Verification record · Standard v1.0

Yellow Springs, Ohio

Yellow Springs has a broad surveillance-technology ordinance that treats technologies including ALPRs and biometric surveillance as surveillance technology subject to an approval process, requires review of preexisting uses, requires annual reporting for approved systems, and makes conflicting contracts prohibited. That is the strongest governance framework among our current leads. The decisive open question is what is actually approved and in use.

This is not a Verified Unsurveilled designation. It is a research record. No badge may be displayed on the basis of this page.

Status
Research candidate
Standard
v1.0
Last reviewed
Aug 14, 2026
Criteria met
3 of 12
RESEARCH CANDIDATEEVIDENCE UNDER REVIEW

The governance lead

Where Ypsilanti is a strong candidate because it banned a specific technology, Yellow Springs is a strong candidate because of how it decides.

The municipal code treats surveillance technology — expressly including ALPRs and biometric surveillance — as a category requiring approval. It requires review of preexisting uses rather than grandfathering whatever was already installed. It requires annual reporting for approved systems. It makes conflicting contracts prohibited.

That is close to the democratic-control principle the Verified Unsurveilled standard is built around, and it is more durable than a single prohibition, because it governs technologies that have not been invented yet.

Why a strong process is not automatically a strong outcome

A rigorous approval process is entirely compatible with having approved something.

The decisive question for Yellow Springs is therefore not about the ordinance at all. It is: what is currently approved, and is any of it a persistent mass-tracking capability?

Until that is answered, three criteria pass and nine remain open — including every criterion that describes actual surveillance practice rather than the rules governing it. That is why this record says candidate and not verified.

The rubric, criterion by criterion

All 12 criteria of the published standard, including the 9 not yet examined. A criterion that has not been assessed is shown as unexamined rather than omitted — otherwise a record could look complete by leaving out the awkward questions.

  1. 01

    No persistent mass ALPR program

    Not yet examined

    The municipality does not operate a persistent automated license plate reader program that routinely records ordinary traffic and builds a searchable history of people’s movements.

    Unexamined, and decisive. A rigorous approval process is entirely compatible with having approved an ALPR system. What is currently approved and operating must be established before this criterion resolves in either direction.

    What would resolve it Municipal code, procurement records, department policy, technology inventory, council minutes.

  2. 02

    No vendor workaround

    Not yet examined

    The municipality has not simply replaced one platform with another providing substantially equivalent dragnet capability.

    Not yet examined.

    What would resolve it Procurement records across all vendors, not only the one that attracted public attention.

  3. 03

    No routine access to another agency’s dragnet

    Not yet examined

    The municipality does not evade the standard by routinely querying regional, private, vendor, or neighbouring ALPR databases as a substitute for operating its own network.

    Not yet examined.

    What would resolve it Mutual-aid agreements, regional fusion or task-force participation, vendor account access, department policy.

  4. 04

    Targeted investigative exception only under defined lawful authority

    Not yet examined

    Short-term or case-specific use is tied to individualized legal justification, a warrant or court order where required, or a tightly defined exigent circumstance documented by policy.

    Not yet examined.

    What would resolve it Written department policy, authorization logs, ordinance text.

  5. 05

    No persistent facial recognition or biometric identification of the public

    Not yet examined

    No persistent facial-recognition or biometric identification system aimed at the general public.

    Not yet examined.

    What would resolve it Municipal code, department policy, technology inventory, procurement records.

  6. 06

    No purchase of sensitive historical location data from data brokers

    Not yet examined

    The municipality does not purchase sensitive historical location data to circumvent warrant or court-order requirements.

    Not yet examined.

    What would resolve it Procurement records, purchase orders, department policy.

  7. 07

    Democratic control of new surveillance technology

    Met

    New systems capable of identifying, tracking, or profiling the public require advance public notice, an impact and use policy, and approval by the elected legislative body or an equivalently accountable process.

    The municipal code subjects surveillance technology — expressly including ALPRs and biometric surveillance — to an approval process, and requires review of preexisting uses rather than grandfathering whatever was already installed. This is the criterion Yellow Springs satisfies most convincingly.

    Village of Yellow Springs, Ohio Village of Yellow Springs, Ohio — checked Aug 14, 2026

  8. 08

    Public surveillance technology inventory

    Not yet examined

    The municipality publishes what surveillance technologies it uses and for what purpose.

    Not yet examined.

    What would resolve it Published inventory, currency of the most recent version.

  9. 09

    Retention and deletion limits

    Not yet examined

    Personally identifying surveillance data is minimized and deleted on defined schedules unless legitimately tied to a specific investigation or legal obligation.

    Not yet examined.

    What would resolve it Written retention schedule, department policy, contract terms.

  10. 10

    Sharing controls

    Not yet examined

    Sensitive data is not casually pooled, sold, or made broadly searchable by outside agencies; sharing rules and legal standards are public.

    Not yet examined.

    What would resolve it Sharing configuration, data-sharing agreements, published policy.

  11. 11

    Annual transparency reporting

    Met

    The municipality publishes meaningful annual reports covering use, sharing, complaints, audits, policy violations, costs, and material changes.

    The code requires annual reporting for approved surveillance systems. Whether reports have in fact been published on schedule is a separate question, listed as open below.

    Village of Yellow Springs, Ohio — checked Aug 14, 2026

  12. 12

    Function-over-brand protection

    Met

    Policies apply to capabilities rather than vendor names, so future technology cannot bypass the spirit of the standard by changing product labels.

    The code regulates surveillance technology by capability and category rather than by vendor or product name, and makes conflicting contracts prohibited.

    Village of Yellow Springs, Ohio Village of Yellow Springs, Ohio — checked Aug 14, 2026

Evidence

Not yet obtained

  • Which surveillance technologies are currently approved and in use in Yellow Springs?Public-records request
  • Does any persistent ALPR or equivalent mass-tracking capability exist, whether operated locally or accessed regionally?Public-records request
  • Have the required annual surveillance reports actually been published, and are they current?Public-records request
  • Is there a published, current surveillance technology inventory?Public-records request
  • What retention and sharing rules apply to approved systems?Public-records request

Verified as of

Change log

  1. status change

    Record opened at status CANDIDATE on the strength of the governance framework.