A recent investigation has revealed significant gaps in Flock's updated policies for police surveillance, raising questions about whether the company's new rules offer meaningful privacy protections. The report, titled “Flock Has New Rules for Police Surveillance, but We Found Plenty of Loopholes,” highlights how the automated license plate reader provider continues to enable expansive tracking despite promising reforms.

What You Need to Know

Flock Safety’s facial recognition and vehicle location tools have faced growing scrutiny from civil liberties groups. The company rolled out new conduct rules this year, but independent analysts discovered exceptions and vague language that could let police departments bypass restrictions. Privacy advocates argue these loopholes effectively preserve surveillance capabilities that the new policies were supposed to limit.

The Policy Changes and Their Limits

Earlier this year, Flock announced updated terms of service restricting how law enforcement agencies can access and retain data from its networked cameras. The stated goal was to curb abuses such as warrantless real-time tracking and prolonged storage of innocent drivers’ information. However, the fine print created carve-outs for “emergency requests” and partnerships with federal agencies, allowing data sharing outside the intended guardrails.

Flock’s new rules require individual departments to certify compliance, but the verification process relies on self-reporting rather than independent audits. Critics note this creates a system where violations may go undetected unless whistleblowers come forward.

  • Emergency exemptions: Police can bypass retention limits during ongoing investigations, a broad category that lacks clear definition.
  • Third-party access: Data can still flow to fusion centers and other shared databases without individual consent.
  • No transparency mandate: Departments are not required to publish how often they invoke emergency provisions.

How Loopholes Emerged

Investigators who analyzed the policy documents found multiple instances where permissive language undercut stricter clauses. The term “reasonable suspicion” was used instead of “probable cause,” a lower legal threshold that allows broader surveillance. In addition, Flock’s product design gives police the ability to search historical location patterns without clicking through any prohibition screens.

These findings contradict Flock’s public statements that it had “closed the door” on certain surveillance practices. The company responded by saying it would review the report and consider further revisions, but did not commit to closing the identified gaps.

Why This Matters

The revelations directly affect millions of drivers whose vehicles pass through Flock’s network daily. Without enforceable restrictions, police departments can continue building vast movement databases indirectly through shared systems and emergency declarations. This undermines the very principle of limited government surveillance that the new rules were meant to establish.

For civil liberties organizations, the loopholes represent a familiar pattern: tech companies announce voluntary reforms but fail to impose real accountability. If left unaddressed, these gaps could encourage other surveillance vendors to adopt similar superficial policies, normalising weaker protections across the industry.

Looking Ahead

Some state legislatures have begun considering laws that mandate independent oversight of automated license plate readers regardless of company policies. California and Washington recently introduced bills requiring annual audits and public reporting. Whether those efforts gain traction could determine if Flock’s loopholes become moot or set a precedent for future surveillance frameworks.