SIA Urges Tighter Oversight of Automated License Plate Readers

SIA is calling for stronger privacy safeguards, greater accountability and limits on misuse as scrutiny of ALPR technology intensifies.

Key Highlights

  • SIA is urging stronger safeguards governing government use of automated license plate readers.

  • The recommendations address privacy, data access, misuse, retention and accountability.

  • Flock Safety has also introduced new guardrails as scrutiny of ALPR technology grows.

The Security Industry Association (SIA) is calling for stronger safeguards governing automated license plate reader technology amid mounting scrutiny over how the systems are used, while urging policymakers to preserve what it describes as their significant public safety and commercial benefits.

The policy push comes as ALPR provider Flock Safety faces growing pushback over privacy, surveillance, data sharing and potential misuse of information collected by its camera network. According to an Aug. 28 report by Ars Technica, the digital rights group Secure Justice has recorded 214 cities and counties that have dropped Flock since 2021, including 93 jurisdictions in August alone. In response to the data, a Flock spokesperson told Ars that new city partnerships in 2026 have outpaced nonrenewals by approximately 10 to one.

The controversy has put broader questions about ALPR oversight in the spotlight, including who can access collected data, how it may be shared and what safeguards should govern law enforcement use.

Flock, meanwhile, announced in August that it is changing its recommended ALPR data retention period and default setting from 30 days to seven days, while allowing specific data to be preserved as evidence for active investigations. Existing customers will retain retention periods already established under their local policies.

The company is also requiring its Audit Assistance misuse-detection feature and case codes for law enforcement searches by the end of the year, while introducing automatic account lockouts for abnormal activity. Flock has also made multi-factor authentication mandatory and added controls allowing communities to restrict the types of offenses for which other agencies can search their cameras.

Against that backdrop, SIA CEO Don Erickson said the association believes ALPR and other security technologies should be limited to lawful, ethical and nondiscriminatory uses.

“ALPR is not — and must never become — a tool for mass surveillance or tracking law-abiding citizens,” Erickson said in a statement.

Erickson said SIA supports stronger accountability for government use, prohibitions against misuse and meaningful enforcement mechanisms while preserving ALPR’s legitimate public safety and commercial applications.

At the same time, the association cautioned against policy approaches that could undermine what it describes as the established public safety value of ALPR technology.

SIA said ALPR has been used over the past two decades in efforts ranging from responding to terrorist attacks and violent crimes to fighting human and drug trafficking, locating missing people and enforcing protective orders. The technology also has commercial applications including parking management, access control and retail services.

SIA proposes framework for ALPR safeguards

An ALPR camera captures an image of a passing vehicle’s license plate and converts it into alphanumeric characters that can be compared against a hotlist or other database. Applications extend beyond criminal investigations to include payments, traffic enforcement, tolling, school bus enforcement and premises security, according to SIA.

SIA is proposing safeguards in three broad areas: privacy protections, preventing intentional misuse and reducing operational or procedural failures.

Among its recommendations, SIA supports defined retention periods for ALPR data collected from public roadways, after which the information would be deleted unless needed as evidence in an investigation.

The association also recommends protecting ALPR data through encryption, access controls and cybersecurity practices. Data sharing between agencies should be authorized by policy and documented through system logs, while agencies accessing ALPR information collected by private entities or non-law enforcement organizations should be subject to the same requirements governing their own data.

SIA also said ALPR systems must not be used to target individuals or groups solely because of protected characteristics or their exercise of First Amendment rights.

Limits on access and use

To reduce misuse, SIA recommends limiting ALPR system access to authorized and trained personnel and requiring that law enforcement queries serve specific, documented public safety purposes.

Those purposes can include investigations based on reasonable suspicion, comparisons against authorized hotlists, locating people with outstanding warrants, recovering stolen vehicles and identifying vehicles associated with missing or endangered people.

ALPR can also be used for certain public welfare purposes, securing government facilities, controlling access to secured areas, traffic analysis and parking enforcement, according to the association.

Unauthorized use for personal, political, commercial or criminal purposes should be prohibited and subject to administrative or legal consequences, SIA said.

The association is also calling for greater transparency from law enforcement agencies. Agencies should publicly disclose when and why ALPR systems are deployed and make their policies governing use, data storage and retention available before deployment.

SIA emphasized that ALPR results should be treated as investigative leads rather than definitive evidence.

“ALPR outputs are investigative leads only, not conclusive evidence, and must not serve as the sole basis for action without human verification,” the association said.

SIA also recommends mandatory training, regular audits and supervisory reviews, along with validated system performance and procedures allowing agencies to discipline personnel who misuse the technology.

Technology providers, according to SIA, also have a role in preventing abuse by supplying systems with appropriate safeguards, access controls, audit capabilities and oversight tools.

Policies should distinguish between ALPR applications

SIA cautioned policymakers against imposing the same requirements across all ALPR applications.

The association said concerns surrounding the technology are primarily focused on law enforcement use and argued that policies should address the specific application creating concern. A roadway ALPR system used during a criminal investigation, for example, differs substantially from technology used to operate a commercial parking garage.

SIA also said policies should not interfere with the ability of individuals, families and businesses to use lawful security technologies, voluntarily share information for public safety purposes or deploy ALPR for legitimate commercial applications.

More than a dozen states and numerous local jurisdictions have adopted ALPR laws or policies since 2011, according to SIA. The association urged policymakers considering additional requirements to follow workable models that incorporate input from relevant stakeholders.

SIA said it is prepared to support what it characterized as responsible and balanced approaches to ALPR use in both the public and commercial sectors. The association is also seeking participation from the public, public safety organizations, academia and privacy advocates in developing additional guardrails for the technology.

“Given the bipartisan concerns expressed by policymakers at all levels, inaction is unacceptable,” SIA said.

About the Author

Rodney Bosch

Rodney Bosch

Editor-in-Chief/SecurityInfoWatch.com

Rodney Bosch is the Editor-in-Chief of SecurityInfoWatch.com. He has covered the security industry since 2006 for multiple major security publications. Reach him at [email protected].

Sign up for our eNewsletters
Get the latest news and updates