Privacy Is Part of Public Safety: Why I Oppose Flock
A trip down Telegraph Avenue should not become a government record of where you were, when you were there, and which direction you traveled. Students cross Bancroft on the way to class. Workers travel down Durant. People visit friends, go to medical appointments, attend meetings, join protests, shop, and return home. Those ordinary movements should not be placed in a searchable database without cause.
That is why I have opposed Berkeley's use of Flock automated license plate readers and the larger surveillance system proposed around them. Privacy is a human right. It is also part of public safety.
This debate is about more than one company. It is about what Berkeley collects, who can read it, how long it exists, how it can be combined with other information, and whether every person should be recorded before the City has any reason to investigate them.
My public record
I first spoke publicly about Flock in March. On March 16, during a Berkeley Copwatch bike tour, I told The Daily Californian that surveillance without meaningful consent undermines public safety. Safety also means food, housing, health, and the ability to move through the city without feeling watched.
On March 24, I went before the Berkeley City Council. I identified cameras near Telegraph and Bancroft and along Durant, raised the danger to students and sanctuary communities, and urged Council to delay or reject the proposed expansion. I said plainly: Flock is not the answer.
At the time, Council was considering a much larger package that could have joined automated license plate readers with drones, fixed surveillance cameras, investigative software, and private community video streams. After extensive public opposition, Council delayed the decision.
When the item returned on May 7, Council declined to approve that full package. It still authorized a 12-month extension of the existing license plate reader network for up to $200,000 and directed staff to run a competitive procurement process.
I returned to Council that night. I said that ordinary public life should not become permanently searchable. Surveillance does not lower rent, house people, remedy inequality, or restore trust. I asked Council to vote no. I also said that any future technology would need strict limits, independent oversight, transparency, public ownership, and end-to-end encryption.
On June 30, I opposed an investigative platform that could combine police records, license plate data, drones, fixed cameras, open-source information, private video, and future systems. When unreliable inputs are combined, they can become official-looking leads with serious consequences for an innocent person. The City also has to account for the full cost while homelessness services, mental-health response, maintenance, lighting, restrooms, and other basic needs remain underfunded.
I carried the same position into my campaign. In May, I wrote that Southside needs safety without fear-driven surveillance. In July, I argued that Berkeley must establish rules before procurement: who can use a system, for what purpose, what data is kept, who can receive it, and who checks for abuse. In August, I opposed networked mass surveillance in a public questionnaire and at a public candidate forum.
On September 27, I signed the Berkeley Against Mass Surveillance pledge. I committed to opposing the approval, renewal, expansion, or continuation of mass surveillance and to working to remove Berkeley's existing Flock readers. I also signed a joint candidate letter asking Council to stop expanding mass surveillance, dismantle the existing system, and leave any post-election decision to the newly seated Council.
My position has developed through public testimony, research, and community discussion. Its direction has remained consistent: Berkeley should not build public safety around the routine collection of everyone's movements.
What Berkeley decided, and what remains unresolved
Berkeley did not approve the full Flock expansion in May. That distinction matters. Council kept the existing license plate reader network temporarily, required stronger protections, and opened a competitive process that covers six categories of public-safety technology. The City's request for proposals includes automated license plate recognition, fixed cameras, two types of drones, community video-stream integration, and investigative software. The City may select multiple vendors or none.
Changing vendors would not resolve the underlying issue if a replacement still creates a searchable history of ordinary travel. The policy must be based on what the system does, the information it keeps, and who can obtain it.
The sanctuary issue also requires precision. Berkeley's 2025 audit reported no direct federal or out-of-state search of Berkeley's Flock network during the audited period. It identified three statewide searches whose stated reasons referenced ICE or CBP and reported that those searches did not target Berkeley. Berkeley later disabled statewide lookup and narrowed outside access.
Those findings do not prove that local policy is meaningless. They show why technical controls and data minimization matter. Federal agencies use commercial license plate databases. A city that promises sanctuary should reduce the amount of location data available for search, sharing, legal demands, credential compromise, or misuse.
Berkeley has also attributed arrests, assisted investigations, and stolen-vehicle recoveries to Flock. Those outcomes should be examined seriously. The City still needs to answer the proportionality questions: How many total plate reads and unique vehicles produced those results? How many alerts were wrong or stale? How many cases could have been handled through narrower methods? What are the complete costs, including staff time, auditing, integration, procurement, and legal risk? What happens to public trust when ordinary movement is routinely recorded?
A list of successful cases does not answer whether citywide collection is necessary or whether a less intrusive method could achieve the same goal.
Encryption is necessary, and it is not enough by itself
I support end-to-end encryption because sensitive data should never travel or sit in storage unprotected. The phrase can also hide an important question: who holds the keys?
Flock's published policy says its license plate data is encrypted from the camera to cloud storage. Its current information-security addendum also says that Flock controls decryption and the management of encryption keys. That means the vendor's system can decrypt the data when authorized by its design, contract, or legal obligations.
My standard is stronger. If Berkeley ever considers a citywide vehicle-safety service, the City must control the entire security boundary. The vendor, cloud host, outside agencies, and unauthorized City personnel must be unable to decrypt routine data. City-controlled keys, strict access roles, and public audit logs would be mandatory.
Existing products show that pieces of a more private design are technically possible, but they do not establish that a turnkey municipal system meeting this standard is available. The legacy OpenALPR library can be run locally under an open-source license. Predator is open source and can operate offline, but its own documentation describes it primarily as a dash-camera platform and warns against relying on it for security-critical work. Plate Recognizer offers an on-premise software development kit that can process images without an internet connection after setup. IncoreSoft advertises on-premise deployment and encrypted data packages. None of those public materials establishes a system in which Berkeley alone controls the decryption keys from camera to authorized user.
Secluso demonstrates a different and useful concept: an open-source Raspberry Pi home-security camera with end-to-end encrypted remote access through an untrusted relay. That is evidence that a service provider can be designed so it cannot read the video passing through its infrastructure. It is not a municipal license-plate-reader product, and Berkeley should not treat it as one without engineering, security, civil-liberties, and procurement review.
Even City-controlled encryption would not justify keeping a general history of everyone's travel. Encryption protects data from some forms of unauthorized access. It does not correct excessive collection, a false match, an authorized but abusive search, or a lawful demand for information that should never have existed.
For a future system to be considered, it would have to avoid creating a mass-surveillance archive. The safest design would compare a plate on the device against a narrow, verified list tied to serious incidents or stolen vehicles. A non-match would be deleted immediately, before it entered any citywide database. Only a confirmed, case-related alert could be retained, with human verification, a written purpose, supervisory approval, and a complete access log.
I would also require:
City ownership and City-exclusive control of encryption keys;
no regional bulk sharing and no voluntary access for civil immigration enforcement;
no facial recognition, predictive policing, behavioral profiling, association mapping, risk scoring, or automated enforcement;
independent security and civil-liberties testing before deployment;
public reporting on alerts, false matches, searches, sharing, retention, cost, and outcomes;
a short sunset date that ends the authority unless Council renews it after a public review; and
a verified shutdown and deletion process written into the contract before any equipment is installed.
If a proposed service cannot meet those standards, Berkeley should not buy it. A system that retains every scan so it can reconstruct a person's movements later would remain mass surveillance, even if the database were encrypted.
What I will do when elected
When elected, I will seek lawful termination of Berkeley's current Flock network, or firm nonrenewal if immediate termination is not legally or financially responsible. I will ask for a public inventory of every camera, account, integration, outside access path, retention rule, case hold, and contract obligation.
The City should preserve evidence lawfully held for a specific case. Routine detections should be deleted, outside access should be closed, integrations should be disconnected, and completion should be independently verified. Berkeley should publish what was done without exposing private case information or creating a new map for misuse.
Before the City considers any replacement, Council should define the need, evaluate non-surveillance alternatives, publish a data-flow map, calculate the full cost, conduct a civil-rights review, set measurable standards, and establish an expiration date. The rules should come before procurement.
Public safety work must continue. Berkeley can investigate serious harm with case-specific warrants, trained investigators, victim support, traffic-safety design, reliable lighting, mental-health response, and services that address the conditions residents face every day. Technology may assist a narrow investigation. It should not become the operating system for public life.
People should be able to move through Southside, seek care, visit a friend, attend a protest, go to work, and participate in civic life without routine location tracking.
Privacy is a human right. Flock is not the answer. Berkeley should end the current network and refuse any future system that cannot protect that principle in its technical design, its governing rules, and its daily operation.
-
A trip down Telegraph Avenue should not become a government record of where you were, when you were there, and which direction you traveled. Students cross Bancroft on the way to class. Workers travel down Durant. People visit friends, go to medical appointments, attend meetings, join protests, shop, and return home. Those ordinary movements should not be placed in a searchable database without cause.
That is why I have opposed Berkeley's use of Flock automated license plate readers and the larger surveillance system proposed around them. Privacy is a human right. It is also part of public safety.
This debate is about more than one company. It is about what Berkeley collects, who can read it, how long it exists, how it can be combined with other information, and whether every person should be recorded before the City has any reason to investigate them.
My public record
I first spoke publicly about Flock in March. On March 16, during a Berkeley Copwatch bike tour, I told The Daily Californian that surveillance without meaningful consent undermines public safety. Safety also means food, housing, health, and the ability to move through the city without feeling watched.
On March 24, I went before the Berkeley City Council. I identified cameras near Telegraph and Bancroft and along Durant, raised the danger to students and sanctuary communities, and urged Council to delay or reject the proposed expansion. I said plainly: Flock is not the answer.
At the time, Council was considering a much larger package that could have joined automated license plate readers with drones, fixed surveillance cameras, investigative software, and private community video streams. After extensive public opposition, Council delayed the decision.
When the item returned on May 7, Council declined to approve that full package. It still authorized a 12-month extension of the existing license plate reader network for up to $200,000 and directed staff to run a competitive procurement process.
I returned to Council that night. I said that ordinary public life should not become permanently searchable. Surveillance does not lower rent, house people, remedy inequality, or restore trust. I asked Council to vote no. I also said that any future technology would need strict limits, independent oversight, transparency, public ownership, and end-to-end encryption.
On June 30, I opposed an investigative platform that could combine police records, license plate data, drones, fixed cameras, open-source information, private video, and future systems. When unreliable inputs are combined, they can become official-looking leads with serious consequences for an innocent person. The City also has to account for the full cost while homelessness services, mental-health response, maintenance, lighting, restrooms, and other basic needs remain underfunded.
I carried the same position into my campaign. In May, I wrote that Southside needs safety without fear-driven surveillance. In July, I argued that Berkeley must establish rules before procurement: who can use a system, for what purpose, what data is kept, who can receive it, and who checks for abuse. In August, I opposed networked mass surveillance in a public questionnaire and at a public candidate forum.
On September 27, I signed the Berkeley Against Mass Surveillance pledge. I committed to opposing the approval, renewal, expansion, or continuation of mass surveillance and to working to remove Berkeley's existing Flock readers. I also signed a joint candidate letter asking Council to stop expanding mass surveillance, dismantle the existing system, and leave any post-election decision to the newly seated Council.
My position has developed through public testimony, research, and community discussion. Its direction has remained consistent: Berkeley should not build public safety around the routine collection of everyone's movements.
What Berkeley decided, and what remains unresolved
Berkeley did not approve the full Flock expansion in May. That distinction matters. Council kept the existing license plate reader network temporarily, required stronger protections, and opened a competitive process that covers six categories of public-safety technology. The City's request for proposals includes automated license plate recognition, fixed cameras, two types of drones, community video-stream integration, and investigative software. The City may select multiple vendors or none.
Changing vendors would not resolve the underlying issue if a replacement still creates a searchable history of ordinary travel. The policy must be based on what the system does, the information it keeps, and who can obtain it.
The sanctuary issue also requires precision. Berkeley's 2025 audit reported no direct federal or out-of-state search of Berkeley's Flock network during the audited period. It identified three statewide searches whose stated reasons referenced ICE or CBP and reported that those searches did not target Berkeley. Berkeley later disabled statewide lookup and narrowed outside access.
Those findings do not prove that local policy is meaningless. They show why technical controls and data minimization matter. Federal agencies use commercial license plate databases. A city that promises sanctuary should reduce the amount of location data available for search, sharing, legal demands, credential compromise, or misuse.
Berkeley has also attributed arrests, assisted investigations, and stolen-vehicle recoveries to Flock. Those outcomes should be examined seriously. The City still needs to answer the proportionality questions: How many total plate reads and unique vehicles produced those results? How many alerts were wrong or stale? How many cases could have been handled through narrower methods? What are the complete costs, including staff time, auditing, integration, procurement, and legal risk? What happens to public trust when ordinary movement is routinely recorded?
A list of successful cases does not answer whether citywide collection is necessary or whether a less intrusive method could achieve the same goal.
Encryption is necessary, and it is not enough by itself
I support end-to-end encryption because sensitive data should never travel or sit in storage unprotected. The phrase can also hide an important question: who holds the keys?
Flock's published policy says its license plate data is encrypted from the camera to cloud storage. Its current information-security addendum also says that Flock controls decryption and the management of encryption keys. That means the vendor's system can decrypt the data when authorized by its design, contract, or legal obligations.
My standard is stronger. If Berkeley ever considers a citywide vehicle-safety service, the City must control the entire security boundary. The vendor, cloud host, outside agencies, and unauthorized City personnel must be unable to decrypt routine data. City-controlled keys, strict access roles, and public audit logs would be mandatory.
Existing products show that pieces of a more private design are technically possible, but they do not establish that a turnkey municipal system meeting this standard is available. The legacy OpenALPR library can be run locally under an open-source license. Predator is open source and can operate offline, but its own documentation describes it primarily as a dash-camera platform and warns against relying on it for security-critical work. Plate Recognizer offers an on-premise software development kit that can process images without an internet connection after setup. IncoreSoft advertises on-premise deployment and encrypted data packages. None of those public materials establishes a system in which Berkeley alone controls the decryption keys from camera to authorized user.
Secluso demonstrates a different and useful concept: an open-source Raspberry Pi home-security camera with end-to-end encrypted remote access through an untrusted relay. That is evidence that a service provider can be designed so it cannot read the video passing through its infrastructure. It is not a municipal license-plate-reader product, and Berkeley should not treat it as one without engineering, security, civil-liberties, and procurement review.
Even City-controlled encryption would not justify keeping a general history of everyone's travel. Encryption protects data from some forms of unauthorized access. It does not correct excessive collection, a false match, an authorized but abusive search, or a lawful demand for information that should never have existed.
For a future system to be considered, it would have to avoid creating a mass-surveillance archive. The safest design would compare a plate on the device against a narrow, verified list tied to serious incidents or stolen vehicles. A non-match would be deleted immediately, before it entered any citywide database. Only a confirmed, case-related alert could be retained, with human verification, a written purpose, supervisory approval, and a complete access log.
I would also require:
City ownership and City-exclusive control of encryption keys;
no regional bulk sharing and no voluntary access for civil immigration enforcement;
no facial recognition, predictive policing, behavioral profiling, association mapping, risk scoring, or automated enforcement;
independent security and civil-liberties testing before deployment;
public reporting on alerts, false matches, searches, sharing, retention, cost, and outcomes;
a short sunset date that ends the authority unless Council renews it after a public review; and
a verified shutdown and deletion process written into the contract before any equipment is installed.
If a proposed service cannot meet those standards, Berkeley should not buy it. A system that retains every scan so it can reconstruct a person's movements later would remain mass surveillance, even if the database were encrypted.
What I would do when elected
When elected, I will seek lawful termination of Berkeley's current Flock network, or firm nonrenewal if immediate termination is not legally or financially responsible. I will ask for a public inventory of every camera, account, integration, outside access path, retention rule, case hold, and contract obligation.
The City should preserve evidence lawfully held for a specific case. Routine detections should be deleted, outside access should be closed, integrations should be disconnected, and completion should be independently verified. Berkeley should publish what was done without exposing private case information or creating a new map for misuse.
Before the City considers any replacement, Council should define the need, evaluate non-surveillance alternatives, publish a data-flow map, calculate the full cost, conduct a civil-rights review, set measurable standards, and establish an expiration date. The rules should come before procurement.
Public safety work must continue. Berkeley can investigate serious harm with case-specific warrants, trained investigators, victim support, traffic-safety design, reliable lighting, mental-health response, and services that address the conditions residents face every day. Technology may assist a narrow investigation. It should not become the operating system for public life.
People should be able to move through Southside, seek care, visit a friend, attend a protest, go to work, and participate in civic life without routine location tracking.
Privacy is a human right. Flock is not the answer. Berkeley should end the current network and refuse any future system that cannot protect that principle in its technical design, its governing rules, and its daily operation.
Sources
The Daily Californian, Berkeley Copwatch bike tour, March 16, 2026
City of Berkeley, March 24, 2026 public-safety technology proposal
Bay Area News Group coverage of the March 24 meeting, republished by Government Technology
OpenALPR, open-source automatic license plate recognition library
Predator, open-source offline-capable dash-camera and ALPR platform
Plate Recognizer, Snapshot cloud and on-premise deployment documentation
Secluso, open-source end-to-end encrypted home-security camera
Aidan Hill, “Southside Issues Brief: Telegraph Should Not Wait,” July 5, 2026
The Daily Californian, surveillance and public-space comments, July 13, 2026
Paid for by Aidan Hill for Berkeley City Council 2026, FPPC ID# 1481885.
Paid for by Aidan Hill for Berkeley City Council 2026, FPPC ID# 1481885.

