When a US city decides to remove surveillance cameras, the decision may appear straightforward: terminate the contract, switch off the equipment and move on. But with automated license-plate readers, the more difficult question is what happens to the information already collected about drivers’ movements.
That issue is becoming central to the controversy surrounding Flock Safety, whose AI-powered cameras are used by thousands of law enforcement agencies and businesses across the United States. As local governments reconsider their contracts, privacy advocates are scrutinising the legal terms governing access to, retention of and continued use of surveillance data.
The debate is not simply about whether cameras remain on roads. It is about who controls the records they generate, what a technology provider can retain after a contract ends and whether residents can verify that data has been deleted.
Contract terms put data control under scrutiny
The American Civil Liberties Union raised concerns in April about changes to Flock’s standard contractual terms. It argued that the revisions appeared to reduce customers’ control over data and expand the company’s rights to use information generated through its services.
Among the issues identified by the ACLU was language granting Flock a perpetual licence to use customer data to support and improve its services. The organisation said this could allow the company to continue using certain surveillance data even after a municipality ends its relationship with the provider.
The distinction between ownership and control is important. A city may retain formal ownership of data while contractual provisions determine how it can access, export, delete or permit further use of that information.
Flock’s published terms, updated in August 2026, say confidential information will be deleted within 90 days of contract termination at the customer’s request, subject to exceptions for information that must be retained under applicable legal obligations or policies. Its evidence policy also says license-plate-reader data is permanently deleted after the applicable customer retention period expires.
Flock says customers control their data and that its systems support safeguards against unauthorised access. The precise position, however, depends on the applicable contract, retention settings and legal requirements. Contractual language about customer data and a vendor’s rights over its own platform or derived information must also be distinguished.
Cities are demanding clearer accountability
The issue is becoming more than a legal debate. In October, South Windsor, Connecticut, voted to terminate its Flock contract, deactivate its stationary license-plate readers and require the removal of previously collected data. The town’s decision followed public opposition over privacy and surveillance.
Other communities are reviewing contracts, considering alternative vendors or imposing stricter controls. These decisions create pressure on local governments to specify deletion requirements, restrict data-sharing arrangements and establish independent audits.
For residents, the questions are practical: How long are vehicle records retained? Which agencies can search them? Are searches logged and audited? Can data be shared across jurisdictions? What happens to information after a contract expires?
A camera network may help police identify vehicles linked to a crime, but that benefit does not remove the need for clear rules governing ordinary people whose journeys are captured incidentally.
The next test for municipalities will be whether they can turn general privacy assurances into enforceable contract provisions. That means defining deletion deadlines, auditing access, disclosing sharing arrangements and requiring evidence that the rules are followed.
Ending a surveillance contract can stop a service. Whether it also ends the associated data relationship depends on the terms and the oversight built around them.
