Resistance Survival Guide #313
Government surveillance rarely operates through one agency or one database. Information can move between police departments, federal agencies, emergency management offices, schools, private contractors, technology vendors, and intelligence centers. Each organization may hold only part of the picture. Together, they can form a powerful government data fusion network.
Mapping that network allows residents, journalists, advocates, and community organizations to discover who collects information, what systems store it, which agencies receive it, and what rules govern its use. The goal is not to collect personal information about individual employees. The goal is to document institutional relationships using public records, official policies, contracts, budgets, meeting records, and verifiable reporting.
The Department of Homeland Security describes fusion centers as state and locally owned organizations that receive, analyze, gather, and share threat related information. However, a government data fusion network can extend beyond a formally recognized fusion center. It may include police databases, license plate readers, camera networks, school reporting systems, private data vendors, federal portals, and informal information sharing arrangements.
Why Government Data Fusion Networks Matter
A single government database may appear limited when examined by itself. The risk changes when that database can be searched alongside information from other sources.
A police department may operate license plate readers. A transportation agency may maintain traffic cameras. A school district may submit threat reports. A private company may provide location information. A fusion center may analyze the resulting records. Federal agencies may then receive intelligence products created from those sources.
This does not mean every participating organization can access every record. Access permissions, laws, contracts, and technical systems vary. A responsible investigation must distinguish confirmed access from possible access.
The Government Accountability Office has documented the federal role in helping fusion centers develop information sharing capabilities and privacy protections. The GAO also found that fusion centers were at different stages of implementing those protections when its review was conducted.
The Brennan Center for Justice has documented concerns about inadequate oversight, broad information sharing, flawed intelligence, and the monitoring of constitutionally protected activities. These findings make public scrutiny essential.
What A Complete Network Map Should Show
A strong government data fusion map contains several distinct layers.
The first layer identifies the organizations involved. These may include municipal police departments, county sheriffs, state police, federal agencies, emergency management offices, prosecutors, transportation agencies, universities, school districts, correctional agencies, public health departments, and private contractors.
The second layer identifies the systems involved. These may include intelligence portals, records management systems, license plate reader databases, facial recognition services, camera networks, social media monitoring tools, dispatch systems, biometric databases, incident reporting platforms, and commercial data products.
The third layer documents the information flowing between those systems. This may include names, photographs, vehicle locations, addresses, incident reports, tips, threat assessments, communications metadata, criminal intelligence, or public social media material.
The fourth layer establishes authority. Every confirmed connection should be supported by a contract, policy, agreement, statute, budget record, meeting document, user guide, audit, official statement, or released communication.
The fifth layer shows safeguards. Record the stated purpose of the system, access limitations, retention period, audit requirements, complaint process, accuracy standards, and procedures for correcting information.
Step by Step Guide
Step 1: Define A Narrow Research Question
Begin with one agency, one system, or one type of information. A useful question might ask which organizations can access a county license plate reader system, where suspicious activity reports are sent, or which contractors support a state fusion center.
Write the question at the top of your research file. Define the geographic area and time period. A narrow question prevents the investigation from becoming an unmanageable collection of unrelated agencies and technologies.
Step 2: Identify The Recognized Fusion Center
Consult the official Department of Homeland Security fusion center directory to identify the recognized center serving your state or major urban area.
Record the center’s name, parent agency, physical jurisdiction, public contact information, and website. Determine whether it operates under a state police agency, emergency management office, city government, county government, or another public body.
Do not assume that every intelligence unit is a federally recognized fusion center. Some local intelligence offices participate in similar information sharing without appearing in the federal directory.
Step 3: Build An Agency Inventory
List every public organization that may contribute information to or receive information from the center. Start with organizations named on official websites, advisory boards, annual reports, budget documents, privacy policies, training materials, and grant applications.
Search for phrases such as information sharing partner, participating agency, intelligence liaison, task force member, authorized user, regional partner, data contributor, system administrator, and private sector partner.
Record only institutional information. Avoid collecting personal addresses, family information, or unrelated details about individual employees.
Step 4: Search Existing Surveillance Research
Search the Atlas of Surveillance for agencies and surveillance technologies in the area. The Atlas is a public interest project from the Electronic Frontier Foundation and the Reynolds School of Journalism at the University of Nevada, Reno.
The database covers technologies including drones, facial recognition, automated license plate readers, camera systems, and other police surveillance tools. Use its entries as research leads, then open the underlying sources and confirm that the information remains current.
An older news article can establish that an agency acquired a system. It may not prove that the agency still uses it or continues sharing the resulting data.
Step 5: Follow The Money
Search agency budgets, purchasing records, check registers, council agendas, grant documents, and contract databases. Technology contracts often reveal relationships that agency websites do not disclose.
Look for the vendor’s legal name, parent company, subsidiaries, subcontractors, contract number, purchase date, renewal period, funding source, system description, and total value. Search for the same vendor across nearby governments because regional networks may use shared contracts or cooperative purchasing agreements.
Pay particular attention to federal homeland security grants. A locally operated system may have been purchased with federal funding while remaining under state or local control.
Step 6: Locate The Agreements That Permit Sharing
Search for memoranda of understanding, data use agreements, interagency agreements, user agreements, service contracts, information sharing agreements, terms of access, and mutual aid agreements.
Read each agreement for the parties involved, data covered, approved purpose, user qualifications, redisclosure rules, retention period, audit rights, termination provisions, and complaint procedures.
A contract showing that an agency purchased software does not automatically prove that information was shared with another agency. The sharing connection should be supported by a separate agreement, technical document, access record, official statement, or other reliable evidence.
Step 7: Read Privacy And Civil Liberties Policies
Locate the fusion center’s privacy, civil rights, and civil liberties policy. Search the parent agency website if the center does not publish the policy on its own page.
Compare the policy with actual contracts and agreements. Record what the policy says about collection standards, protected activity, data quality, retention, access, dissemination, security, complaints, and audits.
Policies describe what an agency says it should do. They do not prove that the agency consistently follows those rules. Mark every policy based protection as a stated safeguard until an audit, access log, inspection report, or other evidence demonstrates implementation.
Step 8: Create A Public Records Request Plan
Do not request every record at once. Divide the investigation into focused requests that an agency can reasonably search.
One request might seek current information sharing agreements. Another might seek contracts and statements of work for a specific platform. A third might seek access policies, user manuals, audit summaries, retention schedules, and a list of participating agencies.
Ask for records in their original electronic format when possible. Spreadsheets should remain spreadsheets. Emails should retain available metadata. Databases should be provided in a searchable export when the law permits.
MuckRock provides nonprofit tools for filing, tracking, and publishing public records requests. Review previously released records before filing because another researcher may already have obtained the documents you need.
Step 9: Request Records That Reveal Information Flow
The most valuable records explain movement rather than mere possession.
Request system architecture diagrams, data dictionaries, interface descriptions, access control policies, agency account lists, audit summaries, dissemination logs, training materials, retention schedules, and documents identifying databases that connect to the system.
Ask for reports showing the number of contributing agencies, authorized accounts, queries, intelligence products, rejected submissions, corrected records, and compliance reviews. Aggregate statistics can reveal scale without exposing sensitive personal information.
Do not request operational details whose disclosure could create an immediate safety risk. The investigation should focus on public accountability, legal authority, institutional access, and privacy protections.
Step 10: Build An Evidence Ledger
Create a research ledger with fields for the source organization, document title, document date, date obtained, system involved, information collected, information recipient, stated purpose, legal authority, retention rule, confidence level, and source link.
Assign each claimed connection an evidence rating. Confirmed means a primary document directly establishes the relationship. Supported means several credible sources point to the relationship but a controlling agreement has not been located. Possible means the relationship is a research lead and must not be presented as fact.
This distinction is essential. A vendor’s ability to connect two systems does not prove that a specific agency activated that connection.
Step 11: Draw The Network
Create one node for each agency, contractor, database, and oversight body. Draw an arrow only when evidence supports a flow of information, system access, funding relationship, or governance role.
Label every arrow with the type of connection and the supporting document. Examples include supplies technology, funds system, contributes reports, receives alerts, maintains database, audits access, or governs retention.
Use different colors for confirmed, supported, and possible relationships. Add the date of the most recent evidence because contracts, access permissions, and agency partnerships can change.
Step 12: Test The Map For Missing Oversight
Once the network is visible, ask who oversees each connection.
Determine whether an inspector general, privacy officer, city council, county commission, state legislature, court, civilian review board, or internal compliance office has authority over the system. Search for audits, complaint reports, breach notices, disciplinary findings, legislative hearings, and annual compliance reviews.
A network with many information sources but no clearly identified correction process presents a serious accountability concern. Incorrect information can become more difficult to challenge after it travels across multiple systems.
Step 13: Seek Agency Responses
Before publishing serious findings, send each relevant agency a concise summary of the connections you believe the records establish. Ask the agency to identify inaccuracies, missing agreements, expired contracts, access restrictions, and current oversight procedures.
Give a reasonable response period and preserve the correspondence. If an agency does not respond, state that plainly. Do not characterize silence as confirmation.
Step 14: Publish The Evidence With The Map
Publish the map with an explanation of the evidence standard, research period, known limitations, and date of the last update. Link each major finding to its source document whenever legally and ethically possible.
Redact personal phone numbers, signatures, private email addresses, security credentials, victim information, and other sensitive details that are not necessary to establish public accountability.
Invite readers and agencies to submit corrections supported by documents. A transparent correction process makes the investigation more credible and keeps the map useful as systems and relationships change.
Questions Every Investigator Should Ask
- Who owns the system?
- Who operates it?
- Who funded it?
- Which agencies contribute information?
- Which agencies can search the information?
- Can private contractors access the information?
- What categories of information are collected?
- What legal standard permits collection?
- How long is the information retained?
- Can information be redistributed?
- Are searches logged and audited?
- Can an individual learn whether inaccurate information exists?
- Is there a procedure for correcting or deleting inaccurate information?
- Has the system experienced a breach, unauthorized disclosure, or compliance failure?
- Which elected body receives reports about the system?
Evidence That Confirms A Data Sharing Connection
The strongest evidence is a signed agreement, executed contract, official system diagram, access list, audit record, or technical document identifying both organizations.
Budget records can establish funding. Meeting minutes can establish approval. Training materials can establish intended use. Emails can document implementation. Aggregate query logs can establish actual use. Privacy policies can establish formal restrictions.
A news report, vendor advertisement, or archived website may provide an important lead. It should not replace primary documentation when the underlying records are obtainable.
Warning Signs Of An Unaccountable Network
Watch for vague descriptions such as public safety platform or information solution when contracts do not identify the information collected.
Other warning signs include indefinite retention, unrestricted redisclosure, contractor access without clear auditing, agreements that are missing from public meeting records, obsolete privacy policies, no correction procedure, inconsistent agency explanations, and technology purchases divided among several contracts.
A missing document is not proof of misconduct. It is a reason to continue searching, submit a narrower request, inspect retention schedules, or ask the agency where the controlling authority is recorded.
Protect The People In Your Research
Never publish a map that exposes victims, confidential sources, witnesses, minors, medical information, immigration information, or the home addresses of public employees.
Store research securely. Restrict editing access. Preserve original documents separately from working copies. Maintain a record showing where every document came from and whether any material was redacted.
If the investigation involves vulnerable communities, consult affected people before publishing details that could increase surveillance or expose community practices. Accountability research should reduce harm, not create another source of sensitive information.
Turn The Map Into Democratic Oversight
A completed map can support focused questions at city council meetings, county commission hearings, budget sessions, legislative committees, and civilian oversight meetings.
Ask officials to publish current agreements, require regular access audits, establish meaningful deletion rules, prohibit monitoring based solely on protected speech, disclose participating vendors, create correction procedures, and report security incidents.
The strongest reform requests connect a documented problem to a specific remedy. Instead of demanding general transparency, identify the missing agreement, absent audit, outdated policy, undisclosed vendor, or undefined retention rule.
In Conclusion
A government data fusion network becomes powerful through its connections. One contract reveals a vendor. One agreement reveals a partner. One policy reveals the official rules. One audit may reveal whether those rules are followed.
Mapping these connections turns a confusing surveillance structure into a system the public can examine. The work requires patience, careful sourcing, privacy protections, and a strict separation between verified facts and unresolved leads. When performed responsibly, a data fusion map gives communities the evidence they need to demand meaningful oversight.
Source List
- Department of Homeland Security Fusion Center Locations And Contact Information
- Department of Homeland Security Fusion Centers Support Of National Strategies And Guidance
- Government Accountability Office Information Sharing And Fusion Center Capabilities
- Government Accountability Office Nationwide Suspicious Activity Reporting Initiative Review
- Brennan Center Ending Fusion Center Abuses
- Brennan Center Local Police Surveillance Guidance
- Electronic Frontier Foundation Why Fusion Centers Matter
- Electronic Frontier Foundation Atlas Of Surveillance
- MuckRock Public Records Research Platform
