Jim de Bree | Ensuring that Flock Camera Controls Work

Jim de Bree
Jim de Bree
Share
Tweet
Email

On Aug. 25, I spoke before the Santa Clarita City Council about serious traffic concerns faced by residents of the Valencia Summit neighborhood. I was followed by eight speakers, mostly students, associated with the DeFlock SCV group who spoke about the threat to personal liberties resulting from the use of Flock cameras. 

At the time, I had no idea that the two subjects were interrelated. 

A few days later, in an attempt to remediate traffic problems in the Summit neighborhood, devices were installed to analyze neighborhood traffic patterns. Those devices appear to be Flock Safety automated license plate reader (ALPR) cameras. 

This precipitated a local debate about the ethics of using ALPR cameras. 

Concerns about ALPR cameras are justified because there are documented cases of data misuse by police and other governmental agencies with which police have shared such data. 

Furthermore, ALPR data is parsed by artificial intelligence, which sometimes results in algorithmic errors identifying the wrong person. 

In response, numerous safeguards were implemented. Although I believe that, when the city of Santa Clarita entered into its Flock contract, the city genuinely believed that there are adequate protocols in place to prevent such abuses, loopholes may exist. 

To understand our local situation, one must read the contract with Flock that was approved by the City Council on Nov. 12, 2024, related information on Flock’s website and the pertinent sections of the California Civil Code. 

After doing so, I noticed that elaborate controls to limit abuses apparently exist, but I wondered about the following potential gaps in those controls. 

Data collected ostensibly does not include live video or facial recognition: 

Article 4.3 of the city’s contract with Flock states, “…Flock shall have the right to collect, analyze, and anonymize customer data.” 

Furthermore, Article 1.2 states, “1.2 ‘anonymized data’ means customer data permanently stripped of identifying details and any potential personally identifiable information, by commercially available standards which irreversibly alters data in such a way that a data subject (i.e., individual person or entity) can no longer be identified directly or indirectly.” 

This implies that the raw data collected by ALPRs includes personally identifiable information, which is subsequently anonymized by Flock. If so, how long does the data remain accessible in its pre-anonymization state? 

Data may be retained for substantially longer than 30 days:

Article 1.14 states, “‘Retention period’ means the time period that the customer data is stored within the cloud storage, as specified in the applicable order form. Flock deletes all footage on a rolling thirty (30) day basis, except as otherwise stated on the order form. Customer (i.e., the city of Santa Clarita) shall be responsible for extracting, downloading and archiving footage from the Flock Services on its own storage devices.” 

Article 1.3 acknowledges that the city of Santa Clarita “does not intend to access services beyond setting up and granting access to authorized end users from the Los Angeles County Sheriff’s Department, which shall access and use the services in accordance with the Los Angeles County Sheriff’s Department’s ALPR policies pursuant to California Civil Code Section 1798.90.5 et. seq.” 

A Signal article published on Sept. 7 stated: “LASD officials said in a Friday email that they store data for up to two years, with searches able to reach back five years in certain situations.” 

If this is true, then although the data is promptly purged from Flock’s servers, presumably the data accessed and retained by LASD is not purged after 30 days.  

On Aug. 13, Flock announced enhancements to its privacy, security and accountability tools including a new recommended and default seven-day ALPR data retention period for law enforcement agencies. Reducing the retention period decreases the opportunities for ALPR data to be misused. 

So how long is Santa Clarita ALPR data actually maintained? 

Data sharing with other agencies: 

In 2015, California enacted Senate Bill 34, which prohibits law enforcement agencies from sharing ALPR data with out-of-state or federal agencies.  

The Sept. 7 Signal article quoted Deputy Daniel Dominguez of LASD’s Information Bureau as saying, “We have been extra vigilant and have ensured that no data sharing has occurred outside California or with any federal law enforcement agencies … We do not blanket-share with any law enforcement agency. Data is only shared with agencies that have a signed memorandum of understanding (MOU) and have agreed to comply with our policies and strict requirements.” 

Does LASD audit whether those agencies actually comply with its policies and requirements? 

I suspect that AI-generated surveillance, including use of ALPR cameras, will eventually become ubiquitous. Therefore, we must ensure that there are no deficiencies in the controls that constrain surveillance abuses. 

Jim de Bree is a Valencia resident.

Related To This Story

Latest NEWS