The Records That Caught the Abuse Are Going Dark
Public audit logs exposed officers tracking ex-partners thousands of times. Flock has since removed key fields from cross-agency audits, and states are now debating how much ALPR data the public should ever see.
Start with a number: 2,890.
That is how many times, from June 2023 to October 2025, a Covington, Georgia detective named Michael Canty searched the license plate of a woman he used to date, according to public Flock audit records. In July 2026, an internal Covington Police audit — using Flock’s new misuse-detection tool — flagged 41 recent searches, enough to refer the case to the Georgia Bureau of Investigation and, ultimately, to charge him. That matters, and it is fair to say so: the internal check worked.
But it caught 41. Who surfaced the other 2,849?
USA TODAY did — by analyzing years of public audit records, the same kind of records that, across the country, exposed a 911 director tracking her estranged husband, an officer running one plate 3,400 times, at least nineteen law-enforcement employees disciplined in five states this summer. In case after case, outside review of the public logs surfaced patterns that internal tools, limited to recent activity, had not. (DeFlockILM keeps a running record of the North Carolina cases in our Flock misuse and abuse tracker.) That is what makes the past nine months worth documenting: the information that enabled that outside review is being reduced — first in Flock’s software, and now, in some states, in the law.
One clarification at the outset: this piece focuses on Flock because it operates by far the largest plate-reader network in North Carolina, but our concern is not with a single company. It extends to every automated license-plate-reader platform and every ALPR deployment in the state — Rekor, Genetec, Motorola/Vigilant, and the rest — and to how all of them are used, audited, and disclosed. The accountability problem belongs to the technology, not to one vendor.
What Flock changed, and when
On December 9, 2025, a Flock vice president emailed customers. The email is more revealing than any characterization of it. Flock said it was seeing increased public-records requests; it noted that a third-party website had begun aggregating audit data released under those laws; and it announced product changes it said were designed in part to protect active investigations and officer safety and to “reduce the risk of broad disclosures like those currently circulating.” The sequence speaks for itself: public-records requests → public aggregation and analysis → a corporate response that changes what the records show.
The change was to the Network Audit — the record of who searched a given agency’s cameras — planned to take effect January 31, 2026. It is worth being precise about what was removed and what was kept:
- Removed from the Network Audit: the individual officer’s name or initials, the specific plate searched, the vehicle “fingerprint,” and the open-text reason the officer typed.
- Retained: the searching agency’s name, the date, a standardized offense type (drawn from NIBRS categories), and a unique search identifier.
So Flock did not make outside searches anonymous at the agency level — you can still see which agency searched. What disappears is which officer, which plate, and the officer’s own words explaining why. The same email also urged agencies to consider temporarily switching from Nationwide to Statewide Lookup — that is, to share less — expressly to reduce the risk of broad disclosures. (Read the December 9 email.)
That last removal matters more than it sounds. The open-text reason is where the worst searches gave themselves away — a typed note, not a tidy category, is what revealed a Texas search tied to a suspected abortion. A camera-owning agency’s audit, and any public-records requester after it, may now see “Drug/Narcotic Violation” where a revealing narrative once sat. Under a standardized label, a search that targeted an ex-partner, a political activist, a journalist, a reproductive-health clinic, or an immigration matter can read exactly like any routine case. We have watched this transition in our own North Carolina data: agency logs that were heterogeneous free text in mid-2025 flipped to standardized offense labels by early 2026 — the same window Flock was redacting the other fields.
A candid word about our own approach. Early on, we did not press for the individual user identifier — the searching officer’s name. We thought the agency doing the searching mattered more than the particular person behind the keyboard. The past year changed our mind. With misuse now documented across the country — officers searching ex-partners, co-workers, and people they simply wanted to track — the identity of the searcher is no longer a secondary detail. It is the field that lets anyone test whether a specific person is being watched by a specific officer. Removing it does not protect the public; it protects the pattern. That is precisely the field Flock’s December change took away.
Flock used to sell the Network Audit as public oversight
Set two Flock statements side by side. Before the controversy, the company publicly described the Network Audit as a tool for oversight — every search and its reason preserved in the audit trail of the agency whose cameras were searched, available for review by command staff, elected officials, and communities, as part of Flock’s stated commitment to transparency. After December 2025, the officer, the plate, and the open-text reason are gone from that same Network Audit. We do not need to call that hypocrisy; the two statements are the exhibit.
In fairness, Flock has a real argument, and it deserves to be stated plainly. Agencies were releasing raw audit logs into public-records responses, and those logs can carry genuinely sensitive material — the targets of an active investigation, a victim’s or a witness’s plate, an officer’s identity. Flock says the redactions protect investigations and officer safety, and that concern is not frivolous. The unresolved question is narrower, and it is the one this piece is about: whether the cure removed precisely the fields that let anyone outside the agency check for abuse — and whether a more careful fix could have shielded victims and investigations without also blinding the public.
And that argument does not fully answer the objection, because North Carolina’s records law already recognizes that public and non-public information can live in the same government record. Using a record in a criminal investigation does not by itself change its public status (§ 132-1.4(f)); and when exempt information is deleted from a record, the agency must note that a deletion was made — it is not authorized to destroy the original (§ 132-1.4(j)). Those provisions support handling genuinely sensitive material through targeted, record-specific redaction. (Whether any particular audit field was compiled as criminal-investigation or criminal-intelligence information — the test under § 132-1.4(a)–(b) — is a record-by-record question, not one answered by the label “audit log.”) What the statute does not support is stripping the officer, the plate, and the reason out of every outside search, forever, whether or not any investigation is involved. A scalpel already exists; Flock reached for a blackout.
About that “misuse detection”
Flock’s answer to the criticism is its Audit Assistance tool. But the tool and the redaction work in opposite directions, and they do not overlap:
- The tool audits an agency’s own users. An administrator can always see their own officers in full, so the tool can flag a local deputy searching one plate at 2 a.m. Nothing in the December change touched that.
- The redaction affects outside searchers — officers from other agencies whose searches reach your cameras. Those are the searches now stripped of officer, plate, and free-text reason.
At some North Carolina agencies whose Network Audits we have analyzed, outside agencies account for the overwhelming majority of searches. UNC Charlotte’s cameras, over three months, were searched 3.7 million times by more than 3,800 different agencies; the single largest searcher was Houston, Texas — about 185,752 searches, roughly 1,100 miles away, and about 94% of all searches came from outside North Carolina. (Those figures come from UNC Charlotte’s own native-CSV Network Audit for March–May 2026, produced in full to DeFlockILM.) Those out-of-agency searches are exactly the ones the redaction now dims.
The tool is also modest on its own terms, per USA TODAY’s investigation: it is opt-in (about a third of agencies had enabled it, mandatory only by the end of 2026) and it looks only at 2026 forward, so it cannot see the years of logs where documented abuse actually lived. Covington is the proof in both directions — it found 41; the public record held 2,890. And here is the sharper point: the issue is not whether misconduct can be detected — in Canty’s case it was. It is that finding one abusive user does not show that similarly situated users are being found, and the public now has no way to check whether they are. Detection you cannot independently verify is a promise, not a safeguard — especially when the tool doing the detecting is proprietary. We do not know what triggers an alert, its false-negative rate, whether an agency can quietly override one, or whether any outside party has ever audited it.
There is a deeper design flaw here. When the only remaining audit of an agency’s cameras runs through the agency head — and no outsider can check it — the system’s safety rests entirely on the character of whoever holds that office. A surveillance network should be judged not by how the best sheriff uses it, but by how the worst one could. Leaving only the sheriff able to audit his own house, and no one able to audit him, is a gift to exactly that official — the case we made in Design for the Worst Sheriff.
Direction two: the states
At the same time, a legislative fight has opened over a genuinely hard question: if a state protects drivers’ captured location data, does that also mean hiding the records needed to audit how police use the system? States are answering differently — this is not a uniform retreat.
| State | Captured driver data secret? | Audit / use-data records? | Can the public tell who searched? |
|---|---|---|---|
| North Carolina | Captured plate data — § 20-183.32(e) | Not expressly addressed (disputed) | Rarely — agencies redact heavily |
| Florida | Yes — since 2014 (§ 316.0777) | Largely shielded | Generally no |
| Illinois | — | State Police ALPR & expressway data now FOIA-exempt (HB 3339) | Not for ISP records |
| Washington | Yes (2026 Act) | Kept public — audit trail carved out | Largely — disclosable (identifiers partly redacted) |
Two of these cut against the easy narrative. Florida’s ALPR secrecy is not a 2026 reaction — its records exemption dates to 2014 — and Florida just moved the other way on deployment: its Department of Transportation, under Gov. DeSantis, administratively pulled the right-of-way permits for license-plate readers on state highways. That was an executive action, separate from the records law. And Washington wrote the countermodel: its 2026 law makes captured plate data confidential but requires agencies to keep a use-record — who searched, their organization, the time, the stated purpose, the case number, the cameras accessed, exports and sharing, even the vendor’s own audit data — retained for two years, with the audit trail carved out of the confidential-data exemption. It is not a blanket public log: unique identifiers must be partially redacted before release, and the plate content of a query stays protected. But Washington did what North Carolina has not — it treated the record of how police use the system as a distinct, disclosable category from the drivers’ data itself. Which raises the question: if Washington can preserve a disclosable audit trail while still protecting drivers’ privacy, why can’t we?
These state decisions need not be coordinated with Flock’s, or with each other, for the effects to converge: Flock reduced what one agency can see about another’s searches, and some states reduced what the public can obtain from government. The result is the same accountability gap — the outsiders who uncovered repeated misuse have less to work with the next time.
And it comes home to New Hanover County
North Carolina has assembled most of a blackout without a new law. The confidentiality statute, N.C.G.S. § 20-183.32(e), makes captured plate data confidential and not a public record. But it does not expressly address Network Audit logs or every field they contain — the searching user or agency, a stated reason, or a plate entered as a search query. Agencies nonetheless withhold or redact plate-related fields, with the practical result that the public often cannot tell whether a particular plate was searched once or a thousand times. And agencies invoke the local-government personnel statutes (§§ 160A-168, 153A-98) to redact officer identities — though those statutes protect qualifying personnel files, do not expressly cover ALPR access logs, and in fact make an employee’s name public information. Whether an officer’s name in a Network Audit is protected is therefore a disputed statutory question, not one settled by any ALPR-specific decision.
We think the stronger reading of the statutes — consistent with North Carolina’s policy of liberal access to public records, see News and Observer Publishing Co. v. Poole, 330 N.C. 465, 475, 412 S.E.2d 7, 13 (1992) — is that an agency should not treat the label “Network Audit” as establishing a categorical exemption. The statutory question remains whether a particular record or field was compiled as criminal-investigation or criminal-intelligence information within § 132-1.4(a)–(b) — a document-by-document inquiry the Court of Appeals has said turns on the statutory definitions and the purpose in compiling each record (McCormick v. Hanson Aggregates Southeast, Inc., 164 N.C. App. 459, 596 S.E.2d 431 (2004)). No North Carolina appellate decision appears to have resolved that question for ALPR audit logs. That it is unsettled is part of the story: agencies are filling the gap with opposite answers, and several — Whiteville, Carolina Beach, Kure Beach, and NC A&T — have already treated these records as public.
Locally, the layers stack up:
- Durham has refused to release its Flock records at all, calling the entire audit part of a criminal investigation (§ 132-1.4) — the same position UNC-Chapel Hill took with us.
- New Hanover County produced its network audit — then redacted the searching-agency name (the field Flock still provides) across roughly three million searches. Residents can see the cameras were searched three million times, but not by whom.
- Wrightsville Beach claims the record no longer exists — a claim we do not accept at face value. Its counsel, Susan Renton, told us the Town has no organization or network audit to produce because “your requested time period for organization and network audits was outside of the software’s lookback period at the time your request was made” (Sept. 1, 2026). That is an assertion by the Town’s lawyer, not a demonstrated fact — we have not verified it, and it conveniently means no one can see who searched Wrightsville’s cameras. If it is true, it is a third way the records go dark: they expire before the public can ask. If it is not, it is simply another refusal dressed up as a retention limit. Either way, the public is left unable to check.
- The “transparency portals” in New Hanover, Brunswick, and Pender — real steps we credited — show reasons and counts but omit who actually ran the searches.
- And New Hanover’s Sheriff has said the public will learn of misuse only if he brings criminal charges — he described monthly audits he alone would review when Commissioner Stephanie Walker pressed him on August 25.
Each of these moves is announced as accountability; each one, in fact, removes a way the public had to hold the system to account — and none of it has to be coordinated to add up to the same result.
And the refusal may be hardening into a statewide rule. According to the Hendersonville Lightning (Sept. 2, 2026), Ron Justice — until his late-August retirement, counsel to the Henderson County Sheriff’s Office — said the SBI and the state Attorney General had determined that Flock audit logs are exempt from the Public Records Law because they could pertain to ongoing criminal investigations. That is a categorical claim over an entire class of records, asserted by state law-enforcement authorities. It is also contradicted by North Carolina agencies that treat these records as public: Whiteville produced four months of Network Audits that name the searching agencies, and Carolina Beach, Kure Beach, and NC A&T released native-CSV audits doing the same. That some North Carolina agencies release these records while others call them categorically exempt shows the state has no uniform standard — and it undercuts any claim that the records simply cannot be public. That position should be tested, not assumed.
A sample of how North Carolina agencies have responded. The list below is only a sample of the public-records requests DeFlockILM has filed across the state — but it shows the whole range, and it undercuts any claim that these records simply cannot be released. Some agencies handed over everything, quickly; others have handed over nothing.
| Agency | What happened |
|---|---|
| Full & complete | |
| UNC School of the Arts | Produced the full request in about three days, no charge |
| Carolina Beach | Full, unredacted production — contract, SBI MOU, camera map, and native-CSV audits that name every searching agency; the most complete we have received |
| Kure Beach | Complete file, including a 2.56-million-search network audit |
| NC A&T | Full Network Audit (1.39 million rows), searchers named (~11 days) |
| Whiteville PD | Four months of Network Audits, searchers named |
| Partial | |
| UNC Charlotte | Complete native-CSV Network Audit (3.7M searches) naming the agencies — but the “reason” field redacted |
| Brunswick County SO | Contract, policy, MOU, an account event log, and a public Search Audit portal — but the Organization and Network Audits are still outstanding (the subject of our deficiency letter to Staff Attorney Glenn Emery) |
| Withholding / exemption claim | |
| New Hanover County SO | Produced the audit, then redacted the searching-agency name across ~3 million searches |
| Wrightsville Beach | Claims no organization or network audit exists (outside the software’s “lookback period”) |
| Durham; UNC-Chapel Hill | Refused the audit entirely as a “criminal investigation” record |
| Henderson County SO | Per its former counsel, cites an SBI/AG position that audit logs are categorically exempt |
The top of that table is the answer to the bottom of it: transparency is not impossible here — several North Carolina agencies simply did it. The rest is a choice.
That last point collides with North Carolina’s own law, which requires each ALPR agency to adopt a written policy addressing annual or more frequent auditing and reporting of the system’s use and effectiveness to the head of the operating agency (§ 20-183.31(a)(7)). The state mandates internal auditing and reporting up the chain; it says nothing about telling the public. The unanswered question — the one worth putting to the Sheriff, every police chief, and the Attorney General — is: what does the public ever get to know about the results?
So here is the test that decides whether any of this is theater. Michael Canty’s 2,890 searches were found in Georgia’s public records. Ask it here:
If an outside officer searched the same New Hanover County resident’s plate 2,890 times over two years, what record — available to the public today — would reveal that pattern?
We think the honest answer is: none. We intend to ask the question formally, and to publish the answers.
Old logs are evidence, not a fix
None of this is solved by the records we already have. The pre-December-2025 logs sitting in public archives are worth preserving — they are the proof of what independent oversight looked like when it was still possible — but they are a snapshot of a window that is closing, not a remedy. They say nothing about the searches run today, or tomorrow, which are already flowing into records that are redacted, withheld, or, agencies now claim, no longer retained. And the trend is not improving: Flock keeps narrowing what its product exposes, and states keep narrowing what their laws require. Left alone, this gets worse, not better.
The most durable fix is a law that keeps the use-record public going forward — who searched, when, why, and which cameras — while protecting drivers’ captured data, along the lines Washington adopted. Other levers (litigation, agency policy, procurement terms, independent audits) can help sooner; but short of a statute, every change announced as “accountability” or a “crackdown on abuse” leaves the public with less ability to verify either.
And until that law exists, none of this moves on its own. The government is holding tight to its data, and voluntary transparency has not come. When a requester is denied access, § 132-9(a) authorizes an action in the General Court of Justice to compel disclosure, after the statute’s mediation step — and that is increasingly where these questions will be settled. The blackout described here is not going to be lifted by asking nicely. It will have to be tested, and in all likelihood ordered, by the courts. It starts, though, with the asking — and anyone can ask. If you want to know who has searched your own community’s cameras, our step-by-step guide to requesting Flock records walks you through filing a public-records request yourself.
The cameras were sold as accountability for the public. The least the public can ask is accountability for the cameras.
Questions & answers
Has Flock made it easier to detect misuse and abuse? Internally, somewhat; independently, no.
Flock’s Audit Assistance tool can help an agency police its own officers — it flagged the Covington detective’s recent searches. But it audits only an agency’s own users, it is opt-in, it looks only at 2026 forward, and it is proprietary — no outsider can verify what it catches or misses. And Flock’s December 2025 change stripped the officer’s name, the plate, and the open-text reason from cross-agency Network Audits — the fields outside reviewers used to catch abuse. Covington shows the gap: 41 flagged internally; 2,890 in the public record. For anyone outside the agency, detection got harder, not easier.
Have the states made it easier to detect misuse and abuse? No — several have made it harder.
Florida’s ALPR records have been confidential since 2014; Illinois (HB 3339) exempted the state police’s ALPR and expressway data from FOIA; and the Electronic Frontier Foundation has documented a wave of states moving to restrict what open-records laws reveal about ALPR use. The clear exception is Washington, which protected drivers’ data while keeping the use-record public — the model for how to do it right. On balance, the legislative trend for outside detection runs neutral to worse.
Has North Carolina made it easier to detect misuse and abuse? No.
North Carolina makes captured plate data confidential (N.C.G.S. § 20-183.32(e)); the statute does not expressly resolve whether an audit log’s query-plate field is disclosable, but in practice agencies withhold plate fields, so the public often cannot tell whether one plate was searched once or a thousand times. Agencies also invoke the personnel statutes to hide the searching officer’s name — a disputed question, since those statutes make an employee’s name public. New Hanover redacted the searching-agency name across roughly three million searches; and Durham and UNC-Chapel Hill withheld their audits entirely as criminal-investigation records. The Hendersonville Lightning reports that the SBI and the state Attorney General now treat Flock audit logs as categorically exempt criminal-investigation records — even though Whiteville, Carolina Beach, Kure Beach, and NC A&T have released such records. North Carolina law does require agencies to audit their own ALPR use and report to the agency head (§ 20-183.31(a)(7)); it does not require them to tell the public what those audits found.
Did Flock delete the audit logs, or narrow them?
Narrowed. As of the December 2025 change, Network Audits still show the searching agency, date, offense type, and a search identifier, but no longer the officer name, the plate, the vehicle fingerprint, or the open-text reason. The records did not vanish; their value as evidence of misuse dropped — and some agencies now claim the older logs were not retained at all.
What would actually fix it?
Not archiving old logs — that preserves evidence of what we have lost, but does nothing about the searches happening now. The most durable fix is a law that keeps the use-record public going forward, along the lines Washington adopted: protect drivers’ captured data, but require that who searched, when, why, and which cameras remain a public record. Litigation, procurement terms, agency policy, and independent audits can help sooner — but a statute is the cleanest.
Sources: Flock Safety customer email from SVP Chris Colwell, December 9, 2025 (full copy; published in Footnote4a’s “The Colwell Files”); USA TODAY, “Our Flock camera investigation sparks police firings, arrests” (Aug. 28, 2026) and follow-ups (Covington/Canty; Audit Assistance); Electronic Frontier Foundation, “Open Records Laws Reveal ALPRs’ Sprawling Surveillance. Now States Want to Block What the Public Sees” (Apr. 2026); Fla. Stat. § 316.0777; Reuters, “Florida bans highway license plate readers” (Sept. 3, 2026); Illinois HB 3339; Washington Driver Privacy Act (2026); N.C. Gen. Stat. §§ 20-183.31, 20-183.32; DeFlockILM analysis of North Carolina Flock Network Audits. General information for public discussion, not legal advice.
Related
You’re not a suspect. So stop being tracked like one.
It takes one minute. Add your name — then tell the officials who represent you to take the cameras down.
