Flock Safety, the embattled vendor of mass surveillance technology, has rolled out a handful of new reforms intended to appease the justified nationwide anger that has seen scores of towns cancel or suspend their contracts with the company for automated license plate readers (ALPRs). The reforms are a combination of long overdue changes along with some cosmetic fixes that fail to address the fundamental dangers of this technology.  

We should not be letting companies decide how much privacy we deserve.

So, what do these reforms actually do?  

The most consequential is Flock’s default setting of an optional 7-day retention period for ALPR data, down from its original default optional 30-day retention period. This means if police want to retain data beyond the duration of their retention setting, they need to access “Evidence Mode,” i.e., when the desired data is associated with an active investigation and not just a fishing expedition. This is significant because, in at least some circumstances, Flock has previously charged its customers to extend their retention period. So, while towns can likely easily flip the switch to longer retention periods, it might come with a price tag some cities will be unwilling to pay.  

Flock also has two other, likely easier-to-bypass reforms. The first is offense filtering so that cities can enable other departments to access their ALPR data only if they are investigating certain crimes, e.g., murder or robbery but not immigration-related investigations. The second is supposedly beefing up their audit feature and proactively locking out officers who file suspicious requests for data. The major problem here is the fact that Flock’s enhanced audit and transparency tools help to address a problem that Flock itself has created—an abusable mass surveillance system that tracks all cars all the time.  

In addition to these reforms, there is also a tone shift coming from Flock’s CEO, Garrett Langley. Langley went from calling the DeFlock movement “terrorists” (which he has since apologized for) and saying that the wave of anti-surveillance anger was more about the current federal administration than it was specifically about his company, to a more conciliatory tone that acknowledges some of the problems of dangerous surveillance, mission creep, and police abuse.  Just look at this report from the BBC 

“Historically, my point of view as a chief executive of a private company was, I don't know if I should be making these decisions. I don't know if it's my job to say how long data should be retained,” Langley said. 

He added that he has come to agree with groups like the American Civil Liberties Union and the Electronic Frontier Foundation that police should need an active case number to search Flock's data. 

“They're right. I think it should be required.” 

To be clear, our position has long been that police, at a minimum, need to get a warrant, signed by a judge, in order to search for historic ALPR data regarding specific vehicles. For us, it’s common sense: if police want to dip into historic ALPR data like they were going back in time to retroactively follow your comings and goings, they need a warrant.  

Fundamentally, these reforms leave us wondering: what is stopping Flock from reversing course on them if their law enforcement customers respond by defecting to another ALPR vendor? Nothing.  

This all leads to the bigger and more important issue: We should not be letting companies decide how much privacy we deserve. If our privacy is determined by how much surveillance technology vendors decide is too much surveillance, then we’re really out of luck. It shouldn’t be up Flock or any other ALPR vendor to decide how long police can collect and retain data on millions, if not hundreds of millions, of innocent people. We need lawmakers to step up and pass laws that restrict police’s use of surveillance technology. After all, the surveillance business model is the problem, and a few company-imposed slapdash reforms aren’t going to change that.

Related Issues