VPointEU

The Camera Is the Easy Part

Automated license plate readers now cover most of the United States, and underneath sits objective question about data and privacy security.

PublishedReading time: 11 min read

The Camera Is the Easy Part - thumbnail

Automated license plate readers now cover most of the United States, and the argument about them has settled into two camps that mostly talk past each other. Underneath it sits a set of questions that have nothing to do with which camp is right: who holds the data, for how long, who can search it, and whether anyone would notice if someone searched it for the wrong reason.

A question the board could not answer

A property manager for a suburban retail park is asked by a tenant why there is a camera on a pole at the entrance to the lot. It went up eighteen months ago as part of a package the ownership group bought after a string of catalytic converter thefts. The manager knows what it cost and who installed it.

Then the tenant asks a second question: who has looked at the footage from it?

Nobody at the property company knows. Nobody has ever asked. The contract is in a shared drive and nobody has opened it since signing. When someone finally does open it, the answers are in there - the retention period, the default sharing settings, the list of agencies with query access - and they are not what anyone on the board assumed. The gap between what an organization thinks it bought and what it actually joined is where the exposure sits.

What the system does, described plainly

Flock Safety is the largest vendor in the automated license plate reader market. The company says its technology is used in more than 6,000 communities across 49 states and that its network exceeds 120,000 cameras. Competitors including Motorola's Vigilant operate on similar principles.

The hardware photographs every passing vehicle. Software extracts the plate number, timestamp and location, and also records vehicle characteristics - color, make, body style, roof racks, bumper stickers - into what the company calls a vehicle fingerprint, which allows a search even when nobody has a plate number. The resulting records are queryable, and in many configurations queryable by agencies other than the one that owns the camera.

Two properties of that design matter to anyone assessing it as a data-protection question.

The first is that the system does not distinguish at the point of collection. A speed camera fires when someone speeds. An ALPR records everyone, and the overwhelming majority of what any such database contains is the movement history of people who are not suspected of anything. That is not a criticism of the technology, it is a description of it, and it is why retention and access controls carry so much weight: they are the only stage at which the distinction can be made.

The second is that the value of the data increases with aggregation, which pushes the whole system toward sharing. A single camera answers whether a car passed one intersection. A network answers where a car has been. Every design decision that makes the tool more useful for investigations also makes the underlying dataset more revealing about everyone in it. Both halves of that sentence are true at once.

Retention turned out to be the whole argument

In August 2026 Flock announced a set of changes: a recommended retention period of seven days rather than thirty, an "Evidence Mode" letting investigators preserve specific records tied to an active case, controls letting a community restrict which outside agencies can search its cameras and for which categories of offense, mandatory case codes on searches, and an audit tool that flags anomalous activity and can automatically suspend a user pending review. The company says these give communities more control; the ACLU called the shorter retention a possible step forward, recommended 48 hours instead, and questioned whether preservation could keep large volumes of location data alive past the nominal window. The seven-day recommendation does not apply automatically to existing customers, who set their own periods.

Whatever one makes of the announcement, it lands on the variable American courts have been reasoning about.

In Schmidt v. City of Norfolk, two residents sued over the city's network of 176 cameras. Discovery established that the system had logged one plaintiff's vehicle 526 times and the other's 849 times over roughly four months - about four sightings a day, for two people who were never suspected of anything. On January 27, 2026, Chief Judge Mark Davis granted summary judgment for the city in a 51-page opinion, reasoning that a 21-day retention window, the maximum Virginia law permits, combined with gaps in camera coverage, did not capture the whole of a person's movements in the sense the Supreme Court described in Carpenter v. United States. The opinion went out of its way to say the answer might change: the technology could become too intrusive at some point, but in Norfolk, at least, not today.

The plaintiffs appealed. The case is now before the Fourth Circuit as No. 26-1227, fully briefed. The same circuit held in 2021 that 45 days of aerial surveillance photography over Baltimore crossed the line. Twenty-one days sits between the two numbers, which is why the retention setting has stopped being an administrative detail.

Then, on June 29, 2026, the Supreme Court decided Chatrie v. United States, holding 6-3 in an opinion by Justice Kagan that obtaining a person's phone location records from a third party is a Fourth Amendment search. The decision does not mention license plate readers. Lawyers on both sides of the ALPR question spent the summer rereading it anyway.

The practical takeaway for anyone operating one of these systems is unglamorous: the number in your retention field is doing constitutional work. It is the single configuration value most likely to determine how a court characterizes what you are running.

Access control, and what audits actually reveal

The second variable is who can search, and there is a documented record to work from.

Earlier this month the Washington Post reported that nearly 50 police officers had been charged with or accused of using Flock cameras for unauthorized purposes, a large share of them involving attempts to track current or former partners or family members. In Savannah, Georgia, four officers and two civilian employees were fired following an internal investigation that found searches involving personal acquaintances and relatives, along with an officer granting an outside agency access to the city's system; all six matters were referred to the Georgia Bureau of Investigation.

The Savannah cases were surfaced by Flock's own audit tooling. That cuts in two directions. Audit logging works: it caught what it was built to catch. It also shows that a search-reason requirement is not by itself a control. Earlier iterations used a free-text field, which officers filled with vague or meaningless entries until it was replaced with a list of approved reasons. A control that can be satisfied by typing anything is a logging feature, not a restriction.

The cross-jurisdictional layer raises the same question one level up. California's ALPR Privacy Act, passed as SB 34 in 2015, restricts sharing ALPR data with out-of-state and federal agencies. A class action filed in San Francisco Superior Court in February 2026 alleges that Flock's architecture and sharing practices violated it; the complaint alleges that out-of-state agencies searched one department's database more than 1.6 million times in a seven-month period. These are allegations and have not been tested. What is not in dispute is that individual departments running their own audits have found federal access they did not intend to grant. El Cerrito's police chief said publicly that his department found federal sharing incidents after settings should have prevented them. Mountain View terminated its contract after finding violations.

None of that requires a position on immigration enforcement or federal-state relations. In a networked system, the default permission setting is the policy. Whatever the written agreement says, the configuration is what executes.

Accuracy is a separate failure mode

Earlier in August a driver in Wisconsin was stopped at gunpoint on the interstate after an ALPR alert flagged her vehicle in connection with a homicide. The vehicle had nothing to do with it. Police later said the cause was a department employee's failure to remove an outdated wanted-vehicle entry from the system rather than an error by the camera. The driver said she had been stopped at gunpoint earlier the same week and was afraid to drive afterward.

Flock's position is that alerts are investigative leads rather than conclusions and that officers should visually confirm a plate before acting; the company states its system produces fewer than nine human-reported errors per million alerts.

For data-protection purposes the attribution of fault is the interesting part. This was not a recognition failure. It was a stale record in a hotlist, a data hygiene failure of the kind every organization running a matching system eventually has. The controls that prevent it are boring and well understood: an owner for each list, an expiry date on each entry, a periodic reconciliation, and a documented human verification step before consequential action. None of that is novel, and none of it is usually included in the procurement conversation.

What a private operator should have pinned down

Most of the public debate concerns police departments. A large share of these cameras sit on private property - retail parks, business campuses, homeowners associations, hospitals, logistics yards - installed by organizations that thought of it as a security purchase. Those organizations are generating and contributing personal data, and a handful of questions determine their exposure.

Know which side of the arrangement you are on. There is a difference between buying cameras for your own use, contributing your feed to a network, and hosting hardware owned by someone else. The contract says which. The people who signed it frequently cannot say which.

Set the retention number deliberately, in writing, with a reason. Defaults are not decisions. If you cannot articulate why the figure is what it is, you will not be able to articulate it later either, and later is when someone asks.

Enumerate who can query, by agency name. "Law enforcement" is not an access control list. Ask the vendor for the current list of agencies with query rights against your data, in writing, and ask again in six months, because the answer changes.

Get the audit log, and read it. Most operators have a right to their own search logs and have never requested one. A quarterly review by a named person is a modest commitment that would have surfaced most of the incidents described above much earlier.

Handle your own people. A camera at the staff entrance produces a continuous record of when your employees arrive and leave and what they drive. That is workforce data with employment-law and works-council implications in some jurisdictions and a live disclosure obligation in others, and it is almost never covered by the security-department memo authorizing the installation.

Know what happens at termination. When the contract ends, the cameras come down. What becomes of records already ingested into the network, and of the derived data built on them, is a separate question that the standard agreement may or may not answer.

Check your notice obligations locally. More than a dozen states have enacted laws governing policing technologies including ALPRs, with no consistent national framework, and legislatures are returning to the subject. Pennsylvania lawmakers from both parties announced a bill this month covering documented search reasons, audit trails, retention, transparency, civil penalties and a private right of action. Two proposals from congressional Republicans would restrict federal purchase and use, and bar state and local police from spending federal funds on these systems. The requirements applicable to your site in 2027 are unlikely to be the ones applicable today.

What this piece is not saying

The technology has closed real cases, and the courts have so far mostly sided with the agencies using it; Flock points to a substantial number of decisions finding no constitutional violation in discrete ALPR use. Meanwhile more than 50 agencies and communities have canceled, suspended or rejected contracts or deactivated cameras since the start of 2026, according to a group that tracks deployments, and some cameras have been vandalized. Reasonable people are landing in different places, and legislation is moving in both directions in both parties.

None of that is the point here.

The point is that a system of this shape produces a durable, searchable record of where ordinary people go, and that the size and reach of that record is set by four values - retention, access, sharing and audit - usually configured once, by whoever did the installation, and never revisited.

Those settings are also the part any individual organization actually controls. The constitutional question is being worked out slowly in the Fourth Circuit and eventually somewhere higher. The configuration question is answerable this week, by someone opening the contract.

We help organizations answer the practical version of this: what your systems collect, how long they hold it, who can query it, and whether anyone would notice if the answer changed. If nobody in your organization can currently say who has searched your cameras, that is the place to start.