HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Police Policy Directs Officers to Conceal Flock License Plate Reader Use, Raising Privacy Risks

Wapello County, Iowa, issued a policy telling police not to mention the use of Flock ALPR cameras to vehicle occupants or in reports. The secrecy undermines privacy compliance and makes it difficult to produce audit‑ready evidence of lawful data collection.

LiveThreat™ Intelligence · 📅 August 21, 2026· 📰 schneier.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
schneier.com

Police Policy Directs Officers to Conceal Flock License Plate Reader Use, Raising Privacy Risks

What Happened – A newly released usage policy for the Flock automated license‑plate‑reader (ALPR) system in Wapello County, Iowa, explicitly instructs police officers not to disclose the presence or use of the cameras to vehicle occupants or in official reports unless absolutely necessary. The directive mirrors historic practices around IMSI‑catchers, where law‑enforcement agencies deliberately hide surveillance tools.

Why It Matters for Compliance & Audit Readiness

  • The policy creates a privacy‑control gap that conflicts with SOC 2 CC6 (Confidentiality) and privacy‑related criteria, which require transparent data‑handling practices and documented consent where required.
  • Hidden surveillance hampers the ability to produce defensible audit evidence of lawful data collection, a core requirement for continuous‑compliance programs.
  • Verisq’s CookiePLUS privacy capability can map ALPR data‑flows to SOC 2 privacy controls, generate evidence of consent/notice, and automate reporting for auditors.

Who Is Affected – Law‑enforcement agencies that deploy ALPR technology, the Flock camera vendor, and any individuals whose vehicle data is captured without notice.

Recommended Actions

  • Conduct a privacy‑impact assessment of ALPR deployments and compare policy language against SOC 2 privacy criteria.
  • Update usage guidelines to require transparent disclosure (e.g., signage, public notices) where legally required, and document the rationale for any exceptions.
  • Capture policy revisions, training records, and data‑retention logs as continuous evidence for SOC 2 audits.
  • Leverage a privacy‑management tool (e.g., CookiePLUS) to automate consent tracking and generate audit‑ready reports.

Source: Schneier on Security – Police Are Hiding Their Use of Flock Surveillance Cameras

Technical Notes – The issue stems from a policy misconfiguration rather than a technical flaw; no CVEs are involved. The data collected includes license‑plate numbers, timestamps, and geolocation, which are personally identifiable information (PII) under many privacy regimes (e.g., GDPR, CCPA).

📰 Original Source
https://www.schneier.com/blog/archives/2026/08/police-are-hiding-their-use-of-flock-surveillance-cameras.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →