Flock backlash could reshape local ALPR use, but company says change is up to police, lawmakers
Months of backlash across social media and public forums over law enforcement’s use and misuse of automated license plate readers — particularly Flock Safety’s cameras and data-sharing network — have prompted scrutiny of how the technology is deployed and governed, forcing changes this week from the industry.
Flock on Thursday announced a slate of changes to its technology and recommended best practices to its law enforcement customers. Although the changes could reshape the role of ALPRs in communities across the country, the company says the most substantive changes still remain up to law enforcement agencies themselves, as well as state and local lawmakers.
The changes included a reduction of the default data-retention schedule for the images of license plates its collects from 30 days to seven days, and new cross-agency data sharing filters. The changes include mandatory and automatic misuse audits, a new requirement for associated case numbers to conduct a system search and several other updated security and data standards. Many of the changes come in direct response to the public backlash that has mounted against the company and the agencies that use its readers. So far, agencies in 23 states have cancelled contracts with the company.
“Nine years ago, we set out to build a company that would make communities safer,” Garrett Langley, Flock’s chief executive, said in a statement shared online Thursday. “These changes reflect years of work and deliberation. They are not the end of that work, but simply the continuation of our commitment to both safety and privacy. We are not perfect, so we will keep listening, improving, and building a better standard for public safety technology together.”
Flock is also urging states and communities to pass laws and rules that would bolster the safeguards on their law enforcement agencies using ALPRs. It was recently discovered that police officers across Georgia, North Carolina, Massachusetts, Wisconsin and other states were using the technology to spy, stalk or harass romantic interests or exes. Langley urged states to pass laws enforcing “real auditing on every law enforcement data system.”
“Raise the penalties for misuse. And if your state wants help building it, we’ll do it for free,” Langley wrote on X this week.
Some experts and law enforcement officials, though, said abuses involving Flock’s data are unsurprising given the broader history of police misconduct. Critics of the technology argue that the company’s data and security changes do little to address the systemic issues, and while state laws are regulating the tech have been welcomed by many, placing the onus on police departments to govern themselves is part of what enabled the abuses of power in the first place, and led to the erosion of public trust.
Creating an ‘attractive nuisance’
Though Flock is just one of the companies that offers ALPR technology for law enforcement agencies, its popularity has exploded over the last few years. Almost 100,000 of its license-plate reading cameras have been installed, and they can be found in every state. According to Flock, more than 6,000 law enforcement agencies have purchased and installed its cameras. Law enforcement agencies enter into agreements with Flock, each purchasing a set of cameras, sometimes numbering into the hundreds or thousands, and they are installed in locations of the agency’s choosing. According to Flock, more than 6,000 law enforcement agencies have purchased and installed its cameras in the United States.
As the number of Flock cameras has expanded, so too have the data-sharing agreements that allow agencies to access one another’s data, which is to Flock’s advantage as a business. Flock representatives told this publication that those agreements are established by the agencies themselves, and that the agencies that own the cameras generally retain ownership of the data. But the arrangements governing who can access that data can be difficult for the public to see. According to data collected by DeFlock, an open-source project that maps ALPRs and the agencies using them, only about 900 — of more than 6,400 agencies using Flock — disclose their data-sharing agreements.
These agreements, and the lack of transparency around them, have fueled concerns that Flock’s network functions as a form of mass surveillance. Concerns have been propelled by the ability of local and federal agencies to share data for controversial criminal investigations, such as those related to immigration or abortion. And while the concerns about police misuse to stalk exes or even strangers that caught their interest are alarming, to some experts, the concern begins at when the system is used as designed.
“The greatest threat presented by license platers doesn’t come when they’re misused,” said Chad Marlow, a senior policy council with the American Civil Liberties Union. “It comes when they’re used as intended, which is to track every single vehicle in an entire city or area, no matter where it travels, all the time with no criminal suspicion. … That is the real problem.”
Marlow uses the legal concept of an “attractive nuisance” — a man-made object, such as a swimming pool or trampoline, that is likely to attract children and lead to their harm — to describe the abuse that happens with the creation of huge location databases that are accessible by any number of law enforcement agencies. By tracking any and all license plates it can read, the system surveils everyone all the time, not just suspects in crimes, he said, and given the scale of that surveillance and the number of agencies with access to it, some misuse is inevitable.
Kam Simmons, Flock’s vice president of government affairs, said in an interview that while Flock cameras do capture a broad swath of data on vehicles, the company has built in some safeguards. One is a 30‑day cap — and Flock recently reduced its recommendation to seven days — on the storage of plate images, unless they are tied to an active investigation. But the retention schedule is up to each agency, as are the inter-agency data-sharing agreements, as is the responsibility for auditing how the systems are used, leaving much of this power with law enforcement to police themselves. The ACLU recommends a 48-hour retention schedule.
“You don’t have the fox guard the henhouse,” Marlow said. “This is the work of legislatures, local and state and federal legislatures. They need to pass laws governing this technology. Police policies can be changed at the drop of a hat. This is too dangerous a technology to leave up to policy. There has to be laws governing them.”
‘Game changer’
Jon Bridges, director of strategic implementation for the Richmond, Virginia, Police Department, has been with the department for 20 years, mainly working in homicide and violent crime. He described his department’s use of Flock as a “huge benefit” and even a “game changer” for certain investigations.
“I get it. I get the concerns and the worries about surveillance state,” Bridges said. “I share many concerns about surveillance technology generally, but you really need to examine it more closely and look at each one of its merits, and how it’s used.”
Richmond, Virginia, has had a contract with Flock since 2023, and it has 99 cameras set up around the city. Bridges said the technology has sped up suspect identification and apprehension, improved evidence collection and contributed to a higher homicide case clearance rate.
“We just took the numbers from last year, 2025, in these six public housing communities, and the public housing communities invested in a good video camera system several years ago, which has been tremendous in addressing and decreasing violent crime,” Bridges said. “So we had 23 homicides, either directly in those [communities] or immediately adjacent, to which the cameras and Flock technology were were deployed, and we were able to clear 21 of those 23, or a 90% clearance rate for homicides.” (According to one analysis relying on FBI data, the national average clearance rate for homicide cases is around 50%.)
But Bridges said though the tech has been helpful in violent crime investigations, it is only valuable when tightly constrained by law and internal policy. Virginia is one of the few states to have an ALPR law on the books. It was enacted last year, and provides a number of usage guardrails: preventing agencies from sharing ALPR data outside Virginia and preventing agencies from sharing ALPR data with federal agencies like ICE or the FBI. It also classifies misuse of ALPRs and their data, or sharing unlawfully, as a Class 1 misdemeanor, with likely job loss.
“We are very committed to using it responsibly. So we have a lot of policy and internal controls. … We do monthly audits. Anybody that has a legitimate reason to use the technology has to sign a very detailed user agreement and it has to be for law enforcement purposes,” he said. “Georgia, I don’t think they have that [law], and them being in the news for officers using it for personal information — it would be against the law here in Virginia. Certainly against our policy, and you know there would be you know very serious repercussions if anybody did that.”
Beyond individual agency statistics on the effectiveness of the company’s tech within their jurisdictions, however, it’s hard to gauge just how accurate and helpful it truly is. Flock claims on its website that its technology has 96% accuracy for counting vehicles, but there is no claim about its accuracy of reading plates. When pressed on the 96% figure, and whether the remaining 4% were false positives or some other type of inaccuracy, Simmons said that “of every one million alerts that we send to local law enforcement, nine of those alerts are flagged to us as inaccurate reads. So we are proud to have a very high accuracy rate.”
But, nine per 1,000,000 inaccurate alerts would make 99.9991% of delivered alerts deemed “not reported as inaccurate,” which is better than 96%. It’s also statistically improbable. Simmons explained that this inconsistency could be attributed to “low‑confidence reads,” which are filtered before becoming alerts, meaning they could factor into that 4% that are deemed false positives or some other inaccuracy.
Simmons said Flock allows and pursues independent, third‑party security and use‑of‑system reviews, such as for testing cybersecurity vulnerabilities, but it does not allow third‑party audits of its accuracy claims. Some agencies may choose to pursue them on their own. When the police department in Roseville, California, conducted its own audit of the tech’s accuracy with reading license plates from almost 1,500 Flock alerts last year, it discovered a 71% failure rate.
In response to abuses of the system, Simmons classified them as rare, and pointed to the company’s “audit assistance” service, which launched in January, to help “proactively surface anomalous search patterns to law enforcement agency leadership.” He called any abuse of the system “horrible,” and added that Flock is “effusively supportive” of strong ALPR legislation and guardrails.
‘Just Trust Us’
Though privacy advocates have conceded that some of the changes Flock announced this week move the needle in the right direction, the mandatory and recommended changes still mean relying on Flock for the veracity of its claims.
“While this measure contains some meaningful improvements, such as the shortened retention policy, ultimately it is the same ‘Just Trust Us’ policy with a fresh coat of paint, Tom Bowman, policy counsel with CDT’s Security & Surveillance Project, wrote in an emailed statement. “Flock is still asking thousands of police departments to police themselves, despite evidence from across the U.S. that this lack of guardrails is unsafe. The changes do not ward off the demonstrated dangers of ALPRs, which include pervasive tracking, vehicle stops based on flawed AI flags of ‘irregular’ driving patterns, and abuse such as stalking. The fix that will actually stop the threats Flock and other ALPRs pose is the same one American privacy law has always relied on: make the government get a warrant.”
This notion of, again, placing the onus on police departments was concerning to the ACLU’s Marlow, too, who penned a response calling for the company to do more. Marlow also argued there is still not enough evidence that the company’s changes will address the problems that have emerged around its technology. He called for independent testing of the company’s safeguards, more meaningful limits on data-retention and data-sharing, and even stronger restrictions on how the system can be used.
Reem Suleiman, senior campaign director at the advocacy group Fight for The Future, said that this moment of reckoning with surveillance technologies extends beyond just a distrust of ALPR technology. She likened it to an awakening about the costs of sacrificing certain rights in exchange for unverified claims of increased safety.
“I see the backlash to Flock as symbolic of people asserting a right to privacy. … There’s this growing insistence that protecting people from always-on surveillance has to be an intrinsic part of how we approach technology,” Suleiman said in an interview. “On paper, cities can write beautiful policies, but without a real culture of privacy they just become rubber-stamp bodies for surveillance tech. … What you’re seeing now is communities saying, No, this isn’t acceptable anymore.”
And until Flock can demonstrate with third-party testing that its controls actually prevent misuse, Marlow said, the changes risk looking more like damage control than substantive reform.
“What really kind of pleases me is how nonpartisan it is,” Marlow said of the backlash. “Everyone is arriving at the same conclusion, which is government mass surveillance is out of control with these things, and it needs to be reined in immediately. Where we’re heading, I hope, is that this becomes a national movement against mass government surveillance and not just license plate readers and not just Flock.”