The short version: the single most effective, entirely lawful lever ordinary people and researchers have against ALPR, device-signature sensors, real-time crime centers, and the rest of the surveillance stack is the public-records request. It forces an agency to put in writing what it bought, what it keeps, who it shares with, and whether anyone is auditing any of it. Below is a plain-English guide to who to ask, what to ask for, and the exemption traps that get requests denied — plus a generator that builds a scoped request for your technology and state. Ask for the contracts and policies, not the raw data; that’s the line between a request that gets filled and one that gets rejected.

Why records requests are the real lever

Every technology Max Intel covers has one thing in common: it was bought with public money, operated under a written policy (or the conspicuous absence of one), and governed by a contract someone signed. All of that is presumptively public. A well-formed request converts a vague community worry — “are they tracking us?” — into a document an agency has to produce or specifically refuse. That is how the Flock cancellation wave actually happened: audits in Mountain View and Oxnard surfaced illegal federal data-sharing because someone obtained the records that showed it. Reporting and records requests, not jammers or gadgets, are what move city councils.

A word on the “increase their workload” theory — stated plainly, because you deserve a straight answer. It is true that a volume of well-formed requests raises the administrative cost of holding surveillance tech, and that cost is a legitimate part of the public-accountability calculus: if a department cannot answer basic questions about what it collects and who it shares with, that is itself the finding. But aim this as transparency, not as a denial-of-service attack. Requests written to bury a clerk — sprawling, duplicative, deliberately vague — get denied as unduly burdensome, poison the well for the next requester, and in some states expose you to bad-faith arguments. A focused request that a small agency genuinely struggles to answer tells the public something real. A junk request just tells the agency to ignore you. Precision is both more ethical and more effective. The generator below is tuned for focus for exactly this reason.

Who to send it to (routing is half the battle)

The most common reason a request dies is that it went to the wrong body. Match the technology to the custodian:

  • Local police / sheriff. The default for ALPR, RTCC/Fusus, gunshot audio, drones, and facial recognition operated at the city or county level. Address the records custodian or public-information officer, not an individual officer.
  • State police / state agencies. For statewide ALPR networks, fusion centers, and DMV-image access. Governed by your state public-records law.
  • City / county government (not the PD). Procurement records, purchase orders, and council-approval materials often sit with the city clerk, procurement office, or manager — sometimes easier to get there than from the police department.
  • Federal agencies — use federal FOIA, and only here. CBP, ICE, and the FBI respond to the federal Freedom of Information Act. This is the single most common mistake: local police are not subject to federal FOIA — they answer to your state law. Sending a “FOIA request” to a city PD invites a brush-off on a technicality.
  • The vendor is not a records target — but the agency’s contract with the vendor is. You cannot FOIA Flock or Leonardo; you can obtain the signed contract from the agency that bought their product.

Not sure which agencies even operate cameras near you? Start from the map — our state-by-state ALPR dataset and surveillance-mapping walkthrough help you identify the operating agency before you write.

What to ask for — the seven records that matter

Across every technology, the same categories carry the accountability weight. This is the pattern EFF, the ACLU, and MuckRock requesters have refined over years of ALPR requests:

  1. Contracts, quotes & renewals with the vendor — the price, the term, and what was actually purchased.
  2. Use / access policy — the written rules (or proof there aren’t any).
  3. Retention schedule — how long data is kept and when it’s deleted.
  4. Data-sharing agreements — especially any MOU touching federal, ICE, CBP, or a national lookup network. This is where the abuses have surfaced.
  5. Records of outside access — how many outside agencies searched the data, and whether access is logged at all.
  6. Audit & misuse records — audits performed, violations found, discipline imposed.
  7. Aggregate counts — detections, hits, alerts, or searches, which reveal scale without touching anyone’s private data.

The exemption trap (read this before you send)

Here is the mistake that gets ALPR requests denied wholesale: asking for the data instead of the documents about the data. In many states the raw captured feed is confidential by statute — for example, North Carolina makes captured plate data confidential under N.C. Gen. Stat. § 20-183.32, but contracts, policies, camera counts, retention schedules, data-sharing agreements, and audit summaries remain generally public. If you ask for “all license plate reads,” you hand the agency an easy, total denial. If you ask for the contract, the retention policy, and the sharing MOUs, you’re requesting exactly the material that’s designed to be disclosable.

Two more phrasings that materially improve outcomes, both drawn from seasoned requesters: ask for segregability — that any exempt portion be redacted and the rest produced, rather than a document withheld in full — and offer to narrow. EFF’s own California templates explicitly tell agencies that the tighter items “would require less labor from your agency to produce,” which both speeds the response and undercuts an unduly-burdensome denial. The generator bakes both of these in.

Records Request Generator

Pick a technology, the records you want, and your state\u2019s law. The tool assembles a scoped, exemption-aware request you can copy, edit, and send. Everything runs in your browser \u2014 nothing is sent anywhere.

Copy-paste starting templates

If you’d rather work from static text, these two cover the most common cases. Fill the bracketed fields. (The generator above tailors these further by technology and state.)

Template A — ALPR / license plate readers (state public-records law)

To the Records Custodian, [AGENCY]:

Pursuant to [YOUR STATE PUBLIC RECORDS ACT + CITATION], I request copies of the
following records concerning your agency’s use of automated license plate reader
(ALPR) systems, including any provided by Flock Safety, Motorola/Vigilant, Genetec,
Leonardo/ELSAG, Rekor, or any other vendor:

1. All current contracts, quotes, purchase orders, and renewals with any ALPR vendor.
2. Any policy or SOP governing ALPR use, access, data retention, and auditing.
3. The number of ALPR cameras operated by or accessible to the agency, and the
   general areas they cover.
4. The retention period for captured plate data and the deletion schedule.
5. Any MOUs or data-sharing agreements with other agencies — local, state, or
   federal (including the sheriff, state police, ICE, and CBP) — and any
   participation in a statewide or nationwide lookup network.
6. Audit summaries and any records of misuse, policy violations, or discipline.

I am not requesting raw captured plate data, which may be confidential; I am
requesting the contracts, policies, retention schedules, sharing agreements, and
audit records above, which are generally public. If any portion is exempt, please
cite the specific exemption and produce all reasonably segregable non-exempt
portions. Please advise of any fees before incurring costs above $25; I am willing
to narrow this request to reduce your agency’s burden.

[Your name] / [Your contact email]

Template B — device-signature sensors (SignalTrace / EOC Plus)

To the Records Custodian, [AGENCY]:

Pursuant to [YOUR STATE PUBLIC RECORDS ACT + CITATION], I request records concerning
any electronic-device-signature or signals-intelligence sensor system attached to or
integrated with license plate readers — including Leonardo/ELSAG SignalTrace or
ELSAG EOC Plus, or any system that collects Bluetooth, Wi-Fi, RFID, or other device
identifiers from passing vehicles:

1. Any records indicating whether the agency operates, has purchased, is piloting, or
   has been solicited to purchase such a system.
2. All contracts, quotes, purchase orders, and vendor communications (including
   marketing materials and demonstrations) concerning device-signature collection.
3. Any policy governing collection, retention, and use of device identifiers.
4. The retention period and deletion schedule for device-signature data.
5. Any data-sharing agreements covering that data with local, state, or federal partners.
6. Any legal review, privacy impact assessment, or warrant-requirement determination
   made before acquiring or using device-signature collection.

If any portion is exempt, please cite the specific exemption and produce all
reasonably segregable non-exempt portions. Please advise of fees before incurring
costs above $25; I am willing to narrow to reduce burden.

[Your name] / [Your contact email]

After you send it — and what it yields for OSINT

Track your request: note the date, the statutory response deadline (it varies by state), and follow up in writing when it lapses. Free tools help — MuckRock files, tracks, and publishes requests, and building a public paper trail is itself a contribution: the next requester in your state starts from your result.

For the OSINT practitioner, the returned records are a primary-source goldmine. A contract reveals the exact product, firmware tier, and camera count. A data-sharing MOU maps the actual network topology — which agencies feed which database. An audit log (or its absence) tells you the real governance posture. Aggregated across a region, a batch of responses reconstructs a surveillance network from authoritative documents rather than inference — the same method behind our surveillance-mapping walkthrough, but sourced straight from the operator. For the citizen, the same documents are what you bring to a council meeting. Same records, two uses: intelligence and accountability.

Bottom line

You don’t need hardware, a legal team, or a confrontation to push back on surveillance tech — you need a well-aimed records request and the patience to follow it. Send it to the right custodian, ask for the contracts and policies rather than the raw data, request segregability, and offer to narrow. Do that, and you either get the documents that let a community make an informed choice, or you get a refusal that is itself a story. Either outcome advances the goal: making the people who deploy this technology account for it.

Sources & templates drawn from: Electronic Frontier Foundation ALPR FOIA project; ACLU of Southern California / California Public Records Act ALPR request templates; MuckRock (Pennsylvania, Pasadena, Redding, Rocklin ALPR requests); DeFlockILM North Carolina records repository (exemption guidance, N.C. Gen. Stat. § 20-183.32); 404 Media and Leonardo US materials (SignalTrace / EOC Plus). This article is general information, not legal advice; public-records statutes, exemptions, and deadlines vary by state — verify your state’s law, and consult a licensed attorney about any specific dispute.