What is the "Function Creep" policy? How does the city guarantee that the technology will not be used for purposes other than its stated intent (e.g., used for tracking political protesters, immigration enforcement, monitoring homeless populations, or general surveillance) in the future?
What are the performance benchmarks? Has the technology been tested for accuracy across different demographics (race, sex, age)? Can the city provide third-party, independent audit results showing the error rates of the software?
What is the escalation protocol? If the system provides a "match," what is the mandatory human review process before any law enforcement action is taken? Who is held accountable if the system produces a false positive that leads to a wrongful interaction?
What is the automated deletion policy? For data where no match is found, is there an automated, instantaneous deletion process? Or is that data stored, even briefly, in a "temp" file that could be accessed or subpoenaed?
What is the retention period? If data is kept for a period after a "no match," what is the specific retention period, and where is the policy document that outlines this?
How is the data "purged"? When data reaches the end of its retention period, is it cryptographically erased, or is it merely archived in a way that could still be recovered?
Who owns the data? Is the data owned by the city or the third-party software vendor? Does the contract grant the vendor the right to use the footage to "train" their AI models or improve their algorithms?
What is the data-sharing policy? Is there a database "interoperability" requirement? Does this system automatically share data with federal agencies (like the FBI or DHS), other state agencies, or private organizations? If so, what oversight do local officials have over those agencies' use of this data?
Are there non-disclosure agreements? Are there any clauses in the city's contract with the vendor that prevent the city from disclosing how the technology works, its error rates, or its limitations to the public?
Where is the public-facing policy manual? Is there a comprehensive, publicly available "Surveillance Impact Report" or "Privacy Impact Assessment" that was conducted before the contract was signed?
What is the community oversight mechanism? Will there be an independent civilian oversight board with the power to subpoena records or shut down the use of the technology if it is found to be used improperly?