Flock Safety Shifts Surveillance Control
2026 Bartholomew Ruling Establishes ALPR Injury
The ACLU documented that in February 2026, the California Court of Appeal ruled in Bartholomew v. Parking Concepts, establishing a basis for consumers to sue when companies fail to provide a required ALPR privacy policy. A 2020 California State Auditor report found the Sacramento Police Department shared Automated License Plate Reader (ALPR) data with over 1,000 agencies nationwide. The ACLU also observed that in July 2026, Mata v. Digital Recognition Network favored the vendor because it maintained a publicly available privacy policy, suggesting compliance protects companies even with extensive data collection.
The Congressional Research Service (CRS) points to other rulings demonstrating judicial reluctance to broadly apply privacy protections to ALPR data. For instance, the Ninth Circuit's 2020 decision in U.S. v. Yang limited individuals' ability to challenge government access to private ALPR databases. Similarly, the Massachusetts Supreme Judicial Court's 2020 ruling in Commonwealth v. McCarthy determined that widespread ALPR use did not violate a reasonable expectation of privacy during limited surveillance. The CRS further reported that a device malfunction leading to a wrongful traffic stop, as seen in Green v. City and County of San Francisco (Ninth Circuit, 2014), revealed that retention policies alone do not prevent misuse stemming from technological inaccuracy.
Marin Sheriff Allowed ICE ALPR Access
The CRS documented that an audit of the Marin County Sheriff's Office revealed confusing vendor settings allowed three Immigration and Customs Enforcement (ICE) agencies to access ALPR data, despite local efforts to limit such sharing. Audits consistently demonstrate that the mere existence of retention limits or internal policies does not guarantee misuse prevention. Police Records Management reported that internal compliance failures are also common; quarterly audits of the Lexington Police Department's Flock Safety system in 2023, for example, showed officers using vague search justifications like "123456" or "investigation." Police Records Management also noted that a 2023 third-party audit of the Minneapolis Police Department uncovered outdated operational accounts for former personnel, indicating a failure in access control policies. The Hill reported on systemic mismanagement identified in a July 2020 City Auditor Report for Brownsville, Texas, which found that records were disposed of without committee approval, suggesting ALPR data would be susceptible to mishandling.
Flock Safety's August 2026 Policy Changes
The Electronic Frontier Foundation (EFF), ASIS International, and NPR reported that Flock Safety introduced a suite of mandatory policy and product changes in August 2026, aiming to tighten oversight and alter police discretion. Stateline.org and the ACLU of Oregon detailed how the company shifted its default data retention period from 30 days to 7 days; however, existing customers retain their democratically approved periods unless they opt into the new recommendation. The EFF and the Municipal Research and Services Center (MRSC) explained that searches now require a specific case code from records management systems to tie queries to active criminal cases, replacing the previously optional requirement. Good Morning America reported that an automated Audit Assistance Tool, featuring proactive lockouts for abnormal search activity, became mandatory for all customers by year-end. Flock Safety's blog announced that communities also gained enhanced offense filtering to block specific crime categories like immigration enforcement, and federal data sharing was set to "default off" for local departments. However, critics from the EFF, ASIS International, and Emeraldbook.org argue that these corporate-imposed reforms amount to "cosmetic fixes" or "window dressing," failing to resolve the fundamental dangers of mass surveillance or restore power to democratic oversight.
Private Vendors Erode Municipal Accountability
This structural shift diminishes human agency by subjecting individuals to widespread, opaque surveillance where parameters of data collection, retention, and sharing are largely determined by corporate policy and proprietary algorithms. Evidence indicates that municipal accountability erodes when operational control and data governance of public space surveillance reside with a private vendor rather than democratically elected bodies. While municipalities retain some contractual power, true democratic oversight remains elusive. This oversight, defined by transparency into and control over the underlying technology, necessitates thorough legislative action and direct access to proprietary systems to rebalance power.
Comments ()