90,000 Flock AI‑Enabled License‑Plate Cameras Deployed Across U.S. Municipalities Without Public Consent
What Happened — Flock Safety’s “Falcon” cameras, equipped with AI‑driven license‑plate recognition, are operating in an estimated 90,000 locations nationwide. The devices capture still images of every passing vehicle and extract plate numbers, make, model, color, and other attributes, often installed by police, schools, businesses or homeowners’ associations with little or no public notice.
Why It Matters for Compliance & Audit Readiness
- The silent, city‑wide collection of personally identifiable information (PII) triggers privacy‑law obligations under GDPR, CCPA/CPRA, and emerging state statutes that require clear notice and opt‑out mechanisms.
- Continuous‑compliance programs must be able to demonstrate documented consent processes, data‑minimization controls, and audit‑ready records of who can access the captured footage.
- Verisq’s CookiePLUS privacy capability provides a centralized consent‑management layer and DSAR‑ready evidence collection that maps directly to SOC 2 CC6 (Privacy) and relevant privacy‑law attestations.
Who Is Affected — Municipal governments, law‑enforcement agencies, schools, homeowners’ associations, and any residents whose vehicles traverse public roadways in the United States.
Recommended Actions
- Inventory all third‑party video‑surveillance systems and verify whether a documented consent process exists.
- Map the data‑capture flow to SOC 2 CC6 controls (privacy notice, consent, data retention, access restriction).
- Deploy a consent‑management solution (e.g., CookiePLUS) to capture, store, and retrieve consent records and DSAR responses.
- Conduct a privacy impact assessment (PIA) and update policies to reflect AI‑driven surveillance risks.
Technical Notes — The cameras are battery‑ or solar‑powered, connect via cellular networks, and run Flock’s proprietary OS. Images are processed locally then sent to cloud services for AI analysis. No known vulnerability or breach has been reported, but the pervasive data collection without notice creates a de‑facto privacy exposure. Source: ZDNet Security