What's documented

Three things happened in the same few weeks, in three unrelated corners of government. San Francisco police left five drone feeds sitting behind a link anyone could open. Officers around the country got caught running license-plate cameras to track exes and, in at least one case, plant a GPS tracker. And a federal agency built to regulate lawnmowers and coffeemakers started pressuring more than 100 hospitals to hand over emergency-room patient records.

Read alone, those are three stories about three agencies making three separate mistakes. Read together, they're the same story: the walls that used to separate what one part of government could see about you from what another part could see are coming down, fast, almost always without a public vote — and once the data moves, a private contractor is usually the one holding it.

This piece is the map. Not every mechanism watching you (that list has no bottom), but the ones with real documentation behind them right now: who collects it, who else gets to see it, what's gone wrong, and — the part most coverage skips — whether you can actually do anything about it.

The cameras and the drones

Local police departments now run networked license-plate cameras (Flock Safety is the dominant vendor) that log every car that passes, logged with a time and a location. Norfolk, Virginia alone runs about 170 of them. There's no official contract letting Immigrations and Customs Enforcement search this data — but officers have typed "ICE" or "immigration" directly into the system's own justification field more than 4,000 times, and San Francisco's camera database alone was queried 1.6 million times by law enforcement agencies from outside California, the basis of a pending class-action lawsuit.

The misuse cases are no longer rare enough to call outliers. A Milwaukee officer ran his girlfriend's plate 124 times and her ex's 55 times; he pleaded guilty. One of the two detectives assigned to investigate him got caught doing the same thing — plus secretly installing a GPS tracker on a woman's car. Five Georgia officers were arrested for the same pattern in July. A running count kept by the Institute for Justice, a nonprofit law firm, is in the high twenties and climbing, and the group itself calls that an undercount, since most cases only surface when a victim complains.

Drones tell a similar story, just newer. As of February 2026, more than 1,000 US police departments have FAA approval to fly autonomous drones out of direct sightline — up from almost none seven years ago. There's no federal privacy floor governing what these drones can record or how long departments keep the footage; it's department-by-department policy, not law. San Francisco's own drone program is the case study in what goes wrong: five live drone feeds — color video, thermal video, pilot names and emails — sat behind a link that needed no password for roughly six months, discovered by two independent security researchers, Sam Curry and Maik Robert, while combing through archived web links.

What you can actually do: haveibeenflocked.com lets you look up whether your own plate shows up in released audit logs (coverage isn't universal, but it's real). deflock.org is a crowdsourced map of more than 116,000 license-plate cameras nationwide, and climbing. Neither stops the cameras from watching. Nothing does.

The walls between agencies are coming down

This is the part that's harder to see, because none of it shows up on a street corner.

Since mid-2025, the Centers for Medicare & Medicaid Services has been handing ICE data on Medicaid enrollees — names, addresses, immigration status. A federal judge found CMS shared more than courts had allowed, sweeping in US citizens' data along with it, then found out it happened a second time. The data didn't stop with ICE: NPR reported in July 2026 that ICE passed the Medicaid data to Palantir, the government-contracted data firm, which is now running it through a tool called ELITE to help map where to find deportation targets.

The IRS's situation with ICE is genuinely unresolved as this piece runs — not spun that way, actually unresolved: a federal appeals court ruled the two agencies can keep sharing taxpayer data, while a separate federal judge in Massachusetts, in a different case, blocked ICE from using what it receives. Both rulings are in effect at the same time.

The Social Security Administration's situation is the most concretely documented misuse of the bunch. In a January 2026 court filing, the Justice Department itself admitted that DOGE's original 2025 access grant included full Social Security numbers. Separately, that January 2026 filing revealed a DOGE team member had moved names and addresses for roughly 1,000 people onto a third-party server that wasn't approved to hold SSA data, and that one DOGE associate had signed an agreement to share SSA data with an outside political advocacy group. A court order limiting DOGE's access to that data was thrown out on appeal in April 2026. Access remains open right now, while the underlying case continues.

Underneath several of these flows sits the same contractor: Palantir runs at least three linked systems for ICE, built through contracts worth well over $150 million combined, pulling together everything from FBI and DEA records to school enrollment, employment history, and license-plate-reader feeds into what amounts to a single searchable profile per target.

What you can actually do: nothing, for any of this specifically. These are mandatory government data flows with no individual opt-out — a citizen doesn't get a form to fill out to keep their Medicaid record, tax data, or Social Security file out of an inter-agency share. The only lever that exists is the same one that's already working: litigation and public pressure, which is what forced the CMS and SSA numbers above into daylight in the first place.

The loophole: buying what they'd need a warrant to take

Here's the mechanism that ties the last two sections together, and it has a name reporters and privacy lawyers already use for it: the data broker loophole. Rather than subpoena your location history — which would need a warrant — federal agencies simply buy it from a company that collected it from your phone's apps.

This isn't theoretical. DHS's own inspector general found in 2023 that ICE, CBP, and the Secret Service had been buying commercial location data in ways that violated the department's own privacy policy, and likely federal law. That specific program was shut down. It has since restarted: a 2025 contract routes the same kind of data through a company called PenLink, and in March 2026, FBI Director Kash Patel told the Senate Intelligence Committee, under questioning from Sen. Ron Wyden, that the Bureau "purchase[s] commercially available information that's consistent with the Constitution" — testimony Wyden and privacy advocates read as confirming the location-data purchases, though an FBI spokesperson later disputed that the Director had specifically said the Bureau buys Americans' location data.

The Federal Trade Commission has started pushing back on the sellers' side — it's banned several of the largest location-data brokers, including one called Gravy Analytics (whose subsidiary Venntel sold data directly to ICE, CBP, and the FBI), from selling the most sensitive categories of location data, like visits to health clinics or places of worship, without real consent. But those bans carve out an exception for transfers to law enforcement and national security — which is exactly the transfer this section is about. A bill that would close the loophole outright, the Government Surveillance Reform Act, has bipartisan sponsors in the Senate. It hasn't passed.

What you can actually do: this is where a real opt-out exists, imperfect as it is. If you live in California, the state's new DROP tool — live since January 2026 — lets you file a single request that reaches every data broker registered in the state; enforcement (with real penalties) starts in August 2026. If you live anywhere else, paid services like DeleteMe or Incogni will work through the individual removal process for you, or you can do it yourself, site by site — Spokeo, Whitepages, and similar people-search sites all have working opt-out forms that take 24 to 72 hours to process. None of this touches the data these brokers have already sold to a government contractor. It only slows the next sale.

The consent you technically gave

There's a reason companies can legally do the first half of the data-broker pipeline in the last section — sell what an app collected from your phone — and it isn't a secret loophole. It's sitting in the agreement you clicked through.

A 2008 Carnegie Mellon-affiliated study calculated that reading every privacy policy the average person encounters in a year would take about 244 hours — a figure later popularized as "76 work days" by The Atlantic in 2012, and still the most-cited estimate of its kind, even though average policy length has dropped substantially since then. Nobody does this. Companies know nobody does this. The two legal forms these agreements take reflect that. A "clickwrap" agreement — the box you actively check, or the button you click before you can continue — creates a real record that you agreed to something specific, and US courts generally enforce it. A "browsewrap" agreement — the quieter version, where the terms just sit linked in a footer and continuing to use the site or app counts as agreeing — is weaker in court, but companies use it constantly anyway, and it has been upheld often enough that "if you keep using this, you agree" functions as real, operative consent, not just a bluff. That's the backdoor: not that the law was broken, but that the law accepts a "yes" nobody meaningfully gave.

There's a genuinely useful irony buried in here. California's CCPA — and most of the 20 state privacy laws that followed it — legally requires companies to disclose your right to opt out of having your data sold, and that disclosure almost always lives inside the exact document this section is about: the privacy policy nobody opens. The opt-out right is frequently real. It's just filed inside the one place built to be skipped.

A volunteer project called Terms of Service; Didn't Read has been reading these agreements since 2012 and grading them A through E — Instagram and PayPal both land at the worst grade, and neither is close to alone. Full breakdown, company by company, is its own piece: I Graded Every App on My Phone From A to E. Instagram and PayPal Both Failed. — worth reading on its own, not crammed in here.

What you can actually do: you don't have to read the document to know what's in it. tosdr.org (Terms of Service; Didn't Read) is a volunteer-run project that's been grading major sites' and apps' terms since 2012, A through E, and flags the specific clauses that are actually a problem — there's a free browser extension that shows you the grade before you agree to anything. It won't stop you from technically consenting. It'll at least tell you what you're consenting to, in the time it takes to glance at a letter grade instead of 2,500 words of legal text.

The part almost nobody knows: none of America's privacy laws reach any of this

This is the finding that ties the whole piece together, and it's the one most stories about any single incident above never get to.

Twenty US states now have a comprehensive consumer privacy law on the books, as of 2026 — California's is the strongest, and it's the only one with a tool like DROP. But every single one of these laws, in every state, defines its target as a "business" or a "controller" — and every one of them explicitly writes government and law enforcement out of that definition. There's no federal version of these laws either: two attempts at one, in 2022 and again in 2024, both died in Congress without ever getting a floor vote, and nothing has replaced them.

The result is exact and specific, not a vague complaint: everything in this piece's first two sections — the license-plate cameras, the drones, the CMS-to-ICE data, the SSA access, the Palantir contracts — sits almost entirely outside what any state privacy law, or any opt-out tool built from one, can touch. The tools in the "loophole" section above work because they target a company. Nothing in this piece works against an agency.

What this piece is not saying

This isn't an argument that surveillance itself is always wrong, or that every officer who runs a plate search is up to something. Milwaukee's own prosecutor, the one who called one officer's conduct "an abuse of power," said at the very same hearing that "the vast majority of law enforcement appropriately uses that tool to investigate crime." Flock's cameras have helped make real arrests; drones have located people who needed help. The pattern documented here isn't that the tools are evil — it's that the guardrails meant to keep them checked keep falling, one exposure or court filing at a time, almost always with nobody outside government finding out until after the fact.

It's also not saying every legal question here is settled. The IRS-ICE data sharing is genuinely contested in two different federal courts right now, with different outcomes standing at the same time. The Fourth Circuit case over whether license-plate networks even count as a Fourth Amendment "search" is still on appeal. Treat anything framed as ongoing litigation as exactly that.

What can I do

There's no single fix, because this isn't one system — it's a dozen separate ones that happen to be moving the same direction at once. But here's what's real, not aspirational:

Check what's already out there about you. haveibeenflocked.com for license-plate history where logs are public; deflock.org to see camera density near you.

If you're in California, use DROP. It's the single strongest consumer tool that exists anywhere in the country right now — one request, every registered broker, real penalties for non-compliance starting August 2026.

Everywhere else, go after the brokers directly. DeleteMe, Incogni, or Optery will do the removal work for a fee; Spokeo, Whitepages, BeenVerified, and similar sites all have their own opt-out forms if you'd rather not pay.

Understand what genuinely has no opt-out, so you're not wasting time looking for one: your bank's suspicious-activity reporting, Medicaid-to-ICE data sharing where it applies, and Social Security access by agencies with the authority to have it. These are legally mandatory. There's no form for any of them.

Push where the pressure has actually worked. Every fix documented in this piece — the CMS ruling narrowing what could be shared, the SSA case forcing DOJ to admit what happened, California's own DROP tool — came from a lawsuit, a records request, or legislative pressure, not from a company or agency volunteering it. That's the lever that's real.

The Receipts