Categories
cameras facial recognition Mission News

Don’t Ban Masks At Protests

Most Boston ICE protesters know to mask up. The rest, we blur out for their safety.

It’s hearings season at the State House, so this is when we put together testimony on bills that particularly relate to privacy, surveillance and the Fourth Amendment. But first, a little history on the issue of face masks and privacy.

Before wearing a surgical mask became politicized as “a thing woke liberals do,” the Boston police, in fall 2019, tried to criminalize the wearing of masks in public without criminal intent. We objected, and testified in masks, because wearing a mask shouldn’t give discretion to police to launch in and arrest you. For some reason, though, by the spring of 2020 nobody was interested in banning mask-wearing.

In 2023-25, as the pandemic receded, and in response to the Gaza ceasefire protests, elected officials also began dusting off mask bans as a way to signal that they, too, found such protests unacceptable. Most notably, Gov. Hochul of New York, citing anti-semitism concerns tried hard to revive a ban (Our national coalition joined NYCLU in opposing it). Police would love these bans to pass, because it’s a lot easier to identify people if they’re not wearing masks, whether you use facial recognition software or not.

Most recently, the Trump administration is trying to require both universities and local governments to hand over drone and camera data of protests, presumably so that the administration can then use facial recognition software to identify unmasked people engaging in disfavored activities as well as crimes. In the Los Angeles area this week, the federal government has directly intervened to conduct aerial surveillance of protests using drones, and connectedly, President Trump posted on June 5 on Truth Social, “From now on, MASKS WILL NOT BE ALLOWED to be worn at protests. What do these people have to hide, and why???”

Inappropriate aerial surveillance of protesters may escalate still further, into violence. Regarding this coming weekend’s military parade in DC, the President has threatened any protesters with “heavy force.” Abroad, U. S. military drone technology has already been used in attacks on weddings, funerals and hospitals. Even domestically, lethal extrajudicial attacks on members of disfavored groups and people accused of violence are not unknown. The guardrails intended to protect us at home from our own government are getting weaker. The new facial recognition and AI-based targeting capabilities of military technology mean that today’s protesters face risks of identification that previous generations of protesters did not. The First Amendment, of course, ought to restrain the President from escalating further; but he already has a track record of only refraining from violating the law, where he faces a realistic chance of personal legal or financial consequences. Who among us can be fully confident that he will rein himself in?

Our own organization has always been explicitly peaceful and law-abiding, but even peaceful people have an interest in being able to protest or just to move around in public, without having their facial features fed into a federal facial recognition algorithm for them to be investigated as an opponent or dissenter and “doxxed”, “swatted”, harassed or prosecuted. Both the Supreme Court and Massachusetts’ Supreme Judicial Court have now recognized that people have a privacy interest in the pattern of their movements in public. So we have good grounds for saying that masks are an important tool for the privacy-conscious.

To sum up, people can have perfectly valid reasons for masking, even if they have no health conditions that a mask would help with. Because of the risks to people’s privacy alone, we should not in any municipality in Massachusetts, at any point, be requiring people to unmask in public. We strongly support a favorable report for S. 1427‘s ban on municipal or board of health measures that prohibit “the wearing of face coverings for protective or medical use in any indoor or outdoor space open to the public.”

Our full testimony to the Joint Committee on Municipalities and Regional Government is here:

https://warrantless.org/wp-content/uploads/2025/06/D4-Municipalities-testimony-on-masking-2025-06-12.pdf

Categories
cameras News

The Risks of Automated Traffic Enforcement

It’s hearings season at the State House, so this is when we put together testimony on bills that particularly relate to privacy, surveillance and the Fourth Amendment.

Today, we submitted comments in opposition to “An Act Relative To Traffic Regulation Using Road Safety Cameras” (S. 2344, H. 3754). In the 1980s, Massachusetts banned automated parking enforcement, out of concerns over driver privacy. Now, influential legislators like Sen. Will Brownsberger are trying to overturn that ban, with the unanimous support of the Cambridge City Council. Here’s part of what we wrote to the Judiciary Committee on this bill:

Data Sharing Concerns

Historically, lawmakers didn’t pass our traffic laws with the thought that one day, technological change would let them be universally, rigidly and digitally enforced. They didn’t know then that it’s possible now to search archived camera footage to form a pattern of drivers’ movements in public, or that license plate reading software, if applied to that camera’s footage, is now being trawled through by officers in red states, searching nationwide for women suspected of having had an abortion. We also now have a federal administration newly interested in making unrealistic deportation quotas, and therefore using camera networks to identify, track and deport immigrants. […] [N]othing you [i.e., the Legislature] do here can bind what police departments in other states lawfully ask a vendor for, or what DHS asks a vendor for. You can’t prevent camera companies from lawfully responding to lawful federal data requests. The only way, therefore, to prevent out-of-state AGs or DHS from accessing such data is to not collect it in the first place.

Racial Profiling Concerns

Some well-meaning activists and legislators hope that automated traffic enforcement will diminish racism in police stops. It’s true that racial profiling in Massachusetts traffic stops has been extensively documented. But speed cameras won’t necessarily reduce racial profiling, because it will still be police who buy, monitor and maintain the cameras, set the thresholds, choose where cameras are placed, and decide who gets arrested. In Washington, DC, when police shifted to automated enforcement, racial biases persisted. Cameras are a diversion from, not a solution to racism, and efforts to automate out the human element merely obscure it from view.

If we’re concerned about police hurting people in traffic stops, then rather than automating policing, one solution is to allow unarmed civilian parking and traffic enforcement, diverting that responsibility from police, as several jurisdictions are currently exploring.

Corruption Concerns

Cities and towns are interested in automated traffic enforcement for two reasons: To increase road safety, and to increase revenue. This bill contains a provision that reasonably limits the income that camera vendors take in (in Section 7(a)), but, by doing so, it increases the incentive for cities and towns to adopt such cameras for revenue generation purposes. In Florida, where automated cameras are permitted, the corruption this has produced has been so severe that it even led to the state having to dissolve one town’s government. So, if this bill is to pass, it should remove the financial incentives to cities and towns, by having all ticket revenues go into the state general fund.

We respectfully urge you to send this bill to study. [ ]

Sincerely,

Alex Marthews, Alexandra Thorn and Christine Felice, Digital Fourth volunteers.

For our full comments, see below:

Categories
Mission News ordinances shotspotter

Cambridge Debates “ShotSpotter” Audio Monitoring

The following is a letter from Stephanie Guirand of The Black Response, a community group of current and former public housing residents concerned with racial justice, police abolition, and surveillance technologies. TBR has developed some good data visualizations of Cambridge’s ShotSpotter deployment here.

Dear Cambridge City Councilors,

I am writing on behalf of The Black Response and the Stop ShotSpotter Coalition – Camberville to thank you for convening a thoughtful and deeply informative Public Safety Committee hearing on ShotSpotter on Monday. We are especially appreciative of Councilor Ayesha Wilson for her skillful facilitation and for managing a logistically complex session with care and focus. We also thank Councilors McGovern, Siddiqui, Sobrinho-Wheeler, Toner, and Zusy for their presence and engagement, as well as Police Commissioner Elow and her colleagues for taking this issue seriously and participating in good faith.

We can all agree that we are in a fight to preserve democracy nationally. At Monday’s hearing, we saw democracy in action. The public, councilors, CPD, researchers, legal experts, and community organizations engaged in meaningful dialogue on a highly consequential issue, ShotSpotter. While we appreciate the opportunity to be heard, several critical concerns raised during the hearing merit follow-up.

ShotSpotter is Always-On and Recording, and Other Privacy Concerns

One of the clearest takeaways from the expert testimony, especially from Professors Spencer Piston and Robert Maher, is that ShotSpotter is a network of microphones that are always on. Regardless of whether audio is stored for 24 or 72 hours, the reality is that these microphones are continuously listening and recording. Whether or not street-level conversation triggers a sensor to send local law enforcement doesn’t matter, the microphones are always listening. Professor Maher affirmed, and Professor Piston supported with legal precedent, that these microphones are capable of picking up and transmitting street-level conversations.

This raises a fundamental difference from personal recording devices (e.g., Smartphones, Alexa), which people knowingly use and control in everyday life. The vast majority of Cambridge residents are unaware of the ShotSpotter microphones. They do not know that they may be recorded while speaking outside or near these microphones. That lack of informed consent raises serious privacy and civil liberties concerns.

The Overstated Utility of ShotSpotter for Law Enforcement

During the hearing, we repeatedly heard from councilors, the police, SoundThinking representatives, and the District Attorney that ShotSpotter is “just one tool among many” used to address gun crime in the city. Police Commissioner Elow opened her remarks by assuring the public that “no one has been arrested solely on the basis of ShotSpotter” (or something to that effect). However, this reassurance raises important questions about the actual utility of the ShotSpotter microphones.

Interpretations of current research (see Carr et al) suggest the presence of ShotSpotter may actually discourage members of the public from calling 911, undermining one of the most direct and community-driven tools for emergency response and investigation.

The data presented by the Cambridge Police Department did not demonstrate a clear or urgent need for ShotSpotter’s microphone technology. Despite the privacy concerns it raises, the numbers failed to show a meaningful impact on reducing gun violence or increasing arrest or conviction rates for gun-related offenses.

Additionally, attorney Connie Tran provided important clarification during the hearing. She debunked a misleading description of a case in which she represented a client who was falsely accused, and ultimately cleared, of gun charges that had originated from a ShotSpotter alert. Tran also noted that the Massachusetts Supreme Judicial Court has raised concerns about the scientific reliability of ShotSpotter and is now requiring courts to evaluate the soundness of ShotSpotter in relevant cases.

If ShotSpotter does not meaningfully reduce gun violence, does not lead to arrests or convictions, and is increasingly under judicial scrutiny for its lack of scientific reliability, we are left wondering: What is its true utility in Cambridge?

Potential Infringement on Civil Liberties of Cambridge Residents

One of the most striking themes to emerge during the hearing, and repeated during public comment, was the tension between the public’s right to privacy and the City’s use of ShotSpotter. At its core, this is more than a debate about a surveillance tool. It is a question of what we value as a community. Should residents be asked to give up their right to privacy in exchange for a law enforcement tool that has demonstrated limited effectiveness?

As experts explained during the hearing, ShotSpotter relies on microphones that are always on and continuously listening. While SoundThinking claims that recordings are only retained for 24 hours (previously 72 hours), the fact remains that these devices are always active in public spaces. Again, most people do not realize that their conversations on the street could be recorded without their knowledge or consent.

The benefits presented by law enforcement were modest at best. In eleven years, ShotSpotter was credited with saving one life in Cambridge. It was unclear whether that incident was also reported through a 911 call. In another instance, there was a confirmed gun incident without a 911 report. It is still not clear if these are two separate cases or the same one. Even if they are different, the impact of ShotSpotter over a decade appears limited.

Despite this, law enforcement and the District Attorney argued that ShotSpotter is a valuable tool beyond its intended function, to identify audio of gun incidents and alert law enforcement to the location of the gun incident. They described instances in which alerts led to broader investigations. For example, in a case discussed at the hearing, a ShotSpotter alert ultimately resulted in a conviction for a restraining order violation, but the person was acquitted of all gun-related charges. This was attorney Connie Tran’s case. While public safety is of course important, using ShotSpotter to extend the reach of investigations raises serious concerns. This pattern suggests that the tool is being used in ways not originally intended, scientifically investigated, or publicly debated.

Professor Spencer Piston raised a similar issue when discussing a class-action lawsuit in Chicago (William v City of Chicago). In that case, plaintiffs argue that ShotSpotter has led to increased policing, stop and frisk, in Black and Brown neighborhoods. They claim that the technology results in over-surveillance and unnecessary police encounters, often unrelated to gun violence. This pattern of overreach is at the heart of their legal challenge.

If local authorities are already stretching the use of ShotSpotter, there is reason to question whether the company itself, or its funders, might also be doing so. In this case, ShotSpotter is funded not by the City of Cambridge, but by the Department of Homeland Security. That funding relationship, between SoundThinking and the Department of Homeland Security, calls into question who truly controls the ShotSpotter technology (and the data it produces) in Cambridge. If the federal government is the real client, what assurances does the City of Cambridge have about how the data is being used or shared?

Without a clear and publicly available contract, it is difficult to verify what protections exist. The City of Cambridge cannot simply rely on verbal assurances from the SoundThinking salesman, or as a Cambridge police officer referred to him, “their colleague.” As attorney Connie Tran points out, the SoundThinking representative during the trial was under oath, and it was there that more information about the function of ShotSpotter was revealed. There must be enforceable limits, transparency, and oversight. The presence of always-on microphones in public spaces, especially without widespread awareness or consent, raises fundamental questions about civil liberties. If the benefits are so limited, is the trade-off worth it?

Cambridge must ask whether this is a reasonable and responsible use of public space and public trust to continue to use ShotSpotter microphones. If not, then it is time to reconsider whether ShotSpotter belongs in our city at all.

Lack of Contract Oversight

We were deeply alarmed to learn during the hearing that the City Solicitor has not yet seen or reviewed the contract that governs the relationship between the City of Cambridge and SoundThinking. The City has a duty to ensure that its agreements, particularly those involving surveillance technologies, are transparent, legally sound, and in compliance with Cambridge’s Surveillance Technology Ordinance.

We strongly urge the Council to:

  • Immediately obtain the full contract with SoundThinking,
  • Make the document publicly accessible, and
  • Schedule a follow-up hearing focused specifically on the contract and its legal implications.

Federal Influence and Sanctuary City Values

Although SoundThinking’s sales representative, Alfred Lewers, claimed that Cambridge data is only shared with the City of Cambridge, the fact that the Department of Homeland Security funds the ShotSpotter system casts serious doubt on that assurance, especially given SoundThinking’s unrestricted ability to share data as established in their contracts (see available contract with Boston). It appears that DHS, not the City, is the true client. We understand this because the City does not appear to even have the contract between the City and SoundThinking. This suggests that SoundThinking has no obligation to uphold Cambridge’s Sanctuary City protections, and the public has no way of verifying who else may access these recordings or how the data is ultimately used.

This raises an important question: if, under the current federal administration, our Sanctuary City status limits federal funding for social programs, why is DHS funding a surveillance system in our city and why is the City of Cambridge working to set it up for them? What does that say about the federal government’s priorities—and about our own?

Lack of Transparency on Device Locations

SoundThinking’s explanation for why device locations are withheld from the public was underwhelming at best. Fortunately, our coalition obtained a leaked list of ShotSpotter microphone locations, which we have since verified by physically visiting the sites. These microphones are disproportionately located on top of public buildings, including public housing and section 8 buildings, confirming that marginalized communities are bearing the brunt of this audio surveillance (see our map).

At the hearing, SoundThinking introduced a paid “dashboard” service that visualizes ShotSpotter data. We see no justification for Cambridge to spend any taxpayer dollars on this, especially when a free and equally effective alternative already exists. In preparation for the hearing, The Black Response developed a publicly accessible dashboard using data from Cambridge’s Bridgestats reports. We offer our dashboard to the city for free (The Black Response’s ShotSpotter data dashboard). If the city does not trust our dashboard, why not contract out this work to other local community organizations or universities in the City?

Incomplete Participation and Need for Follow-Up

Due to time constraints, two of our expert panelists, Jonathan Manes from the MacArthur Justice Center and Abdul Nasser Rad, a quantitative researcher from Campaign Zero, were not able to share their insights during the hearing. In addition, at least a dozen residents who signed up for public comment were not called upon.

We believe a follow-up session is necessary to allow for these important voices to be heard and for unanswered questions to be addressed. We would be more than willing to help coordinate that effort in partnership with the City.

A Call for a Temporary Freeze

We also want to echo the concern raised by Councilor Zusy: perhaps it is time to consider a (temporary) freeze on the use of ShotSpotter in Cambridge. This would be a prudent and responsible step while the City investigates the legal, ethical, and operational implications of ShotSpotter microphones. In an era where federal law enforcement agencies have demonstrated increasing disregard for legal norms and human rights, we cannot afford to take these risks lightly, especially in communities that are already vulnerable.

Thank you again for your leadership and for demonstrating what democratic governance should look like: accessible, informed, transparent, and responsive. We look forward to continuing this vital conversation and working with the City to ensure public safety strategies are both effective and equitable.

In community,

Stephanie Guirand
The Black Response
On behalf of the Stop ShotSpotter Coalition – Camberville

Categories
immigration Mission ordinances

Our New “ICE Agent Identification Ordinance”

There is a (mostly) new trend in ICE raids, where ICE agents show up masked, and refuse to identify themselves, either to the public or local police. There is also a new trend of people impersonating ICE agents, because they find it gives them license to harass members of the public, abduct and sexually assault them, or even spring them from jail. When purported ICE agents show up and refuse to identify, like they did in Chelsea, MA on May 11, 2025, it causes fear among the public and confusion among police officers. Is the person in front of them an ICE agent or not? Does the officer even have the power to try to find out?

To address this problem, Digital Fourth has developed “ICE Agent Identification Ordinance” text for Massachusetts cities (this example is tailored for Cambridge), and is working with City Councilmembers in Cambridge, Boston and Amherst (so far) to get such ordinances passed.

Technical note: The key trouble folks have had in figuring out what to do with unidentified people purporting to be ICE agents, is that federal law doesn’t in fact require federal law enforcement or immigration officers to identify themselves (though DHS regulations do). Local laws don’t supersede federal law, so a local ordinance can’t require actual ICE agents to identify themselves. But, we realized, local laws can require local police to ask, not require, purported ICE agents to identify themselves to local police. Then, if the purported ICE agent refuses to do so, local laws can also require local police to treat the purported ICE agent as they would an ordinary member of the public. If the purported ICE agent does identify themselves successfully, however, local police don’t have the power to “forcibly impede or oppose” them in their conduct of a raid.

Digital Fourth was instrumental in passing surveillance technology oversight ordinances and facial recognition bans in Cambridge, Somerville and Boston in 2017-22. This draft language has been through attorney review. To request text adapted to your Massachusetts city, click here.

UPDATE: C. Scott Ananian in the Town of Brookline has alerted us to the excellent By-Law he helped Brookline pass on the issue of ICE raids in December 2024. Town officials may wish to use this, as an example of language that has already passed Town processes.

Categories
News

DHS Orders Harvard To Hand Over Surveillance Footage Of All Protests “Involving A Nonimmigrant Student”

We regularly tell elected officials that the best way to protect people’s privacy is to not adopt surveillance technologies in the first place. For example, right now, Cambridge City Council is considering whether to allow Cambridge PD to operate drones over protests. We have highlighted to them that no matter what they say about Cambridge values, once they give that permission, they won’t really be able to control what data gets collected, or where that data goes.

Now, that has been vividly brought home by an extraordinary data request to Harvard from the Department of Homeland Security. DHS has suspended Harvard’s ability to admit or to continue teaching already-admitted international students, and is giving Harvard 72 hours to undo that suspension by supplying:

1. Any and all records, whether official or informal, in the possession of Harvard University, including electronic records and audio or video footage, regarding illegal activity whether on or off campus, by a nonimmigrant student enrolled in Harvard University in the last five years. 2. Any and all records, whether official or informal, in the possession of Harvard University, including electronic records and audio or video footage, regarding dangerous or violent activity whether on or off campus, by a nonimmigrant student enrolled in Harvard University in the last five years. 3. Any and all records, whether official or informal, in the possession of Harvard University, including electronic records and audio or video footage, regarding threats to other students or university personnel whether on or off campus, by a nonimmigrant student enrolled in Harvard University in the last five years. 4. Any and all records, whether official or informal, in the possession of Harvard University, including electronic records and audio or video footage, regarding deprivation of rights of other classmates or university personnel whether on or off campus, by a nonimmigrant student enrolled in Harvard University in the last five years. 5. Any and all disciplinary records of all nonimmigrant students enrolled in Harvard University in the last five years. 6. Any and all audio or video footage, in the possession of Harvard University, of any protest activity involving a nonimmigrant student on a Harvard University campus in the last five years.

Harvard is suing, and we hope they win.

But this is also a red alert to colleges and to municipal governments alike, that they can’t assume that any data they collect and retain, will be safe from a government intent on obtaining it. If Harvard or Harvard PD has retained “audio or video footage” of protests going back “five years”, they shouldn’t have done so, except for specific excerpts that are being retained in relation to still-ongoing disciplinary proceedings. College police departments should in general not conduct surveillance of on-campus protests, because this is exactly where it leads.

As a group, we don’t have expertise in how to solve conflicting land claims in the Middle East. But we do know surveillance and privacy, and we have been meeting and working on that issue in Cambridge since 2012. Everybody, including foreign students at U. S. colleges, has the right to peacefully petition for a redress of grievance. That’s a vital part of the First Amendment. As a consequence of the fact that peaceful protest is Constitutionally protected, the Fourth Amendment protects them from the government unreasonably seizing their person for protesting, or from seizing their location data showing they were at a protest, or seizing an image of them being at a protest and using it to sure they lose their place at a college, or their job at a college, as a result of being at a protest. Harvard also has its own rights, to keep its own records private, provided it is complying with the laws and regulations that govern its operation as a university. The government has not alleged that Harvard has violated any regulation or law relating to the operation of the student visa program, and even if they were to allege or even prove that Harvard did, the government should not have the power to obtain footage of this kind.

We claim proudly to be free. But freedom isn’t a theory. It’s a practice, made up of whether we choose day by day to prioritize freedom over other things. Colleges and municipal governments should review what they choose to collect with this principle in mind.

UPDATE 05/23/25, 12:30pm: Temporary restraining order granted, https://www.bloomberg.com/news/articles/2025-05-23/harvard-gets-temporary-block-of-trump-s-foreign-student-ban

Categories
News

Privacy Advances in Massachusetts Senate

We have been working hard with partners like EPIC and Consumer Reports to advance a strong, broad commercial privacy bill in the Massachusetts legislature.

This is part of a national effort to counter industry pressure to pass weak state privacy laws (the “Connecticut model“) that put the profits of large data brokers and social media companies over the privacy of ordinary Americans.

The bill that has come out of committee, S.2516, is a redrafted version of the Massachusetts Data Privacy Act (“MDPA”). If enacted, MDPA would be the strongest state privacy law in the nation. It would be most similar to a bill passed in Maryland in 2024.

MDPA is especially strong on data minimization. It bans the sale of precise geolocation data, data about minors, and health data, incorporating the provisions of the narrower Location Shield Act (which we also support). Crucially, it includes a private right of action, meaning that enforcement isn’t reserved for the overburdened Massachusetts Attorney-General’s office, but can be undertaken by the people themselves whose privacy has been harmed. It includes a data broker registry, and a one-stop mechanism for Massachusetts residents to delete their data held by data brokers.

We commend Democratic Senators Moore, Creem, Stone, Driscoll, Comerford, Rausch, Eldridge, Cyr and Jehlen, and Republican Rep. Bradley Jones, for cosponsoring this bill and for their help in moving it to this point. Particular praise is also due to Digital Fourth Co-Chair Julie B., for tirelessly helping legislators with comparisons of bill texts, and for mobilizing calls to legislators from Digital Fourth members, from teachers, and from American Legion members concerned about the privacy of servicemembers, veterans and their families.

However, the bill still has a long way to go before becoming law. The House High-Technology Committee will likely pass its own version, which may be weaker than the Senate’s. Meanwhile, the Senate Ways and Means Committee will consider whether to report the bill out to the floor, and good bills often die in Ways and Means. So, we ask readers and members to call 617-722-1481 today, to let the Senate Ways and Means to let them know you support this bill, and that passing it should be a priority.

Categories
Uncategorized

Action Alert: Email Boston City Council **UPDATED x 2**

Please email the Boston City Council or call your Councilors, to express opposition to the acceptance of $3.4 million in state funding for the Boston Regional Intelligence Center.

By 2021, a mountain of evidence had accumulated that the Boston Regional Intelligence Center (BRIC), run out of the Boston Police Department, was spying on the residents of Boston and its surrounding municipalities, without reasonable suspicion of a resident’s personal involvement in an actual crime. Their racist “gang database” targets young people of color, even in some cases deporting them, without their having committed any crime. Their license plate reader systems keep tabs on where Bostonians come and go; they harass and intimidate filmmakers, Black Lives Matter protesters, and journalists engaging in First Amendment-protected activity. And nobody has ever obtained redress from them for violating Boston residents’ rights.

As a result, Boston City Council, in 2021, led by now-AG Andrea Campbell and then-Councilor Wu, voted to reject $850,000 in funding for BRIC.

Two weeks ago, now-Mayor Wu and Chair of Public Safety Flaherty brought forward a motion to waive a hearing to accept the same $850,000 in funding that the City Council had previously rejected. And another $850,000, for 2022. Oh, and another $850,000 for 2023. And another for 2024, totaling $3.4 million. The City Council rejected the motion to waive the hearing. On Sep 20, the City Council voted to refer the grants to the Public Safety Committee for a hearing. The hearing took place Friday, September 29 at Boston City Hall. Now, we’re expecting a Council vote this coming Wednesday, October 4, at their 12pm Council meeting.

The public hearing involved two hours of obfuscations and lies from Acting Director Walsh of BRIC and Commissioner Cox. There was explosive public testimony from filmmakers Lauren Pespisa and Rod Webber, who were targeted and harassed by white supremacist BRIC officer Andrew Creed, on the basis of a tip from a Proud Boy:

Local resident Will Justice, who was cleared of a charge of armed robbery, spoke about BRIC circulating alerts to local police after he was acquitted to be on the watch for him, which has led to his being stopped, pulled over and harassed and losing employment opportunities.

Mickey Metts, technologist and free software advocate, testified about how BRIC targets Boston’s “poorest neighborhoods with surveillance and isolation. Small things add up and create an atmosphere of unrest so police may respond with violence.”

We were joined by the Muslim Justice League, the Campaign for Juvenile Justice, and, remotely, by the ACLU of Massachusetts.

Each $850,000 motion simply says it’s for “upgrading, expanding, and integrating technology and protocols related to anti-terrorism, anti-crime, anti-gang and emergency response.” In practice, the grants would pay for more analysts and liaisons, to improve the efficiency of the surveillance state.

We say No. Council should keep rejecting this funding. BRIC is a secretive, unaccountable, scandal-ridden organization, that doesn’t deserve extra public funds on top of the already-large police budget. As Councilor Coletta argued, there should be an external, independent audit, such as those proposed here, to show that they are no longer violating the rights of the residents of Boston and the municipalities that surround it, before Council approves this extra money.

Categories
Uncategorized

The Seven Years’ War

Boston police used their fusion center to surveil my journalistic actions. It took nearly seven years for BPD to hold itself somewhat accountable, and only after they used my information in a Department of Homeland Security conference presentation.

The department violated transparency laws and their own policies to hide their surveillance of me covering the Boston Marathon as a reporter. Despite their silence and purging of records, I finally got answers.


In April 2015, two years after the bombing of the Boston Marathon, the city’s police announced that they would detain anyone present on the streets around the finish line on the day of the race in order to search their personal property. The Boston Police Department also announced a sweeping ban on bags and containers (unless they were small and transparent).

While the events of 2013 spurred compelling reasons to upgrade security measures, they didn’t unwrite constitutional protections against unreasonable search and seizure. Or at least that’s what I thought, and so my goal on Marathon Monday in 2015 was to examine the gray area police were operating in by phrasing the bans as requests but then enforcing them like laws.

My news-gathering activities that day were monitored by law enforcement who identified my former news outlet, the Bay State Examiner, and knew they were tracking a journalist. As part of their targeted monitoring, officers disseminated a live timeline of my travel and activity to all their colleagues and partners from various local, state, and federal agencies. Later, they would use a photo of their surveillance operation-in-progress in a presentation at a Department of Homeland Security conference to brag about their skill in real-time tracking of a target.

Only now, years after I complained about this chilling violation of my First Amendment rights and privacy, do I know the truth about what happened behind the scenes—including how the Boston police handled my complaint. The lesson they appear to have learned: if the department conducts similar surveillance on reporters in the future, they need to do a better job of covering their actions to avoid getting discredited and exposed.

Marathon Monday, 2015

The marathon was in progress when I entered an area near the security hub near the finish line wearing a backpack. To begin documenting the checkpoints, I spoke with security guards and police officers and asked what would happen if I entered the area and exercised my Fourth Amendment rights to refuse to allow a search of my bags. They initially responded that I would not be able to enter through the checkpoint, but I wasn’t threatened with arrest. 

I didn’t know it at the time, but as I advanced to other checkpoints and continued to ask questions about bag searches, police began to monitor me as the only “Sig[nificant]” security event present. At some checkpoints, cops said that I would be arrested if I entered the secure area, despite it being a public sidewalk, while declining to allow a search of my bag (the contents of which included a wooden middle-finger statue and about a hundred printed copies of the Fourth Amendment). 

In speaking with police in Back Bay, there was confusion about what I’d actually be cuffed for. Still, they were explicit in that I would be arrested. Eventually, they said the charges would be for disorderly conduct due to my refusing to allow a search of my bag.

After that explanatory interaction, another cop tailed me to the next checkpoint. When I asked the checkers there if they’d arrest me for trying to enter with my bag, I was told no, but that I would “be dealt with accordingly”—a threat to stop me by force, but without detaining me. Their behavior only escalated from there; I was then physically removed from two other checkpoints by cops. I was not injured, but noted that the use of physical force on a journalist for declining a search of her bags on a public sidewalk is not justifiable. In comparison, police routinely arrest members of the public for using the level of force that they used on me against officers.

As I now know, my journalistic attempts to document the BPD’s unconstitutional bag searches led to my actions being deemed that day’s “significant event.” As a result of this designation, I was tracked, with data on my real-time location and activity broadcast to all working law enforcement by the BPD-run Boston Regional Intelligence Center, better known as the BRIC.

BRIC is one of America’s many regional fusion centers, which are law enforcement hubs built under the guise of the war on terror. They supposedly exist to pass intelligence between federal, state, and local agencies with the idea that such coordination will help foil terrorist plots. In practice, however, the BRIC has been used to, among other things, build a problematic “gang database” that was rebuked by the courts, to target activists and journalists like myself, and to circumvent sanctuary city policies so that Boston school records could be used in deportation hearings against students

On Marathon Monday 2015, BRIC helped officers working the race perimeter target and monitor a journalist. In doing so, those manning the intelligence center failed to follow their own privacy policy by spreading information about me without checking that information’s value. This failure coincides with, and appears to have led to, the aforementioned escalations in tactics including threatening and violent policing of me. They also violated their privacy policy by showing a photo of their surveillance setup in a presentation made to a number of law enforcement agencies, plus broke the Bay State’s public information law by purging records they received and shared about me.

Image via BRIC presentation at DHS headquarters

BRIC city

I learned about the BRIC’s surveillance of me several months after the 2015 Boston Marathon. The discovery came after BPD/BRIC Senior Intelligence Analyst Ryan Walsh spoke at DHS headquarters in Washington, DC during the agency’s National Geospatial Preparedness Summit later that year. His presentation, including a photo from the BRIC’s Boston Marathon command center, was posted online where it was found by another journalist and also flagged by the ACLU

On Oct. 24, 2015, I sought all records related to my surveillance under the Massachusetts public records law. The BPD violated the law by missing the 10(ish) business day deadline to respond; then, on Nov. 16, they claimed to not have any records. I responded by sending them the picture from the BRIC presentation that clearly shows that they had records of law enforcement surveillance occurring. The department never turned over those records, despite the law requiring them to and it being a violation that could carry fines or jail time (if the law were ever enforced).

Seeking another course of action, I then examined the BRIC privacy policy, which states that “if an individual has a complaint with regard to the accuracy or completeness of terrorism-related protected information that … Is exempt from disclosure … or … Is held by the BRIC and … Allegedly has resulted in demonstrable harm to the complainant … the individual may submit a complaint.” After which, “The Privacy Officer, on behalf of the Privacy Committee, will then acknowledge the complaint and state that it will be reviewed, but will not confirm the existence or nonexistence of the information to the complainant unless otherwise required by law.”

On Nov. 28, 2015, I filed a complaint under the above provisions with help from Digital Fourth, a nonprofit that advocates for Fourth Amendment rights. I was in a rare situation, where the existence of the picture from the presentation at the DPH proved the BRIC had watched me and passed records about me and my news outlet to other law enforcement outfits. Due to their reporting about my activity, the officers I met at checkpoints intensified our encounters, first to threats and then to the actual use of physical force. I clearly had standing to make a privacy complaint under the policy, and cited harms related to my physical treatment as well as the chilling effect that such handling and surveillance has on the First Amendment’s free press protections.

My complaint also addressed the violation of the state’s public records law—both in terms of missing the 10-day window to respond to my request, and then for returning a response saying they had no records about me or the Bay State Examiner when their own presentation showed that to be untrue. The state’s public records law is dysfunctional and rarely enforced, but I still asked the Secretary of the Commonwealth’s office (which oversees the law) to send the case to the Attorney General’s Office for criminal prosecution. Violations of the law can carry fines and penalties including up to a year of prison time, but despite the clearcut violations, no enforcement action was taken.

After a long wait … 

Nearly six years passed before I heard anything about my complaint. Even then, the information didn’t come from the BPD or BRIC.

In August 2021, Emiliano Falcon, policy counsel for the Technology for Liberty Program at the ACLU of Massachusetts, received a partial log of cases pending before the BRIC Privacy Committee. My complaint was among them. In September 2022, Digital Fourth obtained a full copy of the fusion center’s privacy log. According to that document, my complaint had moved from “pending” to “resolved.”

Getting a complaint sent to the so-called Privacy Committee sounds like it should have been a step towards some answers. However, subsequent public records work by Digital Fourth found that “prior to September 2022, the ‘Privacy Committee’ was not an official board with standing meetings. … Meeting minutes or agendas were not drafted.” In other words, no records exist that could show what was done about my complaint, by who, or even when.

What we do know is that in the time since they were called out for the activities described herein, the BPD and BRIC have not made public efforts to improve relations with the media or the department’s compliance with the records law. Critics including the ACLU have fried the fusion center on multiple occasions. And while the Boston City Council has put some checks on law enforcement in place around these issues, BPD is always seeking workarounds and back doors.

At this year’s marathon, targeted policing was again on full display. A massive police presence was rolled out at the Heartbreak Hill cheer zone. The area was home base for two of the region’s premier clubs for BIPOC runners, and reportedly had more attention from authorities than locations nearby where there were drunk people vomiting on the actual course. The over-policing was flagrant enough (and documented in enough viral videos) that the Boston Athletic Association even had to apologize.

The policing of a section of this year’s race where Black running clubs were gathered made national news

Let the records show

As Digital Fourth and I learned more than half-a-decade after the incident, the BRIC first fielded an inquiry about their monitoring of me from another journalist whose name and publication are redacted in the privacy log. The reporter asked why the BRIC was monitoring the media, and according to their log from Nov. 9, 2015, the agency explained in response: “The purpose of the presentation was mistaken. The presentation was showing the capabilities of the software to share activities in real time to assist our (BPD) management of dynamic events, and this was an example of that capability, nothing to do with relationship with the media.”

Another BRIC privacy log, from December 2015, addresses my complaint:

On December 8, David Carabin,” [Carabin is now the director of the BRIC, and was on the 2016 National Geospatial Preparedness Summit steering committee]  “received and reviewed a letter addressed to the BRIC Privacy Committee…

Synopsis: On August 4th, the BRIC presented at the National Geospatial Preparedness Summit in Washington, DC. The presentation was intended to share GIS (mapping) related lessons learned by the BRIC over the last several years in our efforts to provide support to BPD’s special events and critical incidents, and our development of a “Common Operating Picture” (COP) for sharing operational information during such events/incidents in real time. On October 19, we were advised that our presentation was posted on the internet by the hosts of the training conference. We requested that it be removed and destroyed, and our request was honored. Unfortunately, the ACLU and others picked up on it, found it controversial and brought additional attention to it on Twitter.

The “unfortunate” part of the incident—that the media and watchdogs caught them, not that they targeted a journalist in the first place. The entry continues:

One of the slides includes a photo of our COP while it was being used during the 2015 Boston Marathon. In the photo (attached), there is a stream of information being shared, advising leadership that “3 individuals from the [REDACTED] [are] going from checkpoint to checkpoint testing security measures and filming interactions…” If you recall, this originally was reported as suspicious activity involving unknown people testing security checkpoints, and it was later determined to be the [REDACTED].”

In Ms. [REDACTED]’s letter, she advises of several matters that she believes to be a violation of the BRIC’s Privacy Policy, but also violations to her rights. She also believes that we did not properly honor her FOIA from March 13, 2015, requesting all BRIC files on “[REDACTED]” and/or the “[REDACTED]”. BPD’s response advised that the BRIC does NOT have records that satisfy her request. 

The fact of the matter is that the BRIC did not and still does not have records on [REDACTED] or the [REDACTED]. The photo is not part of an intelligence file or record of criminal activity, nor was the original information retained for intelligence purposes.

The record does exist. I requested it. Under the law, that is a responsive record. They claim it isn’t responsive because it wasn’t “retained for intelligence purposes,” but the law does not consider why a record exists or what it was retained for, except to check to see if it falls under a specific exemption. If it is exempt, the record’s existence must be disclosed and the exemption must be cited with an explanation as to why it applies to the record. Agencies cannot pretend the record does not exist.

BRIC respondents also claimed that the “original information was shared by a partner agency to advise on the context of a situation that was affecting security procedures during the Boston Marathon, and this information was purged after the event.” This appears to be an explanation of how BRIC agents destroyed records related to the monitoring of a journalist, and since the state has thorough laws determining retention, it could also be a blunt admission of criminal destruction of records.

Left unaddressed in the intel center’s minimal opaque responses is that the BRIC’s privacy policy states agents cannot share information without first assessing it for sensitive data, checking its value, and attempting to verify. The BRIC/BPD received and shared my info, both of which should have triggered copy retention. But if they shared my info in real time, they could not have possibly verified or assessed it. Meanwhile, the BRIC must have determined that the information was not valuable, given the agency’s claim that they “purged” all the records related to me immediately after the event.

Nearly 500 Massachusetts National Guardsmen were activated to augment local authorities in providing public safety missions during the 2015 Boston Marathon, April 20, 2015. The Soldiers and Airmen provided route security along the historic route of the Boston Marathon. (Image and description via Massachusetts National Guard)

Transparency time travel

In an apparent desperate attempt to discredit me internally while dodging my inquiries, the BRIC accused me of either lying or traveling through time. As their logs falsely claim: my “FOIA request was received and handled on March 13, 2015 and handled/resolved on March 18, 2015. This was a month BEFORE the 2015 Boston Marathon. So, both the activities and the photo that she is complaining about did NOT exist at the time of her FOIA, which makes at least part of her argument irrelevant.”

In present-day reality, the request I made on Oct. 24, 2015 did not arrive at the BRIC/BPD on March 13, 2015. I do not have a flux capacitor; rather, they created a bizarre fiction (my copy of the records request can be seen here). The logs also claim my case was sent to a board that we now know didn’t meaningfully exist at the time: “On 12/8/15, this information was forwarded to the BRIC’s leadership and Privacy Committee, as well as BPD Legal and Media Relations, for advisement.”

At no point in the seven-year long complaint process was I contacted—including when the complaint was “resolved.” Still, the incident and coverup had a significant effect on me. The fact that cops can so freely surveil a reporter using a counterterrorism fusion center and broadcast her information to law enforcement brings the First Amendment’s freedom of the press protections into question. In my case, I wound up stepping away from in-person police documentation, in part because I was concerned about having the cops target me among other possible repercussions.

At the same time, I’m glad that I was able to follow up on my complaint. As it turns out, I can travel through time after all—almost eight years, into the future, to finally see how I was targeted and watched, and to then report back to the public about what happens when the media attempts to impugn law enforcement misconduct and blatant violations of our right to privacy.

Categories
Uncategorized

It’s A Whole New World

Every two years, the Massachusetts legislature starts a fresh session. Here, we review bills on the top ten topics relating to surveillance, privacy and the Fourth Amendment, that have been introduced in the new session.

Please contact your legislators via https://malegislature.gov/Search/FindMyLegislator, to express your support, and to ask for theirs. Our thanks to Julie Bernstein for conducting the legislative research for this article.

1. Civil Asset Forfeitures: HD1780 / SD2388, HD1328
2. QUALIFIED IMMUNITY REFORM: SD1970
3. Oversight of Fusion Centers: HD2088
4. Commercial Data Privacy Protection: SD745
5. Restricting Law Enforcement Use Of Facial Recognition: HD2304 / SD750
6. Restricting Automated License Plate Recognition: HD428 & HD2360
7. Protecting Locational Privacy: HD3698
8. Protecting Biometric Information: HD3053
9. Protecting Browsing Information: SD1217
10. SAFE COMMUNITIES ACT: HD2459 / SD1937

Summaries and explanations of each of these bills follow after the jump:

Read more: It’s A Whole New World
1. CIVIL ASSET FORFEITURES: HD1780 / SD2388, HD1328

HD.1780 / SD.2388 An Act Relative to Forfeiture Reform

HD.1328: An Act Relative To Civil Asset Forfeiture Transparency And Data Reporting

HD.2128: An Act Relative to Civil Asset Forfeiture

Restore The Fourth’s Issue Brief on Civil Asset Forfeiture

The threshold for civil asset forfeitures (CAFs) in MA is the lowest in the country, “probable cause” that a crime was committed. Our state is notorious for seizing cash and vehicles from people without them having committed a crime and we were ranked worst in the country for civil asset forfeiture policies by The Institute for Justice.

Last year, a special legislative commission was convened to investigate civil asset forfeiture in MA. They requested civil asset forfeiture data from every District Attorney (DA)  and every local law enforcement agency. The only response that they received was from Suffolk County and in cataloging  how the assets from their seizures and forfeitures were spent, they listed 50% as going to “other”. H.D.1780 is an outcome of the recommendations of the Commission on Civil Asset Forfeiture.

H.D.1780 raises the evidentiary standard for CAFs by one level to “a preponderance of the evidence” which is more typical nationwide. DAs and local law enforcement keep all of the proceeds from forfeiture in our state incentivizing seizures. H.D.1780 requires that all proceeds from seizures and forfeitures go to the Treasurer, who after reimbursing all non-personnel costs associated with the seizure and paying liens, would deposit the remainder in the General Fund.

This bill also narrows a major loophole. Currently police departments participating in joint task forces with the federal government (often cooperating in large seizures of contraband), are required by the federal government to contribute the 80% of the proceeds which they receive into law enforcement. This has enabled law enforcement to purchase surveillance technology like stingrays, without any oversight even when required by a local Surveillance Ordinance. Under the new provisions, if federal law prevents the distribution of CAF proceeds to the General Fund, then police departments can no longer accept forfeited property or proceeds from the federal government. A remaining  gap is that all joint seizures would have to be litigated by a local DA or the AG except for seizures of U.S. currency worth more than $50,000. 

A report by Politico and WBUR about civil asset forfeitures in Worcester County revealed that 1 in 4 seizures of cash and property that the Worcester DA’s office filed forfeitures for in 2018 either were not associated with a criminal conviction or weren’t even linked to a criminal drug charge and another 9% of seizures had no publicly available court records. Among those, there were more than 90 instances where people lost money or cars, taken most often during traffic stops, frisks and home searches — even though there weren’t related drug convictions or drug charges. WBUR documented more than 500 occasions between 2016 and 2019  where funds were held by the DA’s office for ten years or more before officials tried to notify people. More than half of funds seized between 2017 and 2019 were $500 or less. When the county finally got around to notifying someone that their assets were not legitimately seized and could be returned, they published a small notice in the local newspaper.

Elsewhere in the state there was a well-publicized case where a vehicle belonging to Malinda Harris was seized after her son was suspected of using it in a crime. The woman had nothing to do with his crime and needed her car for work. Six years later it was finally returned to her.

H.D. 1780 would require that seizures and forfeitures occur only after a court convicts the suspect of a crime with exceptions for lawful arrests and searches, and seizures of contraband. Police officers would be compelled to itemize everything that they seize and they would be prohibited from seizing currency of less than $200 and vehicles worth under $10,000. A seizure that occurred before a trial for a crime can be appealed via a hearing. Both H.D.1780 and S.D.1328 compel every law enforcement agency including the state police and all DAs to annually report all seizures and forfeitures including those under federal jurisdiction, and the crimes associated with them.  These would be entered by the executive office of administration and finance into a case tracking system and searchable public website.

H.D. 1328 requires that important additional information be reported including the outcome of any criminal charges, the details of all proceedings related to seizures and forfeitures, all case numbers and the zip code in which the seizure occurred. This granularity is crucial in view of the abuses that have occurred and the need to understand whether the new regulations adequately address these. Furthermore, whereas H.D.1780 requires that the data be reported to the AG, H.D. 1328 requires that all of the data also be reported to the Senate and House Committees on Ways and Means and the Joint Committee on the Judiciary.

H. D. 2128 would raise the standard of proof for a civil forfeiture to occur further than H. D. 1780 would do; instead of the Commonwealth having to prove that the asset was associated with a crime on “the preponderance of the evidence”, they would have to meet a standard of “clear and convincing evidence”. That standard or higher is the law in 28 states. The bill would also route all state forfeitures revenue into the Commonwealth Substance Abuse Prevention and Treatment Fund. It includes process improvements similar to H. D. 1780, though less detailed than those in H. D. 1328.

Digital Fourth supports these bills individually, and would support a consolidation of them in committee, using the standard of proof and revenues provisions from H. D. 2128, the detailed process requirements from H. D. 1780, and the detailed reporting requirements from H. D. 1328. These bills should help to ensure that forfeitures occur only when the vehicle, asset, or realty was involved in a crime, that innocent owners do not lose their property, and that law enforcement agencies have no financial incentive to conduct seizures and forfeitures.

2. QUALIFIED IMMUNITY REFORM: SD1970

Qualified immunity reform was left out of the 2020 police reform in Massachusetts, unlike in other states. Currently, Massachusetts imposes an unfeasibly high bar on civil rights lawsuits against state government agents, including police, of having to prove that the civil rights violation involved “threats, intimidation or coercion.” As a consequence, attorneys don’t take these cases, because they don’t expect to win; many plaintiffs can’t afford to pay an attorney unless they win damages.

S.D. 1970 stipulates that: “In an action brought under this section against a person or entity acting under color of law, proof shall not be required that the interference or attempted interference was by threats, intimidation or coercion.”

3. OVERSIGHT OF FUSION CENTERS: HD2088

This bill would require the Commonwealth’s “criminal intelligence systems” – the Boston Regional Intelligence Center, the Commonwealth Fusion Center, and others – to submit to regular outside auditing to ensure that they are complying with 28 CFR Part 23. This federal regulation requires that any information they hold on Massachusetts residents be based on reasonable suspicion of involvement in a crime.

It provides a private right of action to residents who believe that these entities have violated their privacy rights. It also requires the Commonwealth Fusion Center to publish the names of its privacy advisory committee, to have it meet quarterly, and to make its minutes public.

4. COMMERCIAL DATA PRIVACY PROTECTION: SD745

SD. 745: An Act Establishing the Massachusetts Data Privacy Protection Act

This is a very complete data privacy bill that covers large corporations, service providers social media companies and data brokers that either collect, process or transfer data. It requires the originating covered entity (CE), for example, Google, to limit the data that it collects from you to only what is necessary in order to provide you the service that you desire and must give you an easily accessible and user friendly affirmative consent mechanism in which you will be told what data Google collects and where it goes for what purposes and you will be able to consent to or opt out of these uses of your data. The CE must communicate your preferences to all of the service providers(SPs) or data brokers (DBs) or any other third parties with which it shares your data because they must comply with your preferences.

Each covered CE and SP must make publicly available an obvious and understandable privacy policy including a detailed and accurate representation of its data collection, processing, and transfer activities, the purpose of all data collected, the length of time that the data is to be retained, the data security practices implemented, every data broker or third party to whom the data is transferred and several forms of contact information so an individual can readily access the CE or SP to make requests concerning their data.

If the covered entity makes any changes in the data it collects, shares or transfers or sends your data to a new party, this must be communicated to you so that you can consent or opt out. You can change your data preferences and delete data twice a year without paying.

All CEs must allow individuals to access their data in a downloadable, portable, structured, interoperable, and machine-readable format and to make any corrections to inaccurate and incomplete data. Requests to change or delete your data should generally be honored within 30 days and you can make these changes twice annually for free.

Companies will have to report to the Attorney General (AG) how many requests they receive and how they have been handled. Any individual alleging a violation of their privacy rights under this act may bring “a civil action in the superior court or any court of competent jurisdiction” against the CE, DP or third parties. If a violation is found to have occurred, the plaintiff will be eligible for damages as well as an injunction or other relief and attorney fees.

DBs must register with the OCABR Office of Consumer Affairs and Business Regulation)which will maintain a searchable database with information on what data it collects and transfers and how you can contact the data broker about removing or verifying your data, linked to a website provided by the DB where you can opt out of data collection. Failure of the DB to comply will result in a fine.

Each DB will also be required to provide the AG with an impact statement for any algorithms that it uses that can potentially have a disparate impact on any protected group or individual registered to a political party along with steps they are taking to mitigate the impact. The AG can take action against CE or SP that fails to comply with civil rights provisions.

Large data holders (DHs) must hire at least one privacy officer or a data security officer and implement a data privacy program and data security program to safeguard the privacy and security of covered data. All CEs and Large DHs must perform a privacy impact assessment that weighs the benefits of the data collecting, processing, and transfer practices against the potential adverse consequences of such practices, including substantial privacy risks, to individual privacy and mustreview how technologies are being used to secure covered data.

CEs must provide all legal requests for disclosure of personal information that they receive to the AG and the general public on a bimonthly basis. This includes requests for location information and both the number of legal requests that resulted in the covered entity disclosing location or biometric information and those that did not.

The bill bans targeted advertisements to minors.

The bill has strong protections for workers against electronic monitoring that limit the monitoring to the least amount of information necessary from the fewest number of employees for the shortest length of time in order to enable tasks that are necessary to accomplish essential job functions or to monitor production processes or quality. The monitoring must not harm the employee’s mental or physical health. Employers must provide employees with notice that electronic monitoring will occur prior to conducting each specific form of electronic monitoring and include details including the purpose, the specific activities, locations, communications, and job roles that will be electronically monitored, the technologies that will be used and all vendors and third parties who will receive the data.

5. RESTRICTING LAW ENFORCEMENT USE OF FACIAL RECOGNITION: HD2304 / SD750

This bill implements the findings of last session’s Commission on Face Surveillance. The findings had support from law enforcement as well as from civil liberties organizations. The bill would provide that:

1. Law enforcement other than the State Police and FBI cannot directly possess or access a biometric surveillance database.

2. Law enforcement may not use biometric surveillance to infer a person’s emotion or affect nor for analysis of moving images or video data.

3. The State Police can access the facial recognition database used by the registrar of motor vehicles to conduct a search for local law enforcement, a federal agency or the FBI if they are presented with warrant issued by a judge based upon probable cause or if there is an immediate threat of danger of serious injury to someone or a need to identify a deceased person.

4. Law enforcement must document the basis for any emergency requests and file them with the appropriate Superior Court within 48 hours of the request.

5. All searches of the database by the State Police or FBI must be documented and reported to the executive office of public safety and security, quarterly disaggregated, by the requesting law enforcement or federal agency. The same goes for breakdowns of whether the request involved a warrant or emergency. The agency must post the total # of searches performed ID of a deceased person. These must all be publicly posted by EOPSS by March 31 of the following year.

6. Any person charged with a crime in which they were identified by a facial recognition search must be provided notice that the search occurred and defendants and their attorneys in criminal prosecutions must be provided with all records and information pertaining to any facial recognition searches performed or requested during the course of the investigation of the crime or offense.

6. Restricting Automated License Plate Recognition: HD428 & HD2360

HD.428 An Act Relative to All-Electronic Tolling Data Privacy.

This bill provides that:

1. A department may not access, search, review, disclose or exchange tolling data (meaning any data captured or created by an ALPR system or from signals or radio frequencies emitted by a transponder in connection with the assessment or collection of a toll, including, without limitation, GPS coordinates or vehicle location information, dates and times traveled, images, vehicle speed, and license plate numbers, existing in an any form or medium, whether electronic, paper or otherwise) unless this is necessary to:

a. collect, access or pursue payment tolls or fines or surcharges related to unpaid tolls

b. to install, maintain or repair a transponder

c. to respond to a reasonable belief that an individual is at imminent risk of serious physical injury, death or abduction; provided, that not later than 48 hours after responding, the access and detailed reasons for it are provided to the AG.

d. comply with a search warrant, production order, or preservation request issued in connection with the investigation or prosecution of a felony.

3. a. The department must erase or destroy the tolling data accessed within 120 days of access.

    b. The department may retain tolling data beyond 120 to comply with a search warrant, production order, or preservation request, or as necessary to collect unpaid tolls or fines or surcharges related to unpaid tolls.

4. a. A person whose tolling data was retained in violation of the above can institute a civil action in district or superior court for damages or in superior court for injunctive relief.

    b. If a violation has occurred the violator will not be entitled to absolute or qualified immunity and will be liable for proven actual damages, be liable for treble damages or for exemplary damages of between $100 and $1000 along with costs and reasonable attorney’s fees.

Why this is important: ALPR data records everywhere that someone has driven. If it is maintained in a database, then it can be reviewed retroactively for many unlawful purposes such as to identify a suspect in a crime for which there is ho particularized evidence of them having committed the crime This means that potentially many people who have traveled to the vicinity of the location of a crime will now become suspects. In addition, tolling data can be used to identify individuals who have participated in a political event or rally or a protest which are acts protected by the First Amendment and therefore should not be monitored.

HD.2360 An Act Establishing Driver Privacy Protections

This bill provides that:

Law enforcement or other state government employees or officials may not:

  • use an ALPR system to track or monitor activity protected by freedoms of religion or speech guaranteed by the Massachusetts Declaration of Rights or the First Amendment to the United States Constitution;
  • retain ALPR data longer than 14 days except in connection with a specific criminal investigation based on articulable facts linking the data to a crime;
  • disclose, sell or permit access to ALPR data except as required in a judicial proceeding; or
  • access ALPR data from other governmental or non-governmental entities except with a valid search warrant.

Toll collection technologies may only be used to identify the location of any vehicle for tolling purposes.

The department of transportation may not access, search, review, disclose, or exchange tolling data in its possession, custody, or control except to:

  • assess, collect or pursue the payment tolls or fines or surcharges related to unpaid tolls; 
  • install, maintain or repair an ALPR or transponder system or a system storing tolling data;
  • respond when an individual is at imminent risk of serious physical injury, death or abduction
  • comply with a search warrant, production order, or preservation request issued in connection with the investigation or prosecution of a felony.

The department of transportation must eliminate all tolling data that it possesses or controls within 120 days of its was creation unless it is necessary to comply with a search warrant, production order, or preservation request, or as necessary to collect unpaid tolls or fines or surcharges related to unpaid tolls.

No toll collection or vehicle data may be shared with or provided to any law enforcement entity or official without a search warrant, or production order; unless this information is requested  because of a reasonable belief that an individual is at imminent risk of serious physical injury, death or abduction and that such data is necessary to respond. Such a request must be narrowly tailored to address the emergency and subject to the following limitations:

  • the request must document the factual basis for the emergency and the applicability of toll collection and/or vehicle data
  • within 48 hours of accessing these records, the government office must file a written notice describing with particularity the grounds for emergency access and exactly what tolling data was accessed, with the Attorney General.

If ALPR data, tolling data, and vehicle data is collected, retained, disclosed, sold, or accessed without complying with the above requirements, it may  not be admitted, offered or cited by any governmental entity for any purpose in any criminal, civil, or administrative proceeding.

An individual whose rights have been violated by the improper transfer of or access to these data, may introduce evidence concerning this data in a civil action for damages or injunctive relief in a district or superior court or may allow another party in a civil proceeding to do the same.

If a willful violation occurred, the violator will not be allowed to claim any privilege absolute or qualified. In addition to any proven actual liability, the violator will be liable for treble damages, or, alternative, exemplary damages of between $100 and $1000 for each violation as well as costs and reasonable attorney’s fees.

The attorney general will enforce the above and will have the power to petition the court for injunctive relief and other appropriate relief against violators.  

7. PROTECTING LOCATIONAL PRIVACY: HD3698

In this bill, location information is defined as directly or indirectly revealing the present or past geographical location of an individual or device within the Commonwealth of Massachusetts with sufficient precision to identify street-level location information within a range of 1,850 feet or less. Location information includes but is not limited to (i) an internet protocol address (ii) Global Positioning System (GPS) coordinates; and (iii) cell-site location information.

HD. 3698 prohibits the collection, processing, or disclosure by  a Covered Entity (CE) including “any individual, partnership, corporation, limited liability company, association, or other group” (except a state or local government agency or court) of an individual’s location information  from any device that “connects to a cellular, bluetooth, or other wireless network” “for profit or in exchange for monetary or other consideration including selling, renting, trading, or leasing location information without the express consent of the individual except for the following purposes:

Location information can be collected for “(i) provision of a product, service, or service feature to the individual to whom the location information pertains when that individual requested the provision of such product, service, or service feature by subscribing to, creating an account, or otherwise contracting with a covered entity; (ii) initiation, management, execution, or completion of a financial or commercial transaction or fulfill an order for specific products or services requested by an individual, including any associated routine administrative, operational, and account-servicing activity such as billing, shipping, delivery, storage, and accounting; (iii) compliance with an obligation under federal or state law; or (iv) Response to an emergency service agency, an emergency alert, a 911 communication, or any other communication reporting an imminent threat to human life.”

When location information is collected for any but the last two allowed purposes, the CE must list each purpose in a Location Privacy Policy and individuals must provide discrete consent for each purpose to enable the collection of location information. Each CE must provide a clear, conspicuous, and simple means to opt out of the processing of their location information for purposes of selecting and delivering targeted advertisements.

Permission will be valid for one year unless the individual chooses to revoke it before that . If permission is revoked, any location information possessed by a covered entity must be permanently destroyed. An individual can opt in again at a future time. There cannot be any retaliation against someone who chooses not to have their location information collected but a service requiring this information can be withheld.

Covered Entities may not:

  • collect more precise location information than necessary to carry out the permitted purpose,
  • retain location information longer than necessary to carry out this purpose,
  • sell, rent, trade, or lease location information to third parties; or
  • derive or infer from location information any data that is not necessary to carry out the permitted purpose.

The CE may not disclose or assist in any way the disclosure of an individual’s location information to third parties (TPs), unless this is necessary to carry out the permissible purpose for which the information was collected, or requested by the individual to whom the location data pertains.

A CE or service provider (SP) may not disclose location information to any federal, state, or local government agency or official unless:(1) the agency or official presents a valid warrant or establishes the existence of exigent circumstances that make it impracticable to obtain a warrant ,or (2) disclosure is mandated under federal or state law, or (3) the subject of the data requests this disclosure.

The CE must maintain and make available its Location Privacy Policy including:

  • the purpose(s) for which the covered entity is collecting, processing, or disclosing any location information;
  • the type of location information collected, including the precision of the data;
  • the identities of SPs with which the CE contracts with respect to location data;
  • any disclosures of location data necessary to carry out each purpose and the identities of the third parties to whom the location information could be disclosed;
  • whether the CE’s practices include its use of location information for targeted ads
  • the data management and data security policies governing location information;
  • the retention schedule and guidelines for permanently deleting location information

Users of the CE must be given 20 days advance notice of any change in the Location Privacy Policy.

It will be illegal for the government to monetize location data.

Covered entities must annually disclose annually any warrants for location information received by themselves or any associated SPs or TPs (if known), disaggregated by the requesting agency, statutory offense under investigation, and the source of authority to the Attorney General (AG). The AG will make these reports available to the public online.

Any individual alleging a violation of this chapter by a CE or SP may bring a civil action in the superior court or any court of competent jurisdiction. They will not need to file a report with the AG or accept arbitration. If a claim is proven, the plaintiff may be rewarded damages for emotional distress, or $5,000 per violation, whichever is greater, (2) punitive damages; and (3) any other relief, including but not limited to an injunction or declaratory judgment, that the court deems to be appropriate as well as attorney’s fees and other costs.

The AG can bring an action against a CE or SP to remedy violations. The AG must conduct investigations of any possible violations of this chapter and refer cases for criminal prosecution to the appropriate federal, state, or local authorities.

Location information may be collected by a healthcare provider for treatment or research purposes in compliance with HIPPA.

CEs must comply with this chapter within 6 months of enactment and delete any location information retroactively for individuals who withhold consent.

8. PROTECTING BIOMETRIC INFORMATION: HD3053

In this bill, “Biometric information or data” means information or data that pertains to measurable biological or behavioral characteristics of an individual that can be used alone, with each other or with other information, for verification, recognition, or identification of an unknown individual. Examples include: fingerprints, retina and iris patterns, voiceprints, DNA sequences, facial characteristics and face geometry, gait, handwriting, keystroke dynamics, and mouse movements. (The bill excludes medical information protected by HIPPA, medical images used for diagnosis or research. donated organs or tissues stored by a federal agency as well as writing samples, written signatures, mere photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color.)

The Covered Entities (CEs) include any individual, partnership, corporation, limited liability company, association, or another group, however organized but not a state or local government agency, or any court of Massachusetts.

“ Processing includes collecting, accessing, using, storing, retaining, sharing, monetizing, analyzing, creating, generating, aggregating, altering, correlating, operating on, recording, modifying, organizing, structuring, disclosing, transmitting, selling, licensing, disposing of, destroying, de-identifying, or otherwise manipulating biometric information.

A CE or Data Processor (DP) cannot collect or process  (collect access, use, store, retain, share, monetize analyze, create, generate, aggregate, alter, correlate, operate on, record, modify, organize, structure, disclose, transmit, sell, license, dispose of, destroy, or de-identify)

someone’s biometric information unless: they

  • provide a written explanation of exactly what it will collect or process
  • provide the individual with the Biometric Privacy Policy(BPP)
  • receive advance explicit handwritten or electronic consent from the individual or their legal guardian or representative

Consent will expire after 3 years or when the initial purpose for processing the biometric information has been satisfied, whichever occurs first. Upon expiration, any biometric information possessed by a CE must be permanently destroyed. Consent may be renewed

The BPP must include:

  • the use models, detailing whether the biometric information is going to be used for identification or verification purposes; 
  • all data management and data security policies governing biometric information; 
  • all disclosure practices; and 
  • the retention schedule and guidelines for permanently deleting biometric information.

The CE must provide notice of any change to its BPP at least 20 business days in advance of implementation and request consent for the changes.

The CE must store, transmit, and protect from disclosure all biometric data in a manner that is the same as or more protective than the manner that it stores, transmits, and protects other confidential and sensitive information, consistent with the standard for similar private industries.

Any CE, DP or third party (TP) may only disclose biometric information if:

  • disclosure is required for the provision of a service or product by the CE and the individual has consented
  • disclosure is needed to complete a financial or commercial transaction requested by the individual and to which they have consented
  • disclosure is for a single purpose to a TP that has been authorized by the individual in handwritten consent
  • federal or state law requires disclosure but individual must be notified in advance via BPP
  • in response to a valid warrant
  • response to imminent threat to life or property[JB1] 

No CE, DP or TP may monetize biometric information.

If CE, DP or TP are served with a warrant for biometric information (BI), they must immediately provide the individual with a copy of the warrant, to whom and when their BI was provided, an inventory of the data disclosed, whether the CE, DP or TP provided the data, who requested the warrant from the court, if known. However, a government entity may apply to the court for a 30 day delay in notification and for a renewal of that delay.

CEs must annually report to the Attorney General (AG) any warrants for BI received by them or by associated DPs or TPs. CEs required to report BI pursuant to a law must annually report general aggregate information pertaining to these to the AG.

An individual alleging harm by a violation of this law may bring a civil action in any court of competent jurisdiction directed to any CE, DP or TP believed to have committed the violation.

If the defendant prevails they are eligible for liquidated damages ranging from  0.1% of the annual global revenue of the covered entity or $1,000 per violation, whichever is greater for negligent violations to 0.5% of the annual global revenue of the covered entity or $5,000 per violation, whichever is greater for deliberate violations, punitive damages and any other relief, including but not limited to an injunction as well as reasonable attorney’s fees and costs, including expert witness fees and other litigation expenses. Each instance of violation is eligible for damages.

The AG may bring an action pursuant to section 4 of chapter 93A against a CE, DP or TP to remedy violations of this chapter and for other relief that may be appropriate. 

Within 6 months of enactment of the law CEs must obtain consent for all BI collected or stored and must destroy any BI for which consent was not given. The Act will be in effect one year after enactment.

9. PROTECTING BROWSING INFORMATION: SD1217

This law would apply to electronic information collected by any corporation which sends or receives electronic communications, including any service that acts as an intermediary in the transmission of electronic communications, or stores electronic communication information for the general public.

It covers any information pertaining to an electronic communication or the use of an electronic communication service, including, but not limited to the content of electronic communications, metadata, sender, recipients, format, or location of the sender or recipients at any point during the communication, the time or date the communication was created, sent, or received, or any information pertaining to any individual or device participating in the communication.

In order for a government office, law enforcement agency or public official to access your electronic information from either a service provider or an electronic device itself, they would need to get a particularized search warrant supported by probable cause from a superior court judge. Exceptions would include if there were an emergency threatening immediate physical injury or, if you had previously given written consent to the corporation that possesses your electronic data to release it to them. Even in an emergency situation, the government would need to provide a written explanation of why the data was needed to the local superior court within 48 hours. Corporations would have to share the requested information within 14 days or earlier if justified, unless the corporation appeals for and is granted more time.

A Massachusetts corporation that provides electronic communication services, remote computing services, or location information services must respond to a warrant or subpoena from another state to produce records that would reveal the identity of the customers using those services, data stored by, or on behalf of the customer, the customer’s usage of those services, the recipient or destination of communications sent to or from those customers, or the content of those communications, as if that warrant or subpoena had been issued under the law of the commonwealth. This element is concerning, because it would allow a state that prohibits abortion to access content that might reveal that someone either had an abortion or received abortion medication.

The law enforcement or government officer who obtains someone’s electronic information via a search warrant must provide them with a copy of the warrant, the application for the warrant, an explanation of the law enforcement inquiry and the information requested and date of the request within 7 days of collecting their information unless a reason is provided for a delay which may be granted for up to 90 days and may compel the entity providing the data to delay notifying the target person.

A warrant for the electronic information requested is not necessary if the owner of the electronic information or the recipient of the information gives the law enforcement or government officer their written consent to share it.

If a government office, law enforcement agency, or public official believes that an electronic device is lost, stolen, or abandoned they may access electronic device information necessary  in order to attempt to identify, verify, or contact the owner or authorized possessor of the device.

Within 5 business days of issuing or denying a warrant, the court must report to the office of court management within the trial court all of the information pertaining to the warrant described above as well as name of the agency making the application, the offense described in the warrant and any modifications or extensions made to the warrant.

Every June, the court administrator in the office of court management in the trial court must provide the legislature with a complete report of the number of applications for warrants authorizing or requiring the disclosure of or access to information including a summary and analysis of the data which will all be public records.

No government office or law enforcement may ask any court for a reverse-location court order (including a search warrant or subpoena) to obtain the location of a specific device(s) or a reverse-keyword court order to identify who electronically searched for particular words, phrases, or websites, nor may they purchase this data. No court is permitted to issue any court order allowing the disclosure of reverse-location or reverse keyword data.

No government office or law enforcement may make a reverse location request or reverse keyword request from a company. Nor may they seek the assistance of any agency of the federal government or any agency of the government of another state or subdivision thereof in obtaining information or data from a reverse-location court order, reverse-keyword court order, reverse-location request, or reverse-keyword request if they would be barred from directly seeking such information.

No government office, law enforcement agency, or public official may use a cell site simulator (CSS)device for any purpose other than to locate or track the location of a specific electronic device, pursuant to a particularized warrant based on probable cause or if exigent circumstances exist requiring swift action to prevent imminent danger to the safety of an individual or the public. A warrant issued limits the use of the CSS to 15 days unless an application is made for renewal.

A warrant application must specify

  • the facts establishing probable cause to believe the targeted individual has committed, is committing, or is about to commit a felony
  • that less invasive methods of investigation or surveillance to the privacy of non-targeted parties have been tried and failed or are reasonably unlikely to succeed
  • It must disclose the nature and capabilities of the cell site simulator to be used, the name of the government agency that owns the cell site simulator device
  • exactly how it will be deployed, including whether it will obtain data from non-target communications devices
  • the procedures that will be followed to protect the privacy of non-targets during the investigation, including the deletion of data obtained from non-target communication device
  • that all target data must be deleted within 30 days if there is no longer probable cause  that such information or metadata is evidence of a crime

Any individual whose information was obtained by a government entity in violation of the above requirements for the collection of private electronic information must be notified in writing, by the government office, law enforcement agency, or public official who committed the violation and of the legal recourse available to that person.

Any electronic information collected in violation of the above provisions may not be used in evidence any trial, hearing, or other proceeding in or before any court, grand jury, department, officer, agency, regulatory body, legislative committee, or other authority of the commonwealth, or a political subdivision thereof.

Anyone who has been harmed by a violation of these protections of private electronic information may bring a civil action against the government office, law enforcement agency, or public official who violated those sections in the Superior Court or any court of competent jurisdiction. Such a person will not need to  file an administrative complaint with the attorney general or to accept mandatory arbitration of a claim.

When the plaintiff prevails in a civil action, the court may award actual damages, including damages for emotional distress, the greater of either $1000 per violation or actual damages, (punitive damages; and any other relief, including but not limited to injunctive or declaratory relief). In addition to any relief awarded, the court will award reasonable attorney’s fees and costs to the plaintiff.

Any contract whether government or private that infringes the above rights will be considered void.

This bill would also prohibit “library user private data” meaning records of a public library which reveals the identity and intellectual pursuits of a person using the library from being collected by any government or law enforcement agency.

10. SAFE COMMUNITIES ACT: HD2459 / SD1937

This long-standing goal of Digital Fourth and allied organizations, especially MIRA, would prevent local and state law enforcement from sharing information relating to the potential presence of undocumented immigrants, with ICE or other federal agencies.

For further details, please see the action alert here: https://actionnetwork.org/letters/tell-lawmakers-prioritize-the-safe-communities-act-this-session-23

Categories
Uncategorized

Fusion Centers Target The Homeless, Substance Abusers, Protesters And More

A damning report on the Maine Information Analysis Center (MIAC) or Fusion Center, reveals just how intertwined corporate and government surveillance of the public has become.  

“Official secrecy, moreover, cloaks fusion centers, so what little public information is available on a particular fusion center rarely provides much detail on its unique profile.”

The MIAC Shadow Report reveals how law enforcement goes out of their way to hide who’s actually in charge of public surveillance and is pre-occupied with people committing conventional crimes. 

“Fusion centers are the nerve system of mass criminalization” the report warns. A major concern of the authors is how fusion centers use private corporations to conduct secret facial recognition and social media surveillance of ‘people of interest’ and warns that self-governing fusion centers are fraught with peril.

Despite there being a statewide ban of using facial recognition to ID innocent people in Maine there is evidence MIAC uses data brokers to do an end-run around privacy bans.

“This legislation bans the use of the technology in most areas of government and strictly limits its use by law enforcement.9 In our review of BlueLeaks documents, we found documents that raise questions about the MIAC’s use of private data brokers and ability to analyze cell phone data. These systems, like the recently regulated facial recognition technology, also pose existential threats to privacy and other basic rights.”

The report also found that fusion centers are being used to surveil people with mental illnesses, substance abuse, and the homeless.

It appears that the majority of what fusion centers do is ID ‘suspicious people, people of interest, suspects, missing persons, and wanted people.’

“The majority of MIAC documents concern the sharing of criminal information. Two-thirds of the BlueLeaks documents definitely shared by the MIAC—939 of 1,382—are (1) requests to identify a suspect or a wanted person, locate a person of interest or missing person, or provide information about possible crimes or suspicious circumstances or (2) bulletins and reports on specific incidents, cases, or individuals considered relevant to law enforcement but not directly connected to a criminal investigation by a police agency in Maine.”

Supermarkets, gas stations, utility companies, universities and hospitals receive daily ‘civil unrest’ reports 

The report reveals that fusion centers send daily intelligence (civil unrest) reports to 4526 registered users in Maine. The reports focus on protests and political violence, lumping together subjects like “civil unrest,” “extremism,” and “terrorism.” 

“This expansive list includes law enforcement officers and intelligence officials from across Maine, the New England Region, and across the country. It extends beyond law enforcement and intelligence to other government officials such as Department of Motor Vehicles personnel and school superintendents. The MIAC’s reach extends outside of the public sector. Many large corporations receive MIAC products, including Avangrid, Hannaford’s, ExxonMobile, and Bath Iron Works. Civil society organizations and nonprofits are also involved, such as universities, hospitals, and even special interest groups. The president of the Maine Chamber of Commerce, for example, is a registered user of the MIAC but, in contrast, there are no representatives from organized labor listed.” 

The report also revealed that fusion centers are monitoring people who commit property crimes or shoplifting and sends daily reports to businesses.

“Private firms also access documents. The most prolific private sector reader of MIAC reports is the Auburn Mall. Auburn, along with neighboring Lewiston, are the twin cities of Maine. They are post-industrial mill towns, which have not yet been gentrified. They contain the four highest poverty census tracts in the state. The opioid epidemic has devastated this region. Mall security at the Auburn Mall mostly reads documents on persons who have been arrested for opioid use and shoplifting.”

The Maine Beaconwarns, “counterterrorism has morphed into supercharged policing of drug, and property crimes,” and says “this is public-private surveillance.”

How easy is it for police officers to use fusion centers to secretly collect information on an innocent person?

MIAC, like fusion centers everywhere “can acquire and retain information that is unrelated to a specific criminal or public safety threat, as long as it determines that such information is useful.” As the report states, “the policy provides no definitions or standards for determining when information is useful in the administration of public safety.”

Let that sink in for a moment. Fusion centers can basically spy on anyone, even if they are not a ‘public safety threat,’ as long as a police officer determines that the information they collect on a person is useful!  

The report also revealed that fusion centers are ‘acquiring, retaining and sharing information about individuals and organizations based solely on their religious, political, or social views or activities.’

Fusion centers commonly send “situational awareness bulletins” to police departments about a person’s mental illness, saying these types of disclosures are common.

The report also reveals how police departments and the Rand Corporation create “strategic subject and HEAT lists” of anyone police think could commit a future crime[s].

Fusion Centers use TransUnion to secretly monitor people’s social media

“Documents received in response to FOAA requests provide evidence that the MIAC currently uses commercial databases as part of its investigations. For example, one heavily redacted record shows a TransUnion report on a redacted individual, which provides information on jobs, emails, usernames, aliases, and numerous social media profiles and internet sites.118 Another document traces a case that begins with a citizen report of “violent politically motivated rhetoric on Facebook” and leads immediately to a request to “begin to look into this individual” by a MIAC staffer. A case number and record are then created, and multiple reports are completed, including a “TLO (Comprehensive and Social Media)” report.”

The report proves that fusion centers are using data brokers to routinely collect highly sensitive personal information on people without a warrant. 

“The TLO document also contains the report itself, which includes information on bankruptcies, liens, properties, corporate affiliations, and other information which is fully redacted and cannot be identified.”

“MIAC routinely monitors social media accounts and/or conducts background checks on individuals associated with lawful public protests, frequently citing a pretextual criminal offense (subjects may litter during the protest, for example) to justify the collection. MIAC then retains all the data collected even after finding no indication of a threat, hazard, or criminal activity.”

Last week The Intercept reported that the state of New York wants to spend millions to create a statewide fusion center-run social media surveillance network.

“New York’s governor, Kathy Hochul, unveiled details of her own policing initiatives to crack down on gun crime — but hardly anyone seemed to notice. Embedded within the dozen bills and hundreds of line items that make up her plan for next year’s state budget, Hochul’s administration has proposed tens of millions of dollars and several new initiatives to expand state policing and investigative power, including agencies’ ability to surveil New Yorkers and gather intelligence on people not yet suspected of breaking the law.”

According to the MIAC report, fusion centers can use a “possible threat, crime analysis” or essentially any reason to justify spying on a person’s social media accounts. Using fusion centers to ID and surveil homeless people and juveniles is horrifying, as “we do not know what happens to these individuals when they become subjects of the MIAC intelligence reports.” 

As is typical of fusion center research, searching for ‘fusion centers and crime analysis’ returned vague results, as evidenced by this gem from DHS’s Fusion Center Fact Sheet: “Fusion centers conduct analysis and facilitate information sharing, assisting law enforcement and homeland security partners in preventing, protecting against, and responding to crime and terrorism.”


The closest and most disturbing definition of ”fusion centers and crime analysis” can be found in the Bureau of Justices, “Fusion Center Guidelines: Developing and Sharing Information and Intelligence in a New Era” report.

“The goal is to rapidly identify emerging threats; support multidisciplinary, proactive, and community-focused problem-solving activities; support predictive analysis capabilities; and improve the delivery of emergency and nonemergency services.” (page 13.)

What does that mean? It means fusion centers are guessing or predicting that someone could be a threat to the homeland or one of a possible 23 different types of violent extremists.There is a disturbing link between fusion centers and mass incarceration.

 “In addition to the previously discussed role of the MIAC in monitoring racial justice protests and the over-policing of the crimes of poverty, the MIAC records published with BlueLeaks include documents produced by the MIAC and “passed through” from other agencies that concern unhoused people, undocumented people, and youths running away from home or the juvenile justice system.”

It is not hard to see how a person of color, a homeless person or a substance abuser could receive a harsher sentence simply because a fusion center has a secret file on them.

Now is the time to press our leaders and politicians to put an end to fusion centers, the need to keep them going has long since passed. (Twenty-one years and counting since 9/11.) 

Allowing 79 fusion centers to use corporations and data brokers to collect massive amounts of personal information on anyone for any reason has and will continue to come at a high cost to our freedom.