Privacy Alert 25-01 – DRAFT
Date: January 30, 2025
Subject: Automatic License Plate Readers (ALPRs)
What Are Automatic License Plate Readers?
Automatic License Plate Readers (ALPRs) are high-speed camera systems used to capture and analyze license plate information from vehicles. These systems, often employed by governmental entities, collect data from moving or parked vehicles for purposes such as law enforcement, traffic management, and parking enforcement.
Key Privacy Concerns
- Data Collection: ALPRs capture license plate numbers, locations, times, and other metadata. In some cases, they also record details like bumper stickers or vehicle customization, which can reveal personal information or associations.
- Data Retention: Data retention can vary by location, and it is often stored for extended periods, even for individuals not under investigation, increasing the risk of misuse or unauthorized access.
- Sharing and Misuse: Data can be shared between agencies or with third parties without adequate restrictions, leading to potential overreach.
- Surveillance and Chilling Effect: The widespread use of ALPRs may discourage lawful activities by creating a perception of constant surveillance, impacting public trust, and individual freedom.
Lessons from Recent ALPR Exposures
Improper configurations of ALPR systems, such as leaving them connected to public networks without authentication, have led to severe privacy breaches. For example, real-time footage and vehicle data from ALPR cameras were unintentionally exposed online due to misconfigured systems that lacked authentication, allowing anyone with internet access to view live video feeds and access detailed logs of vehicle movements, including license plates, makes, and models.
Best Practices for Protecting Privacy with ALPRs
- Transparency: Clearly publish policies on ALPR usage, including data collection, retention, and sharing practices.
- Data Minimization: Collect only what is necessary and retain data only as long as needed for lawful purposes.
- Access Controls: Restrict access to ALPR data to authorized personnel with robust authentication protocols.
- Regular Audits: Conduct routine system audits to ensure security configurations are strong and policies are being followed.
- Network Security: Keep ALPR systems off public networks and ensure proper encryption and authentication are in place.
- Public Awareness: Inform the public about how ALPR systems are used and their individual rights related to ALPR data.
Your Role as a Resident
As a resident of Utah, you have the right to understand how your data is being collected, used, and shared by the government, under the Governmental Data Privacy Act. You can inquire about your local government’s ALPR notices and related privacy policies. Stay informed about how ALPR systems are used in your community and advocate for strong privacy protections, including limits on data retention and sharing.
For Governmental Entities
- Review and strengthen ALPR system security configurations.
- Eliminate unnecessary data collection or retention practices.
- Include clear privacy policies and disclosures in your notices.
- Ensure compliance with the Governmental Data Privacy Act and conduct regular system reviews to identify vulnerabilities.
For more information or to report concerns about ALPR use, contact the State Privacy Office at privacy@utah.gov.