

Privacy controls are often described like legal boilerplate. Retention is different. It changes the physical capability of the information system.
If data no longer exists, it cannot be searched later.
Thirty days and seven days are different machines.
Flock announced in August that it is changing its recommended default ALPR retention period from 30 days to seven. Numerically, that cuts the ordinary historical window by more than three quarters.
Operationally, the effect is larger than the percentage sounds. A 30-day system can answer questions about movement weeks before an investigation begins. A seven-day system forgets most of that history automatically.
Deletion removes capability.
Access control asks who may search. Retention asks whether there is anything left to search.
That makes retention one of the strongest architectural privacy controls because it does not depend on every future user making a good decision. Proper deletion removes the option.
capture → short operational window → automatic deletion
Compare that with indefinite logging, where governance must remain perfect forever.
Evidence Mode creates a narrow exception path.
Flock says Evidence Mode will let investigators preserve specific ALPR records needed for an active investigation after the ordinary retention period. That is a sensible operational problem to solve: deletion should not destroy evidence already identified as relevant to a legitimate case.
The governance question is whether preservation stays specific. Who can invoke it? Must it be attached to a case? How long can preserved data remain? Is preservation itself audited? Can a broad query result be frozen wholesale?
An exception can preserve evidence without quietly rebuilding the original retention window, but only if its scope is controlled.
Default settings are policy multipliers.
Many agencies will not customize every configuration. A vendor default therefore propagates across customers and shapes real-world surveillance capacity at scale.
Moving the default from 30 days to seven can matter even where law would permit longer storage, because the baseline behavior of the product becomes more privacy-preserving unless a customer deliberately chooses otherwise.
Seven days does not solve the rest of the stack.
A short-retention system can still be abused during those seven days. It can still be shared widely. It can still produce bad alerts. It can still be queried without a warrant where law and policy allow. It can still generate AI-assisted leads.
Retention is one control among several. It is simply one of the rare controls that destroys surveillance capability automatically rather than trusting people not to use it.
The metric to watch is the exception rate.
After the new defaults roll out, the useful accountability number is not merely “seven days.” It is how many customers extend retention, how often Evidence Mode is used, how much data is preserved, for how long, and under what investigative predicate.
That is how we will know whether seven days becomes the real operating norm or just the number on the brochure.
The announced seven-day setting is a recommended default, not a universal statutory limit. Local law, order forms, customer configuration, and evidence-preservation rules can produce different retention periods.