
computer technology office modern — AI-generated illustration
Surveillance Tech Meant for Crime-Solving Gets Turned on Personal Targets — What It Means for Oversight
Law enforcement surveillance systems are creating a new category of misconduct risk, and the numbers aren’t theoretical: prosecutors say one Wisconsin officer ran more than 170 unauthorized searches over two months to track a woman he was dating and her ex-boyfriend. Former Milwaukee police officer Josue Ayala pleaded not guilty this week to attempted misconduct in public office, a misdemeanor, after allegedly using the department’s Flock-branded automated license plate reader system for personal surveillance. He resigned hours before his court appearance.
Ayala is the second Wisconsin officer charged with misusing surveillance technology in recent weeks. In February, Menasha police officer Cristian Morales pleaded not guilty to the same charge after allegedly running five unauthorized searches to track an ex-girlfriend. Similar cases have surfaced in Florida, Kansas, and Georgia over the past few years — including two involving police chiefs, not junior officers.
The pattern extends beyond romantic stalking. A San Francisco officer is under investigation for using Flock’s system to locate his wife’s stolen car, possibly violating conflict-of-interest rules. The unauthorized use was discovered only after he posted a picture of the vehicle on social media and another officer in a neighboring jurisdiction saw it.
The technology at issue — automated license plate readers (ALPRs) — captures images of license plates on public roads and stores those sightings in a searchable database. Flock Safety, an Atlanta-based vendor that has become one of the largest providers, claims its systems help solve hundreds of thousands of crimes annually. But the same cross-jurisdictional search capability that makes the technology useful for crime-solving also makes it exploitable: officers can query vehicle movements far beyond their own jurisdiction, and the material shows they have.
Abuse of law enforcement databases for personal reasons isn’t new — a decade ago, The Associated Press documented hundreds of cases where officers accessed confidential databases to get information on romantic partners, neighbors, journalists, or business associates. But as the systems grow more sophisticated and interconnected, the ROI calculation for public agencies has shifted: the operational gain from shared databases now carries documented compliance costs.
At least 30 cities cancelled contracts with Flock over the first two months of this year, according to NPR. Denver announced it would not renew its contract and would switch to a competitor without a nationwide search option, citing concerns that Flock systems could be accessed by federal agents for immigration arrests. Ithaca, New York, dropped out this week. Public records analyzed by 404 Media revealed more than 4,000 nationwide lookups by local and state police done either at the request of federal agencies or as “informal” favors, plus a Texas sheriff’s office that searched data from over 83,000 ALPR cameras to track down a woman suspected of self-managing an abortion.
Flock Safety spokesperson Holly Beilin acknowledged cases of officer misuse but said they represent a small fraction of overall use. The company argues its audit logs can’t be changed after the fact — meaning an officer who abuses the technology can’t hide their tracks — and has added compliance tools including search filters tied to immigration and reproductive healthcare investigations where state law restricts those searches. The company paused a pilot program facilitating federal cooperation after scrutiny over federal access.
Lawmakers in several states have pushed for laws governing ALPR use, but enforcement remains unclear. A January report from the Virginia State Crime Commission found 55 law enforcement agencies in the state took no public awareness measures related to ALPR use despite a state law requiring public notice before deployment. The report also found 20 Virginia agencies providing data to out-of-state law enforcement and nine providing continuous access to federal agencies — both prohibited under state law.
Some local governments are trying contractual enforcement. The Chicago suburb of Arlington Heights announced a Flock contract this week with penalties of $22,000 to $70,000 per incident of “unauthorized disclosure or access.” The provision doesn’t protect against misuse within the police department itself, but is intended to prevent Flock’s platform settings from allowing outside agencies to query Arlington Heights’ camera data without the department’s permission or knowledge.
The Breakdown
- Automated license plate readers (ALPRs) capture images of license plates and store those sightings in a searchable database accessible across jurisdictions.
- Officers in Wisconsin, Florida, Kansas, and Georgia have been charged with misusing the technology to track people for personal reasons — including stalking romantic partners and ex-partners.
- At least 30 cities cancelled Flock contracts over the first two months of this year, with Denver citing concerns about federal access for immigration enforcement.
- Virginia’s own audit found 55 agencies failed to comply with state law requiring public notice before ALPR deployment, and 29 agencies shared data with out-of-state or federal agencies despite a state prohibition.
- Arlington Heights, Illinois, announced a contract structure with financial penalties ($22,000–$70,000 per incident) for unauthorized data sharing by the vendor.
What This Means for You
The governing bodies you elect — city councils, county boards, state legislatures — are the ones deciding whether to purchase these surveillance systems, under what terms, and with what oversight. The material shows that even when state law sets restrictions (as in Virginia), agencies frequently violate them. Your vote for local and state offices determines who negotiates these contracts and whether compliance failures get treated as a serious accountability problem or quietly ignored. If a neighboring jurisdiction’s officer can query your city’s camera data without your city’s knowledge or consent — as the material describes — the quality of your own city’s vendor contract and council oversight matters less than the lowest common denominator in the shared network.
What to Watch
The material describes a recognized tension between operational efficiency and governance: cross-jurisdictional data-sharing is what makes these systems valuable for crime-solving, and what makes them difficult to govern. Virginia agencies violated state law, San Francisco’s officer violated department policy, and Flock’s own platform enabled the Texas abortion-tracking search the company now distances itself from.
A financial penalty clause like Arlington Heights’ is one attempt to shift accountability, but the material is clear about its limit: it governs what the vendor’s platform allows other agencies to access, not what an officer within the contracting department does with the data once they have it. That’s the gap every audit log and search filter relies on human compliance to close — and the string of criminal charges shows what happens when it doesn’t.
The bigger structural question is whether a city can actually control what happens to surveillance data it generates once that data enters a shared network. If informal sharing and search justifications can defeat policy restrictions, as the material describes, then the contract-negotiation exercise may be limited in effectiveness, and the ROI calculation for these systems needs to account for governance challenges that are built into the architecture. The cities canceling contracts appear to have concluded exactly that.


