Independent desk

The Deep State Times

Institutional power. Public record. Official contradiction.

Surveillance

CBP task orders for Flock ALPR feeds outpace published privacy assessments

Federal procurement records list Customs and Border Protection awards for automated license plate reader services from Flock Safety while the Department of Homeland Security’s public privacy impact assessments lag or omit comparable operational detail. Officials have described the tools as investigative support; civil-liberties groups have cited the gap between contract language and published assessments.

The Times desk · September 12, 2026

CBP task orders for Flock ALPR feeds outpace published privacy assessments

Customs and Border Protection has, according to public procurement postings, issued task orders and related awards covering automated license plate reader services associated with Flock Safety. Those instruments sit in the ordinary stream of federal buying: statements of work, option years, and vehicle contracts that appear on government award systems rather than in classified annexes.

Published privacy impact assessments from the Department of Homeland Security and CBP describe license plate reader programs in general terms. They typically recap collection of plate images, time and location stamps, and sharing with partner agencies. The assessments available on agency websites do not, on their face, map one-to-one onto every task-order line item that procurement records list for Flock-related feeds.

The record shows a familiar sequence. Operational components award work against existing contract vehicles. Privacy offices later update or issue PIAs when a program is deemed to have changed in a way that triggers the E-Government Act process. Between those dates, the public file can show money obligated and services described while the corresponding assessment remains older, narrower, or silent on a particular vendor’s architecture.

Flock Safety markets cloud-hosted ALPR networks used by local police and, in some cases, connected to broader law-enforcement sharing. CBP’s public materials have long acknowledged plate-reader use at and between ports of entry, including mobile and fixed systems. Officials have said such systems support investigations, interdiction, and officer safety. They have not, in public testimony summarized in hearing records, treated vendor-specific task orders as classified in themselves.

Civil-liberties organizations and some members of Congress have pointed to the mismatch. They argue that a PIA written for a legacy CBP plate-reader program does not automatically cover a commercially networked product whose retention, hotspotting, and third-party access rules are set in a vendor’s terms and in a task order’s performance work statement. Agency privacy officers, in published FAQs and assessment preambles, have said they review new technologies when components notify them of a change in collection or sharing.

Procurement dockets do not substitute for privacy assessments. A task order can specify API access, geofence queries, or bulk historical search without the PIA spelling out those functions in the same vocabulary. Conversely, a PIA can describe “license plate reader data” at a high level while the award file names a company and a CLIN. Readers comparing the two files therefore see different layers of the same activity: dollars and deliverables on one side, statutory privacy paperwork on the other.

Inspectors general and the Government Accountability Office have, in prior reports on DHS information sharing and border technology, noted delays between fielding a capability and completing required privacy documentation. Those reports did not uniquely target Flock. They described a pattern in which operational urgency and contract vehicles move faster than the publication cycle for PIAs and system-of-records notices.

CBP’s published privacy notices continue to state that plate data may be retained for defined periods, shared with federal, state, and local partners, and used for law-enforcement purposes. They caution that the agency does not rely on a single commercial product for all plate collection. Flock’s own public materials describe customer-controlled sharing and audit logs. Neither set of documents, as posted, functions as a complete crosswalk to every CBP task order.

The practical effect is documentary. Journalists, auditors, and litigants can pull award numbers and statements of work from procurement systems. They can pull PIAs from dhs.gov. Aligning them requires inference: which award funds which feed, which retention clock applies, which sharing agreement is in force. The agencies have not published a single table that closes that loop.

Oversight committees have asked DHS components to inventory commercial ALPR relationships and to refresh PIAs when new vendors or new query types enter production. Public responses have been high-level: the department says it complies with privacy statutes and that operational details may be withheld when they would reveal techniques. That stance leaves the published assessments as the main official account, even when they predate a given task order.

Nothing in the open record establishes that a particular CBP Flock award was hidden. The awards appear in the same databases as other services contracts. What the record does show is asynchronous paperwork: buying documents that name a capability and a vendor, and privacy assessments that describe a class of systems without matching the award’s specificity. Until those files are updated in tandem, the public comparison remains incomplete by design of the publication calendars, not by a claimed secret annex.

Further awards, option exercises, or PIA revisions would appear in the same channels. Until they do, the gap between task-order language and the last posted assessment is the fact the dockets already display.