Drive through almost any American suburb now and there is a good chance a Flock Safety camera is reading your license plate before you reach the next stop sign. The cameras have spread to thousands of towns, homeowners associations and police departments, and the question residents keep asking is simple: is this legal? The honest answer is yes…for now, but that answer is doing more work than it looks like it is doing.
The License Plate Has No Privacy Interest

The legal foundation for automated license plate readers, or ALPRs, predates the technology by decades. Courts have long held that a driver has no reasonable expectation of privacy in a plate displayed on a public road. A police officer standing on a corner can write down every plate that passes, and the Constitution does not stop that officer. Flock cameras do the same thing, just continuously, at scale and forever.
That is the argument that has won in court so far. Privacy advocates say it misses what changed. One officer cannot watch every intersection at once or cross reference a decade of sightings in a second. A networked camera system can. The question is no longer whether one photograph of one plate violates privacy. It is whether stitching thousands of them into a searchable movement history does.
Norfolk’s Cameras Survive a Fourth Amendment Challenge
That question got its most significant test yet in Norfolk, Virginia, where two residents sued over the city’s network of 176 ALPR cameras with backing from the Institute for Justice. In late January 2026, a federal judge rejected the Fourth Amendment claim, finding that even hundreds of captures per vehicle, spaced forty to fifty minutes apart, were too sparse to reconstruct anyone’s daily routine.
What makes the ruling notable is the reasoning, not the outcome. The judge did not say ALPR surveillance can never violate the Constitution. He wrote that it could become too intrusive at some point, and that the answer in Norfolk today is simply not yet. That is a ruling tied to the current scale of one city’s deployment, not a categorical statement about the technology, and Norfolk’s own plans to expand past 230 cameras mean the underlying facts may not hold for long. The plaintiffs are appealing.
The State Legislatures Are Filling the Gap Congress Left
There is no federal ALPR statute. States are writing their own rules instead, and the resulting patchwork is where the practical legal exposure actually lives.
Washington offers the most detailed example. Its new law, effective March 2026, limits police use of ALPR data to specific purposes such as stolen vehicles, missing persons and felony warrants, bars use for immigration enforcement or tracking protected speech, prohibits cameras near hospitals, schools and houses of worship, and sets strict deletion timelines. A broader survey of these state by state restrictions shows Washington is not alone in moving on this.
Virginia, Maine and New Hampshire impose similarly short mandatory retention windows, part of a state by state legal landscape still filling in. California and Illinois restrict sharing ALPR data with federal agencies or for immigration and reproductive health investigations. Nevada has a pending bill adding further guardrails, and the ACLU is pushing other states to follow.
Most states have nothing on the books. Where no statute exists, the rules governing a camera network come down entirely to local police policy, so two towns twenty minutes apart can operate under meaningfully different rules with no state law choosing between them.
Sharing Data Is Where the Rules Break Down
Even strong statutes are running into practice that does not match the text. Audits in 2025 and 2026 found federal agencies, including Customs and Border Protection, accessing California and Illinois ALPR databases those states’ own laws were built to wall off. The access came through technical gaps and vendor configuration errors, not deliberate policy failure.
That gap between the statute and the software is the real story for any municipality, police department or homeowners association evaluating this technology. A locality can adopt a use policy that mirrors Washington’s model and still fall out of compliance if the underlying system lets a connected agency pull data the policy never authorized. The statute regulates intent. The vendor’s architecture regulates what is actually possible, and those are not the same document.
What This Means Going Forward
Flock cameras are not illegal, and no broad ban is on the horizon. What is coming is continued state by state variation, litigation testing where the Fourth Amendment line falls as camera density increases, and closer scrutiny of the data sharing agreements underneath these systems. A proposed class action against Flock Safety, filed in early 2026 over its data practices, adds another front to watch.
The camera itself is almost certainly lawful. The question worth asking is what happens to the photograph afterward: who can see it, how long it is kept, and whether the answer is written into an enforceable policy or left to a vendor’s default settings. That is where the real legal risk sits, and it is the part of this story that state legislatures, not courts, are currently writing.

You may also enjoy:
- New Jersey’s Comprehensive Privacy Law
- Safeguarding Privacy in the Age of AI
- Meta Will Pay Up to $17.1 Billion and Rebuild Instagram and Facebook for Teenagers
- NIL at Five: AI Is the Next Battleground for Athlete Likeness Rights
and, if you like what you’ve read, please subscribe below or in the right hand column.