There is probably a camera on a pole near your house that photographs the back of your car every time you drive past it, records the time and the direction you were heading, and files it in a database that a police officer three states away may be able to search.
It is legal. Mostly. The word doing the work in that sentence is “mostly,” and the Massachusetts Supreme Judicial Court left a door open in 2020 that nobody has yet walked through.
Here is what these cameras actually are, what they keep, who can look at it, and how you find out whether someone has looked you up.
What a Flock camera is
An automatic license plate reader is a camera bolted to a pole with software behind it. Flock Safety is the company that has sold the most of them to American police departments, which is why “Flock camera” has become the generic term the way “Xerox” once meant photocopier.
The camera is usually solar powered, about the size of a shoebox, mounted eight to twelve feet up, and pointed at a lane of traffic. It does not look like surveillance equipment. That is partly the point.
When a car passes, the system photographs the plate, converts the image to text, and writes a record. The Supreme Judicial Court described the output precisely in 2020: the reader records “a photograph of the plate, the system’s interpretation of the license plate number, and other data, such as the date, time, location, direction of travel, and travel lane.”
Modern systems go further. They capture what the industry calls a vehicle fingerprint: make, body type, colour, roof rack, bumper stickers, a dent on the rear quarter panel. That matters because it means a search does not require a plate. A description will do.
What they do not do is photograph faces or read the inside of your car. The pitch has always been that this is not facial recognition, and on that narrow point the pitch is accurate.
The two things the system produces
Every ALPR network does two separate jobs, and conflating them is where most public arguments go wrong.
The first is the real-time alert. An officer puts a plate on a hot list. When any camera in the network reads that plate, the system emails or texts the officers who asked to be notified, with the image, the time, the location and the direction of travel. This is the function departments talk about: stolen cars, Amber Alerts, a suspect with a warrant.
The second is the historical search. Anyone with credentials types a plate into a box and gets back every time that plate was photographed by any camera the agency can reach.
The first function is a tripwire. The second is a time machine, and it is the one that generates the cases.
Are Flock cameras legal?
In Massachusetts, yes, with a caveat the SJC wrote into the law itself.
The case is Commonwealth v. McCarthy, 484 Mass. 493 (2020), docket SJC-12750, decided on 16 April 2020. Barnstable police suspected Jason McCarthy of running heroin onto Cape Cod. They put his plate on the hot list for the fixed readers at the Bourne and Sagamore bridges, got real-time alerts, and separately pulled a spreadsheet of every crossing he had made between December and February. It showed him crossing on nineteen days in December, twenty-one in January and eight in February, sometimes twice in a day.
He moved to suppress. The court had to decide whether using the readers that way was a search at all.
Justice Gaziano’s answer is the sentence every ALPR argument in this state now turns on:
“We conclude that, while the defendant has a constitutionally protected expectation of privacy in the whole of his public movements, an interest which potentially could be implicated by the widespread use of ALPRs, that interest is not invaded by the limited extent and use of ALPR data in this case.”
Read that twice. The court did not say you have no privacy interest in where you drive. It said the opposite: you do have one, in the whole of your public movements. It then held that four cameras at two bridge ends were not enough to invade it.
That is the mosaic theory, adopted under both article 14 of the Massachusetts Declaration of Rights and the Fourth Amendment. One tile is not a picture. Enough tiles are.
The court was explicit that a more pervasive network would come out differently. In 2020 the question was four cameras on the way to the Cape. Today it is hundreds of cameras across dozens of municipalities, feeding a searchable national network. Nobody has yet put that configuration in front of the SJC.
There is still no statute
People assume something this invasive must be governed by a law written for it. In Massachusetts there is no comprehensive ALPR statute. No general rule on who may search, what reason they must give, how long data may be held, or whether it may cross state lines.
What governs officers instead is policy. The State Police operate under General Order TRF-11, issued in July 2014, which the SJC quoted in McCarthy. It requires that only trained, specially designated users access the system, that the system and its information be “[a]ccessed and used only for official and legitimate law enforcement purpose,” and that an officer visually verify a plate before making a stop on a hit.
That phrase, official and legitimate law enforcement purpose, is the entire safeguard. It is not a statute. It is an employer’s rule, and the consequence for breaking it is employment discipline.
Which is exactly what happened in Revere this year. An officer ran his ex-girlfriend through the city’s Flock system more than a dozen times across four occasions, and looked her up in the state criminal records database as well. Internal affairs sustained the violations. He served three days without pay and went back to work. His department had cleared him on the first review. We covered that case in detail.
Officers in New Bedford, Stow and Lynn have faced similar accusations.
How long is the data kept?
This has moved fast, and any answer older than a few months is wrong.
When McCarthy was decided, the state database run by the Executive Office of Public Safety and Security had a one-year retention policy. The court noted a wrinkle that still applies: alert emails sent to officers can sit on a recipient’s server long after the underlying record is purged, potentially indefinitely.
Flock’s own default was thirty days for a long time. In 2026, after what was described as dozens of police abuse cases, the company cut the default to seven days and made search auditing compulsory. Keeping data longer now requires tying it to an active case number as evidence.
Seven days sounds reassuring. Two things to hold alongside it. A default is a setting, and settings can be changed by whoever administers the account. And a company that lowered a number under pressure can raise it again when the pressure passes.
Who can actually search your plate?
This is the part most residents have never been told, and it is the reason the question “does my town have cameras” is the wrong question.
Flock agencies can opt into a national lookup capability. An officer running a search is then not limited to the cameras his own city paid for. Departments that have opted in can search each other’s data across state lines.
So the real questions are which other agencies can see what your town’s cameras recorded, and whether anybody local has ever audited that.
Federal access has been the sharpest fight. Reporting indicated that thousands of lookups had been run at the request of federal authorities for immigration purposes, giving federal agencies practical access to a system they had no contract for. Flock has said it holds no contracts with DHS or ICE and that direct sharing is not possible within its system. In June 2025 it added automatic keyword blocks for immigration-related and reproductive-health-related search terms. In January 2026 it gave agencies a single toggle to switch off federal sharing entirely.
The existence of a toggle tells you what was flowing before there was one.
The SJC noticed the sharing problem back in 2020. A footnote in McCarthy records the amici pointing out that private companies own and operate ALPR cameras and share data with police, as do individual homeowners, and that federal and state agencies may share with each other.
Where are the cameras?
Until this month, in Massachusetts, that was officially a secret.
The State Police took the position that it could withhold both the locations of its cameras and the audit logs showing who had been running searches. In September 2026 a Suffolk Superior Court judge rejected that, in a case brought by the ACLU of Massachusetts after a five-year effort, and ordered disclosure of camera locations and search logs with plate numbers redacted.
For municipal cameras, the answer has always been closer to hand than people assume, because a police department buying cameras leaves a paper trail: a contract, a purchase order, a council or select board vote, a use policy.
Outside government, the activist project DeFlock has been crowdsourcing a map of Flock installations since 2021, and it is the reason anyone can measure how fast the network grew and how many jurisdictions are now leaving it.
How this differs from the cameras you already accepted
Most people’s mental model is a red light camera, and that model is wrong in a way that matters.
A red light camera is triggered. It watches one intersection and photographs a car only when a specific thing happens, and the output is a ticket that arrives in the post. You know it exists because it is signposted, and its records are about events.
An ALPR is untriggered. It photographs everyone. There is no violation involved, no ticket, and usually no sign. Its output is not an event but a location history, and it accumulates whether or not anything ever happens.
The difference is between a camera that catches something and a camera that keeps everything. The second kind is only useful, from a police perspective, because it is comprehensive, and it is only troubling, from a civil liberties perspective, for exactly the same reason. Those are not two arguments. They are one fact viewed from two chairs.
Toll transponders are the closer comparison, and even they are narrower: you opted in, the operator is one agency, and the purpose is billing.
How to find out if someone ran your plate
Every search generates a log entry. That is the whole design: the searching officer, the agency, the timestamp, the plate, and a reason code. The audit trail exists.
Getting at it is a public records question under G.L. c. 66, § 10. You can request a department’s ALPR audit logs, its use policy, its vendor contract, and its retention settings.
Expect friction over redactions, and expect other people’s plate numbers to be withheld, which is reasonable. What is now much harder for a department to argue, after a Superior Court ruling rejecting exactly that position, is that the whole category is off limits.
If you are going to write to your own department, ask these:
- What ALPR system is in use, under what contract, and when does it expire?
- How long is data retained, and what is the setting today rather than the default?
- Has the agency opted into national lookup, so that out-of-state agencies can search its cameras?
- Is federal sharing enabled or switched off?
- How many people hold search credentials?
- What reason must an officer enter to run a search, and is it a free text box or a menu?
- How often are the logs audited, by whom, and what happened the last time an audit flagged something?
The last one is the question that matters. Revere had the logs. Revere had the policy. The searches were recorded the entire time, and the first review of them found nothing wrong.
When the camera is wrong
The systems misread plates. This is not a fringe complaint, it is in the SJC’s own record.
In McCarthy a testifying expert identified weather conditions, warped or obscured plates, and particularly bad lighting as factors that can cause a reader to fail on a given plate. The court described the bridge cameras as not infallible while still creating what amounts to a comprehensive record of vehicles going on and off the Cape.
A misread is not a filing error. It is a car that did not go where the database says it went, or a plate that resolves to somebody else’s vehicle entirely. A single transposed character turns your Toyota into a stranger’s, and the hot list does not know the difference.
Which is why State Police General Order TRF-11 requires an officer to visually verify the alphanumeric characters on a plate, and confirm its status through another database, before initiating a stop on an alert. That rule exists because the machine gets it wrong often enough to need a human check written into policy.
Worth understanding what that means in practice: the safeguard against a bad read is an officer looking at the actual plate before pulling you over. If that step is skipped, the error rides all the way into the stop.
What this means if you are actually charged
If ALPR data is part of the evidence in a Massachusetts case, McCarthy is where the argument starts, and the argument is about scale.
The court held that four fixed cameras at two bridge ends did not produce a mosaic detailed enough to invade a reasonable expectation of privacy. It also said, plainly, that widespread use could implicate that interest. So the litigable question in any given case is which side of that line the network in question falls on.
Things worth establishing in discovery: how many cameras fed the data used, where they were, over what period, whether the search was a real-time alert or a historical pull, how far back the historical data ran, whether the agency searched only its own cameras or reached into a shared national pool, and what reason the officer entered when running the search.
That last item is the one that connects the constitutional question to the Revere case. Every search carries a stated purpose, recorded in the log. A reason code is a claim an officer made in writing at the time, and like any contemporaneous statement it can turn out to be inaccurate.
None of this is legal advice, and none of it is a promise that a suppression motion works. It is a description of where the seams are in a body of law that was written for four cameras and is now being applied to a network built on a different scale entirely.
Towns are switching them off
More than two dozen Massachusetts cities and towns have opted out of the technology or stopped using it.
Cambridge cancelled its contract after the cameras were already installed. Brookline paused a rollout. Watertown ended its use. Abington, Ayer, Groton and Southbridge have terminated contracts or suspended use.
Nationally, more than twenty jurisdictions moved to cancel in July 2026 alone, the most in any single month since DeFlock began tracking, and more than fifty cities and counties cut ties across the year. The ACLU of Massachusetts publishes a toolkit for residents who want to raise it locally.
None of that is a verdict on whether the cameras work. They do find stolen cars. Departments can point to real cases, and pretending otherwise is not an argument, it is a posture.
The honest summary
Flock cameras are legal in Massachusetts today because of a 2020 decision about four cameras, in a case where the court went out of its way to say that a bigger network might well be a search.
The network is now much bigger. The rules governing who may search it are written by police departments rather than by the Legislature. The safeguard is an audit log, and the one documented Massachusetts case where an officer used the system on a private citizen he was personally entangled with produced a three-day suspension, after his own department cleared him once.
None of which means the sky is falling. It means the questions worth asking are local, they are answerable in writing, and until this month one of the biggest agencies in the state was arguing it did not have to answer them at all.
