footnote4a

Mass surveillance, government contracts, and other bedtime reading.

New Flock Terms: Perhaps You Think You're Being Treated Unfairly?

New Flock Terms Perhaps You Think You're Being Treated Unfairly?

Flock updated its terms again. It violated them before the ink was dry.

by H.C. van Pelt
8 min read
San Diego Public Safety Committee (August 20, 2026)
contract
transparency

Flock adopted new policies and published new Terms of Service this week, in response to the growing backlash against the company. Even on cursory review, the new terms clash with the company’s legal obligations and customer commitments — they show exactly how seriously the company is taking its responsibilities.

#Flock’s ISO27018 Compliance

Flock flaunts its certifications whenever it can. Recently, in addition to falsely claiming the website gets millions in donations,[1] Pulaski County sheriff Stacy Ball posted a somewhat unhinged comparison of haveibeenflocked.com’s certifications and Flock’s certifications.

Stacy Ball comparing "certifications" for HIBF and Flock

However, shortly after that, he canceled the county’s contract and posted an email saying that he had a conversation with Flock “about the transparency and compliance resources”. Draw your own conclusions.

Email between Stacy Ball and Flock

Regardless, ISO 27018 is on sheriff Ball’s list. It’s also on Flock’s trust center.

ISO 27018:2019 is not a certification; it’s a code of practice, described on ISO’s website as: “Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors”

The program sets a standard for how a cloud vendor must handle other people’s personal data. There is no accredited certification for it; auditors issue conformance reports.

#The Baker Tilly Report

On January 23, 2026, Baker Tilly published a report on its audit of Flock’s 27018 compliance. Specifically, the audit was performed on December 8–11 the previous year. But Baker Tilly didn’t audit against the then-current 27018:2025 version of the standard — it audited against 27018:2019, itself a republication of the even older 27018:2014 standard. The 2019 version had been withdrawn on August 26, 2025.

But the report itself is still revealing. Perhaps unsurprisingly, there is little substance to it: one control, “access to data on pre-used data storage space”, is marked “Conforms” next to an empty “Records Inspected” cell (page 14 of the report, page 17 of the PDF). Maybe the vibes were right.

The auditor used a “Statement of Applicability” (SoA) to know what controls to test, but the published SoA is a blank template without information on what Flock commits to. It even includes the mandatory clause 4–10 requirements, which aren’t relevant to the SoA. The 27018 auditor also used a different version of the SoA (dated August 1, 2025) than the 27001 auditor (August 14, 2024).

But, to the more specific point: control A.5.1 requires “Secure erasure of temporary files” within a “specified, documented period”. The standard’s guidance explains:

Information systems can create temporary files in the normal course of their operation. Such files are specific to the system or application, but can include file system roll-back journals and temporary files associated with the updating of databases and the operation of other application software. Temporary files are not needed after the related information processing task has completed but there are circumstances in which they may not be deleted. The length of time for which these files remain in use is not always deterministic but a “garbage collection” procedure should identify the relevant files and determine how long it has been since they were last used.

PII processing information systems should implement a periodic check that unused temporary files above a specified age are deleted.

tl;dr: Temporary files that (may) contain personally identifiable information (PII) must be securely deleted.

On page 12 of the report (page 15 of the PDF), the auditor writes for this control:

Temporary files are maintained on cameras for 30 days and then deleted.

#The PII

The first question you might ask: what PII is being stored on cameras?

Flock wants you to think there isn’t any:

“Since the information collected by itself is not able to identify individuals, it is not considered Personally Identifiable Information (PII).”

What Data Traditional License Plate Readers Collect (March 28, 2019) (archive)

And more recently:

“LPRs do not collect personally identifiable information like names, addresses, or DMV records.”

Has Flock Been Hacked? (January 6, 2026) (archive)

Of course, in true Flock fashion, these are qualified statements. The first is “according to law enforcement.” The second is PII “like names, addresses, or DMV records.” License plates, which are also PII, are presumably not PII “like names, addresses, or DMV records.”

But Flock knows license plates are PII, and it knows it is handling PII — it even hired an auditor to assess its PII-specific compliance program (ISO 27018) and pointed the auditor toward the cameras.

#The Retention Period

The auditor’s finding is straightforward: “Temporary files are maintained on cameras for 30 days and then deleted.” Not even “up to 30 days”. It implies temporary files older than 30 days are deleted (“reaped”) — a very common configuration for temporary file storage, and a sufficient one in most settings.

Here, however, it conflicts directly with Flock’s own new State-Specific Contractual Provisions, as well as with Flock’s (and its customers’) obligations under the laws of several states. For Connecticut and Washington, Flock’s terms say “the Retention Period for ALPR data is 21 days, or such shorter period as Customer has requested.” For Virginia, they promise systems “capable of purging system data collected or generated in Virginia after twenty-one (21) days” — a capability the cameras evidently do not use.

The 21-day limit comes from statute. Virginia’s HB 2724 took effect July 1, 2025. Washington’s SB 6002, the Driver Privacy Act, was signed into law this March;[2] police departments have already paused their cameras to comply. For Connecticut, Flock’s own explainer (archive) says: “SB397 establishes a default retention period of 21 days for ALPR data.” Flock wrote one for Washington, too. There are no exceptions for temporary files written into the statutes.

Per Flock’s auditor, every Flock camera in those states holds customer data nine days longer than Flock’s contracts and state law allow.

#Employee Laptops

Perhaps equally concerning is the new “Customer InfoSec Addendum,” which contains the following clause:

2.3. Flock Laptops. Notwithstanding Section 2.2 above, Customer Data may be temporarily downloaded onto Flock-owned laptops for data analysis and/or troubleshooting. Laptops are security-hardened with a configuration that includes full-disk encryption, endpoint detection and response agent, enforced password authentication, and automatic screensaver with password unlock.

It sets no limit on “temporarily”, no deletion obligation, no access logging, and no notice to the customer. For authentication it requires a password, while access to the same data through FlockOS requires multi-factor authentication — Flock’s auditor verified that.

The Baker Tilly report looks at removable media, like USB sticks, to ensure that PII isn’t walked out of the building. It does not test the laptops. An employee could fill their laptop hard drive to the brim with customer data and take it on vacation. The Addendum also promises that Flock “does not store Customer Data outside of the United States” (§3.2).

It’s not as direct a violation of law as the auditor’s camera finding, but whether laws and contracts are violated hinges on whether employees who take their laptop on vacations to Thailand or Jamaica will remember to delete the Virginia data before it hits 21 days. The auditor didn’t check.

#“A high-accountability commitment”

Flock’s new “guardrails” are a PR stunt. The ACLU reached the same conclusion: the changes follow Flock’s “playbook of treating legitimate privacy concerns as mere public relations problems.” Nothing makes that more clear than the documented violations that already exist, a day later.

In its plain-English statement on Data Ownership, Flock writes:

The phrase “prima facie breach” is legally significant.[3] It means that unauthorized sharing of your data is not a gray area — it is a breach of contract by definition, entitling you to all available legal remedies. This is a high-accountability commitment, not boilerplate.

Flock will presumably object that this commitment covers sharing, not storage. That’s true as far as it goes: §4.1 grants its presumption only to sharing. But the retention breach doesn’t need a presumption.

The contract says the Retention Period is 21 days, the auditor says 30, and §5 bars Flock from using Customer Data “except as permitted under the Agreement.” A breach made out on the face of two documents is prima facie in the ordinary sense — Flock’s “prima facie” clause just spares customers the work for the category Flock chose.

The “high-accountability” language targets only what Flock is being criticized for. The camera data sitting on a stick on the side of the road, or in a folder on a laptop at Sandals Jamaica, doesn’t specifically get that language.

If Flock is serious about guardrails, that shouldn’t matter. The violation on the face of the documents is the same, whether or not Flock wrote “prima facie” in front of it.

Let’s see some accountability.


  1. We’re lucky to break three figures in any given month, so please consider donating! ↩︎

  2. Washington courts found no exemption for ALPR data in public records law. Flock sent a lobbyist to convince the legislature to overrule the court by creating an exemption. The 21-day retention limit was added to appease lobbyists on the other side of the table and make it look like more than merely an anti-transparency bill. ↩︎

  3. Pro-tip for Flock’s legal department: next time you find yourself translating Latin phrases in your terms of service, maybe it’s a sign to use plain English ab initio. ↩︎