Connected Cities
The smart city isn’t just convenient. It’s collecting your data 24/7.
Lesson 4 of 6 · Estimated read: 15 minutes · Level: everyone
Every lesson before this one ended with settings you could change. This one is different, and it’s worth saying so at the start.
You can decline an app’s location request. You cannot decline a street. Public infrastructure collects data about people who never agreed to anything, and no privacy setting on your phone touches a license plate reader or a streetlight sensor.
That doesn’t leave you powerless. It moves the leverage. In the connected city, the effective controls are public records requests, procurement contracts, and local ordinances. Boring words that have repeatedly beaten billion-dollar surveillance deployments. This lesson covers what’s out there, and where the actual pressure points are.
In this lesson
- Smart cameras and surveillance
- IoT sensors and environmental data
- Public Wi-Fi and location tracking
- Transportation and traffic systems
- Utilities and smart meters
- Emergency alerts and public safety
- Data sharing between agencies and vendors
- What it means for policy and consent
- Building privacy into the cities of tomorrow
1. Smart cameras and surveillance
The basics
Municipal camera networks have changed in kind, not just in number. Older systems recorded to a tape someone reviewed after an incident. Current systems do live analytics: reading license plates, detecting objects, tracking a person’s movement across multiple cameras, and searching footage by description.
The multiplier is integration: pulling separate camera systems into one interface.
Go deeper
- Automated license plate readers (ALPR) are the highest-volume system in most cities. Fixed cameras on poles and mobile units on cruisers photograph plates continuously, logging plate, time, location, and often a vehicle image. Commercial networks pool these across thousands of communities into one searchable database, so a local deployment usually means national searchability.
- Real-time crime centers now operate in well over a hundred U.S. cities. These are rooms where municipal cameras, ALPR feeds, gunshot detection, and computer-aided dispatch converge on one wall of screens.
- Retention is the variable that determines the privacy impact, and it’s set locally. Thirty days and five years are both common. Longer retention converts a tool for investigating incidents into a tool for reconstructing anyone’s past movements.
What most people don’t know
Your doorbell camera may already be enrolled in a police-accessible network, and the enrollment was a checkbox.
Integration platforms let a police department maintain a live map of registered private cameras, including residential doorbells, small business systems, and apartment building lobbies. Depending on how the homeowner registered, this ranges from “police know a camera exists here and can request footage” to “police can pull the live stream.”
The consent structure is the interesting part. A homeowner opts in. Everyone who walks past that camera did not, and has no way to know the camera feeds a municipal system. Private surveillance becomes public infrastructure through an aggregation of individual choices, none of which required a public hearing.
If you own a camera, this is a decision you’re making on behalf of your neighbors.
Do this today
- Look up your own city in the EFF’s Atlas of Surveillance (atlasofsurveillance.org), a public database of which technologies which U.S. agencies have deployed. Most people are surprised, and it takes two minutes.
- Check your doorbell camera’s settings for police-sharing or registration features, and decide deliberately.
- Aim cameras at your own property rather than the sidewalk and street where possible.
2. IoT sensors and environmental data
The basics
Cities deploy sensors that mostly aren’t cameras: air quality monitors, noise meters, traffic counters, pedestrian counters, weather stations, water flow, waste bin fill levels, parking occupancy. Individually mundane, and much of it genuinely useful.
Go deeper
- Many “sensors” are cameras with software attached. A pedestrian counter using computer vision is a camera, and whether it stores images or only counts is a configuration choice, not an inherent property.
- Acoustic gunshot detection systems deploy microphone arrays across neighborhoods. Their accuracy and value have been contested; several major cities have declined to renew contracts after audits found limited evidentiary benefit relative to cost and the volume of police deployments generated.
- Sensor data is usually public-records-eligible, which is how researchers and journalists audit these systems.
What most people don’t know
Infrastructure deployed for one purpose gets repurposed for another, and that’s the norm rather than the exception.
The canonical case: a major U.S. city installed several thousand “smart streetlights,” justified and funded as an environmental and traffic-optimization program. They contained cameras. Police accessed the footage hundreds of times before the public learned the capability existed. The resulting backlash shut the program down and produced a surveillance oversight ordinance.
Nothing illegal necessarily happened. The system had a capability, an agency had a need, and no rule said no. Absent a binding purpose limitation written down in advance, mission creep is the default trajectory of any sensor network. This is why “it’s just counting cars” is not a description of a system’s future, only of its present configuration.
The security-professional framing: assume the deployed capability will eventually be used to its technical limit, and evaluate proposals on capability rather than stated intent.
Do this today
- Find out whether your city has a surveillance technology ordinance requiring council approval and public disclosure before new systems are deployed. If it does, read the inventory it produces. If it doesn’t, that’s the gap.
- When a “smart” project is announced, the question that matters isn’t what it’s for. It’s what it can do, and what’s written down about who may use it and for how long.
3. Public Wi-Fi and location tracking
The basics
Free public Wi-Fi is rarely free. The transaction is usually your email address, your device identifier, and a record of your visits, collected through the sign-in page and used for analytics or marketing.
Go deeper
- Retail, airport, and transit Wi-Fi analytics measure dwell time, repeat visits, and movement between zones. The value proposition sold to venue operators is foot-traffic intelligence.
- Both major phone platforms now randomize your Wi-Fi hardware address per network, which meaningfully reduces cross-venue tracking. Research has shown this can sometimes be defeated by fingerprinting the details of how your device broadcasts, so treat it as strong mitigation rather than immunity.
- Bluetooth beacons in stores and venues detect nearby phones and are used for indoor positioning and attribution.
What most people don’t know
You don’t have to connect to be counted.
Your phone broadcasts probe requests looking for known networks whenever Wi-Fi is enabled. Passive collection systems listen for those broadcasts and log devices that never joined anything, never saw a sign-in page, and never agreed to terms. The same applies to Bluetooth.
This inverts the usual advice. “Don’t connect to public Wi-Fi” protects your traffic; it does nothing about being tracked. The mitigation for presence tracking is turning the radios off, not declining to join.
Practically: if you’d rather not be counted walking through a mall or transit hub, Wi-Fi and Bluetooth off is the control. Airplane mode with cellular re-enabled works too.
Do this today
- Turn off auto-join for public networks, and “forget” the ones your phone has accumulated. A phone that remembers an airport network broadcasts that fact everywhere.
- Confirm private/randomized addressing is on for each network your phone remembers.
- Use cellular data rather than public Wi-Fi. It’s more private and usually faster.
- In venues where you’d rather not be tracked, turn the radios off rather than just declining to connect.
4. Transportation and traffic systems
The basics
Transit and roads generate some of the most revealing location data in existence, because movement patterns are habitual and habits identify people.
Sources: transit fare cards, toll transponders, congestion pricing cameras, bike and scooter share systems, parking apps, and rideshare records.
Go deeper
- A registered transit card ties a trip history to your name and payment method. That history of station, turnstile, and timestamp is a record of where you were, and it’s subpoenaable.
- Toll transponders and congestion pricing cameras log plates and times regardless of whether you’re enrolled in anything, because the plate is the identifier.
- Micromobility systems collect precise trip traces. Cities have required operators to share this data, which raised its own re-identification concerns given that a bike trip typically starts and ends near a home or workplace.
What most people don’t know
Anonymous fare media usually exists, and it’s deliberately less convenient.
Most transit systems still sell unregistered cards you can buy with cash and load with cash. Trips accumulate against a card number tied to nothing. The catch is that convenience features like balance protection if you lose the card, autoload, fare capping, and app integration generally require registration. So the private option exists and is quietly penalized.
For most people the tradeoff isn’t worth it. But the option is there, it costs nothing to know about, and it matters for anyone with a specific reason to keep their movements unlinked: journalists, people leaving abusive situations, anyone attending something lawful they’d rather not have logged.
Worth noting too that transit agencies have had real incidents where trip history was exposed to anyone holding a card number, so the data isn’t only reachable by subpoena.
Do this today
- If you have a reason to keep specific trips unlinked, use cash and an unregistered card for those trips. Partial application works. You don’t have to live this way full time.
- Assume plate-reading is happening on tolled and congestion-priced roads regardless of your enrollment.
- Check what trip history your transit app exposes and how long it’s retained.
5. Utilities and smart meters
The basics
A traditional meter was read monthly: one number. A smart meter reports consumption at intervals, commonly every fifteen minutes or every hour, to the utility, automatically.
Go deeper
- Interval data reveals occupancy patterns plainly. When you wake, when you leave, when you return, when you travel, whether the house is empty.
- Utilities offer third-party data sharing programs so you can connect your usage data to energy management apps. Useful, and worth understanding as an additional disclosure.
- Many states allow you to opt out of a smart meter and keep an analog one, typically for an installation fee plus a monthly manual-reading charge.
What most people don’t know
Fine-grained power consumption can identify individual appliances, and a federal appeals court has held that collecting it is a Fourth Amendment search.
The technique is called nonintrusive load monitoring. Every appliance has a characteristic electrical signature, so a sufficiently granular consumption trace can be decomposed to reveal which devices are running when: refrigerator cycles, a washing machine, a space heater, and in research settings finer distinctions than that.
The legal piece is the part even privacy specialists often miss. In a 2018 decision, the Seventh Circuit held that a city’s collection of smart meter data at fifteen-minute intervals did constitute a search under the Fourth Amendment, while concluding that this particular search was reasonable, given that the utility was municipal and the purpose was billing rather than law enforcement.
That’s an unusually clear judicial acknowledgment that utility data is constitutionally protected information, and it’s the doctrinal hook for arguing about retention, granularity, and law enforcement access. Utility records have been used in investigations, and the “reasonable” finding rested on the purpose, which means purpose limitation is doing the legal work.
Do this today
- Ask your utility three questions: at what interval is my consumption recorded, how long is it retained, and under what circumstances is it shared?
- Review any third-party data sharing you’ve authorized.
- If you want an analog meter, ask about the opt-out program and its cost.
6. Emergency alerts and public safety
The basics
Here’s some good news, because this section is where the fear is usually misplaced.
Wireless Emergency Alerts, the tornado and AMBER alerts that arrive unrequested, are one-way broadcasts. They work like radio: the tower transmits to every phone in an area, and your phone does not report back. No one learns your identity or your location from receiving one. Keep them on.
Go deeper
- Opt-in local alert systems are different. Signing up for your city or campus notification service means giving a phone number and often an address, held by a vendor.
- 911 location is a genuine privacy-for-safety trade worth making. Modern systems deliver precise location to dispatchers automatically, which saves lives when a caller can’t speak.
- Set up your phone’s emergency features: medical ID, emergency contacts, crash and fall detection if you want them. These are on-device and pro-social.
What most people don’t know
Geofence warrants were defeated by an architecture change, not a court ruling. That’s the most important idea in this lesson.
For years, law enforcement could serve a geofence warrant: rather than naming a suspect, it named a place and time and demanded a list of every device present. Because one company held a comprehensive, centralized, server-side history of user locations, it could answer. Thousands of such demands were served, sweeping in people whose only connection to an incident was proximity.
Courts split on whether this was constitutional and never definitively resolved it. What ended the practice was the company restructuring how location history works: moving it onto users’ devices, encrypting backups, and shortening default retention. You cannot produce a list you do not have.
The generalizable principle, and the reason this connects to Section 9: privacy by architecture outlasts privacy by policy. A policy protects you until an administration, a vendor, or a subpoena changes. A system that never centralized the data can’t be compelled to hand it over. When you evaluate a smart city proposal, “who has access under current policy” matters far less than “what does the design make possible at all.”
Do this today
- Keep emergency alerts enabled. They’re broadcast, they don’t identify you, and they save lives.
- Set up Emergency SOS and medical ID on your phone.
- Check your location history settings and move them to on-device storage with the shortest retention you’ll tolerate.
- Understand that opt-in alert systems collect your contact details, and decide accordingly.
7. Data sharing between agencies and vendors
The basics
The city rarely holds its own data. A vendor operates the cameras, the analytics, the sensors, and the cloud storage. What happens to the data is governed by a contract, not by a privacy policy you ever saw.
Go deeper
- Data flows sideways between agencies, into regional fusion centers, and out to state and federal partners. A local deployment often means data reachable well beyond the locality.
- Vendors sometimes retain rights to use aggregated data for product improvement. That’s a contract term, and contract terms are negotiable, when someone is paying attention during procurement.
- When a vendor is acquired or goes bankrupt, its data holdings are assets.
What most people don’t know
Government agencies buy location data commercially to avoid needing a warrant, and the intelligence community has acknowledged the scale of it.
The pattern: data brokers assemble location and behavioral data from apps (see Lesson 1) and sell access to federal agencies. A purchase is not a search, so the Fourth Amendment analysis that would apply to compelling the same records doesn’t obviously reach it. Multiple federal agencies have bought such data.
A declassified U.S. intelligence community report made the position remarkably plain: commercially available information now provides insight into Americans’ lives that would previously have required a warrant, and its volume and sensitivity create real civil liberties concerns. Legislation to close the loophole has passed one chamber of Congress without becoming law.
The other half of this section is the empowering half. Public records law is the counterweight, and it works. Surveillance contracts, system inventories, retention schedules, memoranda of understanding between agencies, and vendor privacy impact assessments are usually public records. Nearly everything the advocacy community knows about municipal surveillance came from someone filing a request. It costs a stamp and some patience, and it’s the single most effective tool an individual has in this entire lesson.
Do this today
- File a public records request with your city for its surveillance technology inventory and the contracts for any system you’re curious about. Templates exist. The EFF, ACLU, and MuckRock all publish them, and MuckRock will file and track it for you.
- Find out whether your city has a CCOPS-style ordinance (Community Control Over Police Surveillance), which requires council approval and public reporting for surveillance acquisitions. Roughly two dozen U.S. cities have adopted some version.
- Read the retention schedule. It’s the least glamorous document and it determines almost everything.
8. What it means for policy and consent
The basics
The consent model that governs the rest of privacy law structurally cannot work in public space. There’s no notice to read, no button to decline, and no alternative street. Anyone insisting your presence implies agreement is describing a fiction.
So the governance model has to be different. Instead of consent, the workable framework is: was this necessary, is it proportionate to the problem, is its use limited to the stated purpose, is the data retained only as long as needed, is there an audit trail, and was it democratically authorized before deployment?
Go deeper
- Cities that have done this well require a surveillance impact report and a council vote before acquisition, publish an annual inventory, and attach sunset clauses so systems expire unless renewed.
- Several U.S. cities banned government facial recognition outright; some later narrowed those bans. The policy is contested and moves.
- European AI regulation restricts certain real-time remote biometric identification in public spaces, with carve-outs. It’s the most substantial attempt anywhere to legislate this category directly.
What most people don’t know
“Anonymized” municipal data releases have been re-identified repeatedly, and the track record is bad enough that it should change how you read the word.
The most instructive case: a city released a dataset of over a hundred million taxi trips with driver and vehicle identifiers hashed, believing that protected privacy. A researcher recovered the original identifiers within hours, because the input space was small and enumerable. Every possible medallion number could simply be hashed and compared. Combined with timestamped pickup locations, the data revealed individual drivers’ full working patterns and income, and in some cases identified passengers from paparazzi photos.
The lesson isn’t that the city was careless. It’s that removing names is not anonymization, and intuitions about what’s safe to publish are unreliable when location and time are involved.
The technical answer that actually works is differential privacy: mathematically bounding what any individual’s data can contribute to a published result, at some cost to precision. The U.S. Census adopted it for the 2020 count. It’s the state of the art, it involves real tradeoffs, and “we used differential privacy with this privacy budget” is a meaningfully different claim than “we anonymized it.”
Do this today
When a smart city project comes before your community, five questions cover most of it:
- What specific problem does this solve, and what’s the evidence it will?
- What data is collected, at what granularity, and how long is it kept?
- Who can access it, including other agencies, the vendor, and federal partners?
- What’s the audit mechanism, and who sees the audits?
- When does authorization expire?
A proposal that can’t answer these isn’t ready, and asking them in a public meeting is more effective than it sounds.
9. Building privacy into the cities of tomorrow
The basics
None of this argues against smart infrastructure. Air quality monitoring, adaptive traffic signals, and efficient transit are real public goods. The question is whether privacy gets designed in at the start or bolted on after the contract is signed, and the difference is almost entirely about what happens in the first six months of a project.
Go deeper
What good design looks like, concretely:
- Minimize at the sensor. A radar or thermal sensor that counts pedestrians without capturing images can’t be repurposed into a face recognition feed. The camera can.
- Process at the edge. Compute the count on the device, transmit the number, never store the image.
- Aggregate by default, with individual-level data requiring separate authorization.
- Sunset clauses, so systems require renewal rather than persisting by inertia.
- Publish the register. Several European cities maintain public registries of their algorithmic and sensor systems: what each does, what data it uses, who’s accountable.
What most people don’t know
The most ambitious smart city project of the last decade collapsed over data governance, and that outcome shaped the industry.
A major technology company’s plan to build a sensor-instrumented district on Toronto’s waterfront ran for roughly three years before being abandoned in 2020. It failed on the questions this lesson is about: who would own the data generated by people simply walking through a neighborhood, who would govern it, and whether a private company could hold that role at all. Proposals for an independent civic data trust didn’t resolve it. Advisors resigned publicly. The project ended.
Vendors learned from this. Current pitches lead with privacy commitments in a way they didn’t before, which is progress, and also means the scrutiny has to move from the marketing to the procurement documents, where the enforceable terms live.
Which is the closing insight: the strongest privacy protections in a connected city are contract terms and ordinances, not settings. There’s no toggle on a streetlight. There is a retention schedule, a purpose limitation clause, an audit requirement, and a sunset date. Those get written by people in rooms that are, by law, open to you.
Do this today
- Find out when your city council or transportation board meets, and whether technology procurements appear on the agenda.
- Support or ask about a surveillance oversight ordinance if your city lacks one.
- If your city publishes a technology register or surveillance inventory, read it once. If it doesn’t, that’s a concrete thing to ask for.
Recap
- You can’t consent your way out of public infrastructure; the leverage is records requests, contracts, and ordinances.
- ALPR networks pool locally-collected plate data into nationally searchable databases.
- Private doorbell cameras can be integrated into police-accessible networks by a homeowner’s checkbox.
- Sensors deployed for one purpose reliably get used for others unless a written purpose limitation prevents it.
- You’re counted by Wi-Fi and Bluetooth even when you never connect; turning the radios off is the mitigation.
- Anonymous transit fare media usually exists and is deliberately less convenient.
- Smart meter interval data can identify individual appliances, and a federal appeals court called collecting it a search.
- Emergency broadcast alerts don’t identify you. Keep them on.
- Agencies buy location data commercially to sidestep warrant requirements.
- “Anonymized” location datasets have been re-identified repeatedly; differential privacy is the real answer.
- Privacy by architecture beats privacy by policy; a system that never holds the data can’t be compelled to produce it.
Key terms
- ALPR: automated license plate reader; logs plate, time, and location, often into a shared national database.
- Real-time crime center: a facility integrating camera, ALPR, sensor, and dispatch feeds into a single live interface.
- Mission creep: infrastructure deployed for one stated purpose being used for another.
- Probe request: the broadcast your phone makes looking for known Wi-Fi networks, which allows passive tracking without connecting.
- Nonintrusive load monitoring (NILM): inferring individual appliance use from whole-home power consumption data.
- Geofence warrant: a demand for all devices present at a location and time, rather than for a named suspect.
- Data broker loophole: agencies purchasing commercially available data that they would otherwise need legal process to obtain.
- CCOPS ordinance: Community Control Over Police Surveillance; requires council approval and public reporting for surveillance technology.
- Differential privacy: a mathematical guarantee bounding any individual’s contribution to a published statistic.
- Privacy by architecture: designing systems so sensitive data is never centralized, rather than restricting access by policy.
Check your understanding
1. You never connect to the free Wi-Fi at the mall. Are you being tracked by it? Possibly, yes. Your phone broadcasts probe requests whenever Wi-Fi is enabled, and passive systems log devices that never join. Declining to connect protects your traffic, not your presence. Turning the radio off is what addresses this.
2. Geofence warrants largely stopped working. Why? Because the company holding centralized location history redesigned the system to store it on users’ devices instead of its servers. Courts never definitively resolved the constitutional question. The data simply stopped being available to produce. Architecture, not policy.
3. Your city proposes traffic-counting sensors, and officials assure you no images are stored. What’s the question that matters? Whether the sensors are technically capable of capturing images at all. “We don’t store them” is a configuration choice that a future administration can change without new hardware. A sensor that can’t capture an image can’t be repurposed into one that does.
Next lesson: Connected Home — smart devices, voice assistants, and connected living.