on this).

This bill includes:

  • Strong data minimization provisions, which limit:
    • the collection and use of personal data to what is reasonably necessary for a company to provide the data or service requested by a consumer
    • The collection and use of sensitive data to what is strictly necessary to provide the data or service requested by a consumer
  • A clear list of all of the kinds of data that must be regarded as sensitive.
  • Prohibition on the sale of sensitive data.
  • Requires affirmative consent of a consumer before each transfer of their personal data.
  • Provides every consumer with the right to see, correct verifiable inaccuracies in, and delete their personal data that has been collected by a company.
  • Gives consumers the right to opt out of targeted advertising or automated profiling.
  • Requiring that companies provide a clear and obvious privacy notice about their data collection practice and security measures and method to contact them for execution of all of a consumer’s rights.
  • Establishes a free automated mechanism whereby consumers can learn whether a data broker possesses their data and can request that their data be deleted.

Call your legislator to let them know they should support this bill!

COALITION LETTER: https://warrantless.org/wp-content/uploads/2025/06/MDPA-Leadership-Outreach-Letter-2025-06-12.pdf

DETAILED EXPLAINER: https://warrantless.org/wp-content/uploads/2025/06/The-Urgent-Need-for-Effective-Comprehensive-Data-Privacy-Protections-Created-in-MDPA-S.2516-.pdf

ENDORSERS:

We’re glad to say that we’re not alone in this fight: The letter was cosigned by AFL-CIO, the American Federation of Teachers, Fight for the Future, the National Council of Jewish Women, YW Boston and more, and now also the Consumer Federation of America.