Federal Snoops Tap Local Cameras

The most troubling thing about Flock Safety’s recent data‑sharing scandals is not a single “glitch” or rogue user, but a business model that quietly turns local police cameras into a de facto national surveillance network that federal agencies can tap—often without the knowledge or consent of the communities that paid for it.

Key Points

  • Flock’s “national lookup” and “statewide lookup” settings have repeatedly exposed local license plate data to federal agencies and out-of-state police, even where local policy or state law forbids such sharing.
  • Audits in cities like Mountain View, Oxnard, Ventura County, and Washington state uncovered hundreds of thousands of unauthorized searches by agencies such as ATF, CBP, Border Patrol, and military investigators.
  • Flock’s contracts and defaults create a nationwide pool of ALPR data in which local agencies may “opt in” more broadly than they understand—and in some cases, data was shared even when they tried to opt out.
  • The problem is structural: ALPR vendors build centralized, interoperable networks with broad sharing provisions, while laws and local policies are fragmented and far weaker than the technology.
  • In response, dozens of municipalities have canceled Flock contracts, state auditors have cited legal violations, and civil rights groups are pressing for strict limits on retention and cross‑jurisdictional sharing.

How Flock’s Nationwide Sharing Really Works

To understand how federal agencies ended up querying small city camera feeds, you have to start with the architecture. Flock’s cameras are not stand‑alone devices owned and operated entirely by local police; they are nodes in a centralized, cloud‑based system that Flock itself runs. Each camera captures license plates, vehicle details, time, and location. That data is uploaded over cellular links into Flock’s servers, where it becomes searchable through a web interface and mobile apps. The company’s appeal to law enforcement hinges on interoperability: a police department in one state can, with a few clicks, search data collected by agencies thousands of miles away.

That reach comes from configurable “national lookup” and “statewide lookup” settings—software toggles that sit above whatever local policy may say. When those toggles are enabled, any participating law enforcement user with the right role can query data another agency collected, regardless of whether the data’s origin city ever signed a direct sharing agreement with them. In theory, local agencies decide which external partners can access their data. In practice, public records and audits show that nationwide sharing was frequently on by default, enabled by Flock or re‑enabled by “vendor-based configuration errors,” and in some cases contract language gave Flock itself a license to disclose data for investigative purposes even when customers chose restrictive settings.

Documented Incidents of Unauthorized Federal Access

The cleanest window into this system comes from municipal audits and public records requests rather than Flock’s own marketing. In Mountain View, California, the police department discovered in 2024–2025 that federal agencies and hundreds of other departments had been searching its camera data through Flock’s statewide and national lookup features. A statewide lookup setting had been active on 29 of the city’s 30 cameras for 17 months, during which more than 250 agencies that had never signed a data-sharing agreement with Mountain View ran an estimated 600,000 searches of its license plate data. On one camera, a national lookup feature had also been toggled on. Among the agencies accessing the data were the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), the U.S. Air Force, and the General Services Administration’s Office of Inspector General.

California law expressly prohibits public agencies from sharing ALPR data with federal or out-of-state entities, including agencies like ICE and CBP. Yet in Oxnard and Ventura County, internal audits revealed that Flock’s “nationwide query” had been silently active despite local settings being configured for “California only” access. Ventura County auditors found roughly 364,000 unauthorized queries over a two‑month span in 2025 after a national lookup feature that had been disabled in 2023 mysteriously re‑activated. Officials explicitly stated that “no one from our agency activated the national lookup feature,” pointing instead to vendor-side changes.

Similar patterns emerged in Washington state. The University of Washington’s Center for Human Rights obtained records from 31 agencies and documented that U.S. Border Patrol enjoyed apparent “back door” access to ALPR data from at least ten local departments that had not explicitly authorized such sharing. Some agencies had enabled direct sharing with Border Patrol without public debate; others appear to have been swept into broader network access through Flock’s shared infrastructure.

Illinois offers another strand in the same story. A 2025 state audit found that Customs and Border Protection (CBP) accessed Illinois license plate data through a Flock pilot program, in ways that violated state data protection rules. Flock responded by pausing all federal pilots and promising new “distinct search permissions”—an implicit acknowledgment that its prior controls were insufficient to prevent federal queries of local data.

Flock’s Public Position Versus Contract Reality

Flock’s public messaging stresses that federal access is disabled by default and that communities control sharing. The company’s own blog insists it does not “work with” ICE or hold formal contracts with Department of Homeland Security agencies, presenting this as proof that it does not assist immigration enforcement. In a communication to California agencies, Flock emphasized that customers can choose whether to share data, that sharing relationships are visible, and that they can be revoked at any time.

Those assurances coexist with contract provisions and network features that tell a different story. The ACLU’s analysis of Flock agreements found default language granting the company a “worldwide license” to use ALPR data and to disclose local data to law enforcement nationwide and federal agencies for “investigative purposes,” even when a department selected restrictive in‑app settings. An ACLU Massachusetts letter warned municipal leaders that Flock’s standard terms may give the vendor legal rights to share residents’ data beyond state borders, urging them to amend contracts that allow out‑of‑state or federal access.

When these structural realities collide with fragmented state laws, the result is predictable confusion. Some cities believed limiting sharing in the user interface was enough to comply with sanctuary statutes or ALPR privacy laws, only to discover via audits that their data had been flowing through national networks regardless. In Los Altos, a city whose policy explicitly prohibited sharing ALPR data with federal or out‑of‑state agencies, officials reported in a community message that Flock’s nationwide lookup setting had been turned on “without our knowledge or permission,” contradicting both local policy and state law.

A Pattern Across the ALPR Industry, Not a One-Off Glitch

What is happening with Flock fits a broader pattern in the automated license plate reader industry. For more than a decade, vendors such as Vigilant Solutions (now part of LexisNexis Risk Solutions) have built business models around aggregating plate data across jurisdictions and reselling or redistributing access. The Electronic Frontier Foundation’s analysis of ALPR records from 200 agencies showed more than 2.5 billion license plate scans in 2016–2017—99.5 percent belonging to vehicles not suspected of any crime—and highlighted how these massive datasets are routinely shared with local, state, federal, and even private entities.

State audits and civil liberties reports repeatedly surface the same themes: unclear contracts, long retention periods, automatic sharing to broad networks, and local agencies unaware of who can search their data. The Brennan Center for Justice has argued that, in light of Supreme Court decisions like Carpenter v. United States, historical location data collected by ALPRs should be treated as highly sensitive under the Fourth Amendment, casting doubt on outdated “third‑party doctrine” assumptions that once shielded such collection from constitutional scrutiny. Yet the technology continues to outpace law, with vendors offering turnkey national databases while legislatures struggle to define retention limits, sharing rules, and warrant requirements.

Legal and Policy Fallout: Cities Push Back, Lawyers Move In

As the scale of cross‑jurisdictional sharing has become clear, the legal and political response has sharpened. In California, Civil Code § 1798.90.55(b) and sanctuary laws like SB 54 bar public agencies from sharing ALPR data with federal or out-of-state law enforcement, particularly immigration authorities. Yet violations have now triggered audits, contract suspensions, and litigation. A class action complaint filed in April 2026 alleges that Flock used its cameras to track millions of Californians and illegally shared that data with federal and out-of-state agencies, in direct conflict with state privacy protections.

Municipalities have responded in different ways. Some, like Mountain View and Santa Cruz, terminated Flock contracts after discovering statewide or nationwide sharing that contravened their policies. Others, including Oxnard, suspended camera use pending investigation. NPR reporting and independent tallies indicate that more than 50 cities and counties have either canceled Flock contracts or allowed them to lapse, often citing immigration surveillance concerns and lack of transparent control over data flows.

Policy groups are also moving upstream. The ACLU’s “Roadmap for Regulation” for ALPR technology recommends strict limits on retention (often 30–90 days), categorical bans on sharing with private entities, and clear prohibitions or tightly constrained rules for cross‑border and federal access. Major Cities Chiefs Association guidance emphasizes mandatory audits, usage reports, and confidentiality of ALPR data, recognizing that once shared broadly, vehicle location records are effectively impossible to contain. New Jersey’s statewide directive on ALPR use mandates retention rules and purging procedures, signaling how states can begin to regain control from vendor-led architectures.

Why This Matters for Everyday Drivers

From a purely technical perspective, Flock’s system is impressive: solar‑powered cameras, AI‑assisted plate recognition, real‑time alerts tied to national crime databases. Law enforcement officials understandably appreciate a tool that can ping on stolen vehicles or missing persons. Yet for the average driver, the stakes are less about marginal improvements in auto theft clearance and more about what it means to have one’s movements automatically logged into a network that federal agencies can query without a warrant.

ALPR data is, by design, location history. Over 30 days—or longer, in jurisdictions that extend retention—it paints a detailed map of daily routines: home, workplace, school, religious institutions, medical facilities, political meetings. Legal scholars increasingly argue that such patterns are constitutionally significant, not mere “public observations” in the way traditional police surveillance has been framed. When that data flows from a city’s cameras into a nationwide database, and from there into federal pilot programs or quiet backdoor access by agencies like Border Patrol, the distinction between “local” policing and national surveillance collapses.

This collapse is especially consequential in states that have consciously chosen to limit cooperation with federal immigration enforcement. If a sanctuary city restricts information sharing but its ALPR vendor runs a system in which Border Patrol can search its license plate records through toggle‑driven national networks, the practical effect is to nullify policy choices made by local voters and lawmakers. That is why the controversy around Flock is not only a privacy story but a governance story: who actually controls the data, and whose rules prevail when software design, vendor contracts, and federal investigative priorities meet on the same cloud server.

What Comes Next: Rewriting the Rules of Data Sharing

The evidence now on the public record points to a clear conclusion: if communities want the investigative benefits of ALPR technology without inadvertently building a warrantless national tracking system, they cannot rely on vendor defaults and vague contract language. They have to write the rules themselves, explicitly and in detail. That means specifying retention periods in law, not merely in policy memos; enumerating exactly which agencies can access local data; requiring public disclosure of sharing agreements; and mandating independent audits of both local usage and vendor‑side configuration changes.

For cities that already have Flock cameras, the immediate task is straightforward, if politically fraught: review sharing settings; obtain and scrutinize audit logs; compare vendor contracts with state law; and, where violations have occurred, decide whether to renegotiate, impose tighter controls, or exit the system entirely. For those considering new deployments, the experience of Mountain View, Oxnard, Washington state, and Illinois offers a cautionary roadmap. The problem is not simply a bug that can be patched with better toggles. It is a network designed for maximum interoperability in a legal environment that has not yet decided how much interoperability is compatible with constitutional privacy and democratic control.

Sources:

thegatewaypundit.com, flocksafety.com, paloalto.gov, acluohio.org, placa.ai, reddit.com, losaltosca.gov, aclum.org, haveibeenflocked.com, techdirt.com, facebook.com, newsbreak.com, govtech.com, westfieldin.gov, austintexas.gov, aclu-ia.org, platesmart.com, assets.aclu.org, information.auditor.ca.gov, aclu.org, brennancenter.org