The always-invaluable 404 Media has scored another minor coup. We all know ICE is heavily invested in surveillance tech, ranging from its purchases of cell location data from data brokers to throwing money at Clearview AI, the most notorious of facial recognition tech firms.
But there’s so much more to it than that. On top of the Trump administration trying to force other government agencies to share sensitive data with immigration enforcement agencies, ICE, CBP, and other DHS agencies have access to a plethora of tools, databases, and aggregation services that make it extremely easy to monitors peoples’ lives and movements, whether or not they’re actually the target of enforcement efforts.
A leaked document shows the spread of surveillance and investigative capabilities that Immigration and Customs Enforcement (ICE) officials have access to agency wide, from location data harvested from smartphones, to facial recognition apps that can reveal someone’s identity, to tools that let the agency stay anonymous online and approach people undercover. The document covers everything from monitoring social media to tracking the movements of vehicles.
The full document [PDF] lists everything accessible by CBP and ICE. As 404 Media notes, the information may be out of date, since it was apparently generated in 2024. For instance, it doesn’t mention either of the DHS’s newest mobile tech tools (ELITE, ImmigrationOS). And some of the products/services listed may have been phased out, replaced, or dropped entirely.
Still, it’s as disheartening as it is comprehensive. For instance, it shows ICE has access to something called ISO Claimsearch, which “contains information on property and casualty insurance claims, as well as vehicle information.” It also mentions its nationwide shared database of license plate/location data gathered and compiled by Vigilant Solutions and its partners.
For some reason, ICE also has access to the FTC’s database of customer complaints. While any US resident is capable of requesting this same information from the FTC, the FTC will redact the complainant’s personal information. One assumes this doesn’t happen when ICE/CBP ask for it.
It also mentions Clearview as an option for facial recognition. It says access is controlled by “CIEU,” an acronym that isn’t defined anywhere in the document. According to the line item, access is “given out under specific circumstances.” This phrase also goes unexplained. But one of the names listed to contact for access links to a DHS official.
There’s also Insight, which functions like WHOIS, but also mixes in “geo-location data” as well as the “ability to get around privacy registrars” to identify website owners.
ICE also has access to the ADL (Anti-Defamation League) Hate Symbols Database, but apparently has no interest in other databases detailing hate groups/symbols that might be a bit more focused on groups that support Trump and his administration (SPLC, for instance, which the government considers to be a criminal organization).
There’s plenty to dig through here, but it’s kind of amazing to see just how much info your average ICE officer has access to. It seems like way more than what’s necessary to do this job, especially since most of the people being ejected from the country these days are residents who’ve made no secret about their country of origin and are simply trying to negotiate the now nearly-nonexistent path to permanent residency.
And what’s in here is the best case scenario: a list of everything ICE has access to, along with contact info for access privileges. What’s not in here is everything else: the abuses, the utilization of local agencies to route around federal restrictions, and the tech that’s being deployed without proper authorization or required Privacy Impact Assessment in place. This leak is comprehensive, but as always, one has to wonder if this is just the stuff the government feels comfortable putting down in writing.
Frank Ssekamwa says the United States presented his country with an impossible choice. If it accepted the terms of a new health agreement, Uganda would have to give the U.S. access to the data of millions of his fellow citizens — a decision he worries would make their personal information more vulnerable to breaches and possible exploitation.
But if it refused, the East African nation would likely lose out on more than a billion dollars to address HIV, malaria, tuberculosis and other illnesses, even as its people face ongoing threats from Ebola and other deadly infectious diseases.
So, on Dec. 10, it agreed.
“If you take the deal, you’re going to be exploited. If you don’t take it, you’re going to die,” said Ssekamwa, an attorney and digital rights expert in Uganda. “It’s the essence of digital colonialism.”
Across Africa, countries have faced similar dilemmas as the U.S. has held a series of closed-door negotiations in which lifesaving aid has been conditioned on access to citizens’ health data. The negotiations come in the wake of the dismantling of the U.S. Agency for International Development, which — in contrast with the new contracts — provided billions of dollars in aid with few strings attached. Officials in Zambia, Zimbabwe and Ghana have been so outraged by the demands that they rejected the initial deals.
The demand to access health data is central to the Trump administration’s new America First Global Health Strategy, an openly transactional approach that seeks to leverage the desperate need for medical treatments abroad. Aid will now be given “in a way that directly benefits the American people and directly promotes our national interest,” Secretary of State Marco Rubio stated in September.
The State Department declined to publicly release global aid and data-sharing agreements it has signed with more than 30 countries as part of its new approach. But a ProPublica analysis of nine of the deals offers a window into the extensive U.S. demands for access to data — and the potential risks and vulnerabilities for the citizens of countries that have signed them. ProPublica also reviewed a data-sharing agreement struck with Uganda, which has not previously been reported; a data agreement with Kenya; six agreements over the sharing of pathogens that can cause pandemics that were made public by the State Department this week; generic templates of deals for sharing both data and pathogens that can cause pandemics; and an analysis of the documents the advocacy group Public Citizen shared exclusively with ProPublica.
ProPublica also consulted more than a dozen experts in data privacy and global health, including several with direct knowledge of U.S. policy who said that the insistent demands for data access and other resources as a condition of aid are unprecedented. Without seeing the full suite of agreements, they could not identify all vulnerabilities. But they spotted some red flags: The terms of the deals are vague and lack language standard in most data-sharing agreements that adequately limits what data is collected and how it can be used. That increases the risk that individuals’ personal data could be exposed, misused or commercialized without their consent.
In the Ugandan data deal, the U.S. will get direct, real-time access to nine of the nation’s health data systems for seven years, including the central repository that stores all of its health information, lab data, data collected by community health workers and, critically, its system for managing individuals’ electronic medical records.The agreement calls for the sharing of aggregated data with all personally identifiable information removed. It also says the data should be used for delivering and auditing healthcare services.
But lawyers and digital privacy experts argue that the deal raises questions about who will have access to the massive cache of health data and whether it could be inappropriately accessed and exploited.
Some expressed concern that, because it is possible to reverse-engineer data that has been anonymized, people with HIV, tuberculosis and other diseases could have their records exposed.
Stephanie Psaki, who served as the U.S. coordinator for global health security under President Joe Biden, described the Trump administration’s approach as a “blunt instrument of ‘just give me the login to your data systems.’”
“The U.S. would never agree to that,” she said, if the deal were offered in reverse.
In Uganda, the U.S. will provide up to $1.7 billion over five years for global health security and the treatment and prevention of deadly conditions such as malaria, tuberculosis, HIV and polio.In the past, the U.S. gave this aid without asking for direct benefits in return, saving an estimated 170,000 Ugandan lives per year.
While a significant investment, it is less than the U.S. previously spent in Uganda and will decrease every year of the agreement. By 2030, the African nation will receive 45% less global health funding than when Trump retook office, according to an analysis by Vincent Lin of Partners in Health, which provides healthcare in poor countries.
Several experts said there is broad support for some of the goals of the new plan for aid, including reducing African countries’ dependence on the U.S. for healthcare needs. But they worry the transactional nature of the approach could backfire by undermining trust or, in some cases, driving nations to reject deals altogether.
After withdrawing from the World Health Organization and losing access to its global network that tracks and combats disease outbreaks, the U.S. is attempting to obtain the information necessary to address potential pandemics through a patchwork of deals with individual countries. Each of the agreements ProPublica reviewed includes a section on responding to outbreaks. And some countries have signed separate pathogen-sharing agreements, which state that countries must “initiate sharing specimen(s) and related data” within five days of a U.S. request. The Trump administration is also planning unprecedented involvement of private companies to manage and process data.
The State Department told ProPublica that it needs access to the data to improve health outcomes in recipient countries and keep Americans safe. The new approach also requires countries to invest more in their own health systems in exchange for the aid, a promise many countries will likely struggle to fulfill. And, in some cases, including the deal with Uganda, it aims to boost local manufacturing through partnerships with American companies.
The State Department said it took multiple factors into account to ensure the required investments from other countries were “realistic and achievable.”
“The United States is investing billions of dollars in other countries’ health systems to fight infectious disease. In return, we expect governments to increase their own spending on health, so programs are sustainable and under genuine national ownership, not permanently financed by U.S. taxpayers. For the first time, both sides are putting skin in the game to ensure lasting impact,” a State Department spokesperson said in response to questions about the agreements.
In response to follow-up questions from ProPublica, spokesperson Tommy Pigott said the agreements “share only the same kinds of aggregated, de-identified data that has been shared and used for years in the fight against HIV/AIDS, malaria, tuberculosis, and other diseases. All data sharing is consistent with each country’s laws and approvals. No personally identifiable information is being received or shared by the United States government.”
Uganda’s Ministry of Health, Ministry of Foreign Affairs, Personal Data Protection Office and embassy in Washington, D.C., did not respond to questions for this article.
In the age of artificial intelligence, large health data sets have become so valuable they’ve been referred to as the new gold. The precise value of the health data of an entire nation is unclear, but it could be extremely valuable to AI-driven companies for training models.The industry of buying and selling such information troves is worth billions. And countries around the world have come to regard their citizens’ health records as national assets that deserve special protections and can confer economic and strategic advantages.
Yet the agreements, which are part of a strategy the State Department openly states is intended to make America “more prosperous” and “promote American health innovations,” provide no guarantee that Africans subject to them will have a say in what happens with their data or receive a fair share of its benefits. “Once companies get this data, the value is being accrued. But there’s no way for the [African] population to know how companies will use it,” said Jane Munga of the Carnegie Endowment for Intenational Peace, who has argued that the agreements may violate African privacy laws.
Africans have also expressed concern that they will not be able to access and benefit from medicines and vaccines developed from pathogen samples shared with the U.S. Five of the six specimen-sharing agreements reviewed by ProPublica state that, in the event that a medical product is developed primarily from a specimen from the country, the U.S. government “shall prioritize” a request from that government behind the needs of the U.S. Only one of the agreements, with Nigeria, commits the U.S. to facilitating “priority access” to — and the donation of — any medical products developed using the specimens.
The phenomenon of extracting information and samples from less-resourced populations and failing to credit and compensate them for their contributions to medical developments is well known enough to have several names, including “parachute science.” Just a few years ago, countries, including some in Africa, hosted COVID-19 vaccine trials, only to later struggle to access the shots they helped to develop.
Each agreement includes “benefit-sharing provisions,” the State Department said in response to questions.
After the Trump administration dismantled USAID, the world’s largest provider of humanitarian assistance, it also drastically reduced funding for international health work done by the Centers for Disease Control and Prevention and severely scaled back the President’s Emergency Plan for AIDS Relief, which combats HIV globally. In addition to withdrawing from the WHO, the U.S. removed itself from international negotiations over a pandemic agreement intended to affirm countries’ sovereign rights to their biological resources and ensure equitable access to medical interventions.
Brad Smith, an entrepreneur who served in the first Trump administration, is now in charge of creating the system that would rise from the ashes. Before joining this administration, Smith founded three companies with business models that rest in part on using data to reduce healthcare costs, including CareBridge, a home care provider that sold for a reported $2.7 billion in 2024. During the presidential transition that year, Smith led the government efficiency panel that would become Elon Musk’s Department of Government Efficiency. After Trump took office, he presided over some $67 billion in sweeping cuts to the Department of Health and Human Services before being brought on as an adviser to the State Department.
Although the humanitarian aid system had been largely dismantled, Congress required the executive branch to continue providing aid. So Smith and his team had to find new ways to get the funding to countries, ensure that it was being spent wisely and address potential pandemics — all without most of the international partners and staff the government had previously relied on to carry out this complex work.
A Rhodes scholar known for his intense work ethic, Smith threw himself into the effort. State Department staff fielded calls from him at all hours of the night to explain budget items on spreadsheets. Through his personal lawyer, Smith referred questions to the State Department.
One of the greatest challenges lay in the handling of health data. In the past, PEPFAR, the HIV program, built its own systems to handle anonymized data, separate from government health records — a setup that Trump administration officials and others have criticized as inefficient.
The America First plan proposed standardizing data collection and processing within countries. The Ugandan data agreement requires the country to provide the U.S. — and its contractors — with logins “or other secure access mechanisms” to directly enter the country’s data systems. The new approach, U.S. officials say, will enable the U.S. to continue auditing programs and track outbreaks.
The agreements ProPublica reviewed include statements about the U.S. government’s intent to ensure data security and say that the data is being accessed for the purposes of addressing diseases and auditing that work, but they leave open the possibility that sensitive information could be revealed, according to the data privacy experts ProPublica consulted.
At particular risk are countries that don’t have national data privacy laws, such as Liberia, whose memorandum of understanding requires “interlinked and interoperable” data systems for “surveillance, laboratory, response, health, environment, agriculture.” That country’s main health agreement doesn’t require the U.S. to limit the amount of data it takes to the least needed, a standard clause in U.S. contracts, according to Abdoul Jalil Djiberou Mahamadou, a recent postdoctoral fellow focusing on bioethics at Stanford University. (Neither Liberia nor the State Department has released the supplemental data-sharing agreement.) “Once data is breached, it’s nearly impossible to get it back,” Mahamadou added.
The Liberian government did not respond to a request for comment.
The Ugandan data-sharing agreement says it will comply with the laws of both nations and permits the sharing of “sensitive personal data” if the consent of individuals whose data is shared is obtained, there is a compelling public health emergency of international concern and it is the only way information can be provided in a “timely and accurate format.”
Ssekamwa, the digital rights expert who also founded and runs the African Centre for Digital Justice, said there are important questions that haven’t been answered by the Ugandan government.
“Does the U.S. have appropriate data protections? Can the systems provide anonymized data? Are they really up to that standard?” said Ssekamwa. “If I’m someone who has had health issues, can you deny me a visa because of the health issues I’m having?”
Psaki, the former global health security coordinator, worried about the haste with which the changes to data access are happening. “Even in the best of circumstances, you can’t go from having parallel data systems that were established over 20-plus years to finding some way to integrate those data systems in six months.”
Speed has been a hallmark of the America First global health effort. In September, just a month after Smith joined the State Department, it launched the strategy at an event co-sponsored by the U.S. Chamber of Commerce and five large pharmaceutical companies. By November, Smith was crisscrossing the African continent with a small team of negotiators, trying to persuade dignitaries to agree to deals.
The State Department said the deals were “negotiated in a thoughtful and strategic way over many months.”
On Dec. 4, Kenya became the first country to sign, during a triumphant celebration with Rubio and President William Ruto in Washington. Outcry over the agreement had already begun two days earlier, when a Kenyan activist named Nelson Amenya announced on the social platform X that he had seen a sample of the specimen-sharing agreement as well as a legal analysis that showed it would violate Kenyan law.
As a condition for receiving $1.6 billion in aid, the Kenyan government agreed to provide access to seven years’ worth of health records — two years longer than the U.S. would provide financial support.
Although the Kenyan data-sharing agreement states that the U.S. will take “all reasonable measures to protect the confidentiality of information” and abide by American and Kenyan laws, Amenya worried that wouldn’t be enough. “Every HIV test, TB diagnosis, malaria case – accessible to US officials,” he wrote in the post, which now has one million views. “Your medical records, your children’s health data – all exposed.”
A few days later, a Kenyan senator named Okiya Omtatah sued members of the Kenyan government over the agreement, arguing that it poses a threat to citizens’ constitutional right to privacy by “allowing broad foreign access to sensitive data.” A Kenyan nonprofit also sued, and more than 50 groups weighed in on their side, describing the document as giving the U.S. “excessive access” to African data and raising the possibility of serious human rights violations.
In court filings, the Kenyan government argued that it is obligated to achieve the “highest attainable standard of health” and that it is unable to do that on its own. After blocking the deal for months, in May, the Kenyan court temporarily allowed implementation of the agreement to proceed while it considers the case.
Since outrage bubbled up in Kenya, some other countries have negotiated shorter terms for sharing data and pandemic specimens, and have inserted additional protections, according to the Public Citizen analysis.
Revealing whether someone has had an abortion, mental health condition, substance use treatment or sexually transmitted disease can be devastating anywhere. In Africa, research has shown it can lead to discrimination and violence. And even when personal information has been removed, individuals in “anonymized” data can be reidentified using AI and other tools.
The Ugandan data-sharing agreement calls for the U.S. government to “promptly notify the Government of Uganda of any unauthorized access” in such cases and requires the parties to conduct a joint breach assessment and remediation plan afterward. But by that point, it may be too late, Ssekamwa fears. “Once the data gets out of Uganda, we are skeptical that the government of Uganda will actually have any power to control it,” he said.
The secrecy around both the negotiations and the agreements has raised further suspicions. The State Department has declined to share the agreements, telling ProPublica the agency will release them when negotiations with all partner governments are complete and describing its actions as “protecting sensitive negotiations—not ‘secrecy.’” In response to a public records request filed by ProPublica, the State Department said it planned to provide the documents in September 2027. The advocacy group Public Citizen recently filed suit against the federal government in an effort to obtain the documents.
“Why are they hiding the agreement if they think the terms are OK?” asked Bernard Okpi, a Nigerian lawyer who sued his government in March, alleging that the deal violates the country’s constitutional right to privacy and promotes religious discrimination by prioritizing funding for Christian faith-based health facilities. That suit is pending, and the Nigerian government did not respond to questions from ProPublica.
The State Department said that the agreement with Nigeria “was negotiated in connection with reforms the Nigerian government has made to prioritize protecting Christian populations from violence.”
The Trump administration says that its new global health strategy is designed to save lives and keep the U.S. — and the world — safe from disease outbreaks. But ultimately its hard-driving and secretive negotiations may work against those goals.
While the administration aspired to strike agreements with 50 nations, including the three countries that walked away from negotiations in part over concerns about data sharing, it has fallen far short of that number. (In Zambia, officials also balked at U.S. demands for critical minerals.) The loss of aid in those countries is already proving tobe devastating.
Despite the Trump administration’s stated goal of putting “America first,” the U.S. may feel the consequences of those failed negotiations, too, as mistrust compounds the loss of long-standing systems that provided care and responded to disease outbreaks.
“It’s in everyone’s interest to have a comprehensive approach to respond to an outbreak early,” said Psaki, who pointed to the quickly escalating number of Ebola cases in the Democratic Republic of Congo as evidence. While that country struck a healthcare deal with the U.S., five of the nine countries bordering it have not. “We need to get data and samples from all nine countries to collaborate effectively on that outbreak, and now we don’t have that.”
The State Department said the U.S. has responded swiftly to the outbreak and has provided over $270 million to the global fight against Ebola.
In Uganda, where people have also fallen sick and died from Ebola, Ssekamwa said that his country needs all the help that the healthcare deal can bring, including improved protection from outbreaks, but there needs to be more robust protection of people’s personal data.
“We are happy to benefit from the technological advancement and the fruits of big data,” he said. Instead, he said, “the U.S. has left so many gaps within the agreement, which can be exploited in their favor.”
In October 2025, EFF warned the public that Flock was rolling out a new feature called “Distress Detection” that would be deployed through their acoustic gunshot detection devices (formerly known as Flock Raven, now called Audio Detection). This feature purported to use high-powered microphones scattered throughout a city to search for sounds of human distress, with original advertisements from the product indicating it would search for “screaming.” (Since the publication of our original blog post, Flock quietly amended the ad on this webpage to say “distress” instead of “screaming.”)
Now, Flock has published a blog post stating that “[a]fter careful consideration and community consultation, we decided to remove the feature.” Good riddance.
We said it when the product was announced and we’ll say it again: this was a misguided and dangerous feature because of the civil liberties concerns it poses, the possibility it could summon armed police to every loud interaction happening on the street, and because in several places this type of spying would be illegal under state eavesdropping laws.
We were not quiet about this potential new feature. Flock even mentioned our concern about Distress Detection in an attempt to rebut our opposition to the mass surveillance their products enable.
The suspension of Distress Detection, however, does not mean that these high-powered microphones are now magically safe or beyond our concern. Acoustic gunshot detection is still a dangerous and often highly inaccurate technology that has resulted in real world harm, as in Chicago where it resulted in police shooting at children lighting fireworks. As Flock itself states, “No acoustic system is perfect, and we don’t claim otherwise.” But police response to a situation where they believe guns are actively in use seems like a pretty high-stakes situation to be making, selling, and deploying technology known to be imperfect. Flock’s devices also listen for more than just gunshots. Their marketing materials admit to be listening for “community disruption,” which includes “non-violent” threats like car sideshows and fireworks.
Flock’s failed attempt to roll out Distress Detection teaches us a few important lessons about the current state of police surveillance. First, we should not assume that just because these companies are large and well-funded, that does not ensure that they are complying with local privacy laws before floating new products to customers. Second, companies roll out and police adopt invasive technology under the justification that it will be used to address our society’s very worst crimes. However, both the companies and police will leverage deployed surveillance infrastructure to introduce new uses without necessarily seeking the consent or approval of the public. Gunshot detecting microphones eventually being used to listen for screaming is exactly the type of mission creep that we’ve seen happen with other pieces of surveillance technology, including Flock’s license plate readers. Finally, gun violence is too serious and complex of an issue to purport to solve with one flawed piece of technology. It has become too easy for police and cities to listen to the fancy marketing pitches of tech companies claiming they’re going to solve all crime instead of doing the hard work of addressing the root causes of societal issues. And, in the meantime, that technology creates more problems and hazards for the communities they blanket in police surveillance.
As we’ve also seen with people across the country pushing back on Flock license plate reader contracts in their communities, public pressure can sometimes work to influence both companies and lawmakers that control a city’s purse strings to discontinue or divest from harmful products. Flock’s decision to end “Distress Detection” for human voices is a win.
We — and plenty of others — have been warning that the global rush to mandate age verification wouldn’t stop at “let’s make sure kids can’t see porn” or even just “keep kids off of social media.” It would inevitably expand into treating anonymity and privacy tools themselves as the enemy. Australia is now proving that in real time: Its eSafety regulator has gone from checking whether porn sites gate their content to treating VPN use — one of the best tools people have for protecting their privacy online — as a compliance problem to be stamped out.
The correct term for age verification as it is implemented today is therefore identity verification. Given today’s internet infrastructure, it is unreasonable to assume that this information will not be shared through commercial agreements or with governments.
The consequence of introducing identity verification is therefore that freedom of information is restricted (you can no longer visit regulated websites anonymously) and that you can no longer post anonymously on social media. You cannot be certain that your criticism of the government will not be followed up by the authorities. You can no longer start a digital initiative on a social media platform aimed at gathering people to criticize an authority without facing a significant risk of consequences. Depending on the country you live in, this could even endanger your life. In its current form, social media identity verification removes important tools for activists in countries where criticizing those in power is dangerous.
Freedom of expression is threatened not only in a direct sense (you post something and then the police knock on your door), identity verification also creates a chilling effect. It becomes a cornerstone of censorship machinery in the sense that people begin to self-censor if they know that expressing opinions may have personal consequences. This is also something that changes over time. What is considered acceptable to post online is determined by whoever currently holds power. Different sides of politics often have different views on what constitutes harmful content. Just because what you post today is not considered inappropriate does not mean it will remain acceptable in the future.
Some can argue that they’re biased since they’re in the business of selling VPN service, though arguably, more age verification laws increase demand for VPNs. But, the reality is that as age verification laws spread, so too do the attacks on VPNs and the ridiculous and dangerous threats to somehow outlaw their usage.
The latest is in Australia, where their teen social media ban has been an abject failure. Have no fear, however, they’re going to just start targeting VPN usage. Of course, they’re not framing it as a response to the failure of their social media ban, but rather a response to adult content websites’ age verification being beaten by people using VPNs, because it’s always easier to start your attacks on privacy, security, and anonymity by blaming a more marginalized industry like adult content:
Nine in 10 of the most visited adult sites used by Australians now have age checks for users, according to the online safety regulator, but eSafety has said it will assess whether those sites are allowing users to bypass restrictions with virtual private networks (VPNs)….
But, of course, it’s not just about adult content. They’ll go after VPN usage for social media as well:
Similar to the expectations of the social media companies for the under-16s ban, eSafety said it was expected under the codes that sites “must take reasonable steps” to prevent workarounds like VPNs, and eSafety “will look at this when considering compliance”.
The sheer irony of an agency named “eSafety” claiming that VPN use was a “workaround” that must be blocked? VPNs provide way more safety than anything that the “eSafety” Commission has done regarding internet usage.
Age verification is surveillance. Full stop. And it’s increasingly being closely tied to law enforcement and governments. Tech policy expert Heather Burns recently pointed out that age verification providers were literally reporting people to law enforcement for the crime of… using an alternative OS. As she notes:
age verification providers now hold themselves to be delegated law enforcement and extensions of the judiciary, using the guise of age verification for child safety but for reasons which have nothing to do with it.
Iain Corby: Yeah, just briefly to add, I think there is a distinction here between when we just accept the parent’s word for the child’s age and when services need to get an independent verification of that age. We do know, this was mentioned earlier, that often, parents are complicit in helping their kids to access services which are age-limited when they shouldn’t be accessing those services. So, sometimes you will need to do an independent age verification rather than simply relying on a parental attestation. So, it’s sort of one step up from self-declaration, but it’s not an independent view of the age of that user.
So Australia is just confirming the point privacy folks have been screaming about for years: age verification is inherently an attack on privacy and security. It will absolutely be used to remove anonymity, decrease security, enhance law enforcement surveillance, and, as the last quote shows, diminish even parental decision-making regarding our children.
Age verification was never going to stop at the age gate. VPNs are just the next thing on the list. Other user empowerment tools (Tor? encrypted DNS?) will be next. There’s simply no version of this that ends with your privacy intact.
The 2026 FIFA World Cup is the largest sporting event in history. It’s also the most surveilled World Cup ever. If you’re visiting or traveling around host cities, then you and your face, behavior, movement and devices are being monitored by governments and private companies.
The U.S. government funneled more than US$1 billion to World Cup security to protect transit hubs, stadiums and surrounding areas; improve tactical operations such as bomb squads and SWAT teams; and add and upgrade equipment. It’s been a bonanza for the private sector.
Much of the investment in surveillance was done in the name of preventing harm from unauthorized drone use. Indeed, protecting against that threat is helping fuel the rapidly expanding government-private sector partnership in surveillance technology development and acquisition, which poses a different risk – to privacy.
As an attorney, author and educator who has worked for decades in privacy and surveillance, I’ve advised law enforcement about using drones and understand that security is critical to keeping people safe. The argument for security, however, is too often the catalyst to fund, develop and increase government surveillance capabilities that erode civil liberties, chill speech and undermine freedom of association.
And in my experience, surveillance-friendly policies and tech systems, once in place, rarely go away.
Cameras, drones and AI
The level of surveillance around this World Cup and changes in U.S. law and immigration policies prompted over 120 civil society groups – including Amnesty International and the American Civil Liberties Union – to issue a travel advisory. They warn that people visiting the U.S. may be subject to harms that breach the country’s legal human rights obligations.
That advisory lists risks of invasive social media screening, searches of electronic devices, racial profiling, arrest, detention, deportation and even death. European governments have issued travel advisories warning of surveillance and profiling as well.
AI-driven surveillance is playing a major role across the World Cup. The stadiums in host cities are equipped with facial recognition cameras that can collect and analyze facial biometrics of people in and around the stadiums. That data can be retained and used in future ways, unknown and uncontrolled by those whose biometric data has been collected.
The proliferation of facial recognition at events reflects a broader global trend normalizing biometric surveillance as these systems expand across cities.
Many states, like New York, are using federal funding for World Cup security to increase the number, capabilities and use of drones by law enforcement. Drones are remarkably capable and powerful surveillance tools easy to load with cameras, microphones, advanced sensors and weapons.
AI-supported autonomous software allows drones to monitor areas, track movement and gather intelligence. The drones can be powerful enough to scan entire cities or zoom in and read a milk carton from 60,000 feet (18,288 meters). They can carry technology that allows them to function like a cellphone tower, permitting law enforcement to determine your location or intercept texts and phone calls. Citywide drone networks could become the new normal.
Cameras are proliferating on the ground, as well. Robot dogs equipped with cameras are prowling in Dallas and New Jersey. And Seattle’s mayor decided to turn on and expand a major closed-circuit television system that had been previously shut down because of biometric privacy concerns.
While Seattle’s mayor said that the city is refining its policies to protect the surveillance data, numerous states and cities – with the aid of federal funding related to World Cup security — are rapidly expanding CCTV systems. Some CCTV systems were installed decades ago in major urban, high-tourism areas, like New York’s Times Square and the National Mall in Washington D.C.
Today, CCTV systems cover much greater areas, and with advances in artificial intelligence software, data analytics and increased technical capabilities, like thermal imaging, far more information can be gleaned from the captured data. CCTV systems can now detect, identify and classify objects, people and even people’s behavior. Government data fusion centers can merge that rich data with other intelligence and analyze it to identify individuals and reveal and predict patterns and behavior.
Surveillance traveling into and around the US
Proliferating government use of advanced AI surveillance tools is just one element of the privacy risk. The absence of comprehensive data privacy laws and changes in U.S. law and executive policies around immigration and gender make traveling into and around the United States a security, safety and privacy risk.
Also, President Donald Trump issued an executive order around gender on Jan. 20, 2025, that mandates federal agencies only recognize male and female sex markers on IDs. European nations, including Germany, have warned their transgender and nonbinary citizens that they may be denied entry to the U.S. because of the directive.
Collectively, these changes affect travel logistics, documentation requirements and border crossings.
What happens after the games?
The real test is what happens after the World Cup ends and visitors go home. There is little oversight or governance around these federally funded, public-private surveillance tech partnerships. It’s difficult for the public to determine what data is being collected, how that data is being used, shared and analyzed, and what will happen to these systems, partnerships and data when the final match concludes.
Federal, state and local legislators have an opportunity to address much of this by creating data privacy and AI systems compliance safeguards and requiring transparency, but in my view, governance efforts to date don’t bode well.
Anne Toomey McKenna is Affiliated Faculty Member at the Institute for Computational and Data Sciences, Penn State
We’ve been waiting for this one for a long time. And while it doesn’t disappoint, it doesn’t leave a whole lot of room for celebration.
Okello Chatrie has been challenging the geofence warrant that led to his arrest and prosecution since 2019(!). Nearly seven years later, he’s a step closer to… well, maybe setting precedent that will help others? That’s how it usually works in cases like these: the person experiencing a new violation of rights sets the precedent. But because there was no precedent, the government is generally given a “good faith” pass, even when warrants seem so far removed from Fourth Amendment principles even the government should have known its warrants were unconstitutional.
The Fourth Circuit Appeals Court handled Chatrie’s case multiple times. It reviewed it twice and still decided the government didn’t do anything (intentionally) wrong when it used a geofence warrant to narrow down its list of suspect and, finally, put Chatrie on trial.
Don’t let the word “warrant” fool you. There are legitimate warrants that adhere to particularity standards meant to deter officers from just searching wherever, whenever. Then there are geofence warrants, which are more comparable to the “general warrants” the Fourth Amendment was put in place to prevent.
When investigators have no idea who they’re looking for, they stop looking for people and start demanding Google cough up tons of location data. The government argues these warrants are “particular” because they only ask the most likely repository of this data to search for this data. Normal people would argue these are “general warrants” because they force Google to search everyone’s location data on the government’s behalf, in hopes of generating a list of devices that match up with the government’s date/location range inputs — something that’s also often far more vague than it should be.
The government likes to say it doesn’t even need a warrant. Location info generated by phones is “third party” data “voluntarily” relinquished by phone users. The problem with that argument is that the Supreme Court — via its 2018 Carpenter decision — has already made it clear there is at least some expectation of privacy in that data, especially when the government is capable of gathering it en masse.
The time stamp on the Carpenter ruling works a bit in Okello Chatrie’s favor because the alleged crime happened after that ruling. The Supreme Court majority also agrees with Chatrie’s other arguments, including those pointing out geofence warrants cannot possibly satisfy probable cause/particularity requirements generated by Fourth Amendment case law.
Here’s the briefest description of the Supreme Court’s ruling [PDF], as delivered by SCOTUS itself:
Police officers conducted a Fourth Amendment search when they acquired Chatrie’s location data from Google because an individual has a reasonable expectation of privacy in his cell-phone location information.
More specifically, the Court points to its own precedent:
Everything Carpenter relied on to find that law enforcement officers conducted a Fourth Amendment search when they accessed CSLI records applies as well or better to the police’s accessing of Location History data. First, Location History provides an even more fine-tuned picture of a person’s movements, pinpointing location within around twenty meters rather than within sectors of one-eighth to four square miles; it records location every two minutes or so for a daily average of 720 chartings rather than 101; and it can estimate elevation to reveal which floor of a building a phone is on.
Second, Location History allows police to reconstruct “retrospective[ly],” and with no real effort, people’s comings and goings in any area, enabling “tireless and absolute surveillance” of any number of people in any number of places. Carpenter, 585 U. S., at 312.
And third, Location History implicates personal privacy interests even more than CSLI, because Location History is more the cell-phone user’s own. Most cell-phone users have no awareness of CSLI records, and would never try to retrieve them; by contrast, Google users regularly employ Location History as a personal journal. In that way, Location History resembles other private materials—e.g., emails, documents, photographs, or calendars— that even if stored on Google’s servers, a user reasonably views as his own and expects to be shielded from the “inquisitive eyes” of the government.
While this is a good ruling, it also does little more than tell the Fourth Circuit to do what it has already done: rule the warrant a search under the Fourth Amendment but still give the government a pass for not knowing its warrant was unconstitutional. A concurrence written by Justices Jackson and Sotomayor says the Court should have gone further, declaring this warrant (and any like it — which would be most of them) so unconstitutional the government couldn’t possibly claim to have obtained them in good faith.
Geofence warrants generate waves. The first one is the vaguest. Once more information comes in, investigators approach Google with narrowed lists. These repeat visits are almost never brought to the attention of magistrate judges. If a judge OKs the first search, the government just keeps going back to the well without bothering to seek judicial approval.
This “uncommon, multi-step” process, ante, at 30, meant that officers conducted key portions of the search outside the supervision of “a neutral and detached magistrate,” Johnson v. United States, 333 U. S. 10, 14 (1948). Put differently, officers could obtain additional, sensitive information at steps two and three without having to convince a magistrate that there was probable cause to believe this particular information would uncover evidence related to the crime. In this way, the warrant left “too much to the discretion of the officer[s] executing the order,” giving them a “roving commission” to collect more data absent any justification to a magistrate.
The facts of this case illustrate why the lack of magisterial oversight is dangerous. When executing steps two and three, law enforcement initially sought unbounded data and account information from all 19 devices identified at step one. Nothing in the warrant prevented officers from obtaining this broad set of data; they narrowed the list only because Google insisted on it.
Because that’s only a dissent, it won’t be taken into consideration when the Fourth Circuit takes its third look at the case. That should have been a point raised by the majority. As it stands, it just means the government will take its good faith ruling and sprinkle it generously on the further unconstitutional acts it engages in while holding a single geofence warrant.
There’s a dissent, of course. And if you can guess two of the three authors, you won’t win anything. No one is going to offer those odds.
JUSTICE ALITO, with whom JUSTICE THOMAS joins as to Part I and with whom JUSTICE BARRETT joins as to Parts II–B, II–C–1, and II–C–2, dissenting.
As is always the case when something isn’t about what this president wants to do/get away with, Alito and Thomas are there to LiveJournal their complaints about constitutional rights:
Eight years ago, I warned that this Court’s decision in Carpenter v. United States, 585 U. S. 296 (2018), would produce one of two outcomes. Either the Court would need to clarify Carpenter’s limits in a future decision, or Carpenter would usher in “revolutionary developments” in our doctrine by giving criminal suspects a “protected Fourth Amendment interest in any sensitive personal information about them that is collected and owned by third parties.” Id., at 385 (ALITO, J., dissenting). Today, the Court takes the country down the latter path. In doing so, the Court sheds Carpenter’s self-imposed boundaries and further destabilizes longstanding Fourth Amendment jurisprudence.
To make matters worse, the majority does all this in an advisory opinion. Although today’s decision will send seismic waves through our Fourth Amendment doctrine, not one iota of the majority opinion will affect the outcome of this case. The Court knows this and does not claim otherwise. Indeed, by refusing to review the one question that could have at least theoretically given Chatrie some hope of relief, the Court carefully set the stage for its planned performance: striking a pose as a great champion of privacy in the digital age. I cannot support this irresponsible escapade.
Note the loaded language, where Alito attaches “giving criminal suspects” to his complaint about recognizing the Fourth Amendment needs to be interpreted in conjunction with today’s realities, not left to be a dusty relic that cannot be expanded to cover things that were impossible to envision more than two centuries ago.
Note also that Alito, et al. bitch about the majority not addressing the one thing that might have helped Chatrie: a ruling on the good faith exception itself. And while I have the same complaint, I would have limited myself to asking the court why it didn’t do this, rather than immediately pivot in the very next paragraph to saying the Court should never have taken this case up in the first place.
The Court should not have granted certiorari in this case, and under any faithful application of our precedents.
Right after that Alito immediately says “Fuck Chatrie,” only sentences after (disingenuously) expressing concern for the Court’s unwillingness to tangle with the “one question” that could have given Chatrie “some hope of relief.”
[I[t should now either dismiss this petition or affirm the decision below based on the “good-faith exception” to the exclusionary rule.
I agree with the dissent in terms of the Court’s unwillingness to draw a bright line that will guide future rulings. But I say that because I think this will just allow law enforcement to roll the dice on questionable searches and hope the muddied water will get them forgiven for willfully bypassing the spirit of this ruling, which unfortunately hasn’t carried over to the letter of the ruling.
But these motherfuckers — Justices Alito and Thomas — think the real harm is that the government won’t be able to engage in as much warrantless surveillance as it would like to:
If the Court maintains its unwillingness to engage with such “line-drawing questions,” ante, at 21, n. 9, Carpenter’s warrant requirement might soon come for all forms of digital surveillance.
Take a long walk off a short pier, boys. You are the worst people to be entrusted with standing as a bulwark against government excess. You welcome it. You absolutely crave it when its one of your boys sitting in the Oval Office. You’re supposed to be serving the entire United States, not just those in the ruling class. But you’d clearly rather give the government unlimited power, rather than ensure the only people guaranteed rights — WE, THE PEOPLE — are allowed to use them.
But buried in the Trump FCC plan was another new effort we mentioned: one that involves cracking down on burner phones by forcing telecoms (the ones bone-grafted to our domestic surveillance operations) to dramatically scale up the information they collect from consumers.
That’s… understandably raised concerns among privacy advocates and civil rights groups well aware that greater surveillance will be abused by the Trump administration and beyond. It also ignores that there’s often very good reasons why abuse victims, whistleblowers, journalists, refugees, and others might be seeking an anonymous prepaid burner phone, privacy advocate Eric Null told 404 media:
“To address the scourge of illegal robocalls, the FCC has unfortunately proposed to force every wireless subscriber in the nation to sacrifice their privacy and give up significant personal details before receiving or renewing a wireless line. While some carriers already collect such details, there are specific circumstances where a person may need privacy and anonymity when seeking a cell phone, including if that person is a victim of domestic violence, or is a journalist or whistleblower. This proposal represents a loss of privacy across the board, and from an agency whose remit includes protecting privacy. The FCC might let a few bad apples spoil the whole bunch.”
Anonymity is one of the rights guaranteed by the First Amendment. The EFF notes this also isn’t likely to really stop criminals from finding ways to communicate anonymously:
“This proposal by the FCC will do little to combat scams and robocalls, since most people doing that will have no trouble creating fake documentation or identities,” Cooper Quintin, security researcher and senior public interest technologist with the Electronic Frontier Foundation (EFF), told 404 Media. “Given this administration’s crackdown on free expression, protest, immigrants, and women’s health we have trouble seeing this as a bold attack on freedom of communication. They want to take away our ability to make an anonymous phone call.”
So, in short, it won’t actually stop robocalls or criminal activity, but it will harm people who need anonymous communications tools to survive, and it will almost certainly lead to greater surveillance abuses by America’s corrupt, authoritarian government.
One plus side: the rules aren’t official yet. The FCC’s proposed plan is open to public input until June 25. You can file an express comment here; (the specific proceeding discussing new prepaid phone restrictions is 13-97).
“We’re gonna be aggressive here because Michigan jobs are on the line, but also so is national security. So close our border to Chinese vehicles and Chinese technology in the vehicles, even for day trips. That’s how aggressive we believe we need to be right now,” Stevens said while speaking at a policy conference.
Her partner in the legislation went much further. “They can certainly come across the border, drive up to Selfridge Air Force base, take some video with the car. The car is a traveling surveillance package. And all of that data that the car is collecting is being sent straight back to Beijing,” Slotkin said.”
So, a few things. One, it’s curious how normally very vocal “free market” Libertarian groups always mysteriously get quiet when this sort of obvious anti-competitive pandering to large corporate campaign donors pops up. Two, it’s adorable how Slotkin and Stevens want you to believe that simply banning Chinese cars somehow solves the major privacy issues inherent with modern, connected cars.
For one, U.S. and most of the overseas vehicles sold in the U.S. basically have nonexistent security standards. Carmakers collect an ocean of biometric, location and phone data, and then sell that data to a parade of largely unregulated data brokers, who in turn sell access to that data to any random asshole with money to spend — including domestic and foreign intelligence.
They then lie about it when asked. And if they do openly acknowledge it, they insist it’s okay because the resulting data has been “anonymized” (a term that means absolutely nothing).
Which is to say the Chinese, if they really want access to detailed U.S. street information and public movement data, don’t need to sell their cars in the U.S. to obtain it. Because Congress has been too corrupt to pass a meaningful internet-era privacy law any time in the last quarter century. In part because we’re greedy, but also in part because the U.S. government also buys this data to avoid getting warrants.
As a result of this country’s grotesque corruption, we’ve been awash in major privacy and national security scandals for 25 years, including the recent revelation that sensitive U.S. location data obtained by telecoms, apps, and every other device we use (whether it’s made in China or not) is being bought from data brokers by other countries and then utilized to track, target, and kill U.S. troops.
So maybe Stevens and Slotkin actually care about this stuff, but generally privacy is used as a lazy talking point by politicians who have other motivations; in this case making giant U.S. carmakers who don’t want to face meaningful price competition happy ahead of the midterms to ensure the campaign financing funding keeps flowing.
Slotkin was one of numerous Dems who supported the “banning of TikTok,” which really just involved offloading most of the app and its profits to Trump’s billionaire friends, who are as bad, if not worse, on issues like privacy and propaganda than ByteDance ever was. Now Slotkin is going around calling cheaper Chinese EVs “TikTok on wheels,” as if the whole Dem TikTok face plant never happened.
Pretending you’re being extra tough on privacy by going so far as to even ban cars with Chinese tags from visiting from Canada (as if Canadians want to visit the U.S. right now anyway) is particularly weird, performative, and ignores the real problem.
U.S. politicians need to pass a meaningful internet-era privacy law and tightly regulate data brokers, or shut up about how much they care about consumer privacy and national security.
Back in March I noted how the Trump FCC under Brendan Carr had announced a “new ban” on all routers made overseas (which is pretty much all of them). At the time we also noted how this was less of a ban and more of a shakedown, with router manufacturers required to beg the Trump FCC for conditional waivers (fees, favors, whatever) to continue doing business in the States.
Several router manufacturers (like Amazon’s Eero and Netgear) have subsequently received exemptions from the Trump administration, but because there is zero transparency to the process, we have no idea what they agreed to. Did they pay the Trump administration a bribe? Did they agree to surveillance backdoors for ICE operations? Who knows? Great stuff.
Now the cable lobby appears to be balking at the purported foreign router ban. In a petition filed with the FCC last week (spotted by Ars Technica) NCTA (The Internet & Television Association) — the cable industry’s biggest lobbying org — asked for a massive exemption from the restrictions, noting that they’re simply not practical in real-world practice:
“NCTA requests an expedited grant of this waiver to enable its members and their suppliers to navigate unavoidable supply chain shortages and prevent disruptions in the availability of broadband for NCTA members’ customers, while still fulfilling the rules’ national security and public safety purpose.”
So basically you’ve got a ban on foreign routers that is more about extortion than protecting national security. Which the cable industry says it can’t adhere to because AI hype, tariffs and unnecessary wars have driven up the costs of many internal router components, making adherence expensive if not impossible. Great stuff, very savvy policymaking by people who definitely know what they’re doing.
Part of the “foreign router ban” was supposed to involve forcing hardware manufacturing to return to the states. But because Trump and much of his administration have a fourth-grader-level understanding about how this stuff works (like his desire to suddenly have smartphones built in the U.S.), the cable industry’s filing notes that the “onshoring” of manufacturing and supply chains isn’t realistically possible either:
“Like AT&T, NCTA members are encouraging their suppliers to quickly pursue required onshoring, and, in the meantime, seek Conditional Approvals for Covered Routers as necessary. However, unavoidable supply chain shortages in critical substrate material and memory modules (including both volatile and nonvolatile memory) significantly constrain the industry. AT&T’s suppliers are not unique; the same impediments they are experiencing impose inevitable limitations on NCTA’s suppliers. Accordingly, NCTA seeks the same relief on behalf of its suppliers. Given the immediacy of these issues and the concrete harms that would result from disruptions to the availability of broadband to large swaths of US consumers and businesses, the grant of this Petition is warranted.”
These companies, many of which supported and enabled Trump, now have to pretend this all makes sense as they navigate a costly minefield of weird bullshit that won’t accomplish any of its purported goals.
This is all exceptionally chaotic and dumb, and it’s unlikely that Brendan Carr, who spends most of his time trying to censor comedians and whining about “wokeness,” is capable of managing the scale of this sort of overhaul — even if it were practical, which it isn’t.
When you read most press coverage of this router ban, they don’t really make it clear to readers that this is all very unworkable and stupid. Trump and his administration are given undeserved credit on competency and policy, as the press, companies, and policymakers all try to trip over themselves to normalize the sheer pointless stupidity and expense of it all.
If the country cared about national security we’d focus on corruption. We’d pass a meaningful modern internet privacy law. We’d shore up, staff, and properly fund cybersecurity regulators. We’d regulate data brokers. Instead we get a giant pile of unworkable extortion slop being overseen by weird zealots.
On one hand, the Trump administration wants to destroy most corporate oversight, consumer protection, labor rights, and regulatory autonomy. On the other hand, the administration very much wants to abuse government power and wield regulatory oversight in all sorts of terrible ways that censor speech, stifle journalism, and enable corrupt cronyism.
I’ve long noted how FCC boss Brendan Carr in particular personifies this inconsistency. He wants to abuse FCC authority to bully companies he doesn’t regulate (TikTok) and stifle journalistic criticism of the president (ABC, CBS), but he also routinely wants to try and claim that his agency lacks the authority to do anything to protect consumers or hold telecom and media giants accountable for bad behavior.
Those inconsistencies came to a head last week when the Supreme Court ruled 8-1 in favor of the Biden FCC’s attempt to fine AT&T and Verizon for spying on customer location data, selling access to that data to any random old nitwit, and failing to tell their paying customers about it.
A 2018 New York Times story showcased how stalkers, police, people pretending to be police, and the prison system routinely bought access to this data and then failed completely to secure it. Six years later the Biden FCC finally proposed fining wireless carriers $196 million ($91 million for T-Mobile, $57 million for AT&T, $48 million for Verizon) for the abuses.
But the efforts were upended by a 5th Circuit ruling last year declaring that the FCC fines somehow violated AT&T’s Seventh Amendment right to a jury trial (one of several arguments AT&T and Verizon lawyers through at a wall to see what would stick). The 5th circuit had been supportive of a broader Trump administration second term initiative to basically defang the entirety of regulatory corporate oversight.
The wireless carriers’ case leaned heavily on the Supreme Court’s June 2024 ruling in Securities and Exchange Commission v. Jarkesy, which declared that the SEC system for issuing fines violated the right to a jury trial. Verizon and AT&T lawyers insisted that they couldn’t be fined by the FCC for privacy violations, because it violated their Seventh Amendment rights.
So the Trump-stocked Supreme Court had a tricky choice. Do they support the administration’s effort to defang and neuter corporate oversight? Or do they protect their ambition to wield regulatory agencies as a blunt weapon? The Supreme Court decided to go with the latter, though the ruling shouldn’t be construed as any sort of good faith protection of consumer privacy rights or the public interest.
Only Clarence Thomas decided to buy into the telecom industry’s flimsy arguments.
“The Supreme Court got this one right,” John Bergmayer, Legal Director at consumer group Public Knowledge said in a statement. “AT&T and Verizon sold access to their customers’ location data, then failed to stop bounty hunters and even a rogue sheriff from using it to track people who had no idea they were being followed. The FCC investigated, found the carriers liable, and proposed penalties—which the carriers were always free to challenge in court.”
It’s a useful win, but it bucks the broader Trump court trend of declaring most regulatory agencies largely powerless to hold corporate power accountable across a wide variety of industries. And even here you’ll notice the FCC fines came six years after the initial revelations of wireless carrier misbehavior. They never would have come at all if not for the Biden FCC.
It may likely be years more before fines are collected (assuming Carr bothers), and they’ll still likely only comprise a fraction of the money made on the back of abusing consumer privacy. But in the golden age of corruption and incoherent Trump court rulings, you take whatever victories you can get.