Boston discontinued its use of Flock Safety’s automated license plate reader system following revelations that the company mistakenly enabled access to data collected by Boston Police Department cameras for law enforcement agencies across the country, violating contract terms.

  • Boston ended Flock Safety pilot after data was shared nationwide by error.
  • Contract required disabling nationwide lookup; violation uncovered early in trial.
  • Boston launched new ALPR trials with Motorola and Axon after Flock exit.

What happened

Boston Police Department piloted about 45 Automated License Plate Reader (ALPR) cameras provided by Flock Safety from April to September 2025. The contract mandated that data collected remain accessible only to trained BPD personnel, with nationwide sharing explicitly disabled. However, within three days, BPD discovered that the nationwide lookup feature was mistakenly enabled by Flock, allowing other law enforcement agencies across the country to access Boston’s license plate and vehicle data.

Upon identifying this vendor error, BPD promptly ensured that the nationwide lookup function was disabled. Access to the data then required a formal written request, restoring control over the information. Despite this breach, Boston did not cease exploring ALPR technology, launching subsequent trials with Motorola in February 2026 and Axon in June 2026.

Why it matters

The incident underscores significant privacy concerns around ALPR systems and law enforcement’s access to vehicle data nationwide. An Electronic Frontier Foundation (EFF) report released recently highlighted rampant misuse of Flock’s nationwide database with officers logging frivolous or nonsensical reasons to conduct surveillance, which calls into question the sufficiency of current safeguards and policies.

Boston’s mayor, Michelle Wu, emphasized the need for publicly approved policies that protect privacy and civil liberties before deploying surveillance technologies. The city mandates that vendors commit to data non-sharing provisions and erase ALPR data after 30 days unless legally required to retain it, reinforcing the importance of strict access controls and transparency in maintaining public trust.

What to watch next

Boston’s ongoing ALPR trials with Motorola and Axon will be closely monitored for compliance with stringent data protection policies and adherence to clearly defined access controls. The city’s approach to balancing law enforcement utility with privacy safeguards may serve as a model or cautionary tale for other jurisdictions considering similar technology deployments.

Advocacy groups and privacy watchdogs will likely continue scrutinizing nationwide ALPR databases and their accessibility protocols, pressuring companies and governments to implement stronger verification and justification processes for data searches. How Boston and vendors respond to these calls could influence broader policy debates on surveillance technology regulation in the United States.

Source assisted: This briefing began from a discovered source item from Ars Technica Tech Policy. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings