Technology8 min read

Boston Drops Flock Safety Over Data Sharing Breach

Boston terminated its Flock Safety license plate reader contract after the vendor shared data nationwide in violation of its agreement, Mayor Michelle Wu confirmed.

Boston Drops Flock Safety Over Data Sharing Breach

Key takeaways

  1. 1Boston Terminates Flock Safety Contract Over Unauthorized Data Sharing Mayor Michelle Wu did not mince words.
  2. 2What the Contract Violation Actually Involved What the Contract Violation Actually Involved — Boston Police officer walking on the street during daytime The unauthorized sharing did not happen gradually over months.
  3. 3Boston's Annual Surveillance Technology Report Findings Boston's annual surveillance technology report deserves attention not just for what it revealed but for the fact that it exists at all.
  4. 4The 2025 report — which covers the Flock pilot and its aftermath — documents the data sharing incident, identifies the cause as a vendor error, and confirms that the city has since abandoned the contract.
Sections · 6

Boston Terminates Flock Safety Contract Over Unauthorized Data Sharing

Mayor Michelle Wu did not mince words. During her monthly call-in segment on GBH News, she told listeners plainly: "We have actually abandoned Flock." That single sentence, delivered in a routine civic broadcast, marked the end of Boston's relationship with Flock Safety — one of the country's most aggressive vendors of automated license plate reader technology — and opened a broader conversation about what cities actually sign when they contract with surveillance companies.

The Boston Flock Safety contract violation came to light ahead of the city's release of its annual surveillance technology report, a document that has become one of the more transparent public accounting mechanisms any American municipality has adopted for tracking how police use data-collection tools. That report, covering 2025, confirmed what city officials had already concluded internally: a "vendor error" caused Boston's ALPR data to be shared on a nationwide basis, reaching well beyond the geographic and jurisdictional limits the contract explicitly required.

The episode is not merely a vendor dispute. It is a case study in what happens when municipalities deploy surveillance infrastructure without the enforcement mechanisms to hold vendors accountable when something goes wrong — and an early indicator that cities across the country may be carrying far greater data exposure than their contracts suggest.

How Boston's ALPR Pilot Program Worked

How Boston's ALPR Pilot Program Worked — Boston Police officer walking on the street during daytime
How Boston's ALPR Pilot Program Worked — Boston Police officer walking on the street during daytime

In April 2025, the Boston Police Department began a limited trial deployment of roughly 45 Flock Safety ALPR cameras. The pilot ran through September of that year — a six-month window designed to evaluate whether the technology offered meaningful public safety benefits under conditions the city could control and review.

Read next Top Technology Trends in 2026 You Need to Know

Flock Safety has built its business model on exactly this kind of municipal partnership. The company operates networks of fixed cameras that capture the license plates of passing vehicles, log timestamps and locations, and make that data queryable by law enforcement. Across the United States, hundreds of police departments and city governments have entered similar arrangements. The Electronic Frontier Foundation has documented Flock's footprint across thousands of locations in dozens of states, and the company has marketed itself aggressively to suburban municipalities that lack the resources to build their own camera infrastructure. By some estimates, Flock Safety's cameras now monitor vehicle traffic in communities representing tens of millions of Americans.

Boston's pilot was structured as a contained experiment, with camera deployment concentrated in specific areas and a defined end date. The expectation — reflected in the contract — was that data collected would remain within appropriate jurisdictional boundaries. That assumption collapsed almost immediately.

What the Contract Violation Actually Involved

What the Contract Violation Actually Involved — Boston Police officer walking on the street during daytime
What the Contract Violation Actually Involved — Boston Police officer walking on the street during daytime

The unauthorized sharing did not happen gradually over months. According to the surveillance technology report, the breach occurred during the first few days of the pilot's operation. A Flock vendor error caused Boston's ALPR data to be pushed into a nationwide data-sharing network — meaning plate captures from Boston streets became accessible to law enforcement agencies far outside the city, in jurisdictions with no legal relationship to Boston, no knowledge of the pilot, and no accountability to Boston residents.

Contract language restricting data sharing is standard in responsible ALPR agreements. Cities and civil liberties advocates have pressed for such provisions precisely because networked plate reader systems are not merely local surveillance tools — they are nodes in an interconnected national infrastructure. When a vehicle's plate is captured in Boston and shared with a department in Arizona, residents have no way of knowing, no mechanism for legal redress, and no transparency about how that information is being used or retained.

The Boston Flock Safety contract violation illustrates what privacy scholars and municipal law experts have long warned about: vendor agreements may include the right language while still failing to include the right enforcement architecture. A restriction on data sharing means little if the vendor's technical systems default to open sharing, and if cities lack the monitoring capacity to catch violations in real time. By the time Boston identified the problem, the data had already moved.

Boston's Annual Surveillance Technology Report Findings

Boston's annual surveillance technology report deserves attention not just for what it revealed but for the fact that it exists at all. The city operates under a local surveillance ordinance that requires police to disclose what technologies they use, submit those technologies for public review, and publish annual reports on how they are deployed. Very few American cities have enacted comparable frameworks.

The 2025 report — which covers the Flock pilot and its aftermath — documents the data sharing incident, identifies the cause as a vendor error, and confirms that the city has since abandoned the contract. It is the kind of institutional transparency that makes accountability possible. Without such a reporting requirement, the breach might never have surfaced publicly. Municipal contracts with surveillance vendors are frequently shielded from disclosure as proprietary business information, and police departments do not typically volunteer information about data incidents that reflect poorly on ongoing technology partnerships.

The report's candor should serve as a model for other cities. Surveillance technology oversight does not require adversarial posturing toward law enforcement — it requires the same basic accountability mechanisms that govern any significant public procurement. When vendors make errors that expose resident data, the public has a right to know.

Broader Privacy Implications of License Plate Reader Networks

Plate reader technology feels less invasive than facial recognition or cell-site simulators, and that comparative framing has helped Flock and similar vendors avoid the regulatory scrutiny their networks arguably warrant. But the privacy stakes are significant. A single ALPR capture records where a vehicle was, at what time, and in which direction it was traveling. Across weeks or months, that data constructs a detailed map of a person's movements — their medical appointments, their political associations, their personal relationships.

The ACLU has documented cases where ALPR data retained for extended periods was later accessed in investigations that had nothing to do with the original purpose of data collection. Retention policies vary wildly across jurisdictions, and when data flows across a nationwide sharing network, the retention practices of the receiving agency — not the originating city — govern how long records are kept.

Even the brief, unintended sharing during Boston's pilot carries long-term implications. Data that moves once can be retained, indexed, and queried long after the technical error that created it is corrected. There is no equivalent of a data recall. Cities that fail to audit what their ALPR vendors are doing in the first days of a deployment may be accepting privacy liabilities they cannot later reverse.

Flock Safety's network architecture, which enables plate data to be shared across subscribing agencies, is by design a force multiplier for local surveillance programs. That capability has genuine law enforcement applications. It also means that a configuration error — or a deliberate vendor policy choice — can transform a local pilot into a node in a national surveillance grid without any additional action by the city that contracted for a local service.

What Cities Should Demand From Surveillance Technology Vendors

Boston's experience points toward a set of concrete requirements that municipalities should build into any ALPR contract before a single camera goes live.

First, technical controls must match contractual language. A contract that prohibits nationwide data sharing is not meaningful unless the vendor's systems are configured — and verifiably configured — to prevent it by default. Cities should require written technical attestations, not just contractual promises.

Second, cities need real-time audit logging. If Boston had access to continuous data-flow logs from Flock's system, the unauthorized sharing might have been detected within hours rather than days. Audit access is a standard demand in enterprise software contracts; it should be standard in surveillance technology agreements as well.

Third, breach notification provisions should carry teeth. When a vendor error exposes resident data, the vendor should be contractually obligated to notify the city immediately, document the scope of the breach, and fund any necessary notifications to affected individuals. Those obligations should be enforceable through financial penalties, not just contract termination.

Fourth, and perhaps most importantly, cities should maintain the institutional capacity to walk away — as Boston ultimately did. Wu's decision to abandon the pilot entirely, rather than renegotiate with a vendor that had already demonstrated it could not protect the city's data, reflects the kind of accountability posture that residents deserve. Surveillance technology contracts should include clear termination rights tied to data incidents, so that vendors understand that errors carry real commercial consequences.

The Boston Flock Safety contract violation is, in one sense, a story about a single vendor error in a six-month pilot program. In a larger sense, it is a stress test of the accountability mechanisms cities rely on when private companies operate surveillance infrastructure on their behalf. The test revealed both a failure — the unauthorized sharing — and a model for response: transparency, clear documentation, and the willingness to terminate a relationship that could not be trusted. Other cities would do well to study both lessons.


Source: Ars Technica - All content

Published

17 September 2026

Author

Editorial

Comments

No comments yet. Be the first.

Leave a comment