FLOCKWATCH / PUBLIC RESEARCH

How to audit an ALPR incident

A preservation-first field guide for examining a suspected automated license-plate-reader stop, search, alert, or database query.

Preserve first. Interpret second. Publish last. ALPR records can be overwritten by short retention windows, while screenshots and recollections can lose the metadata needed to reconstruct what happened. Start a written timeline, preserve the original records, and keep an untouched copy before analyzing anything.

Scope guardrail: Documented incident ≠ prevalence. This guide helps reconstruct one event. It does not estimate how often ALPR systems fail, and it does not measure any vendor's proprietary accuracy.

If the event just happened

  1. Write the timeline. Record date, local time, location, agency, unit numbers, names, exact words used, the sequence of detention/search/arrest/release, and when you first learned ALPR was involved.
  2. Preserve your own records. Save original photos, video, dash-camera files, tow or property receipts, citations, court papers, dispatch notifications, and location history. Export originals; do not edit the only copy.
  3. Ask counsel about a preservation notice. Retention periods and legal procedures differ. A defense attorney can identify the correct agency, prosecutor, vendor-held records, and deadlines. This field guide is research guidance, not legal advice.
  4. Separate identifiers from the public copy. Keep plate numbers, home addresses, faces, precise travel history, account IDs, and unrelated people out of any public packet.

Build one incident ledger

Use one row per claim or event. Never collapse the alert, officer confirmation, stop, search, and final disposition into a single sentence.

TimeEvent or claimSourceOriginal preserved?ConfidenceConflict / gap
14:03ALPR alert createdAlert recordyes / nohigh / medium / lowMissing hot-list version
14:05Officer received alertCAD / body camerayes / nohigh / medium / lowDispatch time differs

Record the timezone. Preserve the source filename, byte count, retrieval date, and SHA-256 hash where practical. If a later copy differs, do not overwrite the first one—add a new ledger row.

The fault-chain questions

1. Capture

  • What image, plate string, confidence value, camera ID, location, and timestamp were recorded?
  • Does the system retain the full frame, cropped plate image, vehicle attributes, or only text?
  • Are the displayed string and the machine's underlying query string identical?

2. Match

  • What hot list, watch list, warrant record, stolen-vehicle record, or user-entered plate was queried?
  • What was the exact source agency, record ID, creation time, update time, and expiration status?
  • Was the match exact, partial, wildcarded, normalized, or based on vehicle characteristics?

3. Distribution

  • Which agencies, networks, fusion centers, contractors, or federal users could access the record?
  • Was the alert or query shared outside the collecting agency?
  • Did an external agency create the list entry but a local agency act on it?

4. Human verification

  • What did policy require the officer or analyst to confirm before acting?
  • What did the audit trail show they actually checked?
  • Were plate state, make, model, color, VIN, stolen status, warrant status, and driver identity independently confirmed?

5. Police action and correction

  • Which action followed: observation, stop, high-risk stop, search, seizure, arrest, tow, citation, or no action?
  • Who learned the alert was wrong or stale, when, and how was the originating record corrected?
  • Was the correction propagated to every receiving system, or only noted locally?

Records-request map

Request records by category and date range, not by guessing a vendor's screen labels. Public-records exemptions and criminal-discovery rules vary; redact personal plate data from any public release.

  1. Stop and encounter record — CAD/event history, dispatch audio, incident/offense report, citations, tow/property records, body-worn and dash-camera video, supervisor review, and use-of-force or K-9 records where applicable.
  2. ALPR system record — original and cropped image, OCR output, displayed plate string, confidence or candidate list if retained, camera ID/location, alert timestamp, alert delivery record, and disposition.
  3. Search and access logs — user, date/time, stated purpose or case number, query type, network or agency, result count, exports, and downstream sharing. Ask for deidentified or redacted records when plate disclosure would invade privacy.
  4. Hot-list provenance — source system and agency, entry/change/expiration timestamps, record identifier, synchronization history, reason code, and removal or correction history.
  5. Policy and training — current and incident-date policies, verification requirements, retention schedule, access controls, audit frequency, sharing agreements, training materials, and vendor documentation used by the agency.
  6. Governance and contracts — procurement record, contract and amendments, data-processing terms, network-sharing settings, authorized-user roster, security/audit reports, complaints, corrective actions, and aggregate hit or disposition reports.

The California State Auditor specifically recommended complete user-access and query logs that support periodic audits. California DOJ policy separately describes authorized-user controls, dual-factor access, annual audits, and retained audit information. These are useful audit benchmarks even when another jurisdiction's law differs.

Evidence grade

Grade the support for each important claim—not the person making it.

GradeWorking meaningExamples
AOfficial primary record plus corroborationNative audit log + body-camera timeline; court filing + agency record
BMultiple independent sources or a public-records analysisTwo outlets reviewing named records; deidentified logs with methodology
COne credible secondary source with unresolved primary-record gapsDetailed reporting, original records not available
DInterested-party or advocacy/vendor claim without independent supportMarketing case study; unsourced allegation

Record contradictions instead of averaging them away. A body-camera timestamp, CAD timestamp, and vendor alert timestamp may describe different systems or clock drift; the mismatch itself is evidence to investigate.

Privacy-safe publication

  • Do not publish a plate number, unredacted plate image, home address, precise routine travel history, credential, access token, or unrelated person's identity.
  • Publish an evidence index and redacted excerpts before publishing bulk logs.
  • Keep originals encrypted or access-controlled; work from redacted copies.
  • Explain missing records, denied requests, retention losses, and source limitations.
  • Do not turn an accountability audit into a plate-lookup tool or a map of one person's movements.

Completion test

An audit packet is ready for review when it has: an incident timeline; source inventory; original-preservation record; ALPR alert and hot-list provenance; access/sharing logs or a documented gap; policy-at-the-time comparison; contradiction log; correction/disposition record; privacy review; and an evidence grade for every load-bearing claim.

Sources

  1. California State Auditor, Automated License Plate Readers (Report 2019-118, 2020)
  2. California Department of Justice, General Order 2023-05: Automated License Plate Readers
  3. Electronic Frontier Foundation, Automated License Plate Readers
  4. American Civil Liberties Union, Automatic License Plate Readers
  5. U.S. Government Accountability Office, Law Enforcement: DHS Could Better Address Bias Risk and Enhance Privacy Protections (GAO-25-107302)

Source note: These sources establish audit, policy, privacy, and public-record categories. They do not establish a national incident rate or the accuracy of any proprietary ALPR product.