Boston Ends Flock Safety Partnership Over Unauthorized Data Sharing
Boston Mayor Michelle Wu didn't equivocate. "We have actually abandoned Flock," she told GBH News listeners during her monthly "Ask the Mayor" segment, confirming what would become one of the more striking vendor terminations in recent municipal surveillance history. The announcement landed days before Boston released its annual surveillance technology report, which documented how a "vendor error" caused Boston Police Department camera data to be shared with law enforcement agencies nationwide — well beyond what the city's contract permitted.
The partnership had been limited in scope: roughly 45 Automated License Plate Reader cameras deployed by the Boston Police Department in a pilot running from April through September 2025. The unauthorized sharing happened early, during the first few days of the pilot, before city officials realized the system was transmitting data outside city limits. The Boston Flock Safety license plate reader program is now a concrete example of what goes wrong when cities join large networked surveillance platforms without technical controls to match their contractual promises. Small pilot. National breach. Full termination.
What the Boston Surveillance Technology Report Revealed
Boston's annual surveillance technology report, covering 2025, ranks among the more transparent municipal surveillance disclosures in American local government. Most cities don't publish detailed accounts of law enforcement technology deployments. Boston does, and that practice produced an unusually clear record of what occurred with Flock.
Read next Top Technology Trends in 2026 You Need to KnowThe report was direct: a vendor error caused data from Boston's ALPR cameras to be shared with law enforcement agencies across the country. The scale of the deployment makes that fact more striking, not less. Forty-five cameras over five months is a constrained pilot, yet even that limited deployment generated data sensitive enough that its unauthorized national distribution warranted terminating the entire contract. That proportion — modest deployment, serious breach — illustrates how potent ALPR data is and how quickly a vendor's underlying architecture can override whatever a city has written into an agreement. The report itself is a best practice in municipal transparency; what it documented is a cautionary example of vendor governance failing in real time.
The Contract Breach: What Flock Safety Was and Was Not Allowed to Do
Flock Safety has signed contracts with hundreds of municipalities and law enforcement agencies across the United States, building what functions as a distributed national surveillance network even when individual cities believe they are running isolated local systems. Boston's contract contained a provision limiting data sharing. That provision was violated.
The company attributed the breach to a vendor error rather than deliberate policy — a distinction that carries legal weight but diminishes practically. Flock's platform is designed around interoperability. Agencies querying each other's data is a feature, not a flaw, from the vendor's commercial perspective. Cities that want to restrict sharing must trust not just the contract language but the vendor's implementation of technical controls enforcing that language. In Boston, those controls failed. The system's default behavior transmitted data nationally; the contract said otherwise; the default won.
This is the core governance problem with joining a platform built for network effects. The vendor's business incentives run toward broad sharing; the city's legal obligations run toward restriction. When those two forces meet at the technical layer, cities find out which one the platform was actually built to serve.
Broader Privacy Implications of License Plate Reader Networks
The Electronic Frontier Foundation and the American Civil Liberties Union have long categorized ALPR systems among the most privacy-invasive tools in routine law enforcement use, and the reason is structural. A camera doesn't distinguish between a suspect and a commuter. It records everyone. That indiscriminate collection means ALPR databases accumulate detailed movement histories on people who have never been investigated for anything.
The concern intensifies when data moves into shared networks. A single scan on a Boston street becomes something qualitatively different when it's accessible to agencies in other states — enabling the reconstruction of cross-jurisdictional travel patterns from records no individual jurisdiction intended to contribute to a national dataset. Civil liberties organizations have pressed specifically for strict retention limits and sharing prohibitions because of this networked character. Boston's experience validates the concern. Contractual restrictions were in place. The platform transmitted data nationally anyway. The restriction existed on paper; the architecture didn't honor it.
What This Means for Cities Considering Flock Safety Contracts
Other municipalities evaluating Flock Safety should treat Boston's case as a concrete reference point, not an abstraction. If a five-month pilot with 45 cameras produced an unauthorized nationwide data share, exposure scales with deployment size. A multi-year citywide rollout carries proportionally greater risk when vendor controls fail.
Boston's experience raises practical questions that any city should answer before signing. What does the vendor's default technical configuration actually do with data, separate from what the contract says? How does the city verify in real time that sharing stays within agreed limits — not through vendor assurances, but through independent auditing? And what remedies are genuinely enforceable, not merely listed in a contract, when a breach occurs?
Contract language alone is insufficient protection. Agreements need technical auditing rights, specific incident notification timelines, and defined penalties tied to measurable violations. Boston's termination is a remedy, but it doesn't retrieve the data that was already in agencies' hands. Some state legislatures have begun addressing ALPR governance through statute, but municipal contracts remain the primary instrument most cities have available. Boston's outcome demonstrates that those contracts must address the gap between what a vendor promises and what the vendor's platform does by default — and must enforce that gap technically, not just legally.
Boston's Path Forward on Surveillance Technology Oversight
Boston's annual surveillance technology report is itself a governance model worth emulating. Publishing candid disclosures about vendor failures — including a failure as significant as this one — reflects the kind of institutional transparency that makes public trust in law enforcement surveillance possible over time. Cities that handle vendor errors quietly tend to repeat them; cities that document them publicly create accountability structures that can actually change vendor behavior.
Mayor Wu's public confirmation during a routine civic media segment, rather than a formal press release, signals that the city treats accountability here as ordinary rather than politically costly. That posture matters. It also establishes a standard: surveillance technology contracts are public commitments, and when vendors breach them, residents are entitled to a clear account of what happened and what the city did about it.
Boston's next steps on ALPR remain open. The city may pursue alternative vendors with stronger technical safeguards, or conclude that no commercially available platform currently meets its data governance standards. Either path demands the same discipline: verifying, not simply contracting, that vendor behavior matches what the city has committed to residents.
The Flock episode is not a categorical argument against license plate reader technology. It is an argument for insisting that the technical architecture of any surveillance platform actually enforce the limits a city claims to have negotiated — because a contract provision that a system's default behavior overrides is not a limit at all.
Source: Ars Technica - All content


