DeSpy Privacy Academy Lesson 4

August 4, 2026

Connected Cities

The smart city isn’t just convenient. It’s collecting your data 24/7.

Lesson 4 of 6 · Estimated read: 15 minutes · Level: everyone

Every lesson before this one ended with settings you could change. This one is different, and it’s worth saying so at the start.

You can decline an app’s location request. You cannot decline a street. Public infrastructure collects data about people who never agreed to anything, and no privacy setting on your phone touches a license plate reader or a streetlight sensor.

That doesn’t leave you powerless. It moves the leverage. In the connected city, the effective controls are public records requests, procurement contracts, and local ordinances. Boring words that have repeatedly beaten billion-dollar surveillance deployments. This lesson covers what’s out there, and where the actual pressure points are.

In this lesson

  1. Smart cameras and surveillance
  2. IoT sensors and environmental data
  3. Public Wi-Fi and location tracking
  4. Transportation and traffic systems
  5. Utilities and smart meters
  6. Emergency alerts and public safety
  7. Data sharing between agencies and vendors
  8. What it means for policy and consent
  9. Building privacy into the cities of tomorrow

1. Smart cameras and surveillance

The basics

Municipal camera networks have changed in kind, not just in number. Older systems recorded to a tape someone reviewed after an incident. Current systems do live analytics: reading license plates, detecting objects, tracking a person’s movement across multiple cameras, and searching footage by description.

The multiplier is integration: pulling separate camera systems into one interface.

Go deeper

What most people don’t know

Your doorbell camera may already be enrolled in a police-accessible network, and the enrollment was a checkbox.

Integration platforms let a police department maintain a live map of registered private cameras, including residential doorbells, small business systems, and apartment building lobbies. Depending on how the homeowner registered, this ranges from “police know a camera exists here and can request footage” to “police can pull the live stream.”

The consent structure is the interesting part. A homeowner opts in. Everyone who walks past that camera did not, and has no way to know the camera feeds a municipal system. Private surveillance becomes public infrastructure through an aggregation of individual choices, none of which required a public hearing.

If you own a camera, this is a decision you’re making on behalf of your neighbors.

Do this today

2. IoT sensors and environmental data

The basics

Cities deploy sensors that mostly aren’t cameras: air quality monitors, noise meters, traffic counters, pedestrian counters, weather stations, water flow, waste bin fill levels, parking occupancy. Individually mundane, and much of it genuinely useful.

Go deeper

What most people don’t know

Infrastructure deployed for one purpose gets repurposed for another, and that’s the norm rather than the exception.

The canonical case: a major U.S. city installed several thousand “smart streetlights,” justified and funded as an environmental and traffic-optimization program. They contained cameras. Police accessed the footage hundreds of times before the public learned the capability existed. The resulting backlash shut the program down and produced a surveillance oversight ordinance.

Nothing illegal necessarily happened. The system had a capability, an agency had a need, and no rule said no. Absent a binding purpose limitation written down in advance, mission creep is the default trajectory of any sensor network. This is why “it’s just counting cars” is not a description of a system’s future, only of its present configuration.

The security-professional framing: assume the deployed capability will eventually be used to its technical limit, and evaluate proposals on capability rather than stated intent.

Do this today

3. Public Wi-Fi and location tracking

The basics

Free public Wi-Fi is rarely free. The transaction is usually your email address, your device identifier, and a record of your visits, collected through the sign-in page and used for analytics or marketing.

Go deeper

What most people don’t know

You don’t have to connect to be counted.

Your phone broadcasts probe requests looking for known networks whenever Wi-Fi is enabled. Passive collection systems listen for those broadcasts and log devices that never joined anything, never saw a sign-in page, and never agreed to terms. The same applies to Bluetooth.

This inverts the usual advice. “Don’t connect to public Wi-Fi” protects your traffic; it does nothing about being tracked. The mitigation for presence tracking is turning the radios off, not declining to join.

Practically: if you’d rather not be counted walking through a mall or transit hub, Wi-Fi and Bluetooth off is the control. Airplane mode with cellular re-enabled works too.

Do this today

4. Transportation and traffic systems

The basics

Transit and roads generate some of the most revealing location data in existence, because movement patterns are habitual and habits identify people.

Sources: transit fare cards, toll transponders, congestion pricing cameras, bike and scooter share systems, parking apps, and rideshare records.

Go deeper

What most people don’t know

Anonymous fare media usually exists, and it’s deliberately less convenient.

Most transit systems still sell unregistered cards you can buy with cash and load with cash. Trips accumulate against a card number tied to nothing. The catch is that convenience features like balance protection if you lose the card, autoload, fare capping, and app integration generally require registration. So the private option exists and is quietly penalized.

For most people the tradeoff isn’t worth it. But the option is there, it costs nothing to know about, and it matters for anyone with a specific reason to keep their movements unlinked: journalists, people leaving abusive situations, anyone attending something lawful they’d rather not have logged.

Worth noting too that transit agencies have had real incidents where trip history was exposed to anyone holding a card number, so the data isn’t only reachable by subpoena.

Do this today

5. Utilities and smart meters

The basics

A traditional meter was read monthly: one number. A smart meter reports consumption at intervals, commonly every fifteen minutes or every hour, to the utility, automatically.

Go deeper

What most people don’t know

Fine-grained power consumption can identify individual appliances, and a federal appeals court has held that collecting it is a Fourth Amendment search.

The technique is called nonintrusive load monitoring. Every appliance has a characteristic electrical signature, so a sufficiently granular consumption trace can be decomposed to reveal which devices are running when: refrigerator cycles, a washing machine, a space heater, and in research settings finer distinctions than that.

The legal piece is the part even privacy specialists often miss. In a 2018 decision, the Seventh Circuit held that a city’s collection of smart meter data at fifteen-minute intervals did constitute a search under the Fourth Amendment, while concluding that this particular search was reasonable, given that the utility was municipal and the purpose was billing rather than law enforcement.

That’s an unusually clear judicial acknowledgment that utility data is constitutionally protected information, and it’s the doctrinal hook for arguing about retention, granularity, and law enforcement access. Utility records have been used in investigations, and the “reasonable” finding rested on the purpose, which means purpose limitation is doing the legal work.

Do this today

6. Emergency alerts and public safety

The basics

Here’s some good news, because this section is where the fear is usually misplaced.

Wireless Emergency Alerts, the tornado and AMBER alerts that arrive unrequested, are one-way broadcasts. They work like radio: the tower transmits to every phone in an area, and your phone does not report back. No one learns your identity or your location from receiving one. Keep them on.

Go deeper

What most people don’t know

Geofence warrants were defeated by an architecture change, not a court ruling. That’s the most important idea in this lesson.

For years, law enforcement could serve a geofence warrant: rather than naming a suspect, it named a place and time and demanded a list of every device present. Because one company held a comprehensive, centralized, server-side history of user locations, it could answer. Thousands of such demands were served, sweeping in people whose only connection to an incident was proximity.

Courts split on whether this was constitutional and never definitively resolved it. What ended the practice was the company restructuring how location history works: moving it onto users’ devices, encrypting backups, and shortening default retention. You cannot produce a list you do not have.

The generalizable principle, and the reason this connects to Section 9: privacy by architecture outlasts privacy by policy. A policy protects you until an administration, a vendor, or a subpoena changes. A system that never centralized the data can’t be compelled to hand it over. When you evaluate a smart city proposal, “who has access under current policy” matters far less than “what does the design make possible at all.”

Do this today

7. Data sharing between agencies and vendors

The basics

The city rarely holds its own data. A vendor operates the cameras, the analytics, the sensors, and the cloud storage. What happens to the data is governed by a contract, not by a privacy policy you ever saw.

Go deeper

What most people don’t know

Government agencies buy location data commercially to avoid needing a warrant, and the intelligence community has acknowledged the scale of it.

The pattern: data brokers assemble location and behavioral data from apps (see Lesson 1) and sell access to federal agencies. A purchase is not a search, so the Fourth Amendment analysis that would apply to compelling the same records doesn’t obviously reach it. Multiple federal agencies have bought such data.

A declassified U.S. intelligence community report made the position remarkably plain: commercially available information now provides insight into Americans’ lives that would previously have required a warrant, and its volume and sensitivity create real civil liberties concerns. Legislation to close the loophole has passed one chamber of Congress without becoming law.

The other half of this section is the empowering half. Public records law is the counterweight, and it works. Surveillance contracts, system inventories, retention schedules, memoranda of understanding between agencies, and vendor privacy impact assessments are usually public records. Nearly everything the advocacy community knows about municipal surveillance came from someone filing a request. It costs a stamp and some patience, and it’s the single most effective tool an individual has in this entire lesson.

Do this today

8. What it means for policy and consent

The basics

The consent model that governs the rest of privacy law structurally cannot work in public space. There’s no notice to read, no button to decline, and no alternative street. Anyone insisting your presence implies agreement is describing a fiction.

So the governance model has to be different. Instead of consent, the workable framework is: was this necessary, is it proportionate to the problem, is its use limited to the stated purpose, is the data retained only as long as needed, is there an audit trail, and was it democratically authorized before deployment?

Go deeper

What most people don’t know

“Anonymized” municipal data releases have been re-identified repeatedly, and the track record is bad enough that it should change how you read the word.

The most instructive case: a city released a dataset of over a hundred million taxi trips with driver and vehicle identifiers hashed, believing that protected privacy. A researcher recovered the original identifiers within hours, because the input space was small and enumerable. Every possible medallion number could simply be hashed and compared. Combined with timestamped pickup locations, the data revealed individual drivers’ full working patterns and income, and in some cases identified passengers from paparazzi photos.

The lesson isn’t that the city was careless. It’s that removing names is not anonymization, and intuitions about what’s safe to publish are unreliable when location and time are involved.

The technical answer that actually works is differential privacy: mathematically bounding what any individual’s data can contribute to a published result, at some cost to precision. The U.S. Census adopted it for the 2020 count. It’s the state of the art, it involves real tradeoffs, and “we used differential privacy with this privacy budget” is a meaningfully different claim than “we anonymized it.”

Do this today

When a smart city project comes before your community, five questions cover most of it:

  1. What specific problem does this solve, and what’s the evidence it will?
  2. What data is collected, at what granularity, and how long is it kept?
  3. Who can access it, including other agencies, the vendor, and federal partners?
  4. What’s the audit mechanism, and who sees the audits?
  5. When does authorization expire?

A proposal that can’t answer these isn’t ready, and asking them in a public meeting is more effective than it sounds.

9. Building privacy into the cities of tomorrow

The basics

None of this argues against smart infrastructure. Air quality monitoring, adaptive traffic signals, and efficient transit are real public goods. The question is whether privacy gets designed in at the start or bolted on after the contract is signed, and the difference is almost entirely about what happens in the first six months of a project.

Go deeper

What good design looks like, concretely:

What most people don’t know

The most ambitious smart city project of the last decade collapsed over data governance, and that outcome shaped the industry.

A major technology company’s plan to build a sensor-instrumented district on Toronto’s waterfront ran for roughly three years before being abandoned in 2020. It failed on the questions this lesson is about: who would own the data generated by people simply walking through a neighborhood, who would govern it, and whether a private company could hold that role at all. Proposals for an independent civic data trust didn’t resolve it. Advisors resigned publicly. The project ended.

Vendors learned from this. Current pitches lead with privacy commitments in a way they didn’t before, which is progress, and also means the scrutiny has to move from the marketing to the procurement documents, where the enforceable terms live.

Which is the closing insight: the strongest privacy protections in a connected city are contract terms and ordinances, not settings. There’s no toggle on a streetlight. There is a retention schedule, a purpose limitation clause, an audit requirement, and a sunset date. Those get written by people in rooms that are, by law, open to you.

Do this today

Recap

Key terms

Check your understanding

1. You never connect to the free Wi-Fi at the mall. Are you being tracked by it? Possibly, yes. Your phone broadcasts probe requests whenever Wi-Fi is enabled, and passive systems log devices that never join. Declining to connect protects your traffic, not your presence. Turning the radio off is what addresses this.

2. Geofence warrants largely stopped working. Why? Because the company holding centralized location history redesigned the system to store it on users’ devices instead of its servers. Courts never definitively resolved the constitutional question. The data simply stopped being available to produce. Architecture, not policy.

3. Your city proposes traffic-counting sensors, and officials assure you no images are stored. What’s the question that matters? Whether the sensors are technically capable of capturing images at all. “We don’t store them” is a configuration choice that a future administration can change without new hardware. A sensor that can’t capture an image can’t be repurposed into one that does.

Next lesson: Connected Home — smart devices, voice assistants, and connected living.