The revelations about Alpharetta's expansive data-sharing practices are likely to intensify public scrutiny on the default settings and data governance policies of surveillance technology providers like Flock Safety. Expect increased calls for greater transparency from local municipalities regarding who has access to their data and under what circumstances. It is also probable that privacy advocates and civil liberties organizations will push for new legislation or local ordinances to regulate how such data is collected, stored, and shared, moving beyond the current patchwork of policies.

Image: courtesy of Wired
Beyond Alpharetta: How a Default Setting Quietly Built a National Surveillance Network
A recent analysis has revealed that Alpharetta, Georgia, a suburb with a population of 67,000, is sharing license plate data from its Flock Safety cameras with more than 2,000 organizations across the United States. This extensive data network includes federal agencies, colleges, airports, and even a Medicare fraud unit in Illinois, and has expanded significantly since June 2025. The primary driver behind this broad sharing is a 500-mile auto-approval default setting offered by Flock Safety, which allows police departments to automatically grant access to their data to other agencies within that radius.
Outlook
Background
Alpharetta, Georgia, is a relatively small suburb north of Atlanta, home to approximately 67,000 residents and served by about 120 police officers. Despite its size, the city has become a central node in a vast surveillance network, primarily through its use of Flock Safety's automated license plate recognition (ALPR) cameras. These cameras capture images of license plates, which are then stored and can be searched by authorized users.
What makes Alpharetta's situation particularly notable is the sheer scale of its data sharing. According to a WIRED public records analysis published on August 28, Alpharetta shares its camera data with over 2,000 distinct organizations. These are not just neighboring police departments; the list includes entities as diverse as federal agencies, university campuses, airport authorities, and specialized units like a Medicare fraud investigation team in Illinois and Florida's Fish and Wildlife Commission.
Crucially, this wide-ranging access is not the result of individual, explicit agreements with each of these 2,000+ entities. Instead, it is largely attributed to a default setting within the Flock Safety system that allows police departments to automatically approve data sharing requests from any agency within a 500-mile radius. This 'opt-out' rather than 'opt-in' approach has allowed the network to proliferate rapidly. Since June 2025, the number of entities receiving data from Alpharetta police has grown by roughly 42 percent, while the number of entities sending data to Alpharetta has seen an even larger surge, increasing by about 125 percent, now totaling over 1,300 entities.
Precedents
The rapid expansion of surveillance networks through default settings and broad data-sharing agreements echoes historical patterns in the adoption of new technologies by law enforcement. Throughout the past few decades, innovations from closed-circuit television (CCTV) cameras to facial recognition software have often been deployed first, with policy and public oversight lagging significantly behind.
Early adoption of technologies like DNA databases or even basic crime mapping software often began with limited local scope, only to expand exponentially as inter-agency cooperation became easier and the technical barriers to sharing data diminished. In many cases, the full implications for civil liberties and privacy were not thoroughly debated or legislated until years after the technology was already deeply embedded. The move from localized data collection to expansive, multi-jurisdictional networks often occurs quietly, driven by vendor default settings and the perceived efficiency benefits for law enforcement, rather than explicit public mandates or comprehensive regulatory frameworks.
The case of Alpharetta is not just about one suburb's surveillance practices; it highlights a fundamental tension between public safety goals and individual privacy in the digital age. When a relatively small local police department becomes a data hub for thousands of organizations, it creates a national-scale surveillance infrastructure that operates with minimal public transparency and potentially limited accountability.
For citizens, this means their movements, captured by license plate readers, can be tracked and compiled by an untold number of agencies, often without any suspicion of wrongdoing. The presence of a Medicare fraud unit or a fish and wildlife commission in this network raises questions about the scope creep of surveillance, where data collected for one purpose (e.g., local crime fighting) can be repurposed for entirely different, unrelated investigations.
This broad, default-driven data sharing also presents significant institutional challenges. It creates a complex web of data access that is difficult for local officials to fully comprehend or control, and even harder for the public to monitor. The lack of granular oversight for each data-sharing agreement means that the potential for misuse, data breaches, or the creation of comprehensive personal movement histories without judicial review becomes a much more tangible concern. The story of Alpharetta serves as a stark illustration of how technical defaults can quietly shape public policy and civil liberties on a grand scale.
Scenarios
AnalysisOne immediate outcome is likely to be increased pressure on Flock Safety to re-evaluate its default data-sharing settings. The company may face calls to switch from an 'opt-out' model, where data sharing is automatic unless specifically disabled, to an 'opt-in' model, requiring explicit approval for each new agency connection. This could significantly slow the organic growth of these networks.
A second outcome could involve local governments, particularly those using Flock Safety or similar ALPR systems, reviewing and potentially revising their data-sharing policies. Cities and counties may implement stricter local ordinances that limit the scope of data sharing, require public notification, or mandate periodic audits of who is accessing the data. This could lead to a more fragmented, but potentially more accountable, regulatory environment across different jurisdictions.
A third possibility is that privacy advocacy groups will intensify their legal and legislative efforts. This might include challenging the constitutionality of such widespread, untargeted surveillance or lobbying for federal or state laws that establish clear guidelines for ALPR data retention, access, and sharing. Such efforts could, over time, lead to a more standardized national approach to regulating this technology, rather than the current city-by-city discretion.
Timeline
Frequently Asked Questions
Discussion
Be the first to share your thoughts.