What's Next News Summer 2026 Open Letter To Our Community About

Stanford cancelled Flock, but has installed new Automated License Plate Reader (ALPR) mass surveillance. What's next?

“As an institution of higher education, Stanford has a special obligation to protect privacy. Rights to privacy are intimately connected to academic freedom and freedom of speech.”

— Stanford faculty David Palumbo-Liu and Stephen Monismith

On Monday, August 3rd, 2026, after sustained pressure from the Safe Stanford coalition, including an open letter signed by over 1,100 community members, Stanford officially announced termination of its Flock contract. The announcement came almost two years after the Flock AI surveillance cameras began collecting data on the movements of everyone who entered and exited campus.

Dozens of other communities and universities have cancelled their contracts with Flock and reconsidered their use of Automated License Plate Reader (ALPR) systems, as part of a growing nationwide movement against ALPR surveillance.

We applaud Stanford’s decision to cancel the Flock contract. The university listened to community concerns by recognizing the real risks this data collection posed to our safety, privacy, and academic freedom.

However, Stanford has installed new ALPR cameras on campus from Genetec, a third-party vendor. ALPR cameras are also included in the Stanford Next proposal to Santa Clara County. If approved, this would cement their use on campus in coming years.

As a system of mass surveillance, Genetec is similar to Flock. It “automatically captures vehicle characteristics such as colour, type, make, and model” and “gathers vehicle-based evidence, including characteristics and behaviours” on every car that drives by the cameras. “With high-performing cameras and strong machine learning capabilities, vehicle-based evidence is collected by Cloudrunner day and night, rain or shine.”

While the Genetec system may have more controls than Flock, the continued collection of the movements of everyone who enters or exits campus is inherently risky, especially at this time in history. Many community members, especially activists, journalists, undocumented & international students, and other targeted or marginalized groups, are still at risk of danger from ongoing dragnet surveillance.

We call on Stanford to answer the following questions:

1. Scope of the system

  1. What is the need analysis for an ALPR system for Stanford? What is it intended to do?
  2. What is planned, and what has been implemented?
  3. What analytics will be run on ALPR data?
  4. What does the system include beyond ALPRs, and what will it include in the future? For example, will the system include, now or in the future, data from other forms of surveillance on campus (such as systems used for parking or other ongoing data collection about the movements of people or vehicles)?
  5. What will the data collected by the ALPR system outlined in the Stanford Next proposal to Santa Clara County be used for? Is this the Genetec system? Why are ALPRs, which capture and store detailed data on the movements of everyone who enters or exits campus, the solution for counting commute trips for the county?

2. Security and infrastructure

  1. Data access
    1. Who at Stanford has access to the data/server? What are the training protocols for these data users? Who oversees this access?
    2. Which security controls or standards will be required with this system to align with Stanford IT operations?
    3. Who at Genetec has access to the data/server? For example, we have seen evidence that Flock employees, including in the sales department, had access to Flock cameras and data.
  2. Data storage and management
    1. Who manages the database instance? Is it the vendor or is it the customer? Is the “server Stanford controls” a Stanford cloud tenant separate from Genetec's own Azure environment, or administrative access within Genetec's infrastructure?
    2. If it is a cloud infrastructure provider, how are cloud keys stored and kept safe? How are the cloud storage API keys rotated? What cadence of rotation? What happens to keys if they expire?
    3. How has Stanford ensured that Genetec's Azure environment fully deletes the files (including raw data) after the transferring process? Often, cloud providers retain data for a period in case of a request to undelete.
    4. What happens when Genetec’s private server is offline for maintenance for more than 1 hour? Is data lost, or is it in the cloud longer than intended?
  3. Audit protocol
    1. Who will be responsible for auditing the system's configuration and how often?
    2. What will the audit include?
    3. Will results be shared? With whom and how often?
  4. Networked access to data
    1. Is there any networked access inside or outside of Stanford of any data, at any time, including raw footage?
    2. Will Stanford use the Genetec “Clearance” network at any time?
  5. Machine learning training
    1. Does Genetec have access to any Stanford data at any time for purposes of training their models?
    2. Will AI or machine learning analytics be used by Stanford or by Genetec? If so, what is the data that will be used for training?

3. Governance

  1. Governance
    1. What policy is the new ALPR system governed by? Is it governed by Stanford Transportation’s ALPR policy?
    2. Who authored the policy (Stanford or Genetec)?
    3. How will the policy be made public?
    4. How will Stanford involve principles of faculty governance in planning and maintaining and overseeing campus surveillance? How will the Faculty Senate be involved?
  2. Retention period
    1. What is the retention period at Stanford for data collected by the Genetec system? KQED states the data retention period will be 30 days. Stanford Transportation's ALPR policy (jointly administered with the Department of Public Safety (DPS) states retention for 6 months, far longer than both industry norms (30 days), Flock’s current suggested policy (7 days), and New Hampshire's law that requires deletion within 3–5 minutes for non-hits.
  3. Contracting
    1. To what extent, if any, was the University Privacy Office involved in the contract negotiations with Genetec? Has the Privacy Office reviewed or approved the terms?
    2. Flock changed their Terms & Conditions during Stanford's contract for customers to grant the company an irrevocable, perpetual data license. Does the Genetec agreement contain a perpetual data license to use Customer Data for "product improvement" or AI model training? If yes, will Stanford reject these terms?

4. Safety, civil liberties, and agency compliance

  1. Federal government subpoenas and warrants
    1. The Genetec data will remain subject to subpoenas and warrants, including from the federal government and ICE. What is Stanford’s course of action when a subpoena request arrives, including any tied to immigration enforcement?
  2. Evidence of crime reduction
    1. Using outcomes, rather than anecdotal evidence (e.g. case closure before and after camera installation, not individual stories), what empirical evidence will be collected to verify that ALPRs reduce crime on campus? How will this information be tracked and by whom?
  3. Decision criteria
    1. How did Stanford weigh the significant potential harm created by the data collection for a substantial portion of our community in the decision to launch another ALPR system?
  4. Free expression and assembly
    1. How will Stanford ensure that any campus surveillance system will not infringe on rights to free expression and assembly by members of the community?

Demands

Since its founding, Stanford has committed itself to its motto: "Die Luft Der Frieheit Weht" (The Wind of Freedom Blows). To live up to that commitment to freedom, Stanford must:

  1. Publicly answer all questions above.
  2. Publish the ALPR policy for Genetec Cloudrunner, including retention periods, access controls, and data-sharing terms.
  3. Evaluate effectiveness of ALPRs not only for crime-solving, but also the holistic safety impact of the collection of this sensitive data on our community, alongside transparency on operational costs funded by student tuition.
  4. Publish the FY25–26 Flock report, despite the contract's cancellation, including any documents and/or logs of communication with immigration enforcement or external data-sharing requests.
  5. Implement robust measures for the security of any ALPR data both in terms of cybersecurity and DPS employee training and oversight, notifying breach/misuse to campus within a defined window (especially due to previous data security incidents).
  6. Establish these guardrails to keep our community safe:
    • Require valid judicial warrants for all data searches.
    • Refuse to participate in direct sharing with immigration authorities and indirect sharing in fusion centers.
    • Retain data at Stanford for no more than a few days.
    • Prohibit any campus digital surveillance system from integrating facial recognition software, biometric analysis software, and generative AI technology.
    • Implement contract and policy safeguards to ensure system transparency, protect civil liberties, and reduce cybersecurity risks, including a termination for convenience clause, independent auditability, and strong local controls on data access, sharing, and ownership.
    • Sign the contract with the vendor for a maximum of one year without auto-renewal.
    • Include meaningful remedies to ensure compliance, including $200k in liquidated damages per unauthorized disclosure.

Contact

Mailing list To join our mailing list, fill out this form.
Email To join the coalition as an organization, contact us at safestanford@gmail.com.