Been there with a 33M cost estimate [1]. If the requester is reading this -- hold them to it and request a much smaller but still significant amount of records. Use that as the foundation for "how much time it actually takes". Another option is to get clever with helping them with means and modes of review/redaction. This is how I got the email metadata for 6M emails from Houston for example.
I'm aware of places where this is done because the law sets prices and policies for 'copies' in terms of physical papers and has never updated their laws to reflect the past half century of information technology. Definitely the fault of the local legislators.
Wow, that bash script they wanted him to run would have absolutely thrashed his drive:
head -500000 /dev/urandom > fill_unused_space
while [ 1 ] ; do
echo " "
echo "Making a copy of the large file on `date`"
cp fill_unused_space fill_unused_space`date +%s` || break
echo " "
echo "Pass $counter. Display how full the file systems are:"
df
done
How many times can your system overwrite a 500k file in a second? Hopefully it wouldn't get flushed each time, saving your disk.
There's an interesting thing about the Seattle story.
You asked for records on 32 million emails and they responded that they'd have to review the emails to make sure they (Seattle) didn't release anything sensitive.
They then agreed that because you only requested metadata, they wouldn't need to review the emails. (Your article isn't fully clear about whether they made this observation spontaneously or in response to some communication from you.)
And then, they released the emails to you with no review. This caused a scandal and the city's CTO resigned.
The actual sequence of events tends to suggest that when they thought they'd need to run a review, they were right. When they were persuaded that they shouldn't need to (which was true), they messed up the release, broke a bunch of laws, and caused big problems for themselves. The fact that they shouldn't have needed a review didn't stop them from needing it in reality.
This raises the more general question of how to think about responses along the lines of "for a competent agency, this request wouldn't be burdensome, but we aren't a competent agency".
There are some really hilarious responses when asking for student grade distributions (i.e. records they 100% have):
> Purdue University does not have such a record in existence. One would have to be created in order to fulfill your request. Indiana’s Access to Public Records Act puts no obligation on a public agency to create a record in order to satisfy a records request. Therefore, Purdue has no records to provide.
> The University of Utah received your GRAMA request. In that request you seek grade distributions for all formal courses at the University of Utah for the last five years. You requested this information in a digital CSV format. We can only provide a paper format. The report for the last five years is 9,714 pages. The reasonable copying fee for documents responsive to most GRAMA requests is $.25 per copy. Therefore, your cost for this report will be $2,428.50.
Often you can request it in the format they have available, etc. You can also apply pressure by submitting a different request, i.e. all the invoices or secondary records, then have AI scan them.
The public information thing is so abused. I'm from a nordic european country where my local hackerspace figured out that the public transport app we use should be considered public information, and we should be able to request its source code.
But when we contacted the person in charge of *Digitalisation* they said they can only PRINT the source code for us, and it would cost an estimated 4000 dollars in paper printing. This is the person in charge of digitising their organisation... in a time when we're measuring every page printed and counting it towards our sustainability scores.
Really makes you wonder if they're being difficult on purpose to hide shitty source code.
Less egregious, but still egregious, a few weeks ago a local news investigator in Houston was quoted $121,000 for public records request related to Flock cameras:
FOIA requests that have to be redacted are labor intensive.
However, flock shouldn’t need to be redacted right? They’re just public webcams. Lots of those already exist and many stream live.
The police still have to redact all the times the cops accessed the camera feeds to stalk women, creep on children, and spy on people they don't like, plus remove any instances of the police (both on and off the clock) committing crimes that just happened to get caught by these cameras. Of course it's going to take "14 years of labor" to edit that stuff out.
All digital government records should already be freely distributed. This is basically the same thing as poll extortion tax. You want to use your rights? Then pay up! Oh you didn't go away yet? Pay up even more!
It still will often be expensive, because governments have a lot of personal data about citizens that interact (often involuntarily) with those governments.
Unless you think those citizens should lose their privacy rights the records concerning them need to be redacted before distribution.
> governments have a lot of personal data about citizens that interact (often involuntarily) with those governments.
If it's recorded on a Flock camera it happened in public where there's zero expectation of privacy. If the police in Texas are being so careless about people's actually private data that it's showing up in Flock camera feeds the public should absolutely be able to see the evidence of that so that something can be done to stop it.
I think the whole reason there's controversy about Flock is that whatever the law says people do actually expect a certain amount of privacy in a public place, and being watched and recorded 24/7 in public is meaningfully different.
The comment to which I was responding was saying all digital government records should be free, so I assumed they were not talking just about Flock camera data.
As far as Flock feeds go, do you think that if you do something or something happens to you in a place with no expectation of privacy, but you get lucky and no members of the public are around to see it but it does get captured by a Flock camera the police should be obligated to release it to anyone who asks?
How does that serve the public interest? From a privacy point of view I'd be much happier if the rule is that the government cannot release private info about me, no matter how it was acquired, unless there is a significant public interest in doing so.
Been there with a 33M cost estimate [1]. If the requester is reading this -- hold them to it and request a much smaller but still significant amount of records. Use that as the foundation for "how much time it actually takes". Another option is to get clever with helping them with means and modes of review/redaction. This is how I got the email metadata for 6M emails from Houston for example.
Another example from Vermont's governor's office: https://www.muckrock.com/foi/vermont-80/email-metadata-55744...
Happy to help more but I'll probably be unavailable tonight.
[1] https://mchap.io/that-time-the-city-of-seattle-accidentally-...
That's such an insane response from the government. Why the hell are they printing, cutting and photocopying emails?
I'm aware of places where this is done because the law sets prices and policies for 'copies' in terms of physical papers and has never updated their laws to reflect the past half century of information technology. Definitely the fault of the local legislators.
[1] was a lot crazier than I was expecting and I read the whole thing. I’m glad you didn’t have to face any serious repercussions.
Wow, that bash script they wanted him to run would have absolutely thrashed his drive:
How many times can your system overwrite a 500k file in a second? Hopefully it wouldn't get flushed each time, saving your disk.Ended up not running the script and ran a tool specifically meant for that purpose.
In these kind of situations, bcwipe[0] is a handy tool to have available.
0 - https://www.ia.nato.int/niapc/Product/BCWipe_178
There's an interesting thing about the Seattle story.
You asked for records on 32 million emails and they responded that they'd have to review the emails to make sure they (Seattle) didn't release anything sensitive.
They then agreed that because you only requested metadata, they wouldn't need to review the emails. (Your article isn't fully clear about whether they made this observation spontaneously or in response to some communication from you.)
And then, they released the emails to you with no review. This caused a scandal and the city's CTO resigned.
The actual sequence of events tends to suggest that when they thought they'd need to run a review, they were right. When they were persuaded that they shouldn't need to (which was true), they messed up the release, broke a bunch of laws, and caused big problems for themselves. The fact that they shouldn't have needed a review didn't stop them from needing it in reality.
This raises the more general question of how to think about responses along the lines of "for a competent agency, this request wouldn't be burdensome, but we aren't a competent agency".
In the past I FOIA requested 100 universities for their grades - https://austingwalters.com/foia-requesting-100-universities/
There are some really hilarious responses when asking for student grade distributions (i.e. records they 100% have):
> Purdue University does not have such a record in existence. One would have to be created in order to fulfill your request. Indiana’s Access to Public Records Act puts no obligation on a public agency to create a record in order to satisfy a records request. Therefore, Purdue has no records to provide.
> The University of Utah received your GRAMA request. In that request you seek grade distributions for all formal courses at the University of Utah for the last five years. You requested this information in a digital CSV format. We can only provide a paper format. The report for the last five years is 9,714 pages. The reasonable copying fee for documents responsive to most GRAMA requests is $.25 per copy. Therefore, your cost for this report will be $2,428.50.
Often you can request it in the format they have available, etc. You can also apply pressure by submitting a different request, i.e. all the invoices or secondary records, then have AI scan them.
Good luck with OMB. I’m glad you have the media calling you a “Good Samaritan”.
Oh I won that case! I need to write about it...
(In case I never get to it, here's 2,300 pdf pages of email metadata of the White House OMB I received from FOIA litigation: https://www.dropbox.com/scl/fi/95qlfrsr8a9241vdw590x/Chapman...)
(that URL 404s, brother -- looking forward to seeing it, though!)
Changed to dropbox! not sure what that was about.
Great work, keep at it!
The public information thing is so abused. I'm from a nordic european country where my local hackerspace figured out that the public transport app we use should be considered public information, and we should be able to request its source code.
But when we contacted the person in charge of *Digitalisation* they said they can only PRINT the source code for us, and it would cost an estimated 4000 dollars in paper printing. This is the person in charge of digitising their organisation... in a time when we're measuring every page printed and counting it towards our sustainability scores.
Really makes you wonder if they're being difficult on purpose to hide shitty source code.
I'd call them on that. Printing it out would be a huge pain in the ass they would regret suggesting.
Original article specific to the $2.3M invoice:
https://www.texastribune.org/2026/10/05/texas-flock-cameras-...
Less egregious, but still egregious, a few weeks ago a local news investigator in Houston was quoted $121,000 for public records request related to Flock cameras:
https://www.click2houston.com/news/local/2026/09/24/harris-c...
If the data is so difficult to get, that it's unreasonable to get, just get rid of flock then. You're already not getting any benefit.
Unless... no, that couldn't have been a lie, could it? The government would never try to overcharge anyone, right?
FOIA requests that have to be redacted are labor intensive. However, flock shouldn’t need to be redacted right? They’re just public webcams. Lots of those already exist and many stream live.
The police still have to redact all the times the cops accessed the camera feeds to stalk women, creep on children, and spy on people they don't like, plus remove any instances of the police (both on and off the clock) committing crimes that just happened to get caught by these cameras. Of course it's going to take "14 years of labor" to edit that stuff out.
Texas sure does a lot of treading for being the don't tread on me capital
>for being the don't tread on me capital
That would be New Hampshire. Their state motto is even "Live Free or Die"
It’s “don’t tread on me”, not “don’t tread on all of us”.
“Don’t tread on me, tread on THEM”
Headline should read “North Richland Hills TX…” Texas City TX is near Galveston. ;)
All digital government records should already be freely distributed. This is basically the same thing as poll extortion tax. You want to use your rights? Then pay up! Oh you didn't go away yet? Pay up even more!
It still will often be expensive, because governments have a lot of personal data about citizens that interact (often involuntarily) with those governments.
Unless you think those citizens should lose their privacy rights the records concerning them need to be redacted before distribution.
> governments have a lot of personal data about citizens that interact (often involuntarily) with those governments.
If it's recorded on a Flock camera it happened in public where there's zero expectation of privacy. If the police in Texas are being so careless about people's actually private data that it's showing up in Flock camera feeds the public should absolutely be able to see the evidence of that so that something can be done to stop it.
I think the whole reason there's controversy about Flock is that whatever the law says people do actually expect a certain amount of privacy in a public place, and being watched and recorded 24/7 in public is meaningfully different.
The comment to which I was responding was saying all digital government records should be free, so I assumed they were not talking just about Flock camera data.
As far as Flock feeds go, do you think that if you do something or something happens to you in a place with no expectation of privacy, but you get lucky and no members of the public are around to see it but it does get captured by a Flock camera the police should be obligated to release it to anyone who asks?
How does that serve the public interest? From a privacy point of view I'd be much happier if the rule is that the government cannot release private info about me, no matter how it was acquired, unless there is a significant public interest in doing so.