Clocking Flock: Amid Public Backlash, Flock Safety Releases Accountability Features Dependent on Customer Enforcement
Flock Safety is creating several new accountability features for its automated license plate reader (ALPR) database product following months of significant public outcry about abuse of the technology.
Garrett Langley, CEO of Flock, shared the update in a blog post on the company’s website on 13 August, calling the changes a “continuation of our commitment to both safety and privacy.”
The company is introducing new default data retention policies, administrator review processes, and vulnerability reporting mechanisms. Many of these changes, however, will depend on actual customer enforcement to be effective at addressing misuse and abuse of Flock’s vast camera system and vehicle database.
Flock declined Security Management’s request to interview an executive for this story and instead referred us to Langley’s blog for questions about this week’s announcement.
Flock is rolling out the new features ahead of the National Week of Action Against ALPRs (16-22 August). Thousands of people across the United States have pledged to participate in public meetings, town halls, and other events to raise awareness about the use of ALPRs in their communities, the harms these systems can pose, and how to end their use.
“Blocking Flock is paramount to preserving the privacy and liberties of everyday people,” according to the action week’s website. “It is also the first step in a larger journey to protect ourselves and our communities. By banding together, we can make it loud and clear to not just Flock, but all these corporations and their collaborators that our data, our privacy, and our stories are not for sale.”
Andrew Ferguson, a law professor at George Washington University Law School who studies law enforcement’s use of technology, writes in an email to Security Management that the rejection of Flock has been a fascinating moment in our democratic experiments with mass self-surveillance. More than 80 communities have now rejected or reneged on their Flock contracts, and there are bipartisan efforts by legislators to curb the use of ALPR technology.
“It has been the first sustained rejection of a system of police surveillance in recent years,” Ferguson writes. “In the face of growing adoptions of drones, real-time crime centers, and data-driven video analytics elsewhere, somehow ALPRs struck a nerve and people said no more.”
ALPR and Flock’s Growth
ALPR technology emerged in the 1970s, and as of 2022, the International Association of Chiefs of Police (IACP) estimates that about 40 percent of all U.S. law enforcement agencies now use it in some form.
ALPR uses a camera positioned near a roadway to capture an image of a license plate and a contextual photo of the vehicle passing by, with location, date, and time data. Law enforcement then uses systems that convert that collected data into text to check it against databases, like the FBI’s National Crime Information Center, for stolen vehicle files, AMBER Alerts (missing child alerts), and Silver Alerts (missing senior alerts). If the check returns a match, it notifies law enforcement personnel in the area, says Eric R. Atstupenas, general counsel at the Massachusetts Chiefs of Police Association, Inc.
Flock Safety was founded in 2017, and its original customers were homeowners associations. It soon, however, began marketing its camera system to the United States’s more than 17,000 law enforcement agencies, 7,000 of which are now Flock customers.
The Flock system leverages video cameras installed on poles along roadsides, which depend on solar power and a Wi-Fi connection to operate. Customers lease these cameras, which take photos of every vehicle that passes by the camera to capture its license plate, make, color, and unique features. Flock does not disclose the number of camera installations it has in the United States, but DeFlock—an open-source, volunteer project to identify and document ALPRs—estimates that there are more than 100,000 Flock cameras in use today.
Flock says on its website that out of 1 million vehicle alerts it sends to law enforcement, only nine are flagged as being inaccurate—a claim that Security Management was unable to independently verify.
Jon Polly, PSP, chief solutions officer, ProTecht Solutions Partners and immediate past chair of the ASIS International Emerging Technologies Community Steering Committee, is skeptical of Flock’s accuracy claims. Traditional license plate recognition systems use specialty cameras to capture license plate and vehicles with accuracy at speeds up to 200 miles per hour. Flock’s systems use more traditional surveillance cameras, or what Polly refers to as cameras for license plate capture, which are highly dependent on lighting and weather conditions for accuracy and cannot capture vehicle data at a high rate of speed with accuracy.
“You’ll see a lot of license plate capture cameras at entrances to neighborhoods or things like that where you’ve got a slow speed coming in,” Polly explains. “You’re not on an interstate. You’ll typically see a true license plate recognition camera on those interstates or in areas where they need absolute accuracy.”
Data from Flock’s cameras is sent to a database, which Flock manages. As part of their contract, customers can search the database for specific vehicles—such as a known stolen car. One of its most used features is a Hot List, or a list of vehicles or license plates that might be connected to crimes. When a Flock camera detection matches a Hot List entry, Flock’s system generates an alert for authorized users.
Flock maintains that while the data from its cameras is stored in a database it manages, customers maintain full control of how their data is used and who it is shared with. Customers also have the option to share data collected by their Flock system with other Flock customers, either in one-to-one sharing or a one-to-many sharing network.
Sharing data in this way can be beneficial for law enforcement because it allows officers to detect patterns, such as how a retail theft ring moves from one state to another. But it can also create risks since data in a wide network is governed by the weakest policy in it and accountability diffuses, says Atstupenas, an IACP member, immediate past chair of the Legal Officers Section, and a member of the association’s Committee on Human and Civil Rights.
“On some platforms broad sharing is a default, so the most consequential data-governance choice in the program gets made by a default unless the agency makes it deliberately, and consent on paper is not the same as a decision in fact,” he explains.
U.S. state law also varies, so a search that is routine in one jurisdiction might be illegal in another.
“The last year documented all of this: State audits and reporting found immigration-related queries and an out-of-state abortion investigation reaching cameras in states whose laws forbid exactly that, and in one widely reported case the chief whose data was searched said he had not known his department had opted into nationwide lookup at all,” Atstupenas says.
Many of the incidents that Atstupenas refers to involved misuse of Flock’s cameras and database sharing access. 404 Media reported in May 2025, for instance, that U.S. Customs and Immigration Enforcement officers were accessing Flock data by requesting access to it from local law enforcement agencies.
This activity resulted in damaged trust and significant public outcry against Flock as a company and against ALPR systems as a surveillance tool for law enforcement—especially given the rapid deployment of Flock cameras in recent years. Numerous agencies have canceled or paused their contracts with Flock as a result, including the Los Angeles Police Department, which said it planned to discontinue using Flock until the department can get its data, privacy, security, and sharing concerns addressed.
The fallout shows a growing distrust of how law enforcement is using new technology in the United States and that deeds matter more than words, Ferguson says.
“There have been dozens of stories of officers misusing ALPRs to track ex-girlfriends or love interests. There are stories about targeting protestors,” he says. “There are even stories of police violating their own state law to fulfill out-of-state requests. So, why should police be trusted with a technology that they have routinely abused? Their actions breed mistrust.
“Police departments need to take actionable steps that set out the limits, use cases, and penalties for misuse,” he continues. “For example, if they break the rules, they forfeit use of the technology. They also need to communicate why the technology justifies the privacy invasion. Why store the data for 30 days? New Hampshire has an ALPR law that gets rid of the data in minutes. Why do you need to connect the dots nationwide? Why do you get to surveil patterns of movement? If you can’t explain it, you can’t use it.”
New Flock Features
In response to this criticism, Flock is rolling out some new accountability and security features. They include:
- Requiring law enforcement customers to use Flock’s Audit Assistance to detect abnormal activity and flag it for administrator review by the end of 2026
- Proactive lockouts, which lockdown a user’s ability to search Flock’s database when his or her actions meet defined criteria for abnormal behavior
- Requiring law enforcement customers to use case codes to search its database for vehicle information, except for in emergencies
- Changing default data retention of data from Flock cameras from 30 days to 7 days
- Giving customers the ability to limit how other customers they’ve shared Flock data with can use that data
- Requiring multi-factor authentication for access to Flock systems
- Creating a coordinated vulnerability disclosure program to allow researchers to report vulnerabilities
While Flock touts the new features it’s rolling out as measures to improve accountability and privacy, the effectiveness of the requirements will be dependent on Flock’s customers creating administrative review processes to ensure the technology is used appropriately.
“Officers using these systems to locate current or former partners is documented, it is the abuse scenario these controls exist for, and a department that treats it as a hypothetical has already failed the people most at risk, who are often the officer’s own family members,” Atstupenas says.
He recommends following the procedures of the IACP Technology Policy Framework to create policies and procedures to ensure department technology is only used by authorized personnel for authorized purposes. These policies should be written down and personnel should be trained on them before being able to access department technology. Departments should also limit access to technology to trained personnel on individual accounts that are deactivated at separation.
Officers using these systems to locate current or former partners is documented, it is the abuse scenario these controls exist for, and a department that treats it as a hypothetical has already failed the people most at risk, who are often the officer's own family members.
Search queries for ALPR systems, for instance, should be documented with a legitimate purpose following the need-to-know and right-to-know standard, be anchored to a case or incident number, and technically enforced where the platform allows, Atstupenas adds. Departments should also expressly state prohibited uses of the system and have audit logs that capture who searched what, when, and why, along with having a deliberate retention policy for the data.
Atstupenas stresses that deterring misuse of department technology comes from the certainty officers have that their actions will be reviewed—not the severity of potential penalties. Departments should design detection for misuse into their procedures, such as requiring supervisory checks of justifications against actual case records, conducting randomly scheduled audits rather than compliance-driven ones, and paying special attention to known red flags—queries with no case, self-queries, and license plates tied to spouses, former partners, family, or acquaintances, especially outside of normal working hours.
“An officer who knows the logs are read behaves differently from one who knows they exist,” he says.
When departments detect misuse, officers should have their access to the technology suspended pending an investigation and discipline should follow the agency’s processes and labor obligations. If the conduct violates the law, Atstupenas says that person should be referred for prosecution.
He also recommends owning the incident before being asked twice about it. Police chiefs should confirm the facts of what happened when personnel abuse their access to agency technology and share how that misuse was discovered.
“An agency that caught the violation through its own audit should say so; that is the oversight working,” Atstupenas says. “An agency that learned about it from a reporter or a court filing should say that, too, and then explain what failed in its own review and what has changed so the next one is caught internally.”
Atstupenas adds that police chiefs should disclose what the law allows them to: when conduct violated agency policy, if the matter is in the disciplinary process, if it was referred for prosecution, and if the victim was notified. They should then fix any system gaps the incident exposed and explain what those changes entailed, including in public reports.
“Communities do not expect zero violations; every institution that employs human beings has them,” Atstupenas says. “What communities do not forgive is learning that the institution knew and said nothing. The chief’s job in that moment is to make the incident evident that the safeguards are real.”
Megan Gates is the senior editor at Security Management. Connect with her at [email protected] or on LinkedIn.









