When Security Technology Becomes Surveillance: The Real Problem With Flock-Style Camera Networks

When Security Technology Becomes Surveillance: The Real Problem With Flock-Style Camera Networks

From Observation to Surveillance

There is an important distinction between observing activity at a specific location and creating the ability to reconstruct someone’s movements across an entire community, region, state, or country.A security camera watching the entrance to a building observes an event.A network of interconnected cameras capable of recording a vehicle at hundreds of locations creates something very different: a historical record of movement.That difference is enormously important.One camera might establish that a vehicle entered my property at 10:32 a.m. That is useful security information.Thousands of interconnected cameras potentially allow an authorized user to determine where that same vehicle traveled before arriving, where it went afterward, how frequently it visits particular locations, and whether other vehicles repeatedly appear with it.At sufficient scale, we are no longer simply detecting vehicles.We are identifying patterns of human behavior.And that should concern everyone — including those of us who strongly support law enforcement and security technology.

The Problem Is Aggregation

Much of the debate surrounding automated license plate readers focuses on the fact that license plates are visible in public.That misses the larger issue.Of course someone standing on a street corner can see my license plate. A police officer can see it. A security camera can capture it.But seeing me drive down one street is fundamentally different from maintaining a searchable database capable of showing everywhere my vehicle has been observed.Technology eliminates the practical limitations that once protected a certain degree of anonymity in public life.Historically, following someone required resources. An investigator had to physically conduct surveillance, establish probable cause where required, dedicate personnel, and make decisions about whether the investigation justified the effort.Mass sensor networks invert that model.Instead of deciding whom to surveil and then collecting information, we collect information about virtually everyone first and decide later whose movements we want to examine.That is a profound change in the relationship between surveillance and society.

Flock Is an Important Example, But This Is Bigger Than Flock

Flock Safety has become the most visible example of this issue because of the scale and interconnectivity of its platform.To be fair, the company has implemented and recently strengthened several privacy controls. Flock says customers control their data, agency-to-agency sharing is optional, searches are logged, users must provide investigative reasons for searches, and customer data is not sold. In 2026, the company also reduced its recommended default ALPR retention period from 30 days to seven days and announced additional mechanisms intended to identify suspicious searches and user misuse.

Those are meaningful controls and should be acknowledged.But they do not resolve the fundamental question.Should this capability exist at this scale in the first place?Flock describes agency sharing as permission-based rather than automatic. Yet when participating agencies choose to share data, the platform can provide investigative access extending well beyond the jurisdiction where an individual camera is located. Reporting has documented searches involving multiple jurisdictions and, in some cases, inappropriate use of the system by individual officers.

That illustrates an important principle of security engineering:We cannot evaluate risk based solely upon how a system is intended to be used.We must evaluate how it can be used.

Mission Creep Is Predictable

Every security professional understands mission creep.A system installed for one purpose gradually becomes useful for another.The parking camera becomes an investigative tool. The investigative tool becomes an intelligence platform. The intelligence platform becomes interconnected with other jurisdictions. Additional analytics are added. More data sources are incorporated. Retention periods change. New users obtain access.Each individual decision may appear reasonable.The cumulative result may not be.This is particularly concerning as ALPR systems converge with video analytics, artificial intelligence, vehicle classification, object recognition, facial recognition, mobile device information, commercial databases, and other sources of digital intelligence.The danger is not necessarily any single technology. It is the correlation of them. Once enough independent data points can be associated with the same person, vehicle, device, address, or identity, seemingly insignificant observations become extraordinarily revealing.Where you sleep. Where you work. Where your children attend school. Which physician you visit. Which religious institution you attend. Whom you associate with. Which political events you attend. Where you spend your evenings.
None of those activities needs to be illegal for the information to be extraordinarily sensitive.

Monetization Makes the Question More Complicated

There is another distinction worth making.Flock states that it does not sell customer data, and that is different from the conventional data-broker model.

But we should distinguish between selling someone’s underlying data and commercializing an infrastructure whose value increases because large amounts of data can be captured, searched, analyzed, and subject to customer permissions and applicable restrictions shared.The network itself has economic value precisely because it is a network.A license plate camera protecting one parking lot has one level of usefulness.A platform capable of searching observations across thousands of locations has exponentially greater value.That network effect creates a powerful commercial incentive toward more cameras, more participating organizations, more integrations, more analytics, and more data.The same characteristics that make the system extraordinarily useful also make it potentially dangerous. That is the paradox.

Public Safety Cannot Be the Only Test

“Public safety” is an extremely powerful justification. It is also dangerously broad. Almost any surveillance capability can identify some legitimate public-safety benefit.A camera on every street would undoubtedly solve crimes. Continuous facial recognition across an entire city would undoubtedly identify wanted individuals. Tracking every cellular device would undoubtedly help investigators reconstruct crimes. None of those facts, by themselves, establish that society should deploy those capabilities without substantial limitations.The appropriate question is therefore not simply: “Does this technology help law enforcement?” Of course it does. The more important question is: “What surveillance capabilities should exist in a free society, under what circumstances, with what safeguards, and subject to whose oversight? Those are much harder questions.

Drawing the Line

As security professionals, municipalities, property owners, law enforcement agencies, and technology companies, I believe we should be able to articulate some fundamental principles.
  • Purpose limitation: Deploy technology to address a clearly defined security problem rather than collecting data simply because it may become useful someday.
  • Geographic limitation: Local security problems should generally produce localized data sets unless a legitimate investigative need justifies broader access.
  • Data minimization: Collect only the information reasonably necessary and retain it only as long as necessary.
  • Controlled access: Historical movement searches should require documented justification, strong authentication, immutable audit logs, supervisory review, and meaningful consequences for misuse.
  • Transparency and accountability: Communities should know what is being collected, how long it is retained, which organizations can search it, and under what circumstances information can be shared.
  • Legal safeguards proportional to capability: As surveillance platforms become capable of reconstructing increasingly detailed histories of people’s movements, the threshold for accessing that information should rise accordingly.
  • Separation of security from generalized intelligence gathering: A system deployed to protect a defined property or address a defined crime problem should not quietly evolve into infrastructure for unrestricted population-level surveillance.
  • These concepts are not anti-police. They are not anti-security and they certainly are not anti-technology. They are good security governance.

    Security Professionals Should Be Leading This Discussion

    Those of us in the security profession should resist the temptation to divide this debate into two camps: people who “support public safety” and people who “support privacy.” That is a false choice. Security and liberty are not mutually exclusive. In fact, responsible security professionals should be among the strongest advocates for clearly defining the limits of surveillance technology because we understand better than most people what these systems are capable of doing.

    I want law enforcement to have powerful investigative tools. I want security departments to identify threats. I want stolen vehicles located, missing children found, violent offenders apprehended, and crimes solved.But I also do not want to live in a society where the movements of every innocent person are continuously collected into searchable databases simply because the technology makes it possible. There is a line between security and surveillance.

    A camera protecting a defined environment for a defined purpose is security technology.A vast interconnected network that records everyone’s movements, aggregates those observations, analyzes behavioral patterns, and makes that information broadly searchable begins to look very different. 

    The question we need to address now is not whether these technologies work. They clearly do. The question is whether we have the discipline to define where legitimate security ends and mass surveillance begins, before the infrastructure becomes so ubiquitous that drawing that line is no longer realistically possible.

    More from this category

    Let's Talk

    Contact us now for a FREE, NO OBLIGATION security consultation with an experienced protection professional. Just provide your information using the form below, or call us at 888-793-9380 and a member of our team will contact you within 24 hours.