Fire Tech Brief: 5 Data Policies to Establish Before Collecting Data
Key Takeaways
- Fire departments need to develop clear policies on data ownership, access, retention, and destruction before purchasing new technology to avoid legal and operational issues.
- Understand and comply with jurisdictional laws and regulations related to data protection, especially for sensitive information like personnel, video, and biometric data.
- Implement security measures, such as role-based access, encryption, audit logs, and breach procedures to protect collected data from misuse or breaches.
I remember the first time the issue of effective data policies popped up for me after we deployed new technology in my fire department.
One cool feature of several thermal imaging cameras (TIC) on the market was the ability to record and store a video. After a fire was used to cover up a homicide, we found significant use for one of the TIC videos, but it also brought the internet technology (IT) and legal departments into the conversation of record retention, policies for use, and several other administrative headaches.
This scenario is becoming a commonality as departments are deploying more technology that is generating a ton of data, records, images, and videos. So before you get into a retroactive pursuit to make sure you are compliant with laws, codes, and ordinances, technology and data policies need to be in your procurement process.
Who owns the data?
Failure to do your due diligence when purchasing technology can quickly leave a department stuck without options. Does your organization own your data or does the vendor? What happens when you want to change vendors? What happens when an integration copies that data? Where does your data go when you use an AI tool to analyze it? When building dashboards, especially public facing options, can information be de-identified or aggregated to reduce exposure of protected information? Does a vendor sell your data or use it to train AI models? Can you export your data or maintain a record for life? While all of these are valid questions, it is also important to understand that even if your contract says you own it, that is useless unless you can control, retrieve, and/or delete it.
Collecting data creates an obligation to protect it
While many of us are aware of data protection requirements in specific instances such as patient records, many other sources of data are often overlooked until it becomes an issue. While I wish there were an easy answer, each state, county, and local jurisdiction often have overlapping requirements for what is needed for protection, retention, and even destruction. A great baseline question everyone should be asking is “Do we need to collect this?” Personnel information, video, audio, images taken at a scene, drone imagery, geospatial data, biometric/wearable data, and virtual meeting/AI transcripts or summaries are all adding to the burden of storing, securing, governing, searching, retaining, and disclosing information that may or may not be considered public information.
In these situations, having good policies for use role-based access, audit logs, dual authentication, encryption, and breach procedures are not just nice to have, they are necessary. The Flock Camera debates across the country are a fitting example of why transparency and policies are needed. As law enforcement officials are facing pushback and disciplinary action for misuse of the system, it shows what can happen if your public is not aware of the capabilities, uses, and policies on public safety technology. Everything we collect, generate, or use is a risk that must be properly vetted and mitigated.
Retention policies include forever not being the only answer
I remember going through station basements and attics back in the day to clean out old filing cabinets. Retention rules and laws do not treat every record the same, but most departments have closets, basements, attics, and even storage units full of old paper records. In the digital age, it becomes easier to store massive amounts of information without taking up as much physical space but since most options are cloud based, you are adding potential cost as you keep things that are not needed. Keeping everything forever can quickly add up, especially once you start including video recording or imagery.
Even something as simple as a drone video/image does not have to be treated the same. In many cases, you can evaluate the purpose of the record. Take our drone example, it could be used on operational incidents, to record and preserve evidence, to film training, provide GIS imagery, or even as security footage. Each purpose of that source of data may have different requirements and do not automatically warrant equal treatment. In other cases, laws may clearly spell out things like a personnel record must be maintained until 50 years past a person’s death, or hazmat records must be maintained forever. If there is not a clear requirement, do not just automatically default to forever. Your policies should be at a minimum address:
- Creation
- Classification
- Access
- Retention
- Archival
- Destruction
Someone is eventually going to ask for the data
Public record requests can often be a thorny issue to address, especially if a department is unaware of a law, rule, ordinance, or other requirement to retain certain data points. Long gone are the days of a lawyer’s office send a request for the incident report. The last request for information I got as a chief was for all audio, video, drone footage, CAD information, GIS/GPS data, Radio audio/transcription, email messages, text messages, summaries, and related meta data for a particular incident. This creates a major issue, even more so when you respond back with no data present on a particular request that they know was required by law to protect and retain. The point behind this is that you had better know what data you have, where it is, and how you can search it. This also goes along with a purchasing question, “How can I find and pull my data?” The last thing you want to do is watch hundreds of hours of video looking for the one-minute clip that was relevant or requested or open a ton of old reports because the file structure and name gave you no clue when or where they occurred.
Is policy before purchase the solution?
If you are following a well-established technology procurement process, then another benefit is that you already know most of the answers that are needed to draft a proper policy. The issue erupts when a department is not fully sure what the technology does, what problem or purpose it will serve, and other basic questions. During a proper process, you will already know what problem it is solving (how it will be used), who will own it (and the data), what data it creates and applicable laws to that data, who can access it, how it can be accessed, and how you can prove it has been destroyed when deemed appropriate. While other use cases may come up in the future that will require policy adjustments, every tech purchase should roll out with the applicable policies to make sure we are responsible stewards of the data.
Conclusion
In an age where everything is generating data, are you as a department prepared to go beyond tapping into it and using it? With great data comes an even bigger responsibility to review, retain, and protect it. Policies are one piece of the puzzle that should not be overlooked.
About the Author
Jason MooreJason Moore
Jason Moore is a 23-year veteran of the fire service who began his career with the U.S. Air Force as a fire protection specialist. Moore is involved with the International Association of Fire Chiefs’ Technology Council and is a founding member/associate director of the Indiana University Crisis Technologies Innovation Lab (IU Red Lab). He delivered presentations on implementing technology, using technology for community risk reduction and best practices to justify funding for innovative programs. Moore was the keynote speaker at FireFusion 2024 and is a member of the Firehouse Editorial Advisory Board.
