Privacy Governance
The complaint came from a number the duty supervisor did not recognize. A woman who lived three blocks from a domestic disturbance call said she had seen a news article that included footage from a nearby police incident. Her face was visible in the released body-worn camera (BWC) footage. She had been standing on her own porch, watching police activity on her street, as any neighbor would. She was not involved in the incident. She had not consented to appear in released footage. Her face was now in a news story linked to a domestic violence call in her neighborhood, with her address implied by the context. She was not angry, she said. She was frightened. She had a protective order against someone. Now that person could find her address from a news article based on publicly released police footage. The duty supervisor took the call, took notes, and forwarded the complaint to the records unit supervisor and legal counsel before the end of the shift. The records unit had released the footage two weeks earlier. The AI-assisted redaction tool had missed the porch. The human reviewer had not caught it either.
Why Privacy Governance Is Not a Compliance Checkbox
Privacy governance, in the law enforcement records context, means building the policies, procedures, tools, and accountability structures that protect the privacy of third parties across the entire records pipeline: from the moment footage is captured to the moment it is released, retained, or destroyed. It is not a single step. It is not "run the AI redaction tool and move on." It is a system with written rules, defined roles, documented procedures, regular audits, and a named person responsible for its outcomes.
The woman on the porch is the reason. She was not a suspect. She was not a witness. She was a private citizen going about her life within range of a police camera. Her face was captured without her knowledge and released without her consent to a jurisdiction where it attached to a news story that could, in the scenario above, endanger her safety. This is the harm that privacy governance is designed to prevent. It is not hypothetical. It is a pattern that recurs whenever a records unit treats redaction as a technical problem to be solved by a tool rather than a governance problem to be managed by policy.
The Electronic Frontier Foundation (EFF) has specifically cited the release of footage containing third-party faces as one of its core concerns about AI in law enforcement. The EFF's argument is not that BWC footage should never be released; it is that automated systems for redacting that footage will systematically fail in predictable ways, particularly for faces that appear at the periphery of the frame, in low light, at a distance, or for only a small number of frames. When these systems fail without adequate human oversight and audit, the failures fall hardest on the private citizens who had no part in the incident and no knowledge they were being recorded.
Privacy governance means third-party protection is built into every step of the records pipeline, not bolted on after a complaint. When a failure occurs, governance provides the audit trail to understand what went wrong, the accountability structure to address it, and the policy basis for correcting it.
Who Is a Third Party and Why It Matters
The term "third party" in the records and redaction context refers to any person captured in footage or records who is not a named party to the incident: not the suspect, not the victim where the victim has consented to identification, and not an officer acting in an official capacity. Third parties include bystanders, neighbors, uninvolved witnesses who have not been designated as confidential, store employees visible in a retail theft call, passengers in a vehicle stopped for a moving violation who are not the subject of the stop, and any child visible in footage regardless of their role.
Minors, meaning persons under the age of eighteen, are a distinct and heightened category. In most jurisdictions, a minor's face must be redacted from any public release regardless of whether the minor was involved in the incident. A visible minor's face in released footage is not just an over-sight; it is a potential violation of state juvenile confidentiality statutes, and it can trigger specific legal consequences separate from any general privacy tort. When the AI redaction tool or the human reviewer misses a minor's face, the failure is in the highest category of under-redaction severity.
License plates visible in BWC footage are another third-party category that requires redaction in most release contexts, because a license plate is a unique identifier that allows the lookup of an individual's address, vehicle history, and registration information. A visible plate in released footage is a de facto disclosure of a private individual's address and vehicle information, potentially to persons who would misuse it.
The Governance Structure: Roles and Responsibilities
A privacy governance structure for AI-assisted records release has four roles: the privacy officer, the records reviewer, the legal reviewer, and the platform administrator. In smaller agencies, one person may perform more than one of these roles, but the functions must all be covered and documented.
The Privacy Officer
The privacy officer is the person responsible for the agency's privacy policy and for oversight of compliance with that policy in the records release workflow. The privacy officer does not review every release, but they set the standards that govern every release: what categories of information must be redacted in every context, what categories require case-by-case legal review, what the escalation path is when a reviewer is uncertain, and what constitutes a privacy failure requiring notification, legal counsel involvement, or regulatory reporting.
The privacy officer is also responsible for the relationship with the AI vendor: ensuring the vendor's data-use agreement is current, that the CJIS (Criminal Justice Information Services) Security Policy compliance documentation is on file and audited annually, and that changes to the vendor's tool are reviewed for privacy impact before deployment. CJIS obligations remain with the agency, not the vendor, and the privacy officer is the agency's designated point of accountability for those obligations.
The Records Reviewer
The records reviewer is the person who processes individual release packages: reviewing the AI redaction proposal, completing the human verification pass, building the exemption log, and preparing the release for the four-corners check. The records reviewer's privacy governance function is to apply the agency's privacy policy to each specific release and to catch what the AI tool missed.
The records reviewer is the last human check before a release goes out. The woman on the porch was missed by the AI and then missed by the human reviewer. That double failure indicates a gap in the reviewer's process: either the reviewer did not watch the full footage, did not examine the edges of the frame in scenes with distant or peripheral figures, or applied insufficient attention to the release because it was a high-volume period and the request had been in the queue too long. All of these are governance failures, not just individual errors. The governance structure must build in a review process that is reliable under time pressure, not just under ideal conditions.
The Legal Reviewer
The legal reviewer, typically legal counsel or a designated attorney in the records unit, handles the cases where the records reviewer cannot make a determination: uncertain exemptions, material that may be relevant to pending or foreseeable litigation, redactions that are disputed by the requestor, and any request involving a minor or a confidential witness. The legal reviewer's role is not to approve every release but to be the escalation point when the records reviewer hits a question the policy does not clearly answer.
The escalation path must be defined, staffed, and time-bound. A legal review hold that has no deadline becomes a disclosure delay that violates the statutory response period. The governance structure must set a maximum legal review period (typically twenty-four to seventy-two hours for standard escalations) and must require the legal reviewer to either clear the hold or document a specific reason for extending it.
The Platform Administrator
The platform administrator is responsible for the configuration of the AI-assisted redaction tool: setting detection thresholds, configuring officer-face policy (whether officer faces are preserved in accountability releases or redacted), managing the tool's confidence thresholds for low-light and peripheral-figure detection, updating the tool when the vendor releases new versions, and maintaining the audit log settings that the disclosure and governance records depend on.
Platform administration is a governance function, not a technical task. A misconfigured threshold that causes the tool to miss peripheral faces in low-light conditions is a privacy governance failure with specific consequences, as the porch case demonstrates. The platform administrator must understand what the tool can and cannot do in the agency's specific footage environment and must configure it for the agency's specific policy requirements, not the vendor's default settings.
The Five Failure Points and Their Governance Remedies
Privacy failures in AI-assisted records release cluster into five predictable failure points. Each has a specific governance remedy. Understanding the failure points makes the governance structure concrete: the rules and procedures are not abstract policy; they are the specific answers to the specific ways the system breaks.
Failure point one: AI confidence threshold failures. The AI redaction tool misses faces or plates that fall below its confidence threshold, as happened with the woman on the porch. The governance remedy is a defined human review protocol specifically targeting the conditions where AI detection is unreliable: low-light sequences, peripheral-figure sequences (the edges of the frame), fast-movement sequences, and any sequence flagged by the tool with a confidence score below a defined floor. The human reviewer must be specifically directed to these conditions, not just to "check the AI's work" in general.
Failure point two: officer-face over-redaction. The tool proposes blurring the officer's face in an accountability release. The governance remedy is a written policy stating which release categories require officer faces to be visible and a platform configuration that reflects that policy. The policy must be reviewed against the jurisdiction's case law annually, because the legal landscape on officer-face redaction continues to evolve.
Failure point three: minor identification. A minor appears in footage and the tool either misses the face or identifies it as an adult. The governance remedy is a mandatory minor-identification review step: for any footage from calls involving residential locations, schools, youth facilities, or any call type with elevated minor-presence probability, the human reviewer specifically looks for minor faces before completing the redaction review. Minor faces must be redacted to a more stringent standard than adult civilian faces because the statutory consequences are more severe.
Failure point four: written-record personal information gaps. Personal information fields in written records (Social Security numbers, dates of birth, home addresses, phone numbers, email addresses, medical record numbers) are missed during the written-record redaction review. The governance remedy is a standardized redaction checklist for written records that lists every required redaction category and requires the reviewer to affirmatively check each category against each document. A reviewer who checks the list is more reliable than a reviewer who reads the document and redacts from memory.
Failure point five: data retention and secondary use by the vendor. The AI tool processes footage through a vendor platform. The vendor's platform retains the footage for a period that is not specified in the contract. The vendor's model is updated using data from the platform, potentially including the agency's footage. This is a governance failure at the procurement level: the agency signed a contract without specifying data retention limits and prohibiting secondary use of agency footage for model training. The governance remedy is contract language that specifies the maximum retention period for processed data, prohibits the vendor from using agency data for model training without explicit written consent, and requires the vendor to certify CJIS compliance annually.
CJIS: The Agency's Non-Delegable Obligations
The CJIS Security Policy, administered by the Federal Bureau of Investigation's Criminal Justice Information Services Division, establishes the minimum security requirements for the handling of criminal justice information, which includes the records and footage involved in public-records releases and criminal case disclosure. CJIS obligations are the agency's obligations, not the vendor's. Using a third-party AI platform does not transfer, reduce, or eliminate any CJIS obligation. The agency remains fully responsible for ensuring that CJIS-covered data processed through the vendor's platform is handled in compliance with the CJIS Security Policy.
The specific CJIS requirements most relevant to AI-assisted redaction platforms include: access controls requiring that only authorized personnel access CJIS-covered data; audit logging requiring that all access to and processing of CJIS-covered data is logged with sufficient detail to reconstruct who accessed what data and when; encryption requirements for data in transit and at rest; personnel security requirements for vendor employees who access CJIS-covered data; and physical and technical security requirements for the infrastructure where CJIS-covered data is stored and processed.
An agency that deploys a cloud-based AI redaction platform without verifying the vendor's CJIS compliance has a problem that cannot be fixed retroactively. Every record that was processed through the non-compliant platform was processed in violation of CJIS requirements. In a criminal case, this can become a chain-of-custody issue: if the defense can argue that the footage was processed by a non-CJIS-compliant vendor and therefore cannot be authenticated as unaltered, the footage's admissibility is in question. Verifying CJIS compliance before deployment is not bureaucratic caution. It is the prerequisite for the tool's usefulness in court.
Annual CJIS compliance audits of the vendor are not optional extras. They are required. Vendor compliance certifications expire. Vendor infrastructure changes. Vendor data-use agreements lapse. The privacy officer's governance calendar must include an annual review of the vendor's CJIS compliance documentation and a contract renewal or renegotiation triggered by any compliance gap.
Building a Privacy-by-Design Records Pipeline
Privacy by design is a principle that originated in data protection law and has been adopted in public safety contexts as the standard for building privacy protection into systems rather than adding it after a failure reveals the gap. A privacy-by-design records pipeline means that at every stage from footage capture to release, privacy protection is built into the workflow as a required step, not an optional one.
In the BWC footage context, privacy by design starts at the camera level: body-worn cameras are configured with automatic activation rules that limit unnecessary recording. It continues at the upload and storage level: footage is stored in a CJIS-compliant environment with access controls from the moment of upload. It continues at the processing level: footage submitted for redaction is processed in a CJIS-compliant environment with audit logging. It continues at the release level: the human review protocol specifically targets the known failure points, and the four-corners check is a required step before any release goes out. It continues after release: the agency monitors released footage for misuse, maintains a release log that can reconstruct who received what, and has a notification and remediation protocol when a privacy failure is discovered after release.
The woman on the porch would have been protected by a privacy-by-design pipeline. The AI confidence score for her face would have been reviewed because it was a peripheral-figure scene (porch, across the street) in an incident that occurred partly in low-light conditions. The human reviewer, following a specific checklist item requiring review of peripheral figures and porches in residential calls, would have identified the unredacted face and added the blur. The release would have gone out without her face. The news article would have been published without her face. The call to the duty supervisor would not have happened.
The difference between the outcome that occurred and the outcome that privacy by design would have produced is the governance structure: the written protocol directing reviewers to peripheral-figure scenes, the reviewer training that built the habit of checking edges and low-light frames, and the audit that would have identified the gap in the reviewer's process before the release, not after the complaint.
The Post-Failure Protocol
When a privacy failure occurs despite the governance structure, the response protocol is as important as the prevention protocol. A privacy failure in a records release is a legally and ethically significant event. The response must be documented, must involve legal counsel, and must result in either remediation of the failure (where possible) or a documented decision that remediation is not possible and a rationale for that decision.
In the porch scenario, the remediation options include: contact the news outlet and request removal of the footage (not always possible but sometimes effective), document the contact and the outcome; notify the affected individual that a privacy failure occurred, what the agency is doing about it, and what support resources are available; review the release workflow to identify the specific process failure; update the reviewer training to address the gap; and review all other recent releases for the same failure pattern (if the reviewer missed this porch, did they miss other peripheral-figure scenes?).
The post-failure review is also a governance audit trigger. The privacy officer should conduct a structured review of the failure: what was the AI's confidence score on the missed face, was the reviewer directed to check peripheral figures, what training has the reviewer completed, and what in the workflow allowed the failure to get through two layers of review? The audit findings are the input to policy and procedure updates, not just individual counseling. A systemic failure requires a systemic response.
The Oversight Conversation: Chief, Council, and Community
Privacy governance is not just an internal operational matter. It is an accountability obligation to the community the agency serves, and it is increasingly a matter of active interest to city councils, civilian oversight boards, and community organizations. The EFF and similar organizations actively monitor law enforcement AI deployment and file public-records requests to assess how agencies are handling AI-generated records, redaction quality, and vendor relationships.
An agency with a documented, functioning privacy governance structure is in a fundamentally different position than an agency that cannot answer basic questions about its redaction process, vendor compliance, or failure-response protocol. When a city council asks how the agency is protecting community members' privacy in BWC releases, a chief with a documented governance structure, annual audit reports, and a track record of self-identified and corrected failures can answer with specificity. A chief whose agency has no documented governance structure, no audit trail, and a complaint in the queue from a woman on a porch cannot.
The oversight conversation is not a threat to be managed. It is an accountability structure that privacy governance is designed to satisfy. An agency that has built privacy by design into its records pipeline, that audits its AI tools annually, that trains its reviewers, that documents its failures and its corrections, and that maintains a CJIS-compliant vendor relationship is an agency that can stand in front of its community and its oversight bodies and give a complete, truthful account of how it handles the most sensitive records in its custody.
The bundled, multi-year, sole-vendor contracts that now cover cameras, cloud storage, and AI tools on the order of $45 million and up to ten years also have a privacy governance dimension. When one vendor controls the entire records pipeline, the privacy governance audit must encompass the entire vendor relationship, not just the redaction tool. If the vendor's evidence management system, cloud storage, and AI platform all share a data environment, a CJIS failure in one component is potentially a failure across all. The privacy officer's annual audit must cover the full vendor relationship, and the chief must understand that signing a bundled contract without these governance requirements built in transfers significant control over the agency's privacy obligations to a commercial vendor whose interests are not identical to the community's.
Key Takeaways
- Privacy governance is a system, not a step. Third-party protection in AI-assisted records release requires written policy, defined roles, documented procedures, annual audits, and a named accountability structure, not just an AI redaction tool and a read-through.
- Third parties include all persons in footage who are not parties to the incident: bystanders, neighbors, uninvolved witnesses, and any child regardless of role. Minors are a heightened category: their faces must be redacted from any public release, and a missed minor face can trigger state juvenile confidentiality statute consequences separate from any general privacy tort.
- The five governance failure points are: AI confidence threshold failures in low-light and peripheral-figure scenes; officer-face over-redaction from misconfigured tools; minor identification failures; written-record personal information gaps; and vendor data retention and secondary-use problems from contracts that did not specify these terms.
- CJIS obligations are the agency's, not the vendor's. Every AI platform that processes CJIS-covered data must operate under a current data-use agreement with a demonstrated CJIS-compliant infrastructure, verified before first use and audited annually. Using a non-CJIS-compliant vendor creates a chain-of-custody issue that can affect admissibility in criminal cases.
- Privacy by design means building privacy protection into every stage of the records pipeline from capture to release, not bolting it on after a complaint. A privacy-by-design workflow directs human reviewers specifically to the known AI failure points: peripheral-figure scenes, low-light sequences, and any scene with elevated minor-presence probability.
- When a privacy failure occurs, the response is as important as the prevention. The post-failure protocol includes remediation where possible, notification of the affected individual, a structured governance audit identifying the specific process failure, and policy updates addressing the systemic gap that allowed the failure through two layers of review.
- Bundled, multi-year, sole-vendor contracts covering the full records pipeline (cameras, cloud, AI, evidence management) require governance audits that encompass the full vendor relationship. A CJIS failure in one component of a shared data environment is potentially a failure across all components.
- The oversight conversation with city council, civilian review boards, and community organizations is an accountability structure that privacy governance is designed to satisfy. An agency with documented governance, audit records, and a self-correction history can give a complete, truthful account. An agency without it cannot.
Skill.re