Policing Technology

ALPR Data Sharing With ICE: The New State Restrictions and What Agencies Need to Audit

Washington's SB 6002, Illinois enforcement action, and audits in Dayton and Chico show the same failure: agencies did not know who was querying their ALPR data. Here's the audit.

By IPA-IAC · 6 min · 6 August 2026

License plate reader camera mounted on a pole above a multi-lane roadway at dusk

The 2026 wave of ALPR controversies has a consistent shape, and it is not the one the headlines suggest. In case after case, the agency operating the cameras did not authorize immigration-enforcement queries, had a written policy prohibiting them, and learned they had happened anyway — from an audit, a public-records request, or a state regulator. The failure was not permission. It was visibility.

That distinction matters because it determines the remedy. A policy prohibiting a use does nothing if no one is reading the audit trail that would reveal the use occurring.

What Actually Happened

Dayton, Ohio. An audit found the city’s ALPR data had been searched more than 7,100 times for immigration-enforcement purposes — a use its own policy prohibited. The searches came from outside agencies querying through the shared network, not from Dayton officers. The city suspended the program and physically covered its cameras while it worked out what had happened.

Illinois. The Secretary of State’s office audited ALPR use statewide and found the vendor had facilitated U.S. Customs and Border Protection access to Illinois camera data, contrary to state law. Access was ordered shut off immediately. The finding came from a regulator’s audit, not from the agencies operating the cameras.

Chico, California. The police department disabled data sharing that, until July 8, appears to have violated California law, and the city opened an internal investigation. California already had among the strongest ALPR statutes in the country — SB 34 restricts sharing to in-state agencies, and the Values Act (SB 54) bars local assistance with federal immigration enforcement. Strong law did not produce compliance on its own.

Los Angeles. LAPD discontinued its Flock deployment after an audit reportedly found roughly one in three hot-list alerts were false. That is a separate problem from the sharing question, but it comes from the same root cause: nobody was measuring.

The Electronic Frontier Foundation has documented at least 53 cities across 20 states that terminated or declined ALPR contracts. Whatever one’s view of the technology, the procurement risk is now real and it is being driven by audit findings.

One correction worth making, because it circulates in the other direction: California’s SB 274, which would have tightened ALPR rules and mandated audits and deletion, was vetoed in 2025. It is not law. Agencies planning around it are planning around a bill that did not pass.

Washington’s SB 6002 Is the Detailed Model

Effective March 30, 2026, Washington enacted the most prescriptive ALPR statute in the country, and it is worth reading closely even outside Washington — it reads like a template other legislatures will borrow from.

Retention is tiered by purpose, not set as a single number:

PurposeRetention
Parking enforcement12 hours after final case disposition
All other cases (default)21 days
Traffic studies30 days
Commercial vehicle enforcement6 months
Criminal/civil casesDuration of the case, then deleted

The 21-day default is the shortest among states with operating ALPR programs, and it was lengthened from an even shorter original figure after law enforcement input.

Prohibited uses are enumerated. Immigration investigation and enforcement is barred under the Keep Washington Working Act (RCW 10.93.160). Agencies may not use ALPR data to obtain information about gender-affirming or reproductive health care lawful in the state, and may not track activity protected by the First Amendment or the state constitution.

Collection is barred at specified locations — health care facilities, immigration services providers, schools, places of worship, courts, and food banks.

Audit trails are mandatory and must be kept two years, capturing user identity, access date and time, and the stated purpose of each query.

Registration and certification. Systems had to be registered with the Attorney General by September 30, 2026, with compliance certification from agency heads. Local ALPR use policies are required by December 1, 2027, consistent with the AG model policy or documenting where they diverge.

Sharing and third-party access are constrained. Data may not be shared except in judicial proceedings or with authorized agencies, and accessing data held by a private entity requires a court-issued warrant.

The Audit

The pattern across every incident above is that the operating agency could not answer a simple question: who queried our data, when, and why? These are the checks that answer it.

1. Pull your own query log and read it. Not the vendor’s summary dashboard — the raw audit trail, including queries by external agencies against your cameras. Dayton’s 7,100 searches were visible in the data the whole time. If you cannot export a per-query log with requesting user, agency, timestamp, and stated purpose, that is your first finding, and it is a contract problem before it is a policy problem.

2. Enumerate every agency with access, and confirm each is authorized under your state’s law. National or regional lookup features frequently default to broad sharing. In several of these cases the agency believed it was sharing regionally while the platform’s default exposed data far wider. Verify against the actual access list, not the intended one.

3. Reconcile stated purposes against permitted purposes. Free-text purpose fields are worth little unless someone reads them. Sample them. A purpose field reading “ICE request” or “immigration” in a jurisdiction that prohibits the use is the finding regulators found.

4. Verify retention against your policy and your statute — in the system, not the document. Confirm deletion actually executes. Where retention is tiered by purpose, confirm the tiers are implemented rather than aspirational.

5. Establish whether your ALPR data are public records. A Washington court has held that Flock-captured data are subject to public disclosure, which changes both the retention calculus and the redaction workload. This interacts directly with existing FOIA and redaction obligations for other recorded media.

6. Check the accuracy of hot-list alerts. The LAPD finding is a reminder that a false-positive rate is a measurable quantity and that an unmeasured one tends to be worse than assumed. Alert accuracy is an operational metric, not a vendor claim, and it belongs in the same review as predictive-tool audit frameworks.

7. Determine who is accountable for the audit on a recurring schedule. Every incident here surfaced through an outside party. An annual internal review with a named owner is the difference between finding your own problem and having a regulator find it.

The Governance Point

ALPR sits in a category of systems whose value depends on data sharing and whose legal exposure is created by the same sharing. That tension does not resolve with a better policy document. It resolves with instrumentation — knowing, continuously, who is querying what and for which stated reason.

The shift toward proactive alerting makes this more urgent rather than less, because systems that generate suspicion rather than answer queries produce records that are harder to audit after the fact. Agencies that can produce a clean query log on demand are in a defensible position under any of these statutes. Agencies that cannot are exposed regardless of what their policy says, and regardless of whether their own officers did anything wrong. Dayton’s did not.