Auditen
sector watch

The Privacy Policies Were Updated. The Data Remained Exposed.

Flock Safety is updating its camera policies. This is a classic move. When a governor expresses that he is "deeply troubled" by license plate readers and an officer in Itasca gets fired for misusing the tech, the corporate response is always to rewrite the handbook.

The problem is that policy updates are not technical controls. They are paperwork intended to soothe regulators.

We see this across the surveillance and AI sector right now. There is a concentrated effort to signal compliance through policy pivots and certifications while the actual plumbing remains leaky. This week, we saw the gap between "certified" and "secure" widen into a canyon. tl;dv leaked just over 180,000 meeting records. The company held a SOC 2 certification.

I have long distrusted 'privacy by design' when it is used as a marketing slogan rather than an engineering requirement. If the privacy was designed, a vendor-related security failure wouldn’t turn a SOC 2 report into a piece of irrelevant stationery. A SOC 2 audit is a snapshot of a moment in time; it is not a persistent shield. It proves you have a process for managing vendors, not that your vendors are actually competent.

The pressure is concentrating on any firm that handles "high-trust" data—whether that's police surveillance or generative AI training sets.

Take the investigation opened by Attorney General Austin Knudsen into OpenAI. This isn't just about a data breach; it’s about how these models ingest and protect information at scale. When state AGs start moving, they aren't looking for a policy document that says "we value your privacy." They are looking for evidence of actual control over the data flow.

The surveillance sector is particularly vulnerable here because it relies on a dangerous chain of trust. Flock Safety provides the hardware and software, but the police departments operate the tools. When an officer misuses a license plate reader, it's easy to blame the "bad apple." But from a data protection standpoint, the failure is operational. If a system allows an individual to query sensitive movements without a logged, justified reason, the system is broken by design.

Updating a policy after the fact is just rearranging the deck chairs.

The second-order effect here is the hidden liability shift. When these surveillance firms fail—either through a breach or by enabling misuse—the legal heat doesn't stay with the vendor. It flows downstream to the municipalities and government agencies that contracted them.

These cities are now holding portfolios of high-risk data they cannot actually manage. They’ve outsourced the technical work but kept 100% of the political and legal risk. If a Medusa ransomware attack hits another batch of critical infrastructure—and they've already hit over 500 organizations—the "compliance" certificates provided by the vendors will not stop a class-action lawsuit or a regulatory fine.

Some would argue that certifications like ISO 42001 for AI management, which KuCoin recently earned, are the path forward. They argue that these frameworks create a standardized language for risk.

That's a nice theory. But standardization is not the same as security. You can standardize a failure. If you follow every step of a flawed framework, you simply achieve a certified level of incompetence.

The real test isn't whether a firm can pass an audit; it's whether they can prevent a single officer from abusing a database or a single vendor from leaking 180,000 records. Until the industry moves away from "policy-based trust" and toward technical enforcement—where the system physically prevents the misuse regardless of what the handbook says—these updates are meaningless.

We're seeing this play out in the fines too. GDPR fines hit €225 million in the second quarter of 2026. These aren't usually fines for lacking a policy. They're fines for failing to implement the controls that the policies promised. The regulators are stopped being impressed by the existence of a DPO or a privacy notice. They are looking at the actual movement of bits across borders.

The question now is whether state AGs will move beyond investigations and start demanding technical audits of these surveillance tools before they're allowed on city streets.

I'll believe the sector has changed when I see a vendor admit that their current architecture is incapable of guaranteeing privacy, rather than releasing a revised PDF of their "Terms of Service." Until then, keep an eye on the municipalities. They are the ones who will be left holding the bill when the next "certified" vendor leaks its database.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Investigation opened on OpenAI by Attorney General Austin Knudsen following data breach - Fairfield Sun Times Data Privacy (Google News)
  2. SEC Drafts Major Overhaul Of Transfer Agent Rules, Mentions Blockchain - menafn.com Compliance Week (Google News)
  3. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  4. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  5. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  6. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  7. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  8. SEC Moves to Let Transfer Agents Use Blockchain for Official Ownership Ledgers - finance.biggo.com Compliance Week (Google News)

How stories are selected and assessed