Police Policy Directs Officers to Conceal Flock License Plate Reader Use, Raising Privacy Risks
What Happened – A newly released usage policy for the Flock automated license‑plate‑reader (ALPR) system in Wapello County, Iowa, explicitly instructs police officers not to disclose the presence or use of the cameras to vehicle occupants or in official reports unless absolutely necessary. The directive mirrors historic practices around IMSI‑catchers, where law‑enforcement agencies deliberately hide surveillance tools.
Why It Matters for Compliance & Audit Readiness –
- The policy creates a privacy‑control gap that conflicts with SOC 2 CC6 (Confidentiality) and privacy‑related criteria, which require transparent data‑handling practices and documented consent where required.
- Hidden surveillance hampers the ability to produce defensible audit evidence of lawful data collection, a core requirement for continuous‑compliance programs.
- Verisq’s CookiePLUS privacy capability can map ALPR data‑flows to SOC 2 privacy controls, generate evidence of consent/notice, and automate reporting for auditors.
Who Is Affected – Law‑enforcement agencies that deploy ALPR technology, the Flock camera vendor, and any individuals whose vehicle data is captured without notice.
Recommended Actions –
- Conduct a privacy‑impact assessment of ALPR deployments and compare policy language against SOC 2 privacy criteria.
- Update usage guidelines to require transparent disclosure (e.g., signage, public notices) where legally required, and document the rationale for any exceptions.
- Capture policy revisions, training records, and data‑retention logs as continuous evidence for SOC 2 audits.
- Leverage a privacy‑management tool (e.g., CookiePLUS) to automate consent tracking and generate audit‑ready reports.
Source: Schneier on Security – Police Are Hiding Their Use of Flock Surveillance Cameras
Technical Notes – The issue stems from a policy misconfiguration rather than a technical flaw; no CVEs are involved. The data collected includes license‑plate numbers, timestamps, and geolocation, which are personally identifiable information (PII) under many privacy regimes (e.g., GDPR, CCPA).