LAPD Halts Flock Safety ALPR Contract Over Data Ownership and Privacy Concerns
What Happened — The Los Angeles Police Department announced it will not renew its contract with automated license‑plate‑reader vendor Flock Safety after an Inspector General audit highlighted unclear data‑ownership terms and several false‑positive vehicle identifications.
Why It Matters for Compliance & Audit Readiness
- The situation exemplifies a vendor‑risk scenario that SOC 2‑compliant organizations must assess, document, and continuously monitor to prove due‑diligence.
- Without enforceable privacy and security clauses, a third‑party service can generate audit‑level findings that stall projects and expose agencies to regulatory scrutiny.
- Continuous evidence collection on vendor contracts, data‑handling policies, and audit outcomes is essential to maintain a defensible SOC 2 audit trail.
Who Is Affected — Public‑safety agencies, municipal governments, and any organization that outsources surveillance or data‑intensive services to third‑party vendors.
Recommended Actions
- Map the Flock Safety relationship to SOC 2 Vendor Management (CC6.1) and Privacy (CC6.2) controls; capture contracts, data‑ownership clauses, and audit findings as evidence.
- Implement a continuous‑monitoring process for third‑party risk, including periodic privacy‑impact assessments and automated alerts for contract deviations.
- Update your vendor‑risk policy to require enforceable data‑ownership language before onboarding any ALPR or similar data‑collection technology.
Technical Notes
- No technical vulnerability disclosed; the issue stems from governance, data‑ownership contracts, and privacy‑impact findings from an internal audit. Source: The Record