Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Surveillance Technology topic
No spam. Unsubscribe anytime.
Denver officials defend limits on Flock license-plate data as council demands audits and clearer rules
Summary
City officials told the Health & Safety Committee they have narrowed access to Flock ALPR data, added contractual penalties and will remove certain vendor data uses; councilmembers pressed for unredacted audit logs, subpoena records and a privacy ordinance from the task force.
Get email alerts on the Surveillance Technology topic
No spam. Unsubscribe anytime.
Denver City Council's Health & Safety Committee heard a detailed briefing Oct. 29 from the Mayor's Office, Denver Police Department and Technology Services on the surveillance technology task force and a recent administrative extension of the city's contract with Flock, a license-plate reader vendor.
The mayor's office said it has closed off national searches of Denver's Flock data and limited access to the Denver Police Department, added a dropdown of restricted search reasons tied to Colorado or Denver-specific criminal conduct, prohibited searches tied to immigration or reproductive-health matters, and inserted a $100,000 contractual penalty for improper disclosure. "We turned off access to all jurisdictions other than jurisdictions within the state of Colorado," Tim Hoffman, director of policy in the Mayor's Office, said during the briefing.
Why it matters: councilmembers and task-force members said those steps are necessary but insufficient without meaningful transparency. Councilmember Sarah Paradis (at-large), a task-force member, said the group has not been given unredacted audit logs or a full picture of who used the system. "I finally learned last week that 1,300 people have logged logins to the Denver system," Paradis said, pressing for audit access and clear user accountability.
What officials told council - Commander Cliff Barnes (DPD) described the Cyber Bureau's intake process for technology: vendor risk assessments, a Technical Architecture Review and coordination with Technology Services and the city attorney. He said policy controls for each tool are published in the DPD operations manual before deployment.
- Tara Segura (Technology Services) outlined an enterprise vendor-risk workflow that brings security, architecture, ADA and records stakeholders into an automated assessment to identify and mitigate risk through contract terms or operational changes.
- Tim Hoffman said the city discovered Denver's data had been visible beyond the state and has since restricted external access; he said the city is negotiating contract changes to remove a clause that would allow the vendor to use anonymized agency data to train models.
What DPD said about outcomes Commander Jake Rivera (DPD) displayed a map and five case examples where the ALPR system aided investigations, including identifying suspects in shootings and enabling rapid, real-time alerts that led to arrests. "The Flock system has been used to investigate, arrest, and prosecute the most serious crimes against Denverites in every single council district," Rivera said, citing several vignettes across council districts.
Council concerns and requests Multiple councilmembers urged stronger oversight. Councilmember Sarah Gonzalez Gutierrez (at-large) and others said the task force should produce policy recommendations and, if needed, draft an ordinance to govern data-sharing and privacy citywide.
Council president Sandoval said she had met with Flock's CEO and demanded proof of retention and deletion practices; she said company assurances were insufficient without verifiable audit trails. Several councilmembers asked whether the vendor has responded to subpoenas or evidence requests and whether the city's contract still allows the vendor to retain or use de-identified data; administration officials said they had told Flock to remove the anonymized-data clause and would confirm the final contract language.
Process and next steps Councilmembers criticized the task force process for lacking advance agendas, shared materials and a consistent record of audits and access logs. Members asked for a site visit to the real-time crime center and for DPD and Technology Services to provide the task force with the documents and audit logs needed to evaluate use. Chair Daryl Watson requested an interim task-force report and a timeline for follow-up; the committee adjourned with no votes taken.
Authorities and data points The briefing repeatedly referenced the DPD operations manual (cited in the meeting as section 119 and as section 19.03 for ALPRs) and the existing Flock contract. Councilmembers cited specific contract clauses (sections 4.2, 4.3 and 5.3) when asking whether the vendor can use agency data for product development or disclose footage during retention periods. The administration said it was negotiating removal of the anonymized-data clause and adding notification and penalty provisions, including a $100,000 penalty for improper disclosure and an opt-out requirement for automatic enrollment in new programs.
What remains unresolved Councilmembers asked for: unredacted audit logs showing search histories and user IDs; a count of subpoenas or external evidence requests disclosed to Flock; confirmation of whether the vendor has ever shared Denver images in response to external legal process; and clearer retention and compensation policies for people harmed by erroneous identifications. The administration committed to follow-up and to return with more information; the task force will produce an interim report and may reconvene before the end of the year.
The meeting closed with no formal votes. The committee asked the administration and DPD to provide the requested documents and timeline for the task force's interim report.
