Right to Privacy Not in the Constitution — The Surveillance Consent Gap

No Terms of Service for Your Face: The Constitution Never Wrote Down a Right to Privacy, and Data Intelligence Found the Gap

Right to Privacy Not in the Constitution — The Surveillance Consent Gap
Share This:

Consumers understand the bargain they strike with Verizon, Google and Alexa. No equivalent agreement exists between a driver and a license plate camera, or between a shopper and a facial recognition system — and the Constitution never named the right that would fill the gap.

Americans click “I agree” constantly. Verizon’s customer agreement, Google’s terms of service, the Alexa terms that arrive with a smart speaker — each represents a transaction most consumers understand in general terms, even if few read the fine print. A company collects data, the user accepts, and a contract exists.

That framework has an obvious limit. It requires two parties.

When an automated license plate reader photographs a vehicle on a public road, the driver has signed nothing. When a grocery store runs a customer’s face against a watchlist, the shopper has agreed to no terms. There is no account to close, no setting to toggle, no privacy policy addressed to the person being scanned. The individual is not a customer of the surveillance vendor. The individual is the product being processed.

The reason that gap persists is older than any of the technology involved: the word “privacy” appears nowhere in the U.S. Constitution.

Background: A Right Built From Inference

The Bill of Rights protects specific things. The First Amendment protects speech and association. The Third bars quartering soldiers in private homes. The Fourth prohibits unreasonable searches and seizures of “persons, houses, papers, and effects.” The Fifth protects against compelled self-incrimination.

None of them names privacy as a right. What courts have done instead is assemble one from the pieces.

The foundational case is Griswold v. Connecticut (1965), where Justice William O. Douglas located a right to marital privacy in what he called the penumbras — the shadows — formed by emanations from those specific guarantees. The Ninth Amendment, which states that enumerating some rights does not deny others retained by the people, has served as the textual anchor for the broader proposition that unlisted rights can still be enforced.

In simple terms: the right to privacy in American law is a judicial construction, not a written provision. It exists because courts have said it follows from other rights, which means it can also contract when courts revisit that reasoning.

That vulnerability was demonstrated in Dobbs v. Jackson Women’s Health Organization (2022), when the Supreme Court overruled Roe v. Wade and held that unenumerated rights must be deeply rooted in the nation’s history and tradition. The majority stated the decision did not disturb other privacy precedents. Justice Clarence Thomas, concurring, argued the Court should reconsider Griswold and later cases built on the same foundation.

Policy Explanation: The Third-Party Doctrine and What Just Changed

A separate line of cases governs surveillance, and it is the one that matters for data intelligence.

Katz v. United States (1967) established that the Fourth Amendment protects a reasonable expectation of privacy, not just physical property. Twelve years later, Smith v. Maryland (1979) and United States v. Miller created the third-party doctrine: information a person voluntarily conveys to a third party carries no Fourth Amendment protection.

That rule was written for bank records and telephone billing. Applied to modern life, it swallowed nearly everything. Location, browsing history, purchases, and communications all pass through a carrier, a platform, or a broker.

The Court has narrowed the doctrine incrementally. United States v. Jones (2012) treated GPS tracking as a search. Riley v. California (2014) required a warrant to search a phone incident to arrest. Carpenter v. United States (2018) required a warrant for historical cell-site location records, though Chief Justice John Roberts wrote the opinion narrowly and declined to disturb Smith and Miller generally.

On June 29, 2026, the Court went further. In Chatrie v. United States (read the slip opinion), a 6-3 decision written by Justice Elena Kagan, the Court held that a geofence warrant — a demand that a technology company identify every device near a crime scene during a window of time — constitutes a Fourth Amendment search. The case arose from a 2019 credit union robbery in Midlothian, Virginia, where investigators obtained roughly two hours of Google Location History data.

The reasoning matters more than the outcome. The Court held that an individual retains a reasonable expectation of privacy in cell-phone location information even when a third party holds it, and rejected the government’s argument that a small extraction from a vast database escapes scrutiny. Justice Samuel Alito dissented, joined in part by Justice Thomas; Justice Amy Coney Barrett filed a separate dissent. The Court remanded to the Fourth Circuit without deciding whether this particular warrant satisfied probable cause and particularity.

Chatrie constrains what government can compel. It says nothing about what a private company may collect and then choose to sell, share, or hand over.

Examples: Where the Consent Framework Has No Counterpart

License Plate Networks

Flock Safety, founded around 2017, has grown past 100,000 cameras serving more than 5,000 law enforcement agencies. NBC News reported the network processes over 20 billion plate scans monthly. The system logs plate number, timestamp, location, and direction, and builds what the company markets as a Vehicle Fingerprint — make, model, color, body style, and features as specific as bumper stickers — so investigators can search for a vehicle without a plate number.

No driver consents to this. No driver is notified. The crowdsourced mapping project DeFlock has documented locations for more than 90,000 ALPR cameras nationwide, which is currently the closest thing to public disclosure that exists.

The accountability failures have been jurisdictional rather than technical. Flock’s architecture includes configurable statewide and national lookup permissions. When enabled — in several documented cases without city officials’ knowledge — outside agencies could query local data. Mountain View, California, ended its contract by unanimous council vote after Police Chief Mike Canfield learned out-of-state agencies had accessed city data contrary to policy. Santa Clara County’s Board of Supervisors moved to end county use of Flock data. Dayton, Ohio, suspended its program after learning outside agencies had run immigration-related searches thousands of times. Reporting compiled by TechTimes put the total at 53 cities canceling contracts.

Litigation followed. On February 26, 2026, Gibbs Mura and Milberg PLLC filed a class action in San Francisco Superior Court alleging Flock violated California’s ALPR Privacy Act, enacted as SB 34 in 2015, by sharing data with out-of-state and federal agencies. The complaint alleges out-of-state agencies searched the San Francisco Police Department’s database more than 1.6 million times over seven months. An amended complaint was filed April 3, 2026.

Constitutional challenges have fared worse. In Schmidt v. City of Norfolk, decided January 27, 2026, the U.S. District Court for the Eastern District of Virginia granted summary judgment to the city, finding that 175 camera clusters holding data on a 21-day rolling basis did not track the whole of a person’s movements and therefore did not constitute a search. The Institute for Justice, representing the plaintiffs, has argued that Chatrie strengthens its position by directing courts to what a system is capable of collecting rather than what officers extracted in a given instance.

Facial Recognition

Here the vacuum is more complete. There is no federal facial recognition statute. Roughly two dozen states have enacted some form of biometric regulation, and the protections vary enormously. Illinois’ Biometric Information Privacy Act requires written consent and, critically, provides a private right of action — the reason Clearview AI reached a settlement valued near $51 million over scraping billions of facial images, and the reason Google resolved a $9 million Illinois claim involving student voice and face data. Texas’ Capture or Use of Biometric Identifiers statute, amended effective January 1, 2026, bars commercial biometric capture without consent but permits enforcement only by the attorney general. Portland, Oregon, banned private facial recognition in places of public accommodation. New York City requires disclosure signage but does not prohibit the practice.

In most of the country, a retailer can scan a customer’s face without notice, without consent, and without restriction on retention.

Wegmans acknowledged on January 5, 2026 that it uses facial recognition in a small fraction of stores. Because New York City requires signage, the chain posts notices there; in states without disclosure requirements, it does not. Three days later, Connecticut State Senator James Maroney and Senate Majority Leader Bob Duff announced legislation to ban retail facial recognition statewide.

The adoption curve is not slowing. A 2025 National Retail Federation survey found 18 percent of retailers piloting or using facial recognition, up from 12 percent in 2022, with another 28 percent reporting they had evaluated and declined it. National Institute of Standards and Technology testing found the technology became roughly twenty times better at matching photographs to a database between 2014 and 2018.

Impact: Convergence

The two categories are merging. Flock has developed a product called Nova, in early access with some agencies, that links plate scan data to commercial people-lookup broker records — allowing an officer to move from a vehicle sighting to an individual’s identity, associates, and social connections. The American Civil Liberties Union has noted this conflicts with the company’s longstanding position that its cameras do not collect personally identifiable information.

That convergence is the practical answer to the constitutional question. A plate is not a person and a face is not a name until a broker joins the tables. Once joined, the government can often purchase what Chatrie and Carpenter would require it to obtain by warrant. Legal scholars have identified this as the central gap in the post-Carpenter framework: constitutional limits attach to compulsion, not to procurement.

Vendor substitution illustrates how little contract terms accomplish. Reporting indicates cities that removed Flock cameras have in several cases contracted with Axon Enterprise for plate readers installed on the same poles. The infrastructure persists across the vendor change. Only statute constrains the category rather than the company.

Some legislatures have begun to act at that level. A 2026 Washington state law restricts ALPR collection near schools, places of worship, food banks, and immigration-related sites. Amazon-owned Ring and Flock ended a planned integration on February 12, 2026, following criticism from the Electronic Frontier Foundation and a letter from Senator Edward Markey.

Analysis: What the Absence Actually Costs

There is a defensible case for these systems. Berkeley council members who supported a Flock proposal cited 52 arrests attributed to plate readers in a single year. The Norfolk court’s reasoning was not evasive — it applied Carpenter‘s own framework and concluded that a 21-day window across fixed points on public roads does not produce the comprehensive record Carpenter contemplated. Flock has stated it does not share data with federal agencies absent authorization, and the company has published its position that fixed ALPR use has been repeatedly upheld under existing precedent.

The problem is not that these arguments are unserious. It is that the framework evaluating them was built for a different question.

The Fourth Amendment restrains government. The consumer contract governs voluntary commercial relationships. Neither instrument addresses a private company that collects data about people who are neither its customers nor targets of any investigation, retains it, and makes it queryable by parties the collected person will never identify.

Congress has not filled the gap. Federal privacy law remains sectoral — HIPAA for health information, the Fair Credit Reporting Act for credit files, the Electronic Communications Privacy Act, Gramm-Leach-Bliley for financial institutions, COPPA for children. There is no general federal privacy statute. Roughly a dozen state constitutions include express privacy provisions, with California’s Article I, Section 1 the most heavily litigated. Comprehensive state statutes have been the primary growth area, with Vermont becoming the fourth state in 2026 to enact one, following Oklahoma, Alabama, and Louisiana. The Brennan Center for Justice has described the resulting notice-and-consent regime as largely illusory.

That patchwork produces the Wegmans outcome as a matter of design: identical technology, disclosed in one jurisdiction and silent in the next.

Conclusion

The gap between the technology framework and the constitutional one is not an oversight. The Constitution’s drafters protected papers and effects because papers and effects were where private information lived. They did not anticipate that the record of a citizen’s movements would be generated automatically, held by a private vendor, and retrievable on a search field.

Chatrie signals that at least six justices recognize the third-party doctrine cannot carry its original weight in a digital environment. But Chatrie addressed a warrant. The scanned driver and the scanned shopper have no warrant to challenge, no contract to invoke, and no enumerated right to cite by name.

Until a legislature writes one down, the operative rule is the one the market has already set: consent applies where a customer relationship exists, and nowhere else.

Key Takeaways

  • The word “privacy” does not appear in the Constitution or the Bill of Rights. The right is a judicial construction, primarily from Griswold v. Connecticut (1965), which makes it contractible when courts revisit the reasoning — as Dobbs (2022) demonstrated.
  • The third-party doctrine from Smith v. Maryland (1979) removed Fourth Amendment protection from information conveyed to third parties, which in a digital economy covers nearly everything.
  • Chatrie v. United States, decided 6-3 on June 29, 2026, held that geofence warrants are Fourth Amendment searches and limited the third-party doctrine, but constrained only government compulsion — not private collection or commercial sale.
  • Flock Safety’s network exceeds 100,000 cameras and processes over 20 billion monthly plate scans for more than 5,000 agencies. No scanned driver consents or receives notice. Reporting indicates 53 cities have canceled contracts, largely over unauthorized federal access.
  • There is no federal facial recognition law. Illinois’ BIPA is the strongest state protection because it allows private suits; most states impose no retail restrictions at all.
  • Consumer terms of service require a customer relationship. ALPR networks and retail facial recognition have no counterparty relationship with the people they scan, leaving no contractual mechanism for notice, consent, or deletion.

Related Coverage from NexfinityNews

EDITOR’S NOTE — LINKS PENDING: each item below is hyperlinked to the NexfinityNews home page as a placeholder. Substitute the specific article slug before publication.

Sources

Share This: