Usually, members of the public cannot simply search a police department’s Flock Safety database. There is also no single nationwide rule giving citizens a right to obtain every Flock image or license-plate record through a public-records request. But documented misuse by law-enforcement officials raises a harder policy question: if a community chooses to maintain a taxpayer-funded database of people’s vehicle movements, why should police officers receive privileged access without facing at least the same baseline burden of justification imposed on everyone else?
The answer should not be to give every resident a login to a mass-surveillance system.
It should be to eliminate unaccountable access.
A defensible system would require anyone seeking Flock data to identify a legitimate purpose, define what information is actually needed and leave a permanent audit trail. Police could retain special authority for emergencies and lawful investigations, but that authority should come with more accountability—not less.
That distinction matters because the concern is no longer purely theoretical.
In August 2026, The Washington Post reported that it had identified at least 69 police officials accused, charged or convicted of misusing Flock or other automated license-plate-reader systems for unauthorized purposes. In at least 15 of those cases, the potential misconduct was first identified by someone outside the police department, including victims, activists or journalists.
That changes the surveillance debate.
The question is no longer simply whether we trust police to use these systems responsibly.
It is whether a surveillance system powerful enough to monitor the public should ever depend primarily on the people using it to police themselves.
What Does a Flock Camera Actually Record?
Flock’s automated license plate readers, commonly called ALPRs, are not simply traditional traffic cameras.
They photograph passing vehicles and can record information such as a license plate, vehicle characteristics, location and time. Flock says its search tools can also filter vehicles by characteristics such as body type, make and color. Its cameras capture multiple images as vehicles pass.
That distinction is important because people often refer to all of this as "Flock footage." For the common Falcon license-plate-reader system, vehicle images and associated metadata is generally the more accurate description than continuous surveillance video.
A single observation may not reveal much.
A network of cameras is different.
When observations from many locations become searchable, investigators can potentially determine where a particular vehicle has appeared and when. That is precisely what makes ALPR systems useful for finding stolen vehicles, locating missing people and developing investigative leads.
It is also what makes unauthorized searches so invasive.
Police Misuse of License-Plate Databases Is No Longer Hypothetical
The strongest case for tighter access controls does not require assuming that most police officers abuse Flock.
There is no evidence that they do.
The more important fact is that a relatively small number of people with privileged access can use the system in ways that would be extremely difficult for an ordinary citizen to replicate.
In Milwaukee, former police officer Josue Ayala pleaded guilty in June 2026 to misconduct-related charges after prosecutors said he searched Flock 179 times for license plates associated with a woman he had been dating and her former partner. The complaint said the searches occurred while Ayala was working for the police department.
In Haines City, Florida, investigators alleged that officer Christopher Goodson repeatedly searched his wife’s plate over nearly two years even though neither she nor her vehicle was involved in a criminal investigation during that period. According to an affidavit reviewed by The Washington Post, some searches were entered with purported investigative reasons involving drugs, assault, theft or a fugitive. He was charged in August 2026 with offenses related to misuse of official computer access and falsification of records.
Indianapolis provides an even more revealing example of the oversight problem.
The Washington Post examined publicly available search records and found that an Indianapolis officer appeared to have run 3,759 searches over ten months involving vehicles used by his wife and two close acquaintances. The department subsequently suspended the officer and opened investigations.
The remarkable part was not simply the number of searches.
Indianapolis officials told the newspaper that the department had not previously maintained a regular practice of auditing officers’ Flock searches.
Journalists using public information spotted a pattern that the agency possessing the surveillance system had not.
That is an accountability failure regardless of what anyone thinks about Flock itself.
San Francisco Shows the Problem Goes Beyond Individual "Bad Apples"
Not every failure involves an officer allegedly stalking a spouse or romantic partner.
In February 2026, San Francisco officials publicly discussed an internal case in which an SFPD member had searched Flock multiple times in connection with the officer’s spouse’s stolen vehicle. An image from the system subsequently appeared on a personal Instagram account. The department identified a conflict-of-interest policy failure.
Then another problem emerged.
In June, San Francisco police disclosed that an audit had found 299 improper inquiries of the city’s Flock network associated with federal or out-of-state agencies. SFPD said those inquiries represented roughly 0.005% of the searches during the period and said the review found no inquiries referencing immigration enforcement or reproductive-rights investigations. The department cut off the access path involved after discovering the problem.
The percentage was tiny.
That does not make the finding meaningless.
It illustrates why surveillance governance cannot be evaluated only by asking what percentage of searches were improper. If a database contains sensitive location information, one unauthorized search aimed at the wrong person can matter enormously to that person.
A low abuse rate is an argument about frequency.
It is not an argument against safeguards.
Flock Itself Is Now Tightening Access
Flock Safety’s own response makes the accountability issue harder to dismiss.
On August 13, 2026, the company announced a series of changes including:
- A recommended/default ALPR retention period of seven days instead of 30 days.
- Required case codes for law-enforcement searches by the end of 2026.
- An emergency bypass that is automatically flagged for administrator review.
- Mandatory adoption of Flock’s Audit Assistance system by law-enforcement customers by the end of 2026.
- Automatic lockouts when certain abnormal search behavior is detected.
- New controls allowing communities to restrict outside searches by offense category.
- An "Evidence Mode" for preserving specific data associated with active investigations.
Flock says customers retain ownership and control of their data. Existing agencies may also retain locally selected retention periods rather than automatically moving every deployment to seven days.
These changes are meaningful.
They also validate a central criticism.
If entering a case code, monitoring abnormal searches and reviewing emergency overrides are necessary safeguards today, then mere possession of police credentials was never a sufficient safeguard by itself.
Requiring a "Reason" Is Not Enough
There is an obvious weakness in any system where a user can obtain sensitive information simply by typing a justification into a box.
A dishonest requester can also lie.
That applies to civilians.
It applies to police officers.
And the documented cases demonstrate why the distinction matters.
If someone can enter "investigation," "narcotics" or another plausible-sounding explanation without that explanation being tied to a real event, case or independent review, the justification requirement can become little more than administrative theater.
The better standard is not:
Did the user enter a reason?
It is:
Was there a legitimate reason, was the request proportionate to that reason, and can someone independent of the requester verify it afterward?
That should be the baseline for everyone.
A Better Model: Equal Justification, Not Equal Surveillance Power
There are good reasons not to make an entire ALPR network freely searchable by the public.
A stalker should not be able to enter an ex-partner’s license plate and reconstruct that person’s movements.
An abusive spouse should not be able to search for a victim.
A criminal should not be able to determine where a witness has been traveling.
And a stranger should not be able to browse thousands of vehicle records out of curiosity.
But none of those arguments requires giving law enforcement effectively unrestricted browsing privileges.
There is a middle ground:
The Equal Justification Standard
If a publicly funded surveillance system is going to exist, every request to extract information from it should require a legitimate, documented purpose and generate an auditable record.
The authority granted after that justification does not have to be identical.
The obligation to justify the search should be.
What Public Access Could Actually Look Like
A civilian would not receive a Flock username and password.
Instead, a city or county could operate a controlled request portal.
The requester would provide:
- The purpose of the request.
- The event being investigated.
- A defined location or geographic area.
- A narrow date and time range.
- The vehicle or other relevant description, if known.
- Supporting documentation when appropriate.
- Contact information and a declaration that the request is being made for the stated purpose.
Imagine a hit-and-run victim.
Instead of being told that only the police may search the cameras, the victim could submit the location, approximate time, vehicle description and associated police report if one exists.
The system’s records custodian could perform the narrowly tailored search and release responsive information that can legally and safely be disclosed.
Or consider a missing pet.
If the particular camera system actually captured imagery relevant to where the animal disappeared, an owner could submit a narrow request identifying the location, time and animal. That would not entitle the owner to inspect every vehicle that traveled through the neighborhood. It would authorize a custodian to determine whether responsive material exists and whether releasing it would create a privacy or safety problem.
The governing principle is simple:
Request the evidence you need—not access to the surveillance network itself.
Police Should Have to Clear the Same First Gate
A police officer searching the system would begin with the same basic questions:
Why are you searching?
What event or investigation justifies it?
What data do you actually need?
For routine investigative searches, the officer should then provide a valid case or incident identifier.
The system should automatically preserve:
- The officer’s identity.
- Agency.
- Case or incident number.
- Search reason.
- Plate or vehicle characteristics searched.
- Geographic scope.
- Time range.
- Databases or outside networks queried.
- Results accessed or exported.
- Any subsequent sharing of those results.
The central difference is that police could have lawful investigative authorities unavailable to civilians.
But possessing a badge should not make the first gate—the requirement to articulate a legitimate purpose—disappear.
In fact, because law enforcement has greater investigative power than an ordinary citizen, the argument for auditing that access is stronger.
Emergencies Are a Real Exception—But Not an Accountability Loophole
A kidnapping in progress cannot wait for a public-records clerk.
Neither can an Amber Alert, an armed suspect fleeing a scene or an immediate threat to life.
Police therefore need an emergency pathway.
But emergency access can be both fast and accountable.
An officer could select an exigent-circumstances override and gain immediate access.
The system would automatically flag the search.
A supervisor or independent auditor would then have to confirm afterward that the emergency justification was legitimate.
Flock’s newly announced system already moves in this direction: the company says searches bypassing the case-code requirement because of exigent circumstances will be flagged for administrator review.
That principle should be expanded.
Emergency authority should mean access now and review afterward—not access now and accountability never.
The Public Should Also Be Able to See the Audit Trail
This may be the most important reform.
Search logs already exist.
Flock says its tools can provide information including administrators, users, search timeframes, filters, reasons and timestamps. Independent transparency project Have I Been Flocked has collected Flock audit logs released through state open-records laws and made portions searchable. Its documentation describes organization audit logs that can contain operator names, plates searched, case numbers, reasons and search details.
Those public records have become more than an academic transparency exercise.
They have helped reveal suspicious patterns.
That suggests a powerful rule:
No taxpayer-funded ALPR system should operate without public auditability.
That does not mean publishing the identity of crime victims or displaying active investigative targets in real time.
A public transparency system could redact information that would compromise an investigation, identify protected victims or create a genuine safety risk.
But communities should routinely receive information such as:
- Total searches performed.
- Number of unique users.
- Search purposes.
- Number of emergency overrides.
- Number of searches flagged by automated auditing.
- Number of users temporarily locked out.
- Number of policy violations identified.
- Number of requests from outside agencies.
- Which outside agencies received access.
- Number of civilian requests received, approved and denied.
- Reasons requests were denied.
- Retention settings.
- Data-sharing settings.
- Results of independent audits.
East Palo Alto, California already publishes monthly Flock audits. Its March 2026 audit, for example, reported how many searches officers conducted and stated that the department reviewed whether those searches were supported by valid case numbers or reasons.
The infrastructure for greater transparency therefore does not need to be invented from scratch.
The People Being Watched Should Not Be the Least-Informed People in the System
There is something structurally backwards about a surveillance arrangement in which:
- A government camera photographs the public.
- Public money pays for the system.
- Government personnel can search the resulting database.
- The subjects being recorded have little practical ability to determine who searched the system or why.
- Outsiders sometimes discover misuse only months later through public-records requests.
That arrangement concentrates information in exactly the place where independent scrutiny is weakest.
The August 19 Washington Post investigation is particularly important here because journalists were able to identify suspicious search patterns using publicly available information that several police departments had not been regularly reviewing themselves.
That is an argument for more public oversight, not less.
But Don’t Taxpayers Already Have Public-Records Laws?
Yes, but this is not the same thing.
State public-records laws can allow people to request government ALPR records, including audit logs in some jurisdictions. The exact rules, exemptions and disclosure obligations vary considerably by state.
Investigatory exemptions, privacy protections, victim protections and other restrictions may allow agencies to withhold or redact some records.
And that is appropriate in many circumstances.
The problem is that conventional public-records procedures were not designed as real-time governance systems for enormous searchable surveillance databases.
A person may wait weeks or months for records.
Agencies may produce heavily redacted logs.
Different jurisdictions may interpret disclosure obligations differently.
And the public frequently learns what was possible only after something has already gone wrong.
Public-records laws should remain available.
They should not be the only external accountability mechanism.
"But If Everyone Can Request It, Won’t Stalkers Abuse the System Too?"
They will try.
That is precisely why civilian access should be request-based rather than database-based.
A civilian requester should never be able to roam through historical vehicle movements.
The requester asks for specific evidence.
A controlled system evaluates the request.
Only material responsive to a legitimate request is considered for release.
Sensitive third-party information is redacted or withheld.
Repeated suspicious requests can be flagged.
Requests involving romantic partners, coworkers, neighbors or other potentially sensitive relationships can receive additional scrutiny when circumstances warrant it.
Knowingly submitting a false justification to obtain surveillance information should carry meaningful consequences.
That is not perfect.
No access-control system is.
But "a civilian might abuse access" is not a coherent argument for giving government employees broader, less scrutinized access.
The possibility of abuse is the reason both groups need controls.
Taxpayer Funding Matters, but It Is Not the Entire Argument
It is tempting to say: "We paid for the cameras, so the data belongs to us."
Legally, it is more complicated than that.
Some Flock deployments are privately funded by businesses, homeowners associations or other nongovernmental customers. And even when a city purchases the cameras with public money, taxpayer funding does not automatically make every image a record that must be released without restriction.
Privacy and investigative exemptions still matter.
But taxpayer funding creates a powerful democratic accountability argument.
Flock’s own terms say that, as between Flock and its customer, the customer retains ownership of customer data. For a municipal deployment, that customer is generally the public agency—not the individual officer searching it.
That distinction is critical.
A police department does not purchase surveillance technology for the private benefit of its employees.
It operates the system on behalf of the community.
The community therefore has a legitimate interest in deciding not merely whether the cameras exist, but who may search them, under what circumstances, and how those searches are reviewed.
The Choice Should Not Be "Trust Police" or "Ban Everything"
Some critics believe networked ALPR systems are inherently too invasive and should be removed entirely.
That is a legitimate policy position.
Others believe ALPRs provide enough public-safety value to justify continued use under strong safeguards.
That is also a legitimate policy position.
But communities that choose the second option should not pretend that simply limiting access to law enforcement solves the privacy problem.
Documented cases now demonstrate the opposite.
A trusted-user model can fail precisely because trusted users are people.
People have spouses.
Exes.
Grudges.
Curiosity.
Political beliefs.
Financial incentives.
Personal conflicts.
And occasionally criminal intent.
The proper response is not to assume every officer is corrupt.
It is to design the system so that an honest officer is protected by clear rules and a dishonest officer has a much harder time abusing access without being detected.
Flock’s New Safeguards Are a Start, Not a Complete Governance Model
Flock deserves credit for adding controls that can make abuse harder.
A shorter default retention period reduces the amount of historical information available for misuse.
Case codes make completely casual searches more difficult.
Automated auditing and lockouts can detect certain unusual patterns.
Emergency-search flags create an opportunity for retrospective review.
Those are substantive improvements.
But the ultimate accountability question remains.
Who audits the auditors?
If an automated system flags an officer’s behavior and the only people who ever see that warning are employees of the same department, the public is still being asked to trust an institution to detect, investigate and disclose misuse of its own surveillance system.
Sometimes that works.
The cases uncovered externally demonstrate that sometimes it does not.
A mature surveillance regime therefore needs both internal controls and external visibility.
What a Responsible Flock Policy Should Require
If a community decides to maintain publicly funded ALPR cameras, the minimum standard should look something like this:
No anonymous searches. Every search is permanently associated with an identifiable user.
No reasonless searches. Every request states a specific legitimate purpose.
No unlimited police browsing. Routine law-enforcement searches connect to an actual case or incident.
No unrestricted civilian browsing. Public users submit narrowly tailored requests that are searched by an authorized custodian.
No fake justification without consequences. Deliberately falsifying a purpose or case connection triggers discipline and, where applicable, criminal penalties.
No emergency loophole. Emergency access is immediate but automatically audited afterward.
No invisible sharing. Searches by outside agencies are logged and disclosed in aggregate—and, when legally possible, in greater detail.
No indefinite retention by default. Data expires quickly unless preservation is justified for a legitimate matter.
No purely internal accountability. Independent reviewers, elected oversight bodies, inspectors general or equivalent external authorities receive access to meaningful audit information.
No secret statistics. Communities receive recurring public reports describing how the system is actually being used.
No one-sided access system. A civilian with a legitimate need for evidence has a defined process to request it and appeal a denial.
That is not unrestricted surveillance.
It is controlled access to evidence collected in public using a system the public is being asked to accept.
The Bigger Principle: Surveillance Power Should Increase the Burden of Accountability
The usual surveillance argument works in one direction.
Police need special access because police have special responsibilities.
There is truth in that.
But it leaves out the other half.
Special power should create special accountability.
A police officer may have lawful authority to perform searches that an ordinary citizen cannot perform.
That does not justify giving the officer less scrutiny.
It justifies more.
The same principle applies to Flock.
The person asking for information should have to explain why.
The request should be proportional to the stated purpose.
The access should be recorded.
Abnormal behavior should trigger review.
And when the government operates the system, the public should be able to examine enough of the audit trail to determine whether those promises are actually being honored.
The Bottom Line
The documented misuse of Flock and other license-plate-reader systems does not prove that most police searches are abusive.
It proves something more useful:
Police access is not itself a safeguard against surveillance abuse.
In some documented cases, officers were the alleged abusers.
In others, departments did not identify suspicious behavior until victims, activists or journalists noticed it.
That means the old model—collect data on everyone, restrict meaningful access to government users and ask the public to trust internal controls—is no longer sufficient.
If a community believes Flock cameras are too dangerous to govern safely, removing them is a coherent answer.
But if the cameras are going to remain, there is another principle worth considering:
No one gets carte blanche.
A member of the public should be able to request legitimately needed evidence without receiving unrestricted surveillance powers.
A police officer should be able to perform legitimate investigations without receiving unrestricted surveillance powers.
Both should have to explain why the information is needed.
Both should leave an audit trail.
And the people whose money funds a government surveillance system should have enough visibility into that trail to know whether the rules are being followed.
The answer to surveillance abuse is not to democratize the abuse.
It is to democratize legitimate access while ending privileged, unaccountable access.
References and Further Reading
Primary and Official Sources
-
Flock Safety — Flock Updates Privacy, Accountability, Security, and Transparency Safeguards — Flock’s August 13, 2026 announcement detailing its seven-day retention recommendation, required case codes, Audit Assistance, proactive lockouts, emergency review and new data-sharing controls.
-
Flock Safety — Terms and Conditions — Current contractual language defining customer data ownership, permitted purposes and access to Flock services.
-
Flock Safety — Privacy Policy — Flock’s description of data handling, authorized law-enforcement access, search justification and audit trails. Some retention language predates the company’s August 2026 policy announcement and should be read alongside the newer safeguards.
-
San Francisco Police Department — Disciplinary Review Board Q3 2025 Presentation — Official SFPD material describing the policy failure involving a Flock search connected with an officer’s spouse’s stolen vehicle.
-
East Palo Alto Police Department — March 2026 Monthly Flock Audit — Example of a local government publicly releasing a recurring audit of officer Flock searches and network access.
Investigations and Documented Misuse
-
The Washington Post — Police Departments Weren’t Looking for Officers Abusing Flock. We Did It for Them. — August 2026 investigation identifying at least 69 police officials accused, charged or convicted of misusing Flock or other ALPR systems and examining failures of internal auditing.
-
The Washington Post — How Rogue Officers Turned a Nationwide Camera Network Into a Tool for Stalking — Detailed investigation drawing on police records, court documents and victim interviews to document misuse of ALPR systems, particularly involving intimate partners and acquaintances.
-
WISN — Former Milwaukee Police Officer Pleads Guilty to Misusing Flock Safety Camera System — Reporting on the Josue Ayala case and the 179 Flock searches involving a former romantic partner and another individual.
-
CBS News Bay Area — Audit Shows San Francisco Police Flock Data Accessed by Outside Agencies — Reporting on SFPD’s disclosure of 299 improper queries associated with federal and out-of-state agencies.
-
Institute for Justice — Police Have Reportedly Used License Plate Readers to Stalk Romantic Interests Dozens of Times — Running review of reported ALPR misuse cases. Useful as a case index; individual incidents should be checked against underlying court records or reporting when possible.
Transparency and Public Audit Records
-
Have I Been Flocked — About the Project — Explains the project’s use of government-released Flock audit logs and its transparency methodology.
-
Have I Been Flocked — How to Request and Understand Flock Audit Logs — Describes organization, network and public audit logs and the fields those records may contain.
Editorial currency note: Flock Safety policies, local ALPR contracts, data-retention periods, public-records rules and state surveillance laws are changing rapidly. The factual and policy information above is current as of August 22, 2026. Local rules should be checked before relying on this article for a specific records request or legal determination.



