Denver pulled all 110 of its Flock Safety cameras when its contract lapsed in March 2026. Local coverage, including this journal’s own reporting, called it a city “ripping out Flock’s cameras.” What actually happened: Denver signed with a different vendor and kept running an automated license plate reader network. The surveillance didn’t stop. The brand name did.
That’s worth a note of its own, because “Flock” has become shorthand for this entire technology the same way “Kleenex” means tissue — and shorthand is exactly the kind of thing that gets written into ordinances, contracts, and public debate in ways that don’t actually cover what they’re supposed to cover.
It’s not one company
Flock Safety is the largest and most controversial player, but it isn’t the only one running automated license plate readers (ALPRs) for American police departments. Motorola Solutions’ Vigilant Solutions, Genetec, Rekor, Neology, and half a dozen smaller vendors sell the same core capability — camera, plate-read, timestamp, searchable database — under different names, different data-retention defaults, and different rules about who else can query the system. A city council that votes to “ban Flock” or a resident who organizes to “get Flock out” of their town has, at best, addressed one vendor in a market with several. The cameras that keep the exact same record of who drove past, when, are legally a non-issue if they’re built by someone else and nobody wrote the rule to say otherwise.
Courts have done this to themselves before
This isn’t a hypothetical risk specific to license plates. American Fourth Amendment law has a long, well-documented habit of protecting people from the specific technology named in the case in front of the court — and leaving the next technology to fight the same battle from zero.
Kyllo v. United States (2001) held that police using a thermal-imaging device to detect heat patterns inside a home counted as a search — but the Court’s rule was explicitly limited to technology “not in general public use.” That test doesn’t ban a surveillance method; it expires the moment the device gets cheap and common enough to buy at a hardware store. The privacy protection was written to dissolve as the technology commercializes — which is close to the opposite of durable law.
United States v. Jones (2012) struck down a warrantless month-long GPS tracker on a suspect’s car — but the majority opinion grounded the ruling in physical trespass: officers had committed a search by physically attaching a device to the car. That left an open, and obvious, question: what about tracking a car’s location without ever touching it — through cell towers, or a network of cameras? The Jones opinion, by its own words, didn’t reach that question.
Carpenter v. United States (2018) finally answered a version of that question for historical cell-site records — but Chief Justice Roberts’s majority opinion went out of its way to say the ruling was narrow: “Our decision today is a narrow one.” The Court explicitly declined to say whether the same logic applied to security cameras, or real-time tracking, or other methods of surveillance. Every ALPR lawsuit filed since, including the Norfolk case this journal has followed, has had to argue from scratch that camera networks count too — because the Court that could have said so in plain terms chose not to.
Three landmark privacy wins, three opinions that protected people from one named technology and explicitly left the next one for a future court to sort out. The pattern isn’t an accident of bad drafting. It’s what happens when courts (and legislatures, and advocacy campaigns) write rules around what a piece of technology is called or how it physically works, instead of what it actually does to a person’s privacy.
Where the same trap is sitting right now
Some of the state laws this journal has covered are written well — California’s ALPR Privacy Act defines the technology functionally, covering any automated license plate reader system regardless of manufacturer, which is exactly why the pending class action can target Flock without needing a second lawsuit against whichever vendor Flock’s competitors sell to San Francisco next. That’s the right way to write this kind of rule.
Not every state, city, or advocacy effort has been as careful. A council resolution that names “Flock Safety” specifically, a public records request that only asks about “Flock cameras,” an organizing campaign whose materials only ever say “Flock” — each of those is doing, in miniature, exactly what Kyllo and Jones did at the Supreme Court: writing a rule around one name instead of one capability. Denver’s swap is the proof of concept. The city didn’t beat the surveillance network. It beat one vendor’s brand.
The plain version
“Flock” is a company. “ALPR” is the technology. Every time public debate, a records request, an ordinance, or a lawsuit collapses the second term into the first, it hands whoever’s selling the next camera network an easy way to keep doing the same thing under a name nobody wrote a rule against. Courts have made this exact mistake with thermal imagers, GPS trackers, and cell-site data — each time leaving the next technology to relitigate a fight that should have already been won. There’s no reason to make the same mistake with cameras on a pole.
Sources:
- Denver’s Flock cancellation and vendor switch: this journal’s coverage; contemporaneous local reporting
- ALPR vendor landscape (Flock, Motorola/Vigilant Solutions, Genetec, Rekor, Neology): industry market analyses, 2026
- Kyllo v. United States, 533 U.S. 27 (2001): Justia — full opinion
- United States v. Jones, 565 U.S. 400 (2012): Justia — full opinion
- Carpenter v. United States, 585 U.S. 296 (2018), including the “narrow” holding language: Justia — full opinion
- California ALPR Privacy Act and the Flock class action: this journal’s coverage