In 1989, actress Rebecca Schaeffer was tragically murdered by a stalker who easily acquired her home address through California’s motor-vehicle records. This case highlighted the significant privacy and safety issues stemming from the accessibility of personal data held by state motor-vehicle departments. To address this, Congress passed the Driver’s Privacy Protection Act in 1994. The act aimed to restrict the dissemination and resale of personal information contained in these records, with specific exceptions for law enforcement and public safety purposes.
An irony exists in the history of this law. Congress initially addressed a technological problem. At that time, state motor-vehicle records became accessible due to advances in technology, while existing laws were outdated. Fast forward over 30 years, and technology has evolved once more. Companies like Flock Safety now collect license-plate information without relying on state motor-vehicle databases. According to Flock’s policies, their system captures images of license plates, vehicle characteristics, dates, times, and camera locations, negating the need for a DMV database.
This distinction is crucial. The Driver’s Privacy Protection Act governs personal information in state motor-vehicle records but does not apply to all vehicle data a private entity can gather on public roads. This situation raises significant questions: What happens when technology enables private companies to generate information for identification and tracking without accessing governmental records?
Envision driving past an automated camera on a public road. The camera records your license plate, passing time, and location. While one observation seems trivial, repeated observations can construct a detailed record of a vehicle’s whereabouts over time. Here, a private company generates a new database centered around a license plate, potentially placing it outside the act’s restrictions. Yet, the privacy concern that initially motivated Congress remains relevant. Automated license-plate readers have their purposes. Law enforcement uses them to locate stolen vehicles, investigate crimes, and address public-safety concerns, aligning with legitimate government interests. Privacy laws should facilitate law enforcement efforts without impeding their performance.
However, public safety should not automatically justify extensive surveillance. Key questions arise: What happens after recording? How long is the data kept? Who has access, and with whom can it be shared? Can data collected for one purpose be repurposed?
Flock Safety has begun addressing these concerns. On August 13, the company announced a reduction in the recommended default data retention period from 30 to 7 days. It implemented additional safeguards, like mandatory misuse detection, access controls, and accountability measures. This change warrants acknowledgment. A 7-day retention period is considerably shorter than 30 days, and their system automatically deletes data on a rolling basis. However, this is a recommended default, not a mandated limit. The actual retention period may vary based on the customer’s contract and relevant state or local laws.
This illustrates the need for a nuanced approach to public safety and privacy discussions. A fundamental difference exists between observing a vehicle on the road and maintaining a database with repeated observations. One is simple observation, the other could become historical data.
The Driver’s Privacy Protection Act did not grant Americans an absolute right to anonymity on public roads. Instead, it recognized the potential dangers of collecting, disseminating, and using identifying information without restrictions. Presently, technology offers another avenue to access movement data. Cameras can create records independent of government data. This does not necessitate banning automated license-plate readers. Instead, privacy laws should reflect current technological realities and aim to protect both public safety and personal privacy. Americans should not have to choose between the two when appropriate regulations can safeguard both. The Driver’s Privacy Protection Act was tailored for the technology of 1994; our privacy laws need to evolve for the technological landscape of 2026.
Shaun M. Simmons is a security professional with extensive experience in public safety, spanning private, state, and federal security sectors. He operates as an independent security contractor and grassroots political organizer in Canyon County, Idaho.
© 2026 Nexstar Media Inc. All rights reserved. This material is not authorized for publication, broadcasting, rewriting, or redistribution.
