Fresno Police | License plate readers
A state audit counted eight cameras, no fixed cameras, and 231 people with access to what they collected. The department had authorised sharing the images with 982 outside entities.
At a glance
- Cameras, as of 2019
- 8 mobile, 0 fixed [1]
- People with access to the data
- 231 [1]
- Entities the department had authorised to receive its images
- 982 [1]
- Vendor
- Vigilant Solutions, used since 2016 [1]
- Retention
- A minimum of one year by policy; images relevant to investigations are downloaded and kept longer [1]
- Sharing with immigration enforcement
- The audit found the department had never authorised sharing with an ICE agency, and was continuing to share with the Customs and Border Protection National Targeting Center [1]
- Review of system access logs
- The department confirmed to the auditor that it did not review them [1]
- Anything after February 2020
- unknown to us. Every figure here is from an audit published in February 2020 using data as of 2019. We have not found the department's own plate reader policy [1]
- Cost
- not stated in the audit [1]
How it happened
- Procurement
The department begins using Vigilant Solutions
The audit records 2016 as the date the department began using its current plate reader vendor. By the time of the audit the contract had not been updated for three years; it renewed each year when the department paid a service fee. [1]
- Coverage
The State Auditor publishes its review
Report 2019-118 examined plate reader programmes at four California agencies in detail. It found that none of the four had a policy containing all the information state law requires, and that three of them, this department among them, "did not completely or clearly specify who has system access, who has system oversight, or how to destroy ALPR data." [1]
Eight cameras, 231 people
The clearest thing in the audit is a table. Reproduced for the four agencies it examined:
| Agency | People with access | Fixed cameras | Mobile cameras | Vendor since |
|---|---|---|---|---|
| Fresno | 231 | 0 | 8 | 2016 |
| Los Angeles | 13,000 | 3 | 393 | 2007 |
| Marin | 38 | 0 | 3 | 2010 |
| Sacramento | 539 | 33 | 27 | 2012 |
Fresno had no fixed cameras at all. Eight cameras on vehicles, and two hundred and thirty-one people who could search what those cameras had collected.
The auditor draws no conclusion from that ratio and neither will we. Both numbers are its own, from agency survey responses as of 2019, and they sit next to each other in its table.
982
The department had authorised 982 outside entities to receive its plate reader images. Sacramento’s sheriff had authorised 1,119, Marin’s 554.
The audit’s description of who those entities were is the part worth reading twice:
we could not always ascertain how the agencies determined whether an entity receiving access to images had a right and need to access them or even whether the entity was a public agency. We reviewed the lists of entities and found one that appeared to be a non-public entity and others that were unidentifiable because they were listed only by initials.
The example it gives resolves in the agencies’ favour, and it belongs here for that reason. Fresno, Marin and Sacramento had all approved an entity listed as the Missouri Police Chiefs Association, which is a professional body rather than a public agency. When the auditor asked the vendor, it turned out the account was used by the Missouri State Highway Patrol, which is a police agency.
Nothing went where it should not have. The finding is the one the auditor draws:
Unless a law enforcement agency verifies each entity’s identity and its right to view the ALPR images, the agency cannot know who is actually using them.
Hawaii
All three Vigilant agencies had authorised sharing with the Honolulu Police Department. The auditor noted the distance, and the limited number of cars driving between California and Hawaii, and asked about it.
The report records the answer:
Fresno’s ALPR administrator agreed that not a great deal of thought went into its decision to share with the Honolulu Police Department, and he believes that it probably authorized the share because the entity was a law enforcement agency.
That is the auditor’s account of what the administrator said, not a direct quotation from him, and we are not naming him because the report does not.
It is also the most honest sentence in the document. It describes how a list of 982 gets to 982: not by a decision to share widely, but by the absence of a reason to say no to any particular request.
Immigration enforcement, both halves
The audit found something in this department’s favour that it did not find at two of the others:
In contrast, Fresno had never authorized any sharing relationship with an ICE agency.
Marin and Sacramento had. Sacramento’s administrator removed those shares while the audit was under way.
It also found this:
Fresno continues to share with the Customs and Border Protection National Targeting Center.
Sacramento had authorised the same share and removed it during the audit. All three Vigilant agencies were sharing with the San Diego Sector Border Patrol when the audit began, and none had put agreements in place after the Attorney General’s October 2018 guidance. The auditor’s summary is that the agencies “were either unaware of these guidelines or had not implemented them.”
Both of those sentences are about this department and both are on this page. Neither cancels the other.
What it did narrowly
Two findings run the other way and are worth stating plainly, because a page that lists only the problems is arguing rather than documenting.
The audit found Sacramento and Los Angeles adding names, addresses, dates of birth and criminal charges into their plate reader systems. Fresno is not in that sentence. The auditor reviewed six months of Fresno’s search records and “did not find personal information in combination with other sensitive information”, while noting that the possibility remains, since the search fields accept free text.
And on hot lists, the lists of plates the system watches for:
In contrast to its wide sharing of ALPR images, Fresno shares the hot lists it occasionally uploads with only three law enforcement agencies in the nearby region.
The same department shared images with 982 entities and hot lists with three. The audit does not explain the difference. It is a real one.
Who was watching the system
The audit’s security findings are about arrangements rather than incidents. No breach is described.
The department did not use the two-factor authentication its vendor offered — the auditor is careful that this is a best practice rather than a requirement for a system like this. It confirmed to the auditor that it did not review the logs showing which network addresses had accessed the system. And its main IT unit, in the auditor’s words, “does not manage user accounts or monitor access to the ALPR system”; that work sat with a separate analyst whose “background is not in network security.”
The contract had not been updated in three years, renewing each year on payment of a service fee. The auditor’s comment is general and applies to more than this department: agreements “not kept current may reflect outdated practices or omit needed assurances.”
The date on all of this
Every number and quotation above comes from a report published in February 2020, describing what auditors found in 2019. We do not know what changed afterwards.
We looked for the department’s own plate reader policy, which state law requires it to publish, and did not find one on its website or its transparency page. That is a statement about our search, not a finding about the department. Until someone reads a current policy, this page is a photograph of one year.
What we do not know
- What the department does today. Everything on this page describes what a state audit found in 2019 and published in February 2020. We have not found the department's current plate reader policy, and its transparency page carries no policy links at all.
- Whether the 982 sharing authorisations were reviewed after the audit, and how many remain.
- Whether the department still shares with the Customs and Border Protection National Targeting Center.
- How many cameras it operates now. Eight mobile cameras in 2019 is a small deployment, and small deployments are the ones that grow quietly.
- What the department told the auditor it would change. The report records that it responded it would use the audit to improve its policies; we have not read the response letters in full.
What you can do
Show up
Systems like this one are approved by boards, councils and committees that meet in public. We have not yet confirmed where each of them meets in Fresno County.
What we have documented in Fresno County →Protect yourself
Practical steps to shrink your personal data trail. Our guides publish at launch; until then, EFF's Surveillance Self-Defense is the best starting point.
Surveillance Self-Defense →Sources
- 1.
Get the digest
A regular digest of what changed in the world of surveillance: the counties we published, the devices that appeared on the map, and the public meetings where these decisions get made. We send it when there is enough to report.
One click to unsubscribe. What we do with your address is on the newsletter page.