You're not missing anything. Here is the full text: (this could have been an email:)
On Sept. 30, 2025, a Flock vice president logged into the Dunwoody PD’s Flock system and looked at a camera in the children’s gymnastics room of a private community center here in Dunwoody.
He did not look at any other cameras in the entire 400-camera network that day.
The community center shared their cameras directly to the PD under the pretense that access was “solely for real-time critical incident response.”
Flock and Dunwoody elected officials both say this was for a “sales demo.” They claim this was “part of authorized activity approved under the city's demo partner agreement.”
The problem with that is that the city cannot provide any information that that demo partner agreement exists.
What kind of sales demo would require looking at one camera in a children’s gymnastics room? Can anyone rationally explain why a police agency that is interested in Flock would like to see one third-party camera integration that is in a children’s gymnastics room?
Ever thought that complying with those "random" personal data protection laws shows a respect for users decency and privacy in your own country, as well as those users in the UK/EU?
This would be true if they were working from a baremetal Apache server. But they seem to be using a vendor, Cloudflare, for their CDN. And so I strongly suspect that they used their existing Cloudflare account to do it. Just type the countries you want to block into a field in the Cloudflare UI and you're done. I've used that UI myself (not for GPDR reasons but for compliance with my countries sanctions). Significantly easier than controlling the cookies and data retention and getting an audit to certify compliance, which I've also done.
"It's just a checkbox in cloudflare to not show up there" is so effortless that you need a compelling reason to ignore how easy it is.
And if you don't already have traffic analysis showing that 30% of your readers and thus 30% of your ad revenue is coming from the European continent... You spend the 45 seconds it takes to find the check box and you click. Then worrying about maybe possibly getting screwed by some far away legal something or other is irrelevant.
They are a hyper local business. The chance of making any revenue off EU users is close to 0, which is much higher than the cost of figuring out EU compliance.
The conversation went like this:
IT director: “If we serve ads or collect data from EU users we have to be GDPR compliant. That’ll cost several thousand dollars worth of employee time”
Exec: “how much revenue is attributable to EU users.”
GDPR compliance is good IT practice. It's easy to do, good for users, and states are rolling out similar laws.
But now, instead of their story being read by people all over the world, having gone viral, it's just going to pirated. Not only losing them out on revenue, but recognition as well.
This is part of the long death of online local news. They can't be bothered to do the simplest things for their site (make personal data collection optional). But they have tons of time to fill them with online cancer and make them unusable without ad blocking.
I get resistsnce. GDPR is good in theory but implementation has been shocking. Dark patterns in banners, banners when not required (ie no relevant cookies) etc. the gdpr banners as a whole make the internet a shitter experience. I categorically refuse work on anything requiring gdpr specific compliance and recommend against any practices which would require it on work I accept, and walk if demanded anyway.
I'm lucky in that I mostly work in areas where it really has no value add, and so far always get my way, but fuck I wish GDPR banners had some form of standard that didn't wreck internet experience in general.
Was it too hard to require the already opt-in nature of the cookies to no fuck with average user experience? no one in their right mind clicks accept all.
Was it too hard to enforce some default stance one can set?
Was it too hard to not fuck everything up without fixing the issue?
apprently. so now i have to constantly read and interpret information I have zero interest in to consistently hit the exact same button, to access information I _might_ be interested in. all of which is an excercise in dark pattern gymanastics so draining im near ready to swear off the open web entierly.
A small local news agency prioritizes serving small local news needs. I used to work at a small local newspaper. Spending four or five figures of limited money on IT overhauls means that something else has to be sacrificed. It isn’t that they can’t be bothered, it’s that it costs money and doesn’t serve their community or customers. Being GDPR compliant hinders their ability to do local news since it literally takes resources to accomplish.
Local news is dying, but it is not because of GDPR. That trend started well before then, and is very well understood. The amount of news content is a direct function of advertising revenue not actual news to be reported. Craigslist and google undercut them and that’s really the only relevant part of the story. GDPR noncompliance has nothing to do with the success or failure of a news outlet in middle America.
Do you make sure that your work is fully compliant with all Chinese laws? Why not? They are the world’s largest market, after all. Do you even know if your work is possible to access in China? Or is it the case that compliance with Chinese laws is irrelevant to your business models so it’s easier to just do nothing. Same logic…
"We might, maybe, have some article go viral some day. With unknown revenue implications." is a weak argument for trying to figure out and maintain GDPR compliance, which costs real money right now, today. And you have to be sure to maintain that compliance as the web site evolves.
It's such a low-probability event that I don't blame them for just saying, "Nah. Not gonna hassle with that."
The recognition argument is also quite weak--it's not like recognition pays the bills.
This website is a small, local company. They have a newsletter signup page so they do collect user info. Quite likely they are not GDPR compliant (e.g. take longer than 30d to delete records, don't have a process for answering data requests etc). It is reasonable for them not to want to invest in getting the legal advise to know whether they are compliant or process improvements to become compliant, as there is no ROI on that.
I love GDPR, but it's understandable for folks with no connection to the EU to just nope-out.
I’m still not clear why US companies with no business units in Europe feel the need to make any changes at all to be in compliance with a law that has no jurisdiction over them, but agree that Geofencing is a cheaper solution than asking a lawyer.
You're making the point even stronger for US companies to just block EU traffic entirely. If you have no EU customers, the mere act of letting EU visitors on your site might cause an EU country to "make an example" of you for incorrect data handling, but the alternative of just blocking all traffic would let you travel to the EU without issues.
Well, my point was that a site owner shouldn’t even bother with geofencing, but I guess I’ll accept “may want to travel to europe someday” as a reason to fear legal repercussions
the idea of the owners of a small, regional US news website being arrested while traveling in Europe because that site does not have a GDPR compliant cookie policy seems utterly detached from reality
I would be more worried about being struck by a meteorite than such a thing
It is vanishingly unlikely, or would have been, but given that the US has started examining people’s social media, it is not unreasonable to think tit-for-tat might happen.
Again, I agree it is very, very unlikely. But it’s possible, and in an age of mass outrage it isn’t incomprehensible that some activist, somewhere, might latch onto something they don’t like and just doggedly pursue someone. It does happen.
The GDPR states that websites that serve EU citizens are subject to it, no matter where they are. Many US news organizations chose to geo-block the EU rather than going to the trouble of figuring out compliance.
Yes but it means serve them specifically. If the main audience is US and some EU visitors happen by, it's not violation. Or at least it's not enforceable violation.
And that might even be true. But it's still at least an hour of retained council's time to deal with it. It's not even 90 seconds to find the geo filter button in your CDN of choice and save you the trouble entirely.
The truth is every single website with Google Analytics and no consent screen is in violation so I imagine whoever is in charge of enforcing GDPR has long ago decided to pick his battles.
> The GDPR states that websites that serve EU citizens are subject to it,
The GDPR can state that they're the masters of the universe but that doesn't make it true. They lack jurisdiction, they can't sue in US court. The EU suing an US entity, in US court, for breaking EU law sounds like a great comedy I really want to see.
If the EU doesn't want EU citizens to use some service located in another country, they should stop their citizens from going there, like at the border, like blocking the IP, domain, etc.
The GDPR can state whatever it wants but what are the consequences? If the taliban pass a law about what is required to serve websites in Afghanistan, for instance, what obligation am I under to even notice?
If I am Reuters and AP and have offices in EU of course I am interested in complying with local law, but it doesn’t make sense to me for a local newspaper to care whether they are in compliance with foreign statutes.
Westerners don't travel to Afghanistan. Europe is not a pariah continent. Does this really need to be explained to you? You think global integration with Europe vs Afghanistan is comparable?
Obviously an extreme comparison to make a point because either way it’s not going to result in me being extradited
Still I will maintain that individuals are not going to face repercussions on vacation because they happen to manage a web property out of compliance with GDPR
> Can anyone rationally explain why a police agency that is interested in Flock would like to see one third-party camera integration that is in a children’s gymnastics room?
At what current govt is doing the assumption it's for the pedophiles is far more likely.
Companies push not only age verification (in way that usually is not anonymous) and cameras everywhere will give any pedophile with access to that location of any child they can get their hands of, their daily habits and when it's easiest to nab one of them.
They are creating Pedo Nexus, whether knowingly or not.
Is there more information available? This article is effectively one sentence long:
> On Sept. 30, 2025, a Flock vice president logged into the Dunwoody PD’s Flock system and looked at a camera in the children’s gymnastics room of a private community center here in Dunwoody.
And there is a lot being implied in this sentence.
Flock is such a scummy company. One must just read a bit of the coverage from 404 Media [1] or Benn Jordan [2] and get a whiff of how this company is handling pretty legitimate criticism about privacy and basic device security.
Why is this site blocked in the EU ? Was disabling cookies on your static page that hard ?
You're not missing anything. Here is the full text: (this could have been an email:)
On Sept. 30, 2025, a Flock vice president logged into the Dunwoody PD’s Flock system and looked at a camera in the children’s gymnastics room of a private community center here in Dunwoody.
He did not look at any other cameras in the entire 400-camera network that day.
The community center shared their cameras directly to the PD under the pretense that access was “solely for real-time critical incident response.”
Flock and Dunwoody elected officials both say this was for a “sales demo.” They claim this was “part of authorized activity approved under the city's demo partner agreement.”
The problem with that is that the city cannot provide any information that that demo partner agreement exists.
What kind of sales demo would require looking at one camera in a children’s gymnastics room? Can anyone rationally explain why a police agency that is interested in Flock would like to see one third-party camera integration that is in a children’s gymnastics room?
Jason Hunyar lives in Dunwoody.
why are private community centers installing Flock cameras indoors?
Why do they have any cameras indoors? Outside very specific time limited presentation uses...
[flagged]
No one is going to go around complying with random rules from other countries, man. If you don't serve that population, just opt them out.
> random rules from other countries
Ever thought that complying with those "random" personal data protection laws shows a respect for users decency and privacy in your own country, as well as those users in the UK/EU?
They complied by building a blocking system, instead of just disabling cookies with a flag, which would have taken exactly the same effort.
This would be true if they were working from a baremetal Apache server. But they seem to be using a vendor, Cloudflare, for their CDN. And so I strongly suspect that they used their existing Cloudflare account to do it. Just type the countries you want to block into a field in the Cloudflare UI and you're done. I've used that UI myself (not for GPDR reasons but for compliance with my countries sanctions). Significantly easier than controlling the cookies and data retention and getting an audit to certify compliance, which I've also done.
And by "no one" you mean almost everyone.
Except that it’s an entire continent and loads of people do comply with it. You just sound ignorant.
I've been in meetings where this was discussed.
"It's just a checkbox in cloudflare to not show up there" is so effortless that you need a compelling reason to ignore how easy it is.
And if you don't already have traffic analysis showing that 30% of your readers and thus 30% of your ad revenue is coming from the European continent... You spend the 45 seconds it takes to find the check box and you click. Then worrying about maybe possibly getting screwed by some far away legal something or other is irrelevant.
So we're supposed to deal with your bullshit Patriot Act while GDPR is too "random" for you?
They are a hyper local business. The chance of making any revenue off EU users is close to 0, which is much higher than the cost of figuring out EU compliance.
The conversation went like this:
IT director: “If we serve ads or collect data from EU users we have to be GDPR compliant. That’ll cost several thousand dollars worth of employee time”
Exec: “how much revenue is attributable to EU users.”
IT: “Single digit dollars per year”
Exec: “is there a cheaper solution?”
GDPR compliance is good IT practice. It's easy to do, good for users, and states are rolling out similar laws.
But now, instead of their story being read by people all over the world, having gone viral, it's just going to pirated. Not only losing them out on revenue, but recognition as well.
This is part of the long death of online local news. They can't be bothered to do the simplest things for their site (make personal data collection optional). But they have tons of time to fill them with online cancer and make them unusable without ad blocking.
I get resistsnce. GDPR is good in theory but implementation has been shocking. Dark patterns in banners, banners when not required (ie no relevant cookies) etc. the gdpr banners as a whole make the internet a shitter experience. I categorically refuse work on anything requiring gdpr specific compliance and recommend against any practices which would require it on work I accept, and walk if demanded anyway.
I'm lucky in that I mostly work in areas where it really has no value add, and so far always get my way, but fuck I wish GDPR banners had some form of standard that didn't wreck internet experience in general.
Was it too hard to require the already opt-in nature of the cookies to no fuck with average user experience? no one in their right mind clicks accept all.
Was it too hard to enforce some default stance one can set?
Was it too hard to not fuck everything up without fixing the issue?
apprently. so now i have to constantly read and interpret information I have zero interest in to consistently hit the exact same button, to access information I _might_ be interested in. all of which is an excercise in dark pattern gymanastics so draining im near ready to swear off the open web entierly.
Going viral doesn’t really matter to them.
A small local news agency prioritizes serving small local news needs. I used to work at a small local newspaper. Spending four or five figures of limited money on IT overhauls means that something else has to be sacrificed. It isn’t that they can’t be bothered, it’s that it costs money and doesn’t serve their community or customers. Being GDPR compliant hinders their ability to do local news since it literally takes resources to accomplish.
Local news is dying, but it is not because of GDPR. That trend started well before then, and is very well understood. The amount of news content is a direct function of advertising revenue not actual news to be reported. Craigslist and google undercut them and that’s really the only relevant part of the story. GDPR noncompliance has nothing to do with the success or failure of a news outlet in middle America.
Do you make sure that your work is fully compliant with all Chinese laws? Why not? They are the world’s largest market, after all. Do you even know if your work is possible to access in China? Or is it the case that compliance with Chinese laws is irrelevant to your business models so it’s easier to just do nothing. Same logic…
"We might, maybe, have some article go viral some day. With unknown revenue implications." is a weak argument for trying to figure out and maintain GDPR compliance, which costs real money right now, today. And you have to be sure to maintain that compliance as the web site evolves.
It's such a low-probability event that I don't blame them for just saying, "Nah. Not gonna hassle with that."
The recognition argument is also quite weak--it's not like recognition pays the bills.
This website is a small, local company. They have a newsletter signup page so they do collect user info. Quite likely they are not GDPR compliant (e.g. take longer than 30d to delete records, don't have a process for answering data requests etc). It is reasonable for them not to want to invest in getting the legal advise to know whether they are compliant or process improvements to become compliant, as there is no ROI on that.
I love GDPR, but it's understandable for folks with no connection to the EU to just nope-out.
I’m still not clear why US companies with no business units in Europe feel the need to make any changes at all to be in compliance with a law that has no jurisdiction over them, but agree that Geofencing is a cheaper solution than asking a lawyer.
Because they have identifiable owners who might wish to travel to Europe and not risk someone deciding to make an example of them.
You're making the point even stronger for US companies to just block EU traffic entirely. If you have no EU customers, the mere act of letting EU visitors on your site might cause an EU country to "make an example" of you for incorrect data handling, but the alternative of just blocking all traffic would let you travel to the EU without issues.
Well, my point was that a site owner shouldn’t even bother with geofencing, but I guess I’ll accept “may want to travel to europe someday” as a reason to fear legal repercussions
the idea of the owners of a small, regional US news website being arrested while traveling in Europe because that site does not have a GDPR compliant cookie policy seems utterly detached from reality
I would be more worried about being struck by a meteorite than such a thing
It is vanishingly unlikely, or would have been, but given that the US has started examining people’s social media, it is not unreasonable to think tit-for-tat might happen.
Again, I agree it is very, very unlikely. But it’s possible, and in an age of mass outrage it isn’t incomprehensible that some activist, somewhere, might latch onto something they don’t like and just doggedly pursue someone. It does happen.
The GDPR states that websites that serve EU citizens are subject to it, no matter where they are. Many US news organizations chose to geo-block the EU rather than going to the trouble of figuring out compliance.
> Many US news organizations chose to geo-block the EU rather than going to the trouble of figuring out compliance.
Funny init.
Rather than do the ethical thing and treat their own (American) users personal data with respect, they instead geoblock an entire continent.
Yes but it means serve them specifically. If the main audience is US and some EU visitors happen by, it's not violation. Or at least it's not enforceable violation.
And that might even be true. But it's still at least an hour of retained council's time to deal with it. It's not even 90 seconds to find the geo filter button in your CDN of choice and save you the trouble entirely.
The truth is every single website with Google Analytics and no consent screen is in violation so I imagine whoever is in charge of enforcing GDPR has long ago decided to pick his battles.
> The GDPR states that websites that serve EU citizens are subject to it,
The GDPR can state that they're the masters of the universe but that doesn't make it true. They lack jurisdiction, they can't sue in US court. The EU suing an US entity, in US court, for breaking EU law sounds like a great comedy I really want to see.
If the EU doesn't want EU citizens to use some service located in another country, they should stop their citizens from going there, like at the border, like blocking the IP, domain, etc.
Nonetheless, some people have decided that the risk isn’t worth it, and have decided to geo-block the EU.
You can choose differently, of course, and I’m not making value judgments here. Just explaining why a small local news site would geo-block the EU.
The GDPR can state whatever it wants but what are the consequences? If the taliban pass a law about what is required to serve websites in Afghanistan, for instance, what obligation am I under to even notice?
If I am Reuters and AP and have offices in EU of course I am interested in complying with local law, but it doesn’t make sense to me for a local newspaper to care whether they are in compliance with foreign statutes.
Westerners don't travel to Afghanistan. Europe is not a pariah continent. Does this really need to be explained to you? You think global integration with Europe vs Afghanistan is comparable?
Obviously an extreme comparison to make a point because either way it’s not going to result in me being extradited
Still I will maintain that individuals are not going to face repercussions on vacation because they happen to manage a web property out of compliance with GDPR
This website and topic is protected by a SEP field. Who cares about U.S. problems?
On the one hand, sure, it is a US problem. On the other hand, US culture has a way of travelling.
IE surveillance dickheads see what is in the US and decide to enact it in their local country.
In this case, it is handy to see how the conversation about such surveillance is going.
> Can anyone rationally explain why a police agency that is interested in Flock would like to see one third-party camera integration that is in a children’s gymnastics room?
I could think of one reason
https://en.wikipedia.org/wiki/Columbine_High_School_massacre
The cops stood outside Uvalde. There was an army of police and they stood outside. There is no duty to protect in the US.
At what current govt is doing the assumption it's for the pedophiles is far more likely.
Companies push not only age verification (in way that usually is not anonymous) and cameras everywhere will give any pedophile with access to that location of any child they can get their hands of, their daily habits and when it's easiest to nab one of them.
They are creating Pedo Nexus, whether knowingly or not.
> https://en.wikipedia.org/wiki/Columbine_High_School_massacre
You don't need 24/7, online, searchable, AI enabled video feed to stop any of that
Is there more information available? This article is effectively one sentence long:
> On Sept. 30, 2025, a Flock vice president logged into the Dunwoody PD’s Flock system and looked at a camera in the children’s gymnastics room of a private community center here in Dunwoody.
And there is a lot being implied in this sentence.
Yes, this was a relatively big story months ago:
1. https://www.404media.co/city-learns-flock-accessed-cameras-i...
3. https://www.techdirt.com/2026/05/05/flocks-sales-pitch-inclu... -- commenting on the 404 Media article
2. https://news.ycombinator.com/item?id=47784045
Thank you.
It’s a letter to the editor.
https://archive.ph/mpNEN for us EU peasants (:
Flock is such a scummy company. One must just read a bit of the coverage from 404 Media [1] or Benn Jordan [2] and get a whiff of how this company is handling pretty legitimate criticism about privacy and basic device security.
[1] https://www.404media.co/tag/flock/
[2] https://www.youtube.com/@BennJordan/search?query=flock
[dead]