HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

LAPD Halts Flock Safety ALPR Contract Over Data Ownership and Privacy Concerns

The Los Angeles Police Department stopped renewing its contract with ALPR vendor Flock Safety after an Inspector General audit flagged unclear data‑ownership terms and false vehicle identifications. The incident underscores the need for robust vendor‑risk management and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
therecord.media

LAPD Halts Flock Safety ALPR Contract Over Data Ownership and Privacy Concerns

What Happened — The Los Angeles Police Department announced it will not renew its contract with automated license‑plate‑reader vendor Flock Safety after an Inspector General audit highlighted unclear data‑ownership terms and several false‑positive vehicle identifications.

Why It Matters for Compliance & Audit Readiness

  • The situation exemplifies a vendor‑risk scenario that SOC 2‑compliant organizations must assess, document, and continuously monitor to prove due‑diligence.
  • Without enforceable privacy and security clauses, a third‑party service can generate audit‑level findings that stall projects and expose agencies to regulatory scrutiny.
  • Continuous evidence collection on vendor contracts, data‑handling policies, and audit outcomes is essential to maintain a defensible SOC 2 audit trail.

Who Is Affected — Public‑safety agencies, municipal governments, and any organization that outsources surveillance or data‑intensive services to third‑party vendors.

Recommended Actions

  • Map the Flock Safety relationship to SOC 2 Vendor Management (CC6.1) and Privacy (CC6.2) controls; capture contracts, data‑ownership clauses, and audit findings as evidence.
  • Implement a continuous‑monitoring process for third‑party risk, including periodic privacy‑impact assessments and automated alerts for contract deviations.
  • Update your vendor‑risk policy to require enforceable data‑ownership language before onboarding any ALPR or similar data‑collection technology.

Technical Notes

  • No technical vulnerability disclosed; the issue stems from governance, data‑ownership contracts, and privacy‑impact findings from an internal audit. Source: The Record
📰 Original Source
https://therecord.media/lapd-halts-flock-safety-alpr-contract

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →