A vendor blinks, a market disciplines it
On August 13, 2026, Flock Safety — the dominant US vendor of automated license-plate reader (ALPR) networks — announced reforms after a wave of city and county governments cancelled or suspended contracts. The company cut its default data-retention window from 30 days to 7, let cities restrict officer access by offense type (so a murder investigation can query the database while an immigration lookup cannot), and added audit lockouts against officers filing suspicious searches. The Electronic Frontier Foundation called the changes "too little, too late," noting Flock could reverse any of them unilaterally and that the core problem — a system enabling location tracking of essentially anyone who drives — remains. EFF's baseline demand: police should need a warrant signed by a judge before searching historical plate data (EFF, Aug 13, 2026).
The steelman case for ALPR and similar systems is real and shouldn't be waved away: recovering stolen vehicles, locating missing persons, and building cases against people with existing criminal records are legitimate policing functions that plate and face data genuinely accelerate. Delhi Police told the Supreme Court in August 2026 that its own facial-recognition deployment during the July 20–26 Jantar Mantar protests flagged 2,873 matches against existing criminal databases — 92 people with more than ten cases each, 47 history-sheeters — and insisted the system does not profile ordinary protesters, only cross-checks against records that already exist (Brut India).
The part the US at least has that India doesn't
What's striking is not that Flock had to bend — it's what forced it to. Flock's customers are thousands of individual town and county governments, each with its own contract, budget line, and city council that can vote to cancel. That fragmented market is precisely the lever EFF and local activists pulled. India's equivalent — Delhi's "Safe City" project — has no comparable pressure valve. It is a nationally funded, centrally coordinated rollout under the Ministry of Home Affairs spanning eight metros (Delhi, Mumbai, Chennai, Kolkata, Hyderabad, Ahmedabad, Lucknow, Bengaluru), with Delhi's tranche fully Centre-funded rather than municipally contracted (Drishti IAS). Phase one alone deployed 1,622 automatic number-plate-recognition cameras and 370 facial-recognition units out of 3,500 cameras switched on from October 1, 2025 (Elets eGov). There is no city council anywhere in this chain that can vote to cancel it.
That would matter less if a statutory floor existed instead. It doesn't. The Digital Personal Data Protection Act, 2023, exempts government processing for "prevention, investigation and prosecution of offences" and state-security purposes from most data-principal rights and fiduciary obligations — including storage limitation, meaning government agencies are not required to delete personal data once its purpose is served. PRS Legislative Research flagged this at the bill stage as capable of enabling a "360-degree profile for surveillance" without the necessity and proportionality safeguards the Supreme Court itself has demanded (PRS Legislative Research). India also has no dedicated statute governing police use of ANPR or facial-recognition technology at all — deployments like Delhi's Ikshana surveillance vans currently run on no retention rule and no published privacy impact assessment.
The test case now sitting at the Supreme Court
That gap is exactly what CPI(M) Rajya Sabha MP AA Rahim is now asking the Supreme Court to close. His August 2026 petition — AA Rahim M.P. v. Union of India, diary no. 45049/2026 — argues Delhi Police's Jantar Mantar surveillance operated in "a complete legal vacuum," naming two private vendors whose data-processing agreements have never been disclosed, and invoking Justice K.S. Puttaswamy v. Union of India (2017), the nine-judge ruling that made privacy a fundamental right and required any state surveillance to satisfy legality, necessity, and proportionality (Indian Kanoon). Chief Justice Surya Kant's bench agreed on August 13 — coincidentally the same day as Flock's reforms — to hear the case, tagging it with other pending Jantar Mantar petitions (LiveLaw). No interim relief has been granted; the cameras keep running while the case proceeds.
What proportionate regulation actually looks like here
This publication doesn't think ALPR or facial recognition should be banned — recovering stolen cars and flagging history-sheeters at a 30,000-person protest are legitimate uses of the technology Delhi's affidavit describes. But Flock's episode shows that even a bad accountability mechanism — customers who can walk away — produces real concessions. India's centrally funded model has no such mechanism, and the DPDP Act's blanket law-enforcement carve-out removes the statutory one too. Parliament doesn't need EFF's warrant standard verbatim; it needs what Flock's own reforms gesture at — purpose-limited access, a hard retention ceiling, and an audit trail — written into a dedicated ANPR/FRT statute rather than left to police SOPs and vendor goodwill. Until then, the Puttaswamy test the AA Rahim case will apply is the only backstop India's plate and face-recognition networks currently have — and unlike Flock's US customers, Indian citizens can't just cancel the contract.