

A surveillance vendor can truthfully say documented misuse is rare. A critic can truthfully say dozens of officers have been caught abusing access. Those statements are not mathematically incompatible.
The missing object is the denominator.
Sixty-nine is a count, not a rate.
The Washington Post's August investigation found at least 69 police officials who had been accused, charged, or convicted of misusing Flock or other automated license plate readers for unauthorized purposes. Reported cases included officers searching vehicles associated with spouses, former partners, acquaintances, and other people from their personal lives.
That is enough to establish that insider misuse is not hypothetical. It is not enough to say what fraction of all ALPR use is abusive.
To calculate an abuse rate, we would need comparable national counts for at least four things: total authenticated users, total searches, total users actually audited, and total misuse incidents discovered through a consistent process.
A log is not an audit.
Flock records searches and provides audit tools. But a permanent log only answers what could be reviewed. Oversight depends on whether an agency actually reviews it, how often, using what criteria, and what happens after a flag.
The Post identified suspicious search patterns using publicly available information and Flock audit logs. Its inquiries triggered investigations at departments that said they had not routinely audited use. That is a measurement problem as much as a governance problem.
If nobody looks, “no misuse found” can mean either no misuse occurred or no detection system was operating.
Outside discovery is a warning signal.
The Post reported that at least 15 known cases were initially identified by outsiders. That does not prove agencies systematically failed nationwide. It does show that some internal oversight systems missed behavior that victims, journalists, activists, or later investigators could detect.
The relevant performance measure is therefore not simply “how many officers were disciplined?” It is detection coverage: what fraction of users and searches receive meaningful review before outside events expose a problem?
Flock's new controls improve the measurement system.
Flock announced that Audit Assistance will become mandatory for law-enforcement customers, that abnormal activity can trigger proactive lockouts, and that case codes will become required for searches by the end of the year, with emergency exceptions flagged for review.
Those changes matter because they can turn oversight from passive logging into an active control loop. Whether they work depends on implementation: false positives, administrator response times, bypass rules, training, and whether agencies investigate alerts instead of clicking them away.
The public needs a better scoreboard.
A serious national abuse statistic would publish, by agency and over time: active users, search volume, automated flags, manual audits, confirmed policy violations, criminal referrals, administrative discipline, and appeals or reversals.
Until that exists, confident claims about “the abuse rate” are theater. We can count documented cases. We can measure oversight gaps. We cannot manufacture a percentage the evidence does not support.
The 69-official figure is a documented-case count from Washington Post reporting, not a national prevalence estimate. Cyberdelia will not infer an abuse percentage from incomplete detection coverage.