Before any community adopts ALPR, there are a few basic questions worth asking:
- Who owns the data?
- Who can search it?
- Who can it be shared with?
- How long is it kept?
These shouldn’t be difficult questions to answer.
Good technology needs good guardrails.
A shorter retention period can reduce privacy risk, but it does not answer every question.
Even briefly retained data may be searched, shared or misused.
Responsible ALPR must address how long information is kept and what can happen to it while it exists.
“We have it on video” no longer ends the conversation.
Images and video may support investigations, insurance claims, litigation, journalism, and public accountability. In an era of increasingly sophisticated digital manipulation, those records must also be trustworthy.
Responsible vehicle-recognition systems should help establish:
• Whether media was authentic when captured
• Whether it was altered, shortened, or spliced
• Whether the evidence presented is the same evidence originally recorded
Protecting privacy during collection is essential. Proving the integrity of evidence when it matters is part of the same responsibility.
Communities should not discover how an ALPR system operates only after something goes wrong.
The rules governing access, retention, data sharing and oversight should be clear before deployment and the technology should be able to enforce them.
A shorter retention period can reduce privacy risk, but it does not answer every question.
Even briefly retained data may be searched, shared or misused.
Responsible ALPR must address how long information is kept and what can happen to it while it exists.
Why should every ALPR record be kept for the same amount of time?
Data connected to an Amber Alert or active investigation serves a clear purpose. An ordinary non-hit plate read does not carry the same relevance.
Retention policies should recognize the difference.
Auditing can reveal that ALPR data was misused. Strong access controls can help prevent that misuse from happening.
Responsible systems need both:
• Preventive safeguards
• Detailed audit records
• Meaningful consequences when policies are violated
Privacy protections should apply regardless of which ALPR vendor a community chooses.
In Police1, Rekor EVP Charlie Degliomini calls for a nationwide standard -including a warrant or court order to re-identify protected non-hotlist plate data.
Full interview: https://t.co/D9bJaG7h9h
Why should every ALPR record be kept for the same amount of time?
Data connected to an Amber Alert or active investigation serves a clear purpose. An ordinary non-hit plate read does not carry the same relevance.
Retention policies should recognize the difference.
The question is not only whether an ALPR camera captures a plate.
The questions are:
What happens to that information next?
Is it immediately identifiable?
How can it be searched?
Who can access it?
When is it deleted?
That is where privacy protections matter.
A stolen vehicle and an ordinary commuter should not create the same type of record.
One is connected to a legitimate public-safety need. The other is simply driving through the community.
Responsible ALPR should treat them differently.
Privacy should not depend entirely on every individual using an ALPR system correctly.
Responsible ALPR builds protections into the architecture itself - so limits on collection, access and retention are supported by the technology, not just written into policy.
“We have it on video” is no longer enough.
Responsible ALPR must address evidence integrity too: Was the media authentic when captured? Was it altered later? Can the original be verified?
Privacy protects people. Authentication protects the truth.
A written policy is only as strong as its enforcement.
Every ALPR search should create a reviewable record showing who accessed the data, when, and for what stated purpose. Accountability must be measurable not assumed
ALPR data should not be an open database for agencies to search at will. Access across agencies should require specific authorization, and every search should have a documented, lawful investigative purpose. Responsible ALPR means enforcing those limits before access is granted.
🚨 Breaking: Lexington’s Flock cameras were searched 7 MILLION times in just seven months — and Lexington Police accounted for only about 1% of those searches.
A review of the audit logs from January through July found that just 63,000 searches came from Lexington Police.
So who was doing the other 96% of the searching?
According to WKYT Investigates, those searches came from out-of-state and federal agencies.
Most vehicles passing an ALPR camera are not connected to a crime, alert, or investigation.
Responsible ALPR should recognize that difference. Authorized hits can remain actionable while ordinary, non-hit vehicle data is protected by default.
Responsible ALPR should:
• Protect non-hit data
• Retain information based on purpose
• Record who accesses it and why
• Give communities meaningful control
• Verify the integrity of evidence
The safeguards should be built into the technology from the beginning.
Well, 47 came out in favor of Flock cameras. That'll go over like a turd in a punch bowl😂 He's right though. They do solve a lot of crimes & if used as intended are a great tool for Law Enforcement.🚔
@Mrgunsngear This was an unacceptable abuse of ALPR data. The officer was fired, but no criminal charges were filed - exposing a serious gap in accountability. Responsible ALPR requires safeguards that prevent improper access, audits that detect it and laws that carry real consequences.
Every vehicle captured by an ALPR camera belongs to a person going somewhere.
Most are not suspected of a crime. Their information should be treated accordingly - with data minimization, privacy protections and limits on how it can be searched